<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to prevent business premises from RedBoot ransomware attack? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-prevent-business-premises-from-RedBoot-ransomware-attack/m-p/7537#M59314</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Arun there isn't a signature to prevent that infection&amp;nbsp; for now on any of those blades, the next step should be to incorporate the threat emulation technology on the gateway or in the endpoint with Sandblast Agent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are recommending our customer to have their computes up to date, to configure the shadow copy on their machines to have several copies of their information or at least have a procedure to have a backups once a day, also to be more stricted on the URL or categories that the users can access, for example block uncategorized sites or block high risk sites, also on the antivirus block&amp;nbsp;unusual file extention using the&amp;nbsp;Files Types feature to block some files.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Oct 2017 00:30:38 GMT</pubDate>
    <dc:creator>Pablo_Barriga</dc:creator>
    <dc:date>2017-10-16T00:30:38Z</dc:date>
    <item>
      <title>How to prevent business premises from RedBoot ransomware attack?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-prevent-business-premises-from-RedBoot-ransomware-attack/m-p/7535#M59312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone have any idea about&amp;nbsp;&lt;A href="http://securityaffairs.co/wordpress/63381/malware/redboot-ransomware.html" style="color: #660099; text-decoration: none;"&gt;RedBoot ransomware&lt;/A&gt;&amp;nbsp;and how to prevent it by using IPS/Anti-bot/Anti-Virus blade's:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is any specific protection/Signature needs to prevent in order to avoid such issues on business premises?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Arun.R (Hari)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Oct 2017 07:41:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-prevent-business-premises-from-RedBoot-ransomware-attack/m-p/7535#M59312</guid>
      <dc:creator>Arun_R</dc:creator>
      <dc:date>2017-10-13T07:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent business premises from RedBoot ransomware attack?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-prevent-business-premises-from-RedBoot-ransomware-attack/m-p/7536#M59313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First of all, this is probably a better question for the &lt;A href="https://community.checkpoint.com/space/2060"&gt;Threat Prevention&lt;/A&gt;‌ space.&lt;/P&gt;&lt;P&gt;Second, Ransomware such as RedBoot is really a great example of why you need multiple layers of protection.&lt;BR /&gt;While IPS, Anti-Virus, and Anti-Bot are great technologies, they are not enough to stop Ransomware.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any number of things could potentially deliver the RedBoot payload to a customer--things which could surely be blocked by AV if it's a known variant.&lt;/P&gt;&lt;P&gt;However, it's trivial to make any known variant unknown, reducing the efficacy of AV.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since there's no "phone home" element to this ransomware/wiper, Anti-Bot or IPS wouldn't see anything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the payload is delivered as a Microsoft Office or PDF doc (which is fairly common), then Threat Emulation would surely catch it.&lt;/P&gt;&lt;P&gt;Threat Extraction would strip out these unsafe elements so the end user would never see them.&lt;/P&gt;&lt;P&gt;If on the off chance Threat Emulation/Extraction didn't catch it, then&amp;nbsp;Check Point's AntiRansomware on the endpoint would stop it and quickly undo the damage.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Oct 2017 15:45:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-prevent-business-premises-from-RedBoot-ransomware-attack/m-p/7536#M59313</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-13T15:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent business premises from RedBoot ransomware attack?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-prevent-business-premises-from-RedBoot-ransomware-attack/m-p/7537#M59314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Arun there isn't a signature to prevent that infection&amp;nbsp; for now on any of those blades, the next step should be to incorporate the threat emulation technology on the gateway or in the endpoint with Sandblast Agent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are recommending our customer to have their computes up to date, to configure the shadow copy on their machines to have several copies of their information or at least have a procedure to have a backups once a day, also to be more stricted on the URL or categories that the users can access, for example block uncategorized sites or block high risk sites, also on the antivirus block&amp;nbsp;unusual file extention using the&amp;nbsp;Files Types feature to block some files.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Oct 2017 00:30:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-prevent-business-premises-from-RedBoot-ransomware-attack/m-p/7537#M59314</guid>
      <dc:creator>Pablo_Barriga</dc:creator>
      <dc:date>2017-10-16T00:30:38Z</dc:date>
    </item>
  </channel>
</rss>

