<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why Doesn't Checkpoint MTA Detect Obfuscated JS in Email HTML Body (eval/atob)? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Why-Doesn-t-Checkpoint-MTA-Detect-Obfuscated-JS-in-Email-HTML/m-p/262556#M44425</link>
    <description>&lt;P&gt;You may wish to confrm this 100% with TAC, but Im fairly certain this is a limitation. From my understanding, only way such file would be scanned was if it were saved as .html file.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Nov 2025 20:46:25 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-11-11T20:46:25Z</dc:date>
    <item>
      <title>Why Doesn't Checkpoint MTA Detect Obfuscated JS in Email HTML Body (eval/atob)?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Why-Doesn-t-Checkpoint-MTA-Detect-Obfuscated-JS-in-Email-HTML/m-p/262547#M44417</link>
      <description>&lt;P&gt;We're using Checkpoint R81.20 with the Mail Transfer Agent (MTA) feature enabled on our Security Gateway to inspect SMTP traffic (integrated with Threat Emulation/TE and Threat Extraction). Recently, we analyzed a phishing email where malicious JavaScript was embedded directly in the HTML body (MIME type: text/html), using obfuscated base64-encoded code with &lt;SPAN&gt;atob&lt;/SPAN&gt; for decoding and &lt;SPAN&gt;eval&lt;/SPAN&gt; for execution. The payload was hidden in an &lt;SPAN&gt;&amp;lt;img style=display:none src/onerror="..."&amp;gt;&lt;/SPAN&gt; tag, designed to exfiltrate data to a suspicious domain upon rendering in the browser/iNotes client.&lt;/P&gt;&lt;P&gt;Key details:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;No attachments; purely inline HTML body.&lt;/LI&gt;&lt;LI&gt;The email passed through without quarantine or alert (low spam score ~12%, no URL filtering hit).&lt;/LI&gt;&lt;LI&gt;MTA accepts/relays SMTP, scans MIME parts, but the JS executed client-side without server-side detection.&lt;/LI&gt;&lt;LI&gt;Logs show SMTP negotiation over TLS, but no TE sandboxing triggered for the HTML body.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;From the docs, MTA works with TE for file-based threats and Threat Extraction for content removal, but it seems focused on attachments/files rather than inline scripts in HTML bodies. Is this a known limitation?&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Does MTA/TE scan and emulate inline HTML/JavaScript in email bodies for obfuscated threats like &lt;SPAN&gt;eval(atob(...))&lt;/SPAN&gt;, or is it limited to extractable files/attachments?&lt;/LI&gt;&lt;LI&gt;What configurations (e.g., enabling full MIME recursion, custom signatures for JS patterns) can improve detection of HTML smuggling or client-side JS exploits?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Appreciate any insights or best practices to harden MTA against such attacks.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2025 20:17:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Why-Doesn-t-Checkpoint-MTA-Detect-Obfuscated-JS-in-Email-HTML/m-p/262547#M44417</guid>
      <dc:creator>SubZer0</dc:creator>
      <dc:date>2025-11-11T20:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why Doesn't Checkpoint MTA Detect Obfuscated JS in Email HTML Body (eval/atob)?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Why-Doesn-t-Checkpoint-MTA-Detect-Obfuscated-JS-in-Email-HTML/m-p/262556#M44425</link>
      <description>&lt;P&gt;You may wish to confrm this 100% with TAC, but Im fairly certain this is a limitation. From my understanding, only way such file would be scanned was if it were saved as .html file.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Nov 2025 20:46:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Why-Doesn-t-Checkpoint-MTA-Detect-Obfuscated-JS-in-Email-HTML/m-p/262556#M44425</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-11T20:46:25Z</dc:date>
    </item>
  </channel>
</rss>

