<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using custom URL categories in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/using-custom-url-categories/m-p/252553#M71774</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/104413"&gt;@JackField&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;You would be better off creating a custom threat signature for something like this instead of a URL category.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Mar 2019 18:25:31 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2019-03-06T18:25:31Z</dc:date>
    <item>
      <title>Using custom URL categories</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-custom-url-categories/m-p/252505#M71767</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're trying to stop users from accessing webpages featuring 'momo' content.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We've set up the below custom URL category and it only blocks Google searches for momo while in incognito mode, and still allows Google image and Youtube results.&amp;nbsp; Is there anything wrong with this, we may have gone OTT trying to get this to work:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="URL category.png" style="width: 567px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18987i274D3EECBC5069AB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="URL category.png" alt="URL category.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using asterisks gives us errors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;J&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2019 14:21:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-custom-url-categories/m-p/252505#M71767</guid>
      <dc:creator>JackField</dc:creator>
      <dc:date>2019-03-06T14:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: Using custom URL categories</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-custom-url-categories/m-p/252553#M71774</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/104413"&gt;@JackField&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;You would be better off creating a custom threat signature for something like this instead of a URL category.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2019 18:25:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-custom-url-categories/m-p/252553#M71774</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-03-06T18:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: Using custom URL categories</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-custom-url-categories/m-p/252658#M71793</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;,&amp;nbsp;url filtering will limit your scope while a custom threat will be able to inspect payload etc&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2019 12:37:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-custom-url-categories/m-p/252658#M71793</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2019-03-07T12:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: Using custom URL categories</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-custom-url-categories/m-p/253303#M71947</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the help.&amp;nbsp; I've been looking into this and it certainly seems the right path.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm running into a brick wall at the moment though.&amp;nbsp; My Regex's only work with limited effect, and once a search for the malicious term 'momo' has sucessfully established, my vulnerability protections no longer work.&amp;nbsp; Could you please advise, I've listed them below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A big part of the problem is that regex's have to be 7 bytes or larger without wildcard objects; so momo on it's own won't work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interestingly, one of my Regex's -&amp;nbsp;momohoax|momo|momodanger|momowhatsapp|momochallenge|momo.|.momo|.momo. - context = http-req-message-body - will block me from working on the custom vulnerability object after it's been commited.&amp;nbsp; This is a good thing, since it shows the protection is working on websites holding 'momo' content, but it is only working on the firewall config.&amp;nbsp; I have set up the security profiles and policies correctly, and decryption is enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the regex's that have only limited scope:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Context: http-req-params - Value:&amp;nbsp;search\?q=(.*momo\+.*)&lt;/P&gt;&lt;P&gt;Context: http-req-params - Value:&amp;nbsp;search\?q=(.*.momo.*)&lt;/P&gt;&lt;P&gt;Context: http-req-params - Value:&amp;nbsp;search\?q=(.*.momo*.*)\&amp;amp;source=.&lt;/P&gt;&lt;P&gt;Context: http-req-params - Value:&amp;nbsp;.*(q=momo&amp;amp;rlz=).*&lt;/P&gt;&lt;P&gt;Context: http-req-params - Value:&amp;nbsp;search_query=(.*.momo.*).*&lt;/P&gt;&lt;P&gt;Context: http-req-message-body Value:&amp;nbsp;momohoax|momo|momodanger|momowhatsapp|momochallenge|momo.|.momo|.momo.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know it's possible to create a condition that will block any webpage with momo on it, I'm just stumped as to how!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;J&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 10:11:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-custom-url-categories/m-p/253303#M71947</guid>
      <dc:creator>JackField</dc:creator>
      <dc:date>2019-03-12T10:11:36Z</dc:date>
    </item>
  </channel>
</rss>

