09-23-2016 07:02 PM
Hi Cisco Support,
Our problem is that the attacker attached a picture file and when the user click that picture, it will redirect to a certain shorten url link which hides the real URL and download a malicious file. We found out that the attacker uses goo.gl.com so that ironport has positive scan. We want to automate a filter if other attackers will use other URL shorten link server instead goo.gl.com. We opened a Cisco TAC case but it didn't work about regular expressions. Kindly help us on how to block shorten URL links.
Thank you and best regards!
Solved! Go to Solution.
09-24-2016 01:24 PM
Hello,
We're working on providing the needed support for shortened URL's in the near future in regards to URL Filtering.
In the meantime, you can setup a Content Filter with a condition similar to the one below in order to trigger on these types of links in the message body and/or attachment. Also, please be sure to reference the following enhancement request to your TAC engineer so they can add a sighting to your case.
CSCva56442 - Enhancement Request - URL filtering should resolve shortened URL's
Thanks!
-Dennis M.
09-24-2016 01:24 PM
Hello,
We're working on providing the needed support for shortened URL's in the near future in regards to URL Filtering.
In the meantime, you can setup a Content Filter with a condition similar to the one below in order to trigger on these types of links in the message body and/or attachment. Also, please be sure to reference the following enhancement request to your TAC engineer so they can add a sighting to your case.
CSCva56442 - Enhancement Request - URL filtering should resolve shortened URL's
Thanks!
-Dennis M.
10-04-2016 08:52 PM
Hi Dennis,
Thank you for providing the screenshot. It works but what are the other shorten URL Links? The attacker may use other links and we want to automate if ESA can do that.
Thank you and best regards!
10-05-2016 10:05 AM
Hello,
You're very welcome! :)
I typically don't use URL shortening services very often, so I'm not too sure what the most widely used ones are. With a quick search I was able to find the Wiki for URL Shortening that provides some common services used : https://en.wikipedia.org/wiki/URL_shortening#URL_shortening_services
You can probably search around a bit further if you're interested in others. All you would need to do at that point is edit your content filter to match on other services/URL's.
Thanks!
-Dennis M.
10-05-2016 06:42 PM
Hi Dennis,
Thank you for your prompt response!
CHEERS!
05-01-2020 09:38 AM - edited 05-01-2020 09:41 AM
I know this is an old post..but now that google is migrating their shortened link service from GOO.GL to PAGE.LINK..is this something that will be added into the URL engine? is there a roadmap to add more URL shortener service being abused?
I open a TAC for this abuse, but didn't get quite a good answer if this will be added or evolved.. and seem to have no other choice than block these URL until we get a clear answer if this will be handle.
Thank you
ref : https://firebase.google.com/support/guides/url-shortener
05-01-2020 10:18 AM
In the past, we do work to engage the currently seen shortener services in use. These get updated on the ESA via the updater as Cisco evaluates and pushes those --- at times adding some, at other times removing old. All controlled by the updater service running on ESA.
This is seen on the older AsyncOS versions applicable in websecurityadvancedconfig:
Do you want to enable URL filtering for shortened URLs? [Y]>
For shortened URL support to work, please ensure that ESA is able to connect to following domains:
bit.ly, tinyurl.com, ow.ly, tumblr.com, ff.im, youtu.be, tl.gd, plurk.com, url4.eu, j.mp, goo.gl, fb.me, alturl.com, wp.me, chatter.com, tiny.cc, ur.ly
Moving in 13.5, we will have Cloud URL Analysis (CUA) take this over. The shortened URLs are deprecated into the Talos cloud-driven engine. At which time, Talos will have this running from Cisco-side in the services that feed CUA, allowing a better field of services scanned for URL Analysis.
If there is a shortened URL domain that is NOT covered in the listing, you can open a support note directly to Talos: https://talosintelligence.com/reputation_center/support
The steps provided at the start of the thread here will still apply, too. You can add something you feel is needed, but maybe not yet widely seen to have been included, and create a message or content filter. One other area that may contain some of the shortened URL domains could be from an External Threat Feed. If you subscribe and enable ETF on ESA, these may catch URLs in this fashion as well --- providing a second set of scan/detect, in addition to what Talos provide ESA already.
HTH.
-Robert
05-01-2020 11:40 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide