<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MTA malicious sites inside the | Mail Body | Mail Subject | Attachment [TE100x] in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-malicious-sites-inside-the-Mail-Body-Mail-Subject-Attachment/m-p/50400#M13510</link>
    <description>&lt;P&gt;This is an interesting test - but except the used appliance &lt;SPAN class="lia-message-read"&gt;TE100x, we do neithr know CP Version, TE engine version nor Jumbo take installed !&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Apr 2019 08:48:59 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2019-04-10T08:48:59Z</dc:date>
    <item>
      <title>MTA malicious sites inside the | Mail Body | Mail Subject | Attachment [TE100x]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-malicious-sites-inside-the-Mail-Body-Mail-Subject-Attachment/m-p/50392#M13509</link>
      <description>&lt;P&gt;&lt;STRONG&gt;OS :&lt;/STRONG&gt; R80.20 both Gateway and Management Server and also TE.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TE Engine Version :&lt;/STRONG&gt; 58.990000298&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;HotFix :&lt;/STRONG&gt; R80.20 Jumbo Hotfix Take_33&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;MTA :&lt;/STRONG&gt;&amp;nbsp;R80_20_mta Take 27&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;BLADE:&lt;/STRONG&gt; Threat Emulation | Threat Extraction | Antivirus | AntiBot&amp;nbsp; | IPS&amp;nbsp;&lt;/P&gt;&lt;P&gt;We configure Gateway as a MTA.&lt;/P&gt;&lt;P&gt;We using both Threat Emulation and Threat Extraction only for SMTP traffic.&lt;/P&gt;&lt;P&gt;I did some testing and find below results.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#FF00FF"&gt;Scenario1 :&lt;/FONT&gt;&lt;/STRONG&gt; When we put malicious URL on mail body.&lt;/P&gt;&lt;P&gt;Results: Malicious URL was totally removed.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF00FF"&gt;&lt;STRONG&gt;Scenario2 :&lt;/STRONG&gt;&lt;/FONT&gt; When we put malicious URL on Mail Subject.&lt;/P&gt;&lt;P&gt;Results : Malicious URL was modified but not totally removed.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF00FF"&gt;&lt;STRONG&gt;Scenario3 :&lt;/STRONG&gt;&lt;/FONT&gt; When we put malicious URL on Mail Subject and also in Mail Body.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Results : Malicious URL was modified on Subject but not in the mail body , still the malicious URL in mail body showing as is it.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF00FF"&gt;&lt;STRONG&gt;Scenario4 :&lt;/STRONG&gt;&lt;/FONT&gt; For example I put genuine URL on Mail subject like "&lt;A href="http://www.google.com" target="_blank" rel="noopener"&gt;www.google.com&lt;/A&gt;" and put malicious URL in Mail body.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF00FF"&gt;&lt;STRONG&gt;Results:&lt;/STRONG&gt;&lt;/FONT&gt; Malicious URL was removed from Mail Body and no changes on Mail Subject.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT color="#FF00FF"&gt;&lt;STRONG&gt;QUERY&lt;/STRONG&gt; &lt;/FONT&gt;: If I put the same malicious URL in a attachment then :&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Is this malicious URL is totally we able to removed in attachment ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is this only remove the hyper link in attachment ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is this possible to modified the malicious URL in attachment ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#FF00FF"&gt;Also Scenario5:&lt;/FONT&gt; If I send a malicious URL with out "https or http" then URL is not able to detect.&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;So is URL reputation is only check if URL is in started from http or https&amp;nbsp; only.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 09:04:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-malicious-sites-inside-the-Mail-Body-Mail-Subject-Attachment/m-p/50392#M13509</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2019-04-10T09:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: MTA malicious sites inside the | Mail Body | Mail Subject | Attachment [TE100x]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-malicious-sites-inside-the-Mail-Body-Mail-Subject-Attachment/m-p/50400#M13510</link>
      <description>&lt;P&gt;This is an interesting test - but except the used appliance &lt;SPAN class="lia-message-read"&gt;TE100x, we do neithr know CP Version, TE engine version nor Jumbo take installed !&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 08:48:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-malicious-sites-inside-the-Mail-Body-Mail-Subject-Attachment/m-p/50400#M13510</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-04-10T08:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: MTA malicious sites inside the | Mail Body | Mail Subject | Attachment [TE100x]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-malicious-sites-inside-the-Mail-Body-Mail-Subject-Attachment/m-p/50404#M13511</link>
      <description>Updated&lt;BR /&gt;&lt;BR /&gt;We also plane to upgrade the MTA , HotFix and also TE Engine and check the behavior.&lt;BR /&gt;&lt;BR /&gt;@Chinmaya</description>
      <pubDate>Wed, 10 Apr 2019 09:06:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-malicious-sites-inside-the-Mail-Body-Mail-Subject-Attachment/m-p/50404#M13511</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2019-04-10T09:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: MTA malicious sites inside the | Mail Body | Mail Subject | Attachment [TE100x]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-malicious-sites-inside-the-Mail-Body-Mail-Subject-Attachment/m-p/50408#M13512</link>
      <description>&lt;P&gt;The TE engine itself is two steps from current - your version is from 16-Jan-19,&lt;/P&gt;
&lt;P&gt;current&amp;nbsp;Engine:58.990000617 from 31-Mar-19.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jumbo HotFix : R80.20 Jumbo Hotfix Take_33 is from 08 January 2019, GA from 04 February 2019,&lt;/P&gt;
&lt;P&gt;current General Availability&amp;nbsp;Take 47 is from 24 February 2019, GA from&amp;nbsp;25 Mar 2019, Ongoing Take 73 (08 Apr 2019) is also available (but not yet supported by the MTA update package &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MTA :&amp;nbsp;R80_20_mta Take 27,&lt;/P&gt;
&lt;P&gt;current version is R80_20_mta Take 31 from 4.4.19&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 10:01:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-malicious-sites-inside-the-Mail-Body-Mail-Subject-Attachment/m-p/50408#M13512</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-04-10T10:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: MTA malicious sites inside the | Mail Body | Mail Subject | Attachment [TE100x]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-malicious-sites-inside-the-Mail-Body-Mail-Subject-Attachment/m-p/50409#M13513</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;Yes I understand&amp;nbsp; and I will update to latest version and check But have any body face this behavior yet ?&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 10:08:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-malicious-sites-inside-the-Mail-Body-Mail-Subject-Attachment/m-p/50409#M13513</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2019-04-10T10:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: MTA malicious sites inside the | Mail Body | Mail Subject | Attachment [TE100x]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-malicious-sites-inside-the-Mail-Body-Mail-Subject-Attachment/m-p/57303#M13514</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;Anyone help me to clarify the concept.&lt;/P&gt;&lt;P&gt;I need a clear idea about how exactly MTA work with the malicious link when I send via Mail Body, Mail Subject and Attachment.&lt;/P&gt;&lt;P&gt;We need to give a clear idea to our customer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in Advanced.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Chinmaya&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 05:54:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-malicious-sites-inside-the-Mail-Body-Mail-Subject-Attachment/m-p/57303#M13514</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2019-07-03T05:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: MTA malicious sites inside the | Mail Body | Mail Subject | Attachment [TE100x]</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-malicious-sites-inside-the-Mail-Body-Mail-Subject-Attachment/m-p/57325#M13515</link>
      <description>&lt;P&gt;I would suggest to open a SR# with CP TAC to get answers on this !&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 08:31:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MTA-malicious-sites-inside-the-Mail-Body-Mail-Subject-Attachment/m-p/57325#M13515</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-07-03T08:31:34Z</dc:date>
    </item>
  </channel>
</rss>

