<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-19749459</id><updated>2011-12-16T17:51:43.363+01:00</updated><category term='capra'/><title type='text'>Watchguard Fireware Tips &amp; Tricks</title><subtitle type='html'>Tips &amp; Tricks to get the most out of your Watchguard Fireware firewall.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>25</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-19749459.post-5101976923634660323</id><published>2007-11-15T11:40:00.000+01:00</published><updated>2007-11-15T12:03:57.244+01:00</updated><title type='text'>Keep track of your ip / email</title><summary type='text'>There are some things you might not want to block but just keep track of.All the examples are HTTP proxy URL Path rules set to allow and log:Your external ip:*your_external_ip*Your email domain:*@your_domain.com*China / Hong Kong / Russia:*.cn**.hk**.ru*Another idea would be to track you internal ip's with a regexe rule. To see if bot's are trying to report back to there C&amp;C masters.</summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/5101976923634660323/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=5101976923634660323' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/5101976923634660323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/5101976923634660323'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2007/11/keep-track-of-your-ip-email.html' title='Keep track of your ip / email'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-630839450718504092</id><published>2007-09-04T19:53:00.000+02:00</published><updated>2007-09-04T20:08:45.069+02:00</updated><title type='text'>Spamhaus DROP (Don't Route Or Peer)</title><summary type='text'>I came across this interesting Spamhaus DROP (Don't Route Or Peer) list.Quote:When implemented at a network or ISP's 'core routers', DROP will protect all the network's users from spamming, scanning, harvesting and dDoS attacks originating on rogue netblocks.I added this to my 'Blocked Sites...'. You can do this to:1. Download the list.2. Remove everything except the netblocks and save the file </summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/630839450718504092/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=630839450718504092' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/630839450718504092'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/630839450718504092'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2007/09/spamhaus-drop-dont-route-or-peer.html' title='Spamhaus DROP (Don&apos;t Route Or Peer)'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-9206033577164309626</id><published>2007-06-13T18:50:00.000+02:00</published><updated>2007-06-13T19:04:28.267+02:00</updated><title type='text'>Capra is moving to Sourceforge</title><summary type='text'>To provide better support Capra is moving to Sourceforge.The new URL is:Capra @ SourceforgePlease update your bookmarks.</summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/9206033577164309626/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=9206033577164309626' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/9206033577164309626'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/9206033577164309626'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2007/06/capra-is-moving-to-sourceforge.html' title='Capra is moving to Sourceforge'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-1016977974660999592</id><published>2007-05-17T17:50:00.000+02:00</published><updated>2007-05-17T18:00:01.919+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='capra'/><title type='text'>Capra v0.4</title><summary type='text'>What is Capra:Capra is a Open Source tool to quickly get some nice and useful reports out off your Watchguard Fireware log files.Capra uses PHP and MySQL to accomplish this.Features:v0.4:1. Web interface to import Fireware log files in to the MySQL database. (Only imports FWDeny, ProxyHTTPReq, ProxyMatch and FWStatus messages.)2. CLI (25% faster then web interface) to import Fireware log files in</summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/1016977974660999592/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=1016977974660999592' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/1016977974660999592'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/1016977974660999592'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2007/05/capra-v04.html' title='Capra v0.4'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-116152423006847182</id><published>2006-10-22T15:34:00.000+02:00</published><updated>2006-10-22T15:37:21.043+02:00</updated><title type='text'>On hold...</title><summary type='text'>As I am traveling trough China-Tibet-Nepal-India for a year this blog will be on hold. Want to see the pictures of my trip:https://degroep.org/beijingdelhi/photoalbum/photoalbum.php</summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/116152423006847182/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=116152423006847182' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/116152423006847182'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/116152423006847182'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2006/10/on-hold.html' title='On hold...'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-115642613776887385</id><published>2006-08-24T15:27:00.000+02:00</published><updated>2007-04-07T12:49:13.616+02:00</updated><title type='text'>Webblocker &amp; Surfcontrol 2</title><summary type='text'>On 17-12-2005 I wrote about the link between Webblocker &amp; Surfcontrol.I seams that Watchguard now has it's own page at Surfcontrol.http://mtas.surfcontrol.com/mtas/WatchGuardTest-a-Site.aspThe categories you can select when you are submitting a site are exactly the same as on the Watchguard. How nice!</summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/115642613776887385/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=115642613776887385' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/115642613776887385'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/115642613776887385'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2006/08/webblocker-surfcontrol-2.html' title='Webblocker &amp; Surfcontrol 2'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-115369221405544122</id><published>2006-07-23T23:53:00.000+02:00</published><updated>2006-07-24T00:03:34.066+02:00</updated><title type='text'>Fireboxsupport.com</title><summary type='text'>If you need help with the configuration of your Watchguard Fireware box you might want to take a look at:http://www.fireboxsupport.com/fireware_pro.htmThey have some very detailed guides, that will help you if you are setting up a box for the first time. They also have some Tips and Tricks. Very usefull.</summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/115369221405544122/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=115369221405544122' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/115369221405544122'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/115369221405544122'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2006/07/fireboxsupportcom.html' title='Fireboxsupport.com'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-115037165218449143</id><published>2006-06-15T13:34:00.000+02:00</published><updated>2006-06-15T13:40:52.193+02:00</updated><title type='text'>URL Paths 2</title><summary type='text'>From the comments of my original post about URL Paths:&lt;qoute src="Jon Cavallo"&gt;You can put *.com in the URL Paths. You need to enter it as '/*.com'I use the /*.x convention on all my extension blocking. This helps prevent them from wildcarding some other part of a complex url.&lt;/quote&gt;You are totally right, this is a better way to implement extension blocking with URL Paths. Thanks</summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/115037165218449143/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=115037165218449143' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/115037165218449143'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/115037165218449143'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2006/06/url-paths-2.html' title='URL Paths 2'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-115006320424734155</id><published>2006-06-11T23:59:00.000+02:00</published><updated>2006-06-12T00:03:22.043+02:00</updated><title type='text'>CLI</title><summary type='text'>Did you know that fireware also has a command line interface.You can SSH to your box on port 4118.You can login with:Username = adminpassword = Your read-write password.You can do all sorts of things from the command line.I use it as a replacement for the 'Restart IPSec' function that was in WFS but not in fireware.To clear individual BOVPN, MUVPN, or PPTP tunnels:WG#no vpn-tunnel ipsec </summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/115006320424734155/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=115006320424734155' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/115006320424734155'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/115006320424734155'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2006/06/cli.html' title='CLI'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-114933670885078368</id><published>2006-06-03T13:47:00.000+02:00</published><updated>2006-06-03T14:11:49.040+02:00</updated><title type='text'>URL Paths</title><summary type='text'>I mainly use the URL Paths function of the HTTP Proxy for blocking file extensions. Here is a list of extension that I deny:*.acf*.ade*.adp*.ani*.arj*.bas*.bat*.cab*.chm*.class*.cmd*.clp*.cpl*.cur*.dat*.dcr*.dif*.fav*.hhk*.hhp*.hlp*.ht*.hta*.htt*.htx*.hqx*.idc*.inf*.ins*.isp*.jar*.jav*.java*.job*.lnk*.m3u*.mad*.maf*.mam*.maq*.mar*.mat*.mcw*.mda*.mdb*.mde*.mdn*.mdt*.mdv*.mdw*.mht*.mnd*.mp3*.mpc*.</summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/114933670885078368/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=114933670885078368' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/114933670885078368'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/114933670885078368'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2006/06/url-paths.html' title='URL Paths'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-114690581833310607</id><published>2006-05-06T10:51:00.000+02:00</published><updated>2007-04-07T12:44:40.450+02:00</updated><title type='text'>Capra v0.1 Beta</title><summary type='text'>What is Capra:Capra is a Open Source tool to quickly get some nice and useful reports out off your Watchguard Fireware log files.Capra uses PHP and MySQL to accomplish this.Features:v0.1:1. Interface to import Fireware log files in to the MySQL database. (Only imports FWDeny messages.)2. Reports:Top 50 denied src IP's.Top 50 denied dst IP's.Top 50 denied src ports.Top 50 denied dst ports.Beta?:</summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/114690581833310607/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=114690581833310607' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/114690581833310607'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/114690581833310607'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2006/05/capra-v01-beta.html' title='Capra v0.1 Beta'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-114553416156417434</id><published>2006-04-20T13:40:00.000+02:00</published><updated>2006-04-20T13:56:02.013+02:00</updated><title type='text'>Authentication Solution's</title><summary type='text'>Wayne Campbell has writen a good article about ways to:1. Have users directed to login screen automatically when not logged in.2. Have a personalized login screen.3. Have users logged out automatically after x amount of time.You can read it here.</summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/114553416156417434/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=114553416156417434' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/114553416156417434'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/114553416156417434'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2006/04/authentication-solutions.html' title='Authentication Solution&apos;s'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-114315060735871444</id><published>2006-03-23T22:23:00.000+01:00</published><updated>2006-03-23T22:50:07.380+01:00</updated><title type='text'>Advanced Diagnostics</title><summary type='text'>You are having a problem with a new VPN connection you are trying to make. You just know you can do this yourself, you just need a little more information from your firebox logs. But they are not showing you the information you need.Do I really need to open a new incident for this?No.Open your "Fireware Policy Manager" and goto --&gt; Setup --&gt; Logging... --&gt; Click on the "Advanced Diagnostics" </summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/114315060735871444/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=114315060735871444' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/114315060735871444'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/114315060735871444'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2006/03/advanced-diagnostics.html' title='Advanced Diagnostics'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-114168579444862778</id><published>2006-03-06T23:41:00.000+01:00</published><updated>2006-03-07T00:09:04.853+01:00</updated><title type='text'>GAV &amp; ClamAV</title><summary type='text'>Do you have a virus that is not blocked by GAV.On the ClamAV website (http://www.clamav.net/) you can submit your sample (http://cgi.clamav.net/sendvirus.cgi) so one of the 'virus database maintainers' of the ClamAV project can make a anti-virus for it.The great benefit of submitting your sample to ClamAV is that you help out your fellow GAV/ClamAV users by doing so.</summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/114168579444862778/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=114168579444862778' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/114168579444862778'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/114168579444862778'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2006/03/gav-clamav.html' title='GAV &amp; ClamAV'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-114010999919496603</id><published>2006-02-16T17:33:00.000+01:00</published><updated>2006-02-16T18:13:19.230+01:00</updated><title type='text'>MS06-005 prevention</title><summary type='text'>Yesterday the security bulletin: MS06-005Today the exploit: WMP BMP Handling Buffer Overflow ExploitOff course the first solution is the patch. But if you did not yet have the time to test/deploy the patch you can use the following rules to protect your network.1. Go to the 'Body Content Types' of your HTTP-Proxy and add '%0x424D%*' as a pattern match with the 'Rule action' set to Deny, Alarm and</summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/114010999919496603/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=114010999919496603' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/114010999919496603'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/114010999919496603'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2006/02/ms06-005-prevention.html' title='MS06-005 prevention'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-113939478345198520</id><published>2006-02-08T11:17:00.000+01:00</published><updated>2006-02-08T11:33:03.463+01:00</updated><title type='text'>You better keep blocking WMF file's</title><summary type='text'>Microsoft has released a new security advisory describing a new vulnerability in older versions of Internet Explorer. Again a 'a specially crafted Windows Metafile (WMF) image' could allow remote code execution.Still using?:Internet Explorer 5.01 Service Pack 4 on Microsoft Windows 2000 Service Pack 4Internet Explorer 5.5 Service Pack 2 on Microsoft Windows Millennium.Then you better keep the </summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/113939478345198520/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=113939478345198520' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/113939478345198520'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/113939478345198520'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2006/02/you-better-keep-blocking-wmf-files.html' title='You better keep blocking WMF file&apos;s'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-113896268665765374</id><published>2006-02-03T11:20:00.000+01:00</published><updated>2006-02-03T12:35:28.536+01:00</updated><title type='text'>Body Content Type rules</title><summary type='text'>I have a nice virus collection on my test computer, looking at the headers of all those little critters I found out that the default "Windows EXE/DLL" "Body Content Type" rule is far from sufficient for blocking executable content. I think it was build to block ActiveX (in combination with the "Windows CAB archive" rule) and it does a reasonable good job at that.If you want to go further and also</summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/113896268665765374/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=113896268665765374' title='17 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/113896268665765374'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/113896268665765374'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2006/02/body-content-type-rules.html' title='Body Content Type rules'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>17</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-113693217710860873</id><published>2006-01-10T23:29:00.000+01:00</published><updated>2006-01-19T14:46:30.270+01:00</updated><title type='text'>Who needs .info/.biz, anyway?</title><summary type='text'>To quote the people from Sans.org:Who needs .info/.biz, anyway?I have blocked access to the *.info and *.biz TLD's at my watchguard firewall 4 months ago. I had to add 5 *.info domains to a whitelist but I got so much in return.In my blog about the 0-day wmf exploit I recommend the blocking of beehappyy.biz. Guess what showed up in my log's as being block by the 'block all *.biz websites' rule?</summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/113693217710860873/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=113693217710860873' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/113693217710860873'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/113693217710860873'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2006/01/who-needs-infobiz-anyway_10.html' title='Who needs .info/.biz, anyway?'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-113692905345839211</id><published>2006-01-10T22:21:00.000+01:00</published><updated>2006-01-11T14:45:14.453+01:00</updated><title type='text'>MS06-002 prevention (updated)</title><summary type='text'>As part of there regular patch cycle, Microsoft has release 2 security patches. MS06-002 describes a vulnerability in Embedded Web Fonts. These files can be blocked by your watchguard firewall.What can you do to protect your network:1. Go to the 'URL Path' function of your HTTP-Proxy and add '*.eot' as a pattern match with the 'Rule action' set to Deny, Alarm and Log.UPDATE:My 'Body Content Types</summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/113692905345839211/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=113692905345839211' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/113692905345839211'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/113692905345839211'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2006/01/ms06-002-prevention-updated.html' title='MS06-002 prevention (updated)'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-113614985458321650</id><published>2006-01-01T21:23:00.000+01:00</published><updated>2006-01-01T22:15:21.320+01:00</updated><title type='text'>WMF - The story continues</title><summary type='text'>Another WMF exploit has been release:http://isc.sans.org/diary.php?storyid=992http://www.frsirt.com/exploits/20051231.ie_xp_pfv_metafile.pm.phpUS-CERT (http://www.kb.cert.org/vuls/id/181038) is recommending to block the following byte sequences:0100090002000900D7CDC69AGo to the 'Body Content Types' function of your HTTP-Proxy and add '%0x01000900%*', '%0x02000900%*' and '%0xD7CDC69A%*' as a </summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/113614985458321650/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=113614985458321650' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/113614985458321650'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/113614985458321650'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2006/01/wmf-story-continues.html' title='WMF - The story continues'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-113576691014035135</id><published>2005-12-28T11:25:00.000+01:00</published><updated>2006-01-10T22:45:29.153+01:00</updated><title type='text'>Windows WMF 0-day exploit (updated)</title><summary type='text'>A 0-day exploit against the Windows Graphics Rendering Engine has been posted on Bugtraq. For more information see:http://isc.sans.org/diary.php?storyid=972http://www.securityfocus.com/bid/16074/infohttp://vil.mcafeesecurity.com/vil/content/v_137760.htmhttp://www.frsirt.com/exploits/20051228.ie_xp_pfv_metafile.pm.phpWhat can you do to protect your network:1. Go to the 'Body Content Types' of your</summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/113576691014035135/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=113576691014035135' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/113576691014035135'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/113576691014035135'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2005/12/windows-wmf-0-day-exploit-updated.html' title='Windows WMF 0-day exploit (updated)'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-113483112998912923</id><published>2005-12-17T15:19:00.000+01:00</published><updated>2005-12-18T14:30:33.630+01:00</updated><title type='text'>Webblocker &amp; Surfcontrol</title><summary type='text'>Do you have a website that is not blocked by the webblocker, but you think it should be based on your category settings?On the Surfcontrol website (http://mtas.surfcontrol.com/mtas/MTAS.asp) you can see the category of the website, and if it's not categorized, you can add the site to the database. If you update your webblocker database daily u will see it getting blocked in 2 to 4 days.The great </summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/113483112998912923/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=113483112998912923' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/113483112998912923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/113483112998912923'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2005/12/webblocker-surfcontrol.html' title='Webblocker &amp; Surfcontrol'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-113447971872511916</id><published>2005-12-13T14:01:00.000+01:00</published><updated>2005-12-13T14:15:18.733+01:00</updated><title type='text'>Sober</title><summary type='text'>Quote from http://isc.sans.org/diary.php?storyid=925 :You may have read from news that there will be a Sober worm attack on 5 Jan 06. This is due to the pre-programmed date of current Sober variant to activate on 5 Jan 06. The interesting part is that the Sober variant has the intelligence to create pseudorandom URLs which will change based on date. It also can synchronize the systems via atom </summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/113447971872511916/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=113447971872511916' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/113447971872511916'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/113447971872511916'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2005/12/sober.html' title='Sober'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-113423126602846485</id><published>2005-12-10T16:56:00.000+01:00</published><updated>2005-12-10T17:49:53.653+01:00</updated><title type='text'>Trouble with JS/Wounk-A</title><summary type='text'>Add "*s_ta_ts.js" as a pattern match to the "URL Paths" function of your HTTP proxy, and set it to deny.I see it getting block almost 2 times a week. This saved me allot of phone calls.Off course most off the times this would not work but for some unknown reason JS/Wounk-A always goes by the name s_ta_ts.js.More information on JS/Wounk-A can be found here http://www.sophos.com/virusinfo/analyses/</summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/113423126602846485/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=113423126602846485' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/113423126602846485'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/113423126602846485'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2005/12/trouble-with-jswounk.html' title='Trouble with JS/Wounk-A'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19749459.post-113422998942781756</id><published>2005-12-10T16:45:00.000+01:00</published><updated>2005-12-10T16:53:09.436+01:00</updated><title type='text'>Use your Watchguard firewall to the max</title><summary type='text'>This blog is to help users of the Watchguard firewall to use all of its function to there max.I hope it is to some use.</summary><link rel='replies' type='application/atom+xml' href='http://watchguardtricks.blogspot.com/feeds/113422998942781756/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19749459&amp;postID=113422998942781756' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/113422998942781756'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19749459/posts/default/113422998942781756'/><link rel='alternate' type='text/html' href='http://watchguardtricks.blogspot.com/2005/12/use-your-watchguard-firewall-to-max.html' title='Use your Watchguard firewall to the max'/><author><name>Placebo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>5</thr:total></entry></feed>
