<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: signature based http-req-message-body in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/signature-based-http-req-message-body/m-p/537446#M466</link>
    <description>&lt;P&gt;You may see this post for how to try regex match &lt;A href="https://live.paloaltonetworks.com/t5/custom-signatures/custom-vulnerability-to-block-old-browser-versions/td-p/518666" target="_blank"&gt;https://live.paloaltonetworks.com/t5/custom-signatures/custom-vulnerability-to-block-old-browser-versions/td-p/518666&lt;/A&gt; as the regex match should be added in ( ).&lt;/P&gt;</description>
    <pubDate>Mon, 03 Apr 2023 14:12:05 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2023-04-03T14:12:05Z</dc:date>
    <item>
      <title>signature based http-req-message-body</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/signature-based-http-req-message-body/m-p/536780#M464</link>
      <description>&lt;P&gt;HI all,&lt;/P&gt;
&lt;P&gt;I'm trying to create a custom signature based on the POST payload the client is sending.&lt;/P&gt;
&lt;P&gt;This is the POST collected from the server:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;POST /pds HTTP/1.1
Accept: application/x-ms-application, image/jpeg, application/xaml+xml, image/gif, image/pjpeg, application/x-ms-xbap, */*
Referer: https://aaa.com.cn
Accept-Language: zh-CN
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/7.0)
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip, deflate
Host: aaa.com.cn
Content-Length: 276
Connection: Keep-Alive
Cache-Control: no-cache
X-Forwarded-Proto:https
Cookie: __Secure-UqZBpD3n3keyY3Yp6VvxpmySSbQF5o9Gf5ec6w__=v1FKp4gw__Zls


func=login&amp;amp;calling_system=primo&amp;amp;term1=short&amp;amp;institute=12ABC&amp;amp;selfreg=&amp;amp;bor_id=1&amp;amp;bor_verification=1&amp;amp;url=http%3A%2F%2Faaa.com.cn%2Ftransition%3FtargetUrl%3Dhttp%253A%252F%252Faaa.com.cn%252Fhelp%252Fcontent%253Fid%253DmyLibrary&lt;/LI-CODE&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;I am trying to create a signature that will alert each time the payload contains:&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;"func=login&amp;amp;calling_system=primo&amp;amp;term1=short&amp;amp;institute="&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;Can you guide me through the configuration?&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;Thanks in advanced,&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;Noam.&lt;/P&gt;
&lt;P style="-qt-block-indent: 0; text-indent: 0px; margin: 0px;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="body.png" style="width: 959px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49064i2DDE834BF45B107C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="body.png" alt="body.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 10:37:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/signature-based-http-req-message-body/m-p/536780#M464</guid>
      <dc:creator>NoamRotter</dc:creator>
      <dc:date>2023-03-28T10:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: signature based http-req-message-body</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/signature-based-http-req-message-body/m-p/537446#M466</link>
      <description>&lt;P&gt;You may see this post for how to try regex match &lt;A href="https://live.paloaltonetworks.com/t5/custom-signatures/custom-vulnerability-to-block-old-browser-versions/td-p/518666" target="_blank"&gt;https://live.paloaltonetworks.com/t5/custom-signatures/custom-vulnerability-to-block-old-browser-versions/td-p/518666&lt;/A&gt; as the regex match should be added in ( ).&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 14:12:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/signature-based-http-req-message-body/m-p/537446#M466</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-04-03T14:12:05Z</dc:date>
    </item>
  </channel>
</rss>

