<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Filteting question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/url-filteting-question/m-p/248259#M70620</link>
    <description>&lt;P&gt;Tested this feature by downloading a specific pdf file from a non-SSL site.&lt;/P&gt;&lt;P&gt;For a category that includes this site i set - alert.&lt;BR /&gt;For Custom URL&amp;nbsp;"*/test.pdf" - block&lt;/P&gt;&lt;P&gt;When accessing a file by link or downloading, the category does not change, there is no lock. Alert in log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For interest added to the Custom URL site:&lt;BR /&gt;testsite.com&lt;BR /&gt;* .testsite.com&lt;BR /&gt;When i access the site, in the logs i see that its category has changed to Custom and access to the site has been blocked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thus, this solution does not work.&lt;/P&gt;</description>
    <pubDate>Thu, 31 Jan 2019 07:32:26 GMT</pubDate>
    <dc:creator>aaobuhov</dc:creator>
    <dc:date>2019-01-31T07:32:26Z</dc:date>
    <item>
      <title>URL Filteting question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filteting-question/m-p/248135#M70586</link>
      <description>&lt;P&gt;We received an alert about the behavior of the virus.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The malicious loader is downloaded from the URL of compromised legitimate sites, where it is disguised as an image.&lt;BR /&gt;The URL by which the malicious loader is hosted, all addresses end with the string abc.jpg.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The string in the URLs where the encryptor is hosted is:&lt;BR /&gt;hxxp://[anything]/abc.jpg&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I read that "File Blocking" does not block files by masks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to block the address by the mask "*/abc.jpg" by creating a Custom URL Category?&lt;/P&gt;&lt;P&gt;If yes, then this category is better to connect to Policies -&amp;gt; URL Category -&amp;gt; Action: Deny&lt;BR /&gt;Either in Profiles -&amp;gt; Url Filtering&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ready to discuss other options.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 10:56:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filteting-question/m-p/248135#M70586</guid>
      <dc:creator>aaobuhov</dc:creator>
      <dc:date>2019-01-30T10:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filteting question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filteting-question/m-p/248159#M70592</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97840"&gt;@aaobuhov&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;We received an alert about the behavior of the virus.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The malicious loader is downloaded from the URL of compromised legitimate sites, where it is disguised as an image.&lt;BR /&gt;The URL by which the malicious loader is hosted, all addresses end with the string abc.jpg.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The string in the URLs where the encryptor is hosted is:&lt;BR /&gt;hxxp://[anything]/abc.jpg&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I read that "File Blocking" does not block files by masks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to block the address by the mask "*/abc.jpg" by creating a Custom URL Category?&lt;/P&gt;&lt;P&gt;If yes, then this category is better to connect to Policies -&amp;gt; URL Category -&amp;gt; Action: Deny&lt;BR /&gt;Either in Profiles -&amp;gt; Url Filtering&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ready to discuss other options.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not 100% sure on what you're saying...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you saying a legit site his hosting a malicious file which someone is attempting to obfuscate by labelling&amp;nbsp;it as a ".jpg?"&amp;nbsp; Users click on what they think is an image, when in-fact it's some other malicious&amp;nbsp;file?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not certain, but I thought the file-blocking policy actually looks at the file type and not merely the file extension.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That said these two scenarios should work:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The site isn't an SSL site it should see the URI path and you should be able to add the URL to custom URL category which you can then override&amp;nbsp;and block&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OR&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The site is SSL and you are decrypting the original URL category...The firewall will be able to see the full URI which you can place in a custom URL category, override&amp;nbsp;and block the specific URI.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 13:08:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filteting-question/m-p/248159#M70592</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2019-01-30T13:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filteting question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filteting-question/m-p/248162#M70594</link>
      <description>&lt;P&gt;Thanks for reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as i know,&amp;nbsp;&lt;SPAN&gt;sites are not an SSL, but it is about hundreds of URLs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Common&amp;nbsp;- file name only.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;*/abc.jpg - is this part will be enough for URL?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;it should see the URI path and you should be able to add the URL to custom URL category which you can then override&amp;nbsp;and block.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You tell about "Profiles -&amp;gt; Url Filtering"?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 13:37:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filteting-question/m-p/248162#M70594</guid>
      <dc:creator>aaobuhov</dc:creator>
      <dc:date>2019-01-30T13:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filteting question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filteting-question/m-p/248164#M70595</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97840"&gt;@aaobuhov&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Thanks for reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as i know,&amp;nbsp;&lt;SPAN&gt;sites are not an SSL, but it is about hundreds of URLs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Common&amp;nbsp;- file name only.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;*/abc.jpg - is this part will be enough for URL?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* = anything preceeding what comes next&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So if the filename is always /abc.jpg and you're wanting to catch randomness ahead of /abc.jpg then yes */abc.jpg would be correct.&amp;nbsp; I would be warry of thinking this won't potentially catch other legit things you're wanting to allow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97840"&gt;@aaobuhov&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Thanks for reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;gt;it should see the URI path and you should be able to add the URL to custom URL category which you can then override&amp;nbsp;and block.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You tell about "Profiles -&amp;gt; Url Filtering"?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;Yes security profiles --&amp;gt; URL Filtering, but you'll want to also create a "custom object" --&amp;gt; "URL Category" object set that custom group to a "Deny" in your URL filtering profile.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 13:57:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filteting-question/m-p/248164#M70595</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2019-01-30T13:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filteting question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filteting-question/m-p/248259#M70620</link>
      <description>&lt;P&gt;Tested this feature by downloading a specific pdf file from a non-SSL site.&lt;/P&gt;&lt;P&gt;For a category that includes this site i set - alert.&lt;BR /&gt;For Custom URL&amp;nbsp;"*/test.pdf" - block&lt;/P&gt;&lt;P&gt;When accessing a file by link or downloading, the category does not change, there is no lock. Alert in log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For interest added to the Custom URL site:&lt;BR /&gt;testsite.com&lt;BR /&gt;* .testsite.com&lt;BR /&gt;When i access the site, in the logs i see that its category has changed to Custom and access to the site has been blocked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thus, this solution does not work.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jan 2019 07:32:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filteting-question/m-p/248259#M70620</guid>
      <dc:creator>aaobuhov</dc:creator>
      <dc:date>2019-01-31T07:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filteting question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filteting-question/m-p/248265#M70621</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;You could also try adding a custom application.&lt;BR /&gt;Objects -&amp;gt; Applications -&amp;gt; Add&lt;BR /&gt;In the Configuration screen, make sure to use web-browsing as Parent App and check the Capable of File Transfer&lt;BR /&gt;In the Advanced screen, add 'tcp/80' as default port and check 'File Types' &amp;amp; 'Viruses'&lt;BR /&gt;In the Signatures screen, add a signature and add one Condition:&lt;BR /&gt;Operator: Pattern Match&lt;BR /&gt;Context: http-req-uri-path&lt;BR /&gt;Pattern: abc\.jpg&lt;/P&gt;&lt;P&gt;You might need to change the scope to session and re-test if it does not work at first.&lt;BR /&gt;The premise here is to create a custom application based on web-browsing that will match when the URI (everything after the first slash for any URL/site) regex-matches abc.jpg. After you are successfuly matching (you'll see this application name in the traffic log) &lt;U&gt;&lt;STRONG&gt;then just block this new custom application in policy&lt;/STRONG&gt;&lt;/U&gt;.&lt;/P&gt;&lt;P&gt;As stated above, this could match other traffic so be aware of this.&lt;/P&gt;&lt;P&gt;If you take a packet-capture you should be able to see more http-headers that might help you narrowing down false positives.&lt;/P&gt;&lt;P&gt;Lastly - rolling back in case of problems is to just disable or delete the new custom application you created.&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;BR /&gt;Shai&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jan 2019 08:43:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filteting-question/m-p/248265#M70621</guid>
      <dc:creator>ShaiW</dc:creator>
      <dc:date>2019-01-31T08:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filteting question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filteting-question/m-p/248270#M70623</link>
      <description>&lt;P&gt;Thanks, ShaiW. Good idea.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Creating a separate application for each file mask seems to me&amp;nbsp;not correct.&lt;BR /&gt;Is it possible to make same in Custom Objects -&amp;gt; Vulnerability for this scenario?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jan 2019 09:19:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filteting-question/m-p/248270#M70623</guid>
      <dc:creator>aaobuhov</dc:creator>
      <dc:date>2019-01-31T09:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filteting question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/url-filteting-question/m-p/248389#M70644</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97840"&gt;@aaobuhov&lt;/a&gt;,&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97840"&gt;@aaobuhov&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Thanks, ShaiW. Good idea.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Creating a separate application for each file mask seems to me&amp;nbsp;not correct.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;So the set extension isn't staying the same then, or what do you mean by file mask?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue with trying to help you build a vulnerability signature with a file that has a renamed extension like this is we can't really do it for you&amp;nbsp;without samples to work with. You need to take a packet capture to see if you actually can build a custom vulnerability signature to match what you are looking for;&amp;nbsp;&lt;EM&gt;can&lt;/EM&gt; a vulnerability signature be built to detect this, absolutely, but we would need a few examples to actually work with.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Feb 2019 03:14:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/url-filteting-question/m-p/248389#M70644</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-02-01T03:14:06Z</dc:date>
    </item>
  </channel>
</rss>

