- Products
- Learn
- Local User Groups
- Partners
- More
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
Join our TechTalk: Malware 2021 to Present Day
Building a Preventative Cyber Program
Be a CloudMate!
Check out our cloud security exclusive space!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hi,
I received a question from customer running a 1590 box and R80.20.20 version
Can IPS detect this pattern ( \$\{\s*(j|\$?\{.+?\}) } )
If the test is done:
1. By the request POST
2. In the HTTP header
3. In the HTTP data stream
Or is WAF required for this?
Thank you
Looks like RegEx - why should IPS match that ?
Let me see if I can have more info from the customer and see from there
In the SMB Users & Objects > Applications & URLs page you can define custom applications by Regular Expressions that match URLs - but your example will not match URLs...
Thank you, I know that, but I don't think they had that in mind.
I have some assumptions that are on the path of what @Ruan_Kotze wrote, but didn't want to get ahead of myself.
Like I said let me see if I can get more info from the customer which may shed some light
I agree with @G_W_Albrecht . I dont think IPS can match that at all. Not sure if WAF can...maybe.
Long shot but perhaps worth investigating is if you can write a Snort signature containing your regex.
Once you have the Snort signature you can import it into your manager, assuming your gateway is centrally managed.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY