<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block File in My Network in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/block-file-in-my-network/m-p/807691#M87054</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created this custome signature:&lt;/P&gt;&lt;P&gt;signatures 60000 0&lt;/P&gt;&lt;P&gt;alert-severity high&lt;/P&gt;&lt;P&gt;sig-fidelity-rating 75&lt;/P&gt;&lt;P&gt;promisc-delta 10&lt;/P&gt;&lt;P&gt;sig-description&lt;/P&gt;&lt;P&gt;sig-name VirtualRap3D.exe&lt;/P&gt;&lt;P&gt;sig-string-info &lt;/P&gt;&lt;P&gt;sig-comment &lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;engine string-tcp&lt;/P&gt;&lt;P&gt;event-action produce-alert&lt;/P&gt;&lt;P&gt;regex-string [\]\x00V\x00i\x00r\x00t\x00u\x00a\x00l\x00R\x00a\x00p\x003\x00D\x00&lt;/P&gt;&lt;P&gt;[.]\x00e\x00x\x00e\x00&lt;/P&gt;&lt;P&gt;service-ports 139-139,445-445&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;event-counter&lt;/P&gt;&lt;P&gt;event-count 1&lt;/P&gt;&lt;P&gt;event-count-key Axxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But this doesnt work yet.&lt;/P&gt;&lt;P&gt;I also try with a atomic IP, filtering the traffic betweeen two host and logging packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;     port: 139  &lt;/P&gt;&lt;P&gt;      os:   idSource=unknown  type=unknown  relevance=relevant  &lt;/P&gt;&lt;P&gt;  actions:   &lt;/P&gt;&lt;P&gt;    ipLoggingActivated: true  &lt;/P&gt;&lt;P&gt;    logPairPacketsActivated: true  &lt;/P&gt;&lt;P&gt;  ipLogIds:   &lt;/P&gt;&lt;P&gt;    ipLogId: 1701868400  &lt;/P&gt;&lt;P&gt;  triggerPacket: &lt;/P&gt;&lt;P&gt;000000  00 0A F3 57 5E 3C 00 18  FE 63 B1 33 81 00 00 73  ...W^&amp;lt;...c.3...s&lt;/P&gt;&lt;P&gt;000010  08 00 45 00 00 A0 51 88  40 00 80 06 79 DF 8E D2  ..E...Q.@...y...&lt;/P&gt;&lt;P&gt;000020  0F D3 8E D4 01 77 07 CD  00 8B 1F A0 A3 36 70 B5  .....w.......6p.&lt;/P&gt;&lt;P&gt;000030  1D CB 50 18 FC 00 25 84  00 00 00 00 00 74 FF 53  ..P...%......t.S&lt;/P&gt;&lt;P&gt;000040  4D 42 32 00 00 00 00 18  07 C8 00 00 00 00 00 00  MB2.............&lt;/P&gt;&lt;P&gt;000050  00 00 00 00 00 00 02 08  D8 06 00 08 90 3E 0F 30  .............&amp;gt;.0&lt;/P&gt;&lt;P&gt;000060  00 00 00 0A 00 00 40 00  00 00 00 00 00 00 00 00  ......@.........&lt;/P&gt;&lt;P&gt;000070  00 30 00 44 00 00 00 00  00 01 00 01 00 33 00 00  .0.D.........3..&lt;/P&gt;&lt;P&gt;000080  00 00 16 00 56 05 07 00  04 01 00 00 00 00 5C 00  ....V.........\.&lt;/P&gt;&lt;P&gt;000090  56 00 69 00 72 00 74 00  75 00 61 00 6C 00 52 00  V.i.r.t.u.a.l.R.&lt;/P&gt;&lt;P&gt;0000A0  61 00 70 00 33 00 44 00  2E 00 65 00 78 00 65 00  a.p.3.D...e.x.e.&lt;/P&gt;&lt;P&gt;0000B0  00 00                                             ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  riskRatingValue: 85  targetValueRating=medium  attackRelevanceRating=relevant  &lt;/P&gt;&lt;P&gt;  threatRatingValue: 85  &lt;/P&gt;&lt;P&gt;  interface: ge0_8  &lt;/P&gt;&lt;P&gt;  protocol: tcp  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please Help, i really need block this file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Apr 2007 23:48:32 GMT</pubDate>
    <dc:creator>e.basto26</dc:creator>
    <dc:date>2007-04-09T23:48:32Z</dc:date>
    <item>
      <title>Block File in My Network</title>
      <link>https://community.cisco.com/t5/network-security/block-file-in-my-network/m-p/807689#M87051</link>
      <description>&lt;P&gt;Hi!,&lt;/P&gt;&lt;P&gt;I want to configure my sensor such that it sends a reset packet if it detect a file "VirtualR3D.exe".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created a custome signature with STRING.TCP, but it does not work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Engine: String.TCP&lt;/P&gt;&lt;P&gt;Service Port: 139,445&lt;/P&gt;&lt;P&gt;Regex String : [V][i][r][t][u][a][l][R][a][p][3][D][.][e][x][e]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, I clone a signature with this parameters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Smb.Advanced&lt;/P&gt;&lt;P&gt;SMB Command: 162&lt;/P&gt;&lt;P&gt;service port:139,445&lt;/P&gt;&lt;P&gt;Regex:[V][i][r][t][u][a][l][R][a][p][3][D][.][e][x][e]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please can you help me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tks in advaced.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:33:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-file-in-my-network/m-p/807689#M87051</guid>
      <dc:creator>e.basto26</dc:creator>
      <dc:date>2019-03-10T10:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: Block File in My Network</title>
      <link>https://community.cisco.com/t5/network-security/block-file-in-my-network/m-p/807690#M87053</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is best to capture the traffic on the wire so you can visually see how a file is transmitted through different protocols.  I created a dummy file VirtualR3D.exe and shared it between two hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following string.tcp regexp has fired on this traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[\]\x00V\x00i\x00r\x00t\x00u\x00a\x00l\x00R\x00a\x00p\x003\x00D\x00[.]\x00e\x00x\x00e\x00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that helps.&lt;/P&gt;&lt;P&gt;-jonathan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Apr 2007 01:31:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-file-in-my-network/m-p/807690#M87053</guid>
      <dc:creator>jlimbo</dc:creator>
      <dc:date>2007-04-09T01:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: Block File in My Network</title>
      <link>https://community.cisco.com/t5/network-security/block-file-in-my-network/m-p/807691#M87054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created this custome signature:&lt;/P&gt;&lt;P&gt;signatures 60000 0&lt;/P&gt;&lt;P&gt;alert-severity high&lt;/P&gt;&lt;P&gt;sig-fidelity-rating 75&lt;/P&gt;&lt;P&gt;promisc-delta 10&lt;/P&gt;&lt;P&gt;sig-description&lt;/P&gt;&lt;P&gt;sig-name VirtualRap3D.exe&lt;/P&gt;&lt;P&gt;sig-string-info &lt;/P&gt;&lt;P&gt;sig-comment &lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;engine string-tcp&lt;/P&gt;&lt;P&gt;event-action produce-alert&lt;/P&gt;&lt;P&gt;regex-string [\]\x00V\x00i\x00r\x00t\x00u\x00a\x00l\x00R\x00a\x00p\x003\x00D\x00&lt;/P&gt;&lt;P&gt;[.]\x00e\x00x\x00e\x00&lt;/P&gt;&lt;P&gt;service-ports 139-139,445-445&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;event-counter&lt;/P&gt;&lt;P&gt;event-count 1&lt;/P&gt;&lt;P&gt;event-count-key Axxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But this doesnt work yet.&lt;/P&gt;&lt;P&gt;I also try with a atomic IP, filtering the traffic betweeen two host and logging packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;     port: 139  &lt;/P&gt;&lt;P&gt;      os:   idSource=unknown  type=unknown  relevance=relevant  &lt;/P&gt;&lt;P&gt;  actions:   &lt;/P&gt;&lt;P&gt;    ipLoggingActivated: true  &lt;/P&gt;&lt;P&gt;    logPairPacketsActivated: true  &lt;/P&gt;&lt;P&gt;  ipLogIds:   &lt;/P&gt;&lt;P&gt;    ipLogId: 1701868400  &lt;/P&gt;&lt;P&gt;  triggerPacket: &lt;/P&gt;&lt;P&gt;000000  00 0A F3 57 5E 3C 00 18  FE 63 B1 33 81 00 00 73  ...W^&amp;lt;...c.3...s&lt;/P&gt;&lt;P&gt;000010  08 00 45 00 00 A0 51 88  40 00 80 06 79 DF 8E D2  ..E...Q.@...y...&lt;/P&gt;&lt;P&gt;000020  0F D3 8E D4 01 77 07 CD  00 8B 1F A0 A3 36 70 B5  .....w.......6p.&lt;/P&gt;&lt;P&gt;000030  1D CB 50 18 FC 00 25 84  00 00 00 00 00 74 FF 53  ..P...%......t.S&lt;/P&gt;&lt;P&gt;000040  4D 42 32 00 00 00 00 18  07 C8 00 00 00 00 00 00  MB2.............&lt;/P&gt;&lt;P&gt;000050  00 00 00 00 00 00 02 08  D8 06 00 08 90 3E 0F 30  .............&amp;gt;.0&lt;/P&gt;&lt;P&gt;000060  00 00 00 0A 00 00 40 00  00 00 00 00 00 00 00 00  ......@.........&lt;/P&gt;&lt;P&gt;000070  00 30 00 44 00 00 00 00  00 01 00 01 00 33 00 00  .0.D.........3..&lt;/P&gt;&lt;P&gt;000080  00 00 16 00 56 05 07 00  04 01 00 00 00 00 5C 00  ....V.........\.&lt;/P&gt;&lt;P&gt;000090  56 00 69 00 72 00 74 00  75 00 61 00 6C 00 52 00  V.i.r.t.u.a.l.R.&lt;/P&gt;&lt;P&gt;0000A0  61 00 70 00 33 00 44 00  2E 00 65 00 78 00 65 00  a.p.3.D...e.x.e.&lt;/P&gt;&lt;P&gt;0000B0  00 00                                             ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  riskRatingValue: 85  targetValueRating=medium  attackRelevanceRating=relevant  &lt;/P&gt;&lt;P&gt;  threatRatingValue: 85  &lt;/P&gt;&lt;P&gt;  interface: ge0_8  &lt;/P&gt;&lt;P&gt;  protocol: tcp  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please Help, i really need block this file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Apr 2007 23:48:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-file-in-my-network/m-p/807691#M87054</guid>
      <dc:creator>e.basto26</dc:creator>
      <dc:date>2007-04-09T23:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Block File in My Network</title>
      <link>https://community.cisco.com/t5/network-security/block-file-in-my-network/m-p/807692#M87055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The regexp is correct based on the trigger packet information.  When I tested this I shared the VirtualRap3D.exe file and accessed that file from another client through smb.  From memory I set the direction "From service" based on the traffic information.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could not find the setting on your signature settings but I would check this setting based on the traffic flow (from or to the service port) to ensure its correctly set.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2007 07:28:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-file-in-my-network/m-p/807692#M87055</guid>
      <dc:creator>jlimbo</dc:creator>
      <dc:date>2007-04-10T07:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: Block File in My Network</title>
      <link>https://community.cisco.com/t5/network-security/block-file-in-my-network/m-p/807693#M87056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, but the IPS send me alert with all .exe files, not just the file VirtualRap3D.exe&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;?what?s wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2007 18:48:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-file-in-my-network/m-p/807693#M87056</guid>
      <dc:creator>e.basto26</dc:creator>
      <dc:date>2007-04-16T18:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: Block File in My Network</title>
      <link>https://community.cisco.com/t5/network-security/block-file-in-my-network/m-p/807694#M87058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I need a bit more information to figure out the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please send me your updated signature settings, and if possible an output or produce-verbose-alert.  You can e-mail this output directly if you like.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2007 00:44:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-file-in-my-network/m-p/807694#M87058</guid>
      <dc:creator>jlimbo</dc:creator>
      <dc:date>2007-04-17T00:44:58Z</dc:date>
    </item>
  </channel>
</rss>

