<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS - Custom Signature url Alert in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-custom-signature-url-alert/m-p/1994373#M54819</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; OK, thank you for your quick response.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 06 Aug 2012 19:45:35 GMT</pubDate>
    <dc:creator>Shannon Sutter</dc:creator>
    <dc:date>2012-08-06T19:45:35Z</dc:date>
    <item>
      <title>IPS - Custom Signature url Alert</title>
      <link>https://community.cisco.com/t5/network-security/ips-custom-signature-url-alert/m-p/1994371#M54811</link>
      <description>&lt;P&gt;I just need a little help with one simple custom signature.&lt;/P&gt;&lt;P&gt;I am running a ASA-SSM-10 on a ASA5520.&lt;/P&gt;&lt;P&gt;IPS Version: 7.0(7)E4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;I've been trying to customized a signature to send/log alerts if someone is accessing &lt;A href="http://www.dropbox.com/" rel="nofollow" target="_blank"&gt;www.dropbox.com&lt;/A&gt; and can't get it to work.&lt;/P&gt;&lt;P&gt;I have read multiple posts and ended up configuring the custom signature like this: (based on Cisco 3204 signature)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using engine == &lt;STRONG&gt;Service-HTTP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;URI regex == &lt;STRONG&gt;[.][Dd][Rr][Oo][Pp][Bb][Oo][Xx]&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;service ports == #&lt;STRONG&gt;WEBPORTS&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The status is enabled and the Event action is Produce Alert.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Am I missing something? I am not getting any alerts.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have attached a screenshot of the custom sig. &lt;/P&gt;&lt;P&gt;Any help will be great, thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Zeek&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:44:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-custom-signature-url-alert/m-p/1994371#M54811</guid>
      <dc:creator>Shannon Sutter</dc:creator>
      <dc:date>2019-03-10T12:44:52Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - Custom Signature url Alert</title>
      <link>https://community.cisco.com/t5/network-security/ips-custom-signature-url-alert/m-p/1994372#M54814</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That can't work as Dropbox is using HTTPS and the IPS can't look into these encrypted sessions. Your signature will only work for sessions that use plain HTTP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Aug 2012 19:33:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-custom-signature-url-alert/m-p/1994372#M54814</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2012-08-06T19:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - Custom Signature url Alert</title>
      <link>https://community.cisco.com/t5/network-security/ips-custom-signature-url-alert/m-p/1994373#M54819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; OK, thank you for your quick response.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Aug 2012 19:45:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-custom-signature-url-alert/m-p/1994373#M54819</guid>
      <dc:creator>Shannon Sutter</dc:creator>
      <dc:date>2012-08-06T19:45:35Z</dc:date>
    </item>
    <item>
      <title>IPS - Custom Signature url Alert</title>
      <link>https://community.cisco.com/t5/network-security/ips-custom-signature-url-alert/m-p/1994374#M54820</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually, "dropbox.com" will appear in the Hostname in the traffic, but in the custom signature, you are using uri-regex. If you change it to header-regex, it might work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondly, we have sig 38686 subsigs 0 and 1 to detect Dropbox usage. Subsig 0 in service-http is what you might be looking for. These sigs were released in S604.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Radhika&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Aug 2012 22:32:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-custom-signature-url-alert/m-p/1994374#M54820</guid>
      <dc:creator>rupadras</dc:creator>
      <dc:date>2012-08-10T22:32:37Z</dc:date>
    </item>
    <item>
      <title>IPS - Custom Signature url Alert</title>
      <link>https://community.cisco.com/t5/network-security/ips-custom-signature-url-alert/m-p/1994375#M54824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks a lot! It is what I needed to know.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Aug 2012 14:57:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-custom-signature-url-alert/m-p/1994375#M54824</guid>
      <dc:creator>Shannon Sutter</dc:creator>
      <dc:date>2012-08-13T14:57:05Z</dc:date>
    </item>
  </channel>
</rss>

