<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sandblast TE250X on premises engine Release  6.9/55.990001702 not available in Email and Collaboration</title>
    <link>https://community.checkpoint.com/t5/Email-and-Collaboration/Sandblast-TE250X-on-premises-engine-Release-6-9-55-990001702-not/m-p/37511#M142</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My understanding is&amp;nbsp;.js is currently only emulated when received as an email attachment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm assuming when you upload it via the URL, it is doing a full emulation similar to what's done with email.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not entirely sure that limitation&amp;nbsp;with .js and http is removed in 5.9.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Oct 2017 16:17:14 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2017-10-04T16:17:14Z</dc:date>
    <item>
      <title>Sandblast TE250X on premises engine Release  6.9/55.990001702 not available</title>
      <link>https://community.checkpoint.com/t5/Email-and-Collaboration/Sandblast-TE250X-on-premises-engine-Release-6-9-55-990001702-not/m-p/37508#M139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As per sk95235 engine Release&amp;nbsp; 6.9/55.990001702&amp;nbsp;is available since 26 Sep 2017 and&amp;nbsp;for&amp;nbsp; Deployment: 26/09-10/10.&lt;/P&gt;&lt;P&gt;My TE250X engine remain is version in 6.8.2/54.990001557.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does mean Deployment: 26/09-10/10 ? &lt;SPAN lang="en"&gt;&lt;SPAN&gt;The engine availability&lt;/SPAN&gt;&lt;/SPAN&gt; for Customer&amp;nbsp;using threat emulation in the cloud&amp;nbsp;? &lt;SPAN lang="en"&gt;&lt;SPAN&gt;When will the latest version be available for on premises ? &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;I have an open&amp;nbsp;case at checkpoint but it seems difficult for them to answer this simple question.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;Why this question ?&lt;/SPAN&gt; &lt;SPAN&gt;Simply because I have a zip that contains a malicious javascript.&lt;/SPAN&gt; &lt;SPAN&gt;In the Checkpoint Cloud this java script is detected as malicious (i use this link to test &lt;A href="https://threatemulation.checkpoint.com/teb/upload.jsp"&gt;https://threatemulation.checkpoint.com/teb/upload.jsp&lt;/A&gt;)&amp;nbsp;but it is not on my Te250X on premises when i download it on http with a browser.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN lang="en"&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;The sk106123 specifies the File types supported by SandBlast Threat Emulation and that for&amp;nbsp;.js / .js : these files are supported when arriving in archive as email attachment only. The protection is for the use of the files.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN lang="en"&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;I can understand that for http feeds it is not possible to analyze javascript loaded by html pages without generating a high latency for users as far as most pages contain javascript.&lt;BR /&gt;But when javascript is in a zip it should be. No ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN lang="en"&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;So my problem is related to the version of the engine or to this specific case? In this case why this difference between the cloud and the version on premise?&lt;SPAN style="display: none;"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN lang="en"&gt;&lt;SPAN style="display: none;"&gt;Than&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Oct 2017 17:31:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Email-and-Collaboration/Sandblast-TE250X-on-premises-engine-Release-6-9-55-990001702-not/m-p/37508#M139</guid>
      <dc:creator>Antoine_Nucera</dc:creator>
      <dc:date>2017-10-03T17:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: Sandblast TE250X on premises engine Release  6.9/55.990001702 not available</title>
      <link>https://community.checkpoint.com/t5/Email-and-Collaboration/Sandblast-TE250X-on-premises-engine-Release-6-9-55-990001702-not/m-p/37509#M140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When we release a new engine, it is not deployed to all on-premise customers at once, but gradually over the course of a few weeks.&lt;/P&gt;&lt;P&gt;26 September - 10 October 2017 is the timeframe during which&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;6.9/55.990001702 is being deployed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;If you do nothing, you can expect the new engine to be deployed to your TEX appliance in the next week or so.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;You can also do a manual update by using the steps in the following SK:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92509" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92509"&gt;Offline updates for Threat Emulation images and engine&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for why the js is not detected on your on-premise appliance, we make continual improvements to catch malware and reduce false positives.&lt;/P&gt;&lt;P&gt;It's possible something in the 6.9 catches it, whereas the 6.8.2 engine did not.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you see a difference after getting the 6.9 engine on your local TEX appliance, I recommend opening a support ticket.&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="http://www.checkpoint.com/support-services/contact-support/index.html" title="http://www.checkpoint.com/support-services/contact-support/index.html"&gt;Contact Support | Check Point Software&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Oct 2017 18:57:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Email-and-Collaboration/Sandblast-TE250X-on-premises-engine-Release-6-9-55-990001702-not/m-p/37509#M140</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-03T18:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: Sandblast TE250X on premises engine Release  6.9/55.990001702 not available</title>
      <link>https://community.checkpoint.com/t5/Email-and-Collaboration/Sandblast-TE250X-on-premises-engine-Release-6-9-55-990001702-not/m-p/37510#M141</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;The sk106123 specifies the "File types supported by SandBlast Threat Emulation and that for&amp;nbsp;.js / .js&amp;nbsp;" and&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;mentions that :&amp;nbsp;"these files are supported when arriving in archive as email attachment only. The protection is for the use of the files."&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;What you anderstand ? That&amp;nbsp;malicious js in zip are detected in mail only ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;Remmener that when i download my zip on Threat Cloud Test (last engine) it is detected as malicious.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;So, will the last engine detect the malicious JS in the ZIP in http.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;/SPAN&gt;&lt;SPAN lang="en"&gt;&lt;SPAN&gt;I do&amp;nbsp;understand that the restriction in the sk106123 does not applie to the last engine version ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Oct 2017 07:23:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Email-and-Collaboration/Sandblast-TE250X-on-premises-engine-Release-6-9-55-990001702-not/m-p/37510#M141</guid>
      <dc:creator>Antoine_Nucera</dc:creator>
      <dc:date>2017-10-04T07:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: Sandblast TE250X on premises engine Release  6.9/55.990001702 not available</title>
      <link>https://community.checkpoint.com/t5/Email-and-Collaboration/Sandblast-TE250X-on-premises-engine-Release-6-9-55-990001702-not/m-p/37511#M142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My understanding is&amp;nbsp;.js is currently only emulated when received as an email attachment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm assuming when you upload it via the URL, it is doing a full emulation similar to what's done with email.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not entirely sure that limitation&amp;nbsp;with .js and http is removed in 5.9.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Oct 2017 16:17:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Email-and-Collaboration/Sandblast-TE250X-on-premises-engine-Release-6-9-55-990001702-not/m-p/37511#M142</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-04T16:17:14Z</dc:date>
    </item>
  </channel>
</rss>

