Custom App to allow Office 07/10 (docx/xlsx/etc) while blocking zip

Reply
Highlighted
L1 Bithead

Custom App to allow Office 07/10 (docx/xlsx/etc) while blocking zip

Our current file blocking policy blocks zip files, however, users are getting blocked from downloading compressed Office documents.  Office 2007 and 2010 save files in the docx, pptx, xlsx type extensions.  They are technically zip files, since you can change the extension to .zip and it will open in a zip program.

The thought was to create a custom signature to allow these files, since the following seems to be persistent.

The file starts with: 50 4B 03 04 14 00 06 00 08 00 00 00 21 00

At offset 1E, it contains: 5B 43 6F 6E 74 65 6E 74 5F 54 79 70 65 73 5D 2E 78 6D 6C  (this is the description for the file name [Content_Types].xml, which appears in these types of files)

Is there a way to make this work?

Thanks,

Carlo


Accepted Solutions
Highlighted
L6 Presenter

I guess so, take a look at rkim's first reply in https://live.paloaltonetworks.com/thread/2898?tstart=0 for guidelines on how to submit app requests.

View solution in original post


All Replies
Highlighted
L6 Presenter

I guess so, take a look at rkim's first reply in https://live.paloaltonetworks.com/thread/2898?tstart=0 for guidelines on how to submit app requests.

View solution in original post

Highlighted
L1 Bithead

How do I create a custom application or data filtering profile for this?

Highlighted
L1 Bithead

If I could do a pattern match in the context of file-ZIP-body, that would help, but that doesn't seem to exist.

Highlighted
L4 Transporter

We have the same problem. I'm looking for ...

Do you know any solution?

:smileyconfused:

Regards,

Highlighted
L4 Transporter

hi,

feature request already open: FR ID:1829

please contact your SE to vote for it! I already did and we need more votes :smileywink:


Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!