<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enduser still can download Malware from Public Github although implement Https inspection and IP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enduser-still-can-download-Malware-from-Public-Github-although/m-p/219980#M42083</link>
    <description>&lt;P&gt;Is Anti-Virus enabled?&lt;BR /&gt;If not, it needs to be.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jul 2024 17:51:56 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-07-08T17:51:56Z</dc:date>
    <item>
      <title>Enduser still can download Malware from Public Github although implement Https inspection and IPS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enduser-still-can-download-Malware-from-Public-Github-although/m-p/219362#M41925</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;I have a problem with IPS and HTTPS Inspection on CheckPoint Firewall.&lt;/P&gt;&lt;P&gt;I implemented HTTPS Inspection and IPS for Internal traffic and everything seems to work fine (HTTPS traffic being inspected and IPS, Antivirus detect and block access to malicious files).&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 557px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26568i371DD18A6D07A0FC/image-dimensions/557x313?v=v2" width="557" height="313" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;But when I tried to use git clone to download a malware test file from git hub, nothing happened and I still can successfully download this file.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;➜ ~ git clone&amp;nbsp;&lt;A href="https://github.com/fire1ce/eicar-standard-antivirus-test-files.git" target="_self"&gt;https://github.com/fire1ce/eicar-standard-antivirus-test-files.git&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cloning into 'eicar-standard-antivirus-test-files'...&lt;BR /&gt;remote: Enumerating objects: 42, done.&lt;BR /&gt;remote: Counting objects: 100% (13/13), done.&lt;BR /&gt;remote: Compressing objects: 100% (10/10), done.&lt;BR /&gt;remote: Total 42 (delta 4), reused 5 (delta 1), pack-reused 29&lt;BR /&gt;Receiving objects: 100% (42/42), 177.01 KiB | 280.00 KiB/s, done.&lt;BR /&gt;Resolving deltas: 100% (18/18), done.&lt;/P&gt;&lt;P&gt;➜ ~ ls | egrep eicar&lt;BR /&gt;eicar-standard-antivirus-test-files&lt;/P&gt;&lt;P&gt;HTTPS traffic is still inspected by the Firewall, but IPS and antivirus do not work. I tried downloading this file/folder directly from my browser but everything worked fine.&lt;/P&gt;&lt;P&gt;Does anyone have the same problem as me? Does anyone have any advice or suggestions on where I've misconfigured?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2024 08:01:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enduser-still-can-download-Malware-from-Public-Github-although/m-p/219362#M41925</guid>
      <dc:creator>CheckPoint_IT</dc:creator>
      <dc:date>2024-07-02T08:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: Enduser still can download Malware from Public Github although implement Https inspection and IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enduser-still-can-download-Malware-from-Public-Github-although/m-p/219546#M41972</link>
      <description>&lt;P&gt;For testing anything with EICAR, make sure you do the following on the relevant gateways:&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;fw ctl set int g_ci_av_eicar_handling_mode 2&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;See also:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk109113" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk109113&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2024 12:37:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enduser-still-can-download-Malware-from-Public-Github-although/m-p/219546#M41972</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-03T12:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: Enduser still can download Malware from Public Github although implement Https inspection and IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enduser-still-can-download-Malware-from-Public-Github-although/m-p/219676#M42004</link>
      <description>&lt;P&gt;Thank&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have changed&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;int g_ci_av_eicar_handling_mode&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;as you mentioned above.&amp;nbsp; But, I still can download EICAR by git clone command.&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Cloning into 'eicar-standard-antivirus-test-files'...&lt;/P&gt;&lt;P&gt;remote: Enumerating objects: 42, done.&lt;BR /&gt;remote: Counting objects: 100% (13/13), done.&lt;BR /&gt;remote: Compressing objects: 100% (10/10), done.&lt;BR /&gt;Receiving objects: 14% (6/42)&lt;/P&gt;&lt;P&gt;Receiving objects: 26% (11/42)&lt;BR /&gt;Receiving objects: 38% (16/42)&lt;BR /&gt;Receiving objects: 40% (17/42), 68.00 KiB | 104.00 KiB/s&lt;BR /&gt;Receiving objects: 47% (20/42), 68.00 KiB | 104.00 KiB/s&lt;BR /&gt;remote: Total 42 (delta 4), reused 5 (delta 1), pack-reused 29&lt;BR /&gt;Receiving objects: 100% (42/42), 177.01 KiB | 175.00 KiB/s, done.&lt;BR /&gt;Resolving deltas: 38% (7/18)&lt;BR /&gt;Resolving deltas: 100% (18/18), done.&lt;/P&gt;&lt;P&gt;The connection is still inspected by HTTPS Inspection but IPS and antivirus do nothing.&lt;/P&gt;&lt;P&gt;Do you have any other suggestions? Am I configuring something wrong or is the git clone running in some other way that Checkpoint cannot inspect?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 07:46:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enduser-still-can-download-Malware-from-Public-Github-although/m-p/219676#M42004</guid>
      <dc:creator>CheckPoint_IT</dc:creator>
      <dc:date>2024-07-04T07:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Enduser still can download Malware from Public Github although implement Https inspection and IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enduser-still-can-download-Malware-from-Public-Github-although/m-p/219980#M42083</link>
      <description>&lt;P&gt;Is Anti-Virus enabled?&lt;BR /&gt;If not, it needs to be.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 17:51:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enduser-still-can-download-Malware-from-Public-Github-although/m-p/219980#M42083</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-08T17:51:56Z</dc:date>
    </item>
  </channel>
</rss>

