Skip to main content
Fullmoon
New Member
November 19, 2014
Solved

how to add new signature

  • November 19, 2014
  • 3 replies
  • 17327 views

hi fellas,

 

im out of direction, how to add custom signatures? im running on fortios 5.2.1 and I want add signature thats block Psiphon3.

current version cant block the said application.

 

 

Regards,

    Best answer by Dave_Hall

    Fullmoon wrote:

    hi paulo thanks for the quick response.

    [...] Seems cant find my self on how to add the said signatures.

     

    Use the config ips custom setting from the CLI.  Also, people have posted examples, such as this one by emnoc (he has a nice tutorial on his blog).

     

    3 replies

    pcraponi
    New Member
    November 19, 2014

    Start here: http://video.fortinet.com/video/81/create-custom-ips-signatures-to-block-attacks

     

    and here: http://video.fortinet.com/uploads/documents/IPS%20Signature%20Syntax%20Guide.pdf

     

    If exist a signature that does not work currently, it's more easy you open a ticket with IPS/AppCtrl team...

     

     

    Regards,

    Paulo

    Fullmoon
    FullmoonAuthor
    New Member
    November 19, 2014

    hi paulo thanks for the quick response.

    I saw the video you provided and have the signatures already. Seems cant find my self on how to add the said signatures.

     

    here's the signatures

     

    F-SBID( --protocol tcp; --flow from_client; --dst_port :1000; --seq >,24,relative; --seq <,8220,relative; --pattern !"|17 03|"; --context packet; --within 2,context; --pattern !"|16 03|"; --context packet; --within 2,context; --pattern !"|00 00 00|"; --context packet; --within 37,context; --data_size =37; --tag test,Tag.Psiphon.SSH+.21.test; --app_cat 6; ) F-SBID( --protocol tcp; --seq =,1,relative; --service http; --flow from_client; --pattern "POST / HTTP/1.1"; --context packet; --within 15,context; --pattern "Host: "; --context packet; --distance 0; --pcre "/[\d]{1,3}\.[\d]{1,3}\.[\d]{1,3}\.[\d]{1,3}/"; --distance 0; --within 15; --pattern "|3a|"; --context packet; --within 3; --pattern !"User-Agent"; --context packet; --no_case; --pattern "Accept-Encoding: gzip"; --context packet; --no_case; --data_size >24; --app_cat 6; ) F-SBID( --protocol tcp; --service http; --flow from_client; --pattern ".psiphon3."; --context host; --no_case; --app_cat 6; )

     

    Dave_Hall
    Dave_HallAnswer
    New Member
    November 19, 2014

    Fullmoon wrote:

    hi paulo thanks for the quick response.

    [...] Seems cant find my self on how to add the said signatures.

     

    Use the config ips custom setting from the CLI.  Also, people have posted examples, such as this one by emnoc (he has a nice tutorial on his blog).

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.