<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: best way to block new zip domain in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183065#M33590</link>
    <description>&lt;P&gt;On R80.40 setting up a custom application/site with "*.zip" non-regex expression with HTTPS inspection enabled hits on every request that has .zip in it (i.e.: test.zip {good}, test.com/test.zip {bad}, test.com/test?q=test.zip {bad}).&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jun 2023 14:26:58 GMT</pubDate>
    <dc:creator>PSushko</dc:creator>
    <dc:date>2023-06-02T14:26:58Z</dc:date>
    <item>
      <title>best way to block new zip domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183017#M33571</link>
      <description>&lt;P&gt;hi guys,&lt;BR /&gt;I have read about a new phishing technique called "file archiver in the browser" can be leveraged to "emulate" a file archiver software in a web browser when a victim visits a .ZIP domain, so I would like block any sites of the .zip domain on my R81.10 firewall.&lt;/P&gt;&lt;P&gt;What is the best way to do that without taking a lot of resources of the firewall?&lt;/P&gt;&lt;P&gt;I was thinking using "custom application site" without regex *.zip&lt;/P&gt;&lt;P&gt;On my firewall I have all capabilities enabled (url filtering, and application control, https inspection).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;thanks a lot&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 07:06:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183017#M33571</guid>
      <dc:creator>emiliano_mastro</dc:creator>
      <dc:date>2023-06-02T07:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: best way to block new zip domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183057#M33584</link>
      <description>&lt;P&gt;Personally, I was hoping I could do it with a simple *.zip in a custom application, but that ended up matching regular zip file downloads, and even googling of the string ".zip". I then tried with a much more complex regex: /^(?:(?!-)[A-Za-z0-9-]{1,63}(?&amp;lt;!-)\.)+(zip|mov)$/ (without the /, simply used those to delimit the regex in this comment).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp_regex.png" style="width: 477px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21245iD4130C742954D0CA/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp_regex.png" alt="cp_regex.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But policy fails to push with this regex. It might be too complex for CheckPoint. I have a ticket open, I'll keep you updated on the results.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 13:23:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183057#M33584</guid>
      <dc:creator>PSushko</dc:creator>
      <dc:date>2023-06-02T13:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: best way to block new zip domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183062#M33589</link>
      <description>&lt;P&gt;Thats exactly how I blocked it in my R81.20 lab with https inspection enabled and once tested, it was indeed blocked fine. Not sure if there is more 'official" way of doing it though : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 13:54:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183062#M33589</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-06-02T13:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: best way to block new zip domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183065#M33590</link>
      <description>&lt;P&gt;On R80.40 setting up a custom application/site with "*.zip" non-regex expression with HTTPS inspection enabled hits on every request that has .zip in it (i.e.: test.zip {good}, test.com/test.zip {bad}, test.com/test?q=test.zip {bad}).&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 14:26:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183065#M33590</guid>
      <dc:creator>PSushko</dc:creator>
      <dc:date>2023-06-02T14:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: best way to block new zip domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183106#M33611</link>
      <description>&lt;P&gt;I believe ya, as I only tested on R81.20, so its most likely different.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 18:47:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183106#M33611</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-06-02T18:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: best way to block new zip domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183115#M33617</link>
      <description>&lt;P&gt;I recently explored the Custom Application/Site expression matching pretty extensively and arrived at &lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Custom-Application-Site-Findings/m-p/179619#M32884" target="_self"&gt;this set of expressions&lt;/A&gt;. Later in the thread (currently the bottom-most post), I also described my findings after enabling HTTPS Inspection.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 20:39:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183115#M33617</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-06-02T20:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: best way to block new zip domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183189#M33642</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have just tried,&amp;nbsp; on R81.10,&amp;nbsp; an Application/Site rule&amp;nbsp; *.zip (&lt;STRONG&gt;no regex&lt;/STRONG&gt;), but unfortunately it doesn't work well because it blocks even zip files&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 09:54:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183189#M33642</guid>
      <dc:creator>emiliano_mastro</dc:creator>
      <dc:date>2023-06-05T09:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: best way to block new zip domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183198#M33649</link>
      <description>&lt;P&gt;I will try later today with R81.10, but logically, unless you have content awareness blade enabled to block.zip extension, app control/urlf should not block it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 11:03:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183198#M33649</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-06-05T11:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: best way to block new zip domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183212#M33651</link>
      <description>&lt;P&gt;Put a slash after it, as I described in &lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Custom-Application-Site-Findings/m-p/179751/highlight/true#M32898" target="_self"&gt;the most recent post in the thread I linked&lt;/A&gt;.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;*.zip/&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 05 Jun 2023 13:39:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183212#M33651</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-06-05T13:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: best way to block new zip domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183218#M33653</link>
      <description>&lt;P&gt;This works for me!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 14:57:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183218#M33653</guid>
      <dc:creator>PSushko</dc:creator>
      <dc:date>2023-06-05T14:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: best way to block new zip domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183219#M33654</link>
      <description>&lt;P&gt;I tested it exactly way you described and was fine, even in R81.10. But. as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27871"&gt;@Bob_Zimmerman&lt;/a&gt;&amp;nbsp;advised, if it works with /, then use that.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 15:10:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183219#M33654</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-06-05T15:10:05Z</dc:date>
    </item>
    <item>
      <title>Re: best way to block new zip domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183226#M33655</link>
      <description>&lt;P&gt;Yessss, adding the slash (*.zip/)&amp;nbsp; it works well !!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks a lot&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 15:33:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183226#M33655</guid>
      <dc:creator>emiliano_mastro</dc:creator>
      <dc:date>2023-06-05T15:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: best way to block new zip domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183227#M33656</link>
      <description>&lt;P&gt;I found the following regex in another topic, and worked for me:&lt;/P&gt;&lt;P&gt;Just replace TLD with a domain you want to match.&lt;/P&gt;&lt;P&gt;^[^:\/]+:\/?\/?[^\/]+\.TLD\/&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Regex-for-TLD-Blocks/td-p/24704" target="_blank"&gt;Regex for TLD Blocks - Check Point CheckMates&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 15:35:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183227#M33656</guid>
      <dc:creator>Yuber_Sierra_av</dc:creator>
      <dc:date>2023-06-05T15:35:10Z</dc:date>
    </item>
    <item>
      <title>Re: best way to block new zip domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183237#M33660</link>
      <description>&lt;P&gt;That's a lot messier than it needs to be. Almost none of the backslashes are needed. It also matches exactly one subdomain. &lt;A href="http://www.somesite.tld" target="_blank"&gt;www.somesite.tld&lt;/A&gt;&amp;nbsp;would not be matched. Here's a better version, which is basically what I wrote in the linked post:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;^[^:]+?://([^/]+?\.)+TLD/&lt;/LI-CODE&gt;
&lt;P&gt;It matches the scheme non-greedily, which will be faster in almost all cases. It removes the optionality for the slashes in the :// separator between the scheme and the domain, since they are always present in the input space. Finally, it requires one subdomain but matches any number.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 16:08:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/best-way-to-block-new-zip-domain/m-p/183237#M33660</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-06-05T16:08:29Z</dc:date>
    </item>
  </channel>
</rss>

