- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Check Point Proactive support
Free trial available for 90 Days!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
The 2022 MITRE Engenuity ATT&CK®
Evaluations Results Are In!
Now Available: SmartAwareness Security Training
Training Built to Educate and Engage
MITRE ATT&CK
Inside Check Point products!
CheckFlix!
All Videos In One Space
Hi,
I received a question from customer running a 1590 box and R80.20.20 version
Can IPS detect this pattern ( \$\{\s*(j|\$?\{.+?\}) } )
If the test is done:
1. By the request POST
2. In the HTTP header
3. In the HTTP data stream
Or is WAF required for this?
Thank you
Looks like RegEx - why should IPS match that ?
Let me see if I can have more info from the customer and see from there
In the SMB Users & Objects > Applications & URLs page you can define custom applications by Regular Expressions that match URLs - but your example will not match URLs...
Thank you, I know that, but I don't think they had that in mind.
I have some assumptions that are on the path of what @Ruan_Kotze wrote, but didn't want to get ahead of myself.
Like I said let me see if I can get more info from the customer which may shed some light
I agree with @G_W_Albrecht . I dont think IPS can match that at all. Not sure if WAF can...maybe.
Long shot but perhaps worth investigating is if you can write a Snort signature containing your regex.
Once you have the Snort signature you can import it into your manager, assuming your gateway is centrally managed.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY