<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Harmony not catching Browser exploit in cpcheckme in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202679#M7962</link>
    <description>&lt;P&gt;Can you please open the relevant section in the CheckMe report? What does it say there?&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jan 2024 08:52:40 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2024-01-10T08:52:40Z</dc:date>
    <item>
      <title>Harmony not catching Browser exploit in cpcheckme</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202618#M7951</link>
      <description>&lt;P&gt;Hi, we are testing Harmony endpoint complete in our organisation. I tried to turn on everything to prevent and turn on many defensive/preventive settings. But every time I run&amp;nbsp;&lt;A href="http://www.cpcheckme.com/checkme/" target="_blank"&gt;Check Me (cpcheckme.com)&lt;/A&gt;&amp;nbsp;for Endpoint I always get Browser Exploit vulnerable. (see attached screenshot). Am i doing something wrong? we are deciding between ESET and Harmony. Or is there some best practice guide on how to configure Harmony endpoint for best security?&lt;/P&gt;&lt;P&gt;Any help much appreciated. Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2024 15:46:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202618#M7951</guid>
      <dc:creator>adamec</dc:creator>
      <dc:date>2024-01-09T15:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony not catching Browser exploit in cpcheckme</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202619#M7952</link>
      <description>&lt;P&gt;Look into &lt;SPAN class="css-13y3t3g"&gt;&lt;SPAN class="css-vy7rm"&gt;sk115236&lt;/SPAN&gt;&lt;/SPAN&gt;:&lt;/P&gt;
&lt;TABLE class="footnote" border="1" width="100%" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR valign="top"&gt;
&lt;TD&gt;Browser&lt;BR /&gt;Exploit&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Network &amp;amp; Cloud&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;This test checks if your network is protected against Cross-Site&amp;nbsp;Scripting (XSS).&lt;BR /&gt;&lt;BR /&gt;CheckMe &lt;STRONG&gt;simulates&lt;/STRONG&gt; this test by connecting to:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://files.cpcheckme.com/1.asp?xss=%3Cscript%3Ealert%28%221%22%29%3C%2Fscript%3E" target="_blank"&gt;http://files.cpcheckme.com/1.asp?xss=%3Cscript%3Ealert%28%221%22%29%3C%2Fscript%3E&lt;/A&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;BR /&gt;Endpoint&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;This test checks if your browser is exploit by simulating a shellcode execution in the Internet Explorer.&lt;/TD&gt;
&lt;TD&gt;Improve your network security with &lt;A href="https://www.checkpoint.com/products-solutions/threat-prevention-appliances-and-software/" target="_blank" rel="noopener"&gt;Check Point Next Generation Threat Prevention&lt;/A&gt; and &lt;A href="https://www.checkpoint.com/products-solutions/endpoint-security/" target="_blank" rel="noopener"&gt;Endpoint Security&lt;/A&gt; that includes &lt;A href="https://www.checkpoint.com/products/ips-software-blade/" target="_blank" rel="noopener"&gt;Intrusion Prevention System (IPS)&lt;/A&gt; and Anti Exploit blades.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Network &amp;amp; Cloud&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Configure the IPS protections against Cross-Site Scripting (such as "&lt;A href="https://www.checkpoint.com/defense/advisories/public/2016/cpai-2016-0042.html" target="_blank" rel="noopener"&gt;Cross-Site Scripting Scanning Attempt&lt;/A&gt;") to "Prevent" mode.&lt;BR /&gt;&lt;BR /&gt;
&lt;OL&gt;
&lt;OL&gt;
&lt;LI&gt;Enable the IPS blade and ensure that IPS protections are up to date.&lt;/LI&gt;
&lt;LI&gt;In case it is not possible to update the IPS protections to the latest release, enable the following IPS protection:&lt;/LI&gt;
&lt;/OL&gt;
&lt;/OL&gt;
&lt;BR /&gt;
&lt;OL&gt;Cross-Site Scripting Scanning Attempt&lt;/OL&gt;
&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Endpoint&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Enable &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121793" target="_blank" rel="noopener"&gt;Anti-Exploit &lt;/A&gt;on your Check Point &lt;A href="https://www.checkpoint.com/products-solutions/endpoint-security/" target="_blank" rel="noopener"&gt;Endpoint Security&lt;/A&gt; to improve your security risk against exploits.&lt;BR /&gt;&lt;BR /&gt;Note that Anti-Exploit protection is available from version E80.83&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Tue, 09 Jan 2024 15:58:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202619#M7952</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-01-09T15:58:25Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony not catching Browser exploit in cpcheckme</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202661#M7954</link>
      <description>&lt;P&gt;As already said, please check that you enabled Anti-Exploit feature in HE&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 07:36:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202661#M7954</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-01-10T07:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony not catching Browser exploit in cpcheckme</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202668#M7957</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;Hi, so I checked and anti exploit is turned on to prevent. I have my rule base like on screenshot where rule number 0 is for my PC and rule number 1 is for entire organisation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the problem still persist still the only bulnerable check is Browser Exploit. What else could be wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 08:25:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202668#M7957</guid>
      <dc:creator>adamec</dc:creator>
      <dc:date>2024-01-10T08:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony not catching Browser exploit in cpcheckme</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202673#M7958</link>
      <description>&lt;P&gt;Just to make sure, your browser does show the Harmony Endpoint extension installed and active, right?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 08:37:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202673#M7958</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-01-10T08:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony not catching Browser exploit in cpcheckme</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202674#M7959</link>
      <description>&lt;P&gt;Also, can you please show the details about detected vulnerability? There might be some clues as well.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 08:38:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202674#M7959</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-01-10T08:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony not catching Browser exploit in cpcheckme</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202675#M7960</link>
      <description>&lt;P&gt;sure, harmony web protection extension is active in the browser.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 08:43:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202675#M7960</guid>
      <dc:creator>adamec</dc:creator>
      <dc:date>2024-01-10T08:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony not catching Browser exploit in cpcheckme</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202676#M7961</link>
      <description>&lt;P&gt;It looks like Anti-Exploit blade does not even generate anti logs. see screenshot&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 08:47:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202676#M7961</guid>
      <dc:creator>adamec</dc:creator>
      <dc:date>2024-01-10T08:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony not catching Browser exploit in cpcheckme</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202679#M7962</link>
      <description>&lt;P&gt;Can you please open the relevant section in the CheckMe report? What does it say there?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 08:52:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202679#M7962</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-01-10T08:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony not catching Browser exploit in cpcheckme</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202682#M7964</link>
      <description>&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Here yoou go&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 09:08:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202682#M7964</guid>
      <dc:creator>adamec</dc:creator>
      <dc:date>2024-01-10T09:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony not catching Browser exploit in cpcheckme</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202683#M7965</link>
      <description>&lt;P&gt;Is Harmony Endpoint (which version?) the only solution installed or is there also a 3rd party A/V in play here?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 09:11:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202683#M7965</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-01-10T09:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony not catching Browser exploit in cpcheckme</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202684#M7966</link>
      <description>&lt;P&gt;We used to have also ESET but for testing purposes we uninstalled ESET and currently only active and installed security solution is HArmony Endpoint version E&lt;SPAN&gt;87.62.2002&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 09:15:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202684#M7966</guid>
      <dc:creator>adamec</dc:creator>
      <dc:date>2024-01-10T09:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony not catching Browser exploit in cpcheckme</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202685#M7967</link>
      <description>&lt;P&gt;Ok, triple-check that your Anti-Exploit is properly configured, does not have any exceptions, and that you pushed the policy to the HA client in question.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If you still cannot figure it out, please open a TAC request to troubleshoot.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 09:18:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202685#M7967</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-01-10T09:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony not catching Browser exploit in cpcheckme</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202686#M7968</link>
      <description>&lt;P&gt;Ok maybe it wasn't uninstalled cleanly, see if&amp;nbsp;&lt;SPAN&gt;sk154454 helps?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;(Note may require TAC assistance if cloud managed to test this)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 09:28:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202686#M7968</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-01-10T09:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony not catching Browser exploit in cpcheckme</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202687#M7969</link>
      <description>&lt;P&gt;where should i connect to with GuiDBedit when we are using infinity portal -&amp;gt; harmony endpoint as a management?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 09:30:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202687#M7969</guid>
      <dc:creator>adamec</dc:creator>
      <dc:date>2024-01-10T09:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony not catching Browser exploit in cpcheckme</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202689#M7971</link>
      <description>&lt;P&gt;I believe TAC may need to do this on your behalf if Cloud managed.&lt;/P&gt;
&lt;P&gt;Otherwise if ESET have a "cleaner / removal" tool maybe try that to ensure it's gone...&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 09:37:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202689#M7971</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-01-10T09:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony not catching Browser exploit in cpcheckme</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202690#M7972</link>
      <description>&lt;P&gt;okay i will try to look for eset cleaner first then reboot and try again. If the issue still persist I m gonna contact TAC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks all for your help so far&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 09:38:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-not-catching-Browser-exploit-in-cpcheckme/m-p/202690#M7972</guid>
      <dc:creator>adamec</dc:creator>
      <dc:date>2024-01-10T09:38:48Z</dc:date>
    </item>
  </channel>
</rss>

