<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Singature for Jabber tcp/2748 in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78223#M69</link>
    <description>&lt;P&gt;Hi, I try to create a custom signature for Jabber CTI (&lt;A href="http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/port/9_0_1/CUCM_BK_T98E8963_00_tcp-port-usage-guide-90/CUCM_BK_T98E8963_00_tcp-port-usage-guide-90_chapter_01.html)" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/port/9_0_1/CUCM_BK_T98E8963_00_tcp-port-usage-guide-90/CUCM_BK_T98E8963_00_tcp-port-usage-guide-90_chapter_01.html)&lt;/A&gt; running on port 2748.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The packet dump give me this result for the client request:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;5e 00 00 00 00 00 00 00 dd dd ff ff 00 00 0f 00 ^....... ........&lt;BR /&gt;36 01 00 00 20 00 00 00 24 00 00 00 22 00 00 00 6... ... $..."...&lt;BR /&gt;01 00 00 00 44 00 00 00 0b 00 00 00 4f 00 00 00 ....D... ....O...&lt;BR /&gt;04 00 00 00 53 00 00 00 07 00 00 00 5a 00 00 00 ....S... ....Z...&lt;BR /&gt;0c 00 00 00 55 43 50 72 6f 76 69 64 65 72 00 31 ....UCPr ovider.1&lt;BR /&gt;2e 30 00 53 68 69 62 75 69 00 43 69 73 63 6f 20 .0.Shibu i.Cisco &lt;BR /&gt;4a 54 41 50 49 00 JTAPI.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;and I want to intercept the string "&lt;SPAN&gt;&lt;FONT color="#0000FF"&gt;&lt;STRONG&gt;UCProvider 1.0&lt;/STRONG&gt;&lt;/FONT&gt;"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I tried with a signatures with:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;parent App: &lt;STRONG&gt;jabber&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;port: &lt;STRONG&gt;tcp/2748&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Signature: &lt;STRONG&gt;Pattern Match&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Scope: &lt;STRONG&gt;Session&lt;/STRONG&gt; (&lt;EM&gt;also I tried with &lt;STRONG&gt;Transaction&lt;/STRONG&gt;&lt;/EM&gt; )&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Context: &lt;STRONG&gt;unknown-req-tcp-payload&lt;/STRONG&gt; (&lt;EM&gt;also I tried with&amp;nbsp;&lt;STRONG&gt;unknown-rsp-tcp-payload&lt;/STRONG&gt;&lt;/EM&gt; )&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Pattern:&amp;nbsp;&lt;EM&gt;follow all the patterns that I've tried, one for a time...&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;UCProvider 1.0&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;\x&amp;nbsp;55 43 50 72 6f 76 69 64 65 72 20 31 2e 30 \x&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;BUT NOT WORK everytime unknown-tcp or insufficent-data result on traffic monitor&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;How can resolve this problem without write a policies with any in&amp;nbsp;application and a custom service (tcp/2748) ???&lt;/FONT&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;thank you&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 17 May 2016 14:12:46 GMT</pubDate>
    <dc:creator>RepartoSistemi</dc:creator>
    <dc:date>2016-05-17T14:12:46Z</dc:date>
    <item>
      <title>Singature for Jabber tcp/2748</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78223#M69</link>
      <description>&lt;P&gt;Hi, I try to create a custom signature for Jabber CTI (&lt;A href="http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/port/9_0_1/CUCM_BK_T98E8963_00_tcp-port-usage-guide-90/CUCM_BK_T98E8963_00_tcp-port-usage-guide-90_chapter_01.html)" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/port/9_0_1/CUCM_BK_T98E8963_00_tcp-port-usage-guide-90/CUCM_BK_T98E8963_00_tcp-port-usage-guide-90_chapter_01.html)&lt;/A&gt; running on port 2748.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The packet dump give me this result for the client request:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;5e 00 00 00 00 00 00 00 dd dd ff ff 00 00 0f 00 ^....... ........&lt;BR /&gt;36 01 00 00 20 00 00 00 24 00 00 00 22 00 00 00 6... ... $..."...&lt;BR /&gt;01 00 00 00 44 00 00 00 0b 00 00 00 4f 00 00 00 ....D... ....O...&lt;BR /&gt;04 00 00 00 53 00 00 00 07 00 00 00 5a 00 00 00 ....S... ....Z...&lt;BR /&gt;0c 00 00 00 55 43 50 72 6f 76 69 64 65 72 00 31 ....UCPr ovider.1&lt;BR /&gt;2e 30 00 53 68 69 62 75 69 00 43 69 73 63 6f 20 .0.Shibu i.Cisco &lt;BR /&gt;4a 54 41 50 49 00 JTAPI.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;and I want to intercept the string "&lt;SPAN&gt;&lt;FONT color="#0000FF"&gt;&lt;STRONG&gt;UCProvider 1.0&lt;/STRONG&gt;&lt;/FONT&gt;"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I tried with a signatures with:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;parent App: &lt;STRONG&gt;jabber&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;port: &lt;STRONG&gt;tcp/2748&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Signature: &lt;STRONG&gt;Pattern Match&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Scope: &lt;STRONG&gt;Session&lt;/STRONG&gt; (&lt;EM&gt;also I tried with &lt;STRONG&gt;Transaction&lt;/STRONG&gt;&lt;/EM&gt; )&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Context: &lt;STRONG&gt;unknown-req-tcp-payload&lt;/STRONG&gt; (&lt;EM&gt;also I tried with&amp;nbsp;&lt;STRONG&gt;unknown-rsp-tcp-payload&lt;/STRONG&gt;&lt;/EM&gt; )&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Pattern:&amp;nbsp;&lt;EM&gt;follow all the patterns that I've tried, one for a time...&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;UCProvider 1.0&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;\x&amp;nbsp;55 43 50 72 6f 76 69 64 65 72 20 31 2e 30 \x&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;BUT NOT WORK everytime unknown-tcp or insufficent-data result on traffic monitor&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;How can resolve this problem without write a policies with any in&amp;nbsp;application and a custom service (tcp/2748) ???&lt;/FONT&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;thank you&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2016 14:12:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78223#M69</guid>
      <dc:creator>RepartoSistemi</dc:creator>
      <dc:date>2016-05-17T14:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: Singature for Jabber tcp/2748</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78225#M70</link>
      <description>&lt;P&gt;Good morning.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My skillset is more around writing threat signatures (vulnerability and anti-spyware) rather than application signatures. However, if you provide a packet capture of some sample traffic you'd like to identify, this would likely be helpful, as many folks with varying skillsets frequent this forum. In order to test any of our ideas, having a packet capture&amp;nbsp;of some sample traffic to replay in our lab environments would help to lead towards resolution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this possible?&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2016 14:36:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78225#M70</guid>
      <dc:creator>rcole</dc:creator>
      <dc:date>2016-05-17T14:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: Singature for Jabber tcp/2748</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78226#M71</link>
      <description>&lt;P&gt;Yes it's possible, but I cannot attach the pcap file on my post.&lt;BR /&gt;Perhaps a account limitation ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2016 14:47:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78226#M71</guid>
      <dc:creator>RepartoSistemi</dc:creator>
      <dc:date>2016-05-17T14:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: Singature for Jabber tcp/2748</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78230#M72</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="download.jpg" style="width: 225px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4062i9E90FC0854CD5F1C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="download.jpg" alt="download.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;Ok bypass the limitation&lt;/P&gt;
&lt;P&gt;-Download this file.&lt;/P&gt;
&lt;P&gt;-Rename it to download.rar&lt;/P&gt;
&lt;P&gt;-Exctract two file (a unusefull jpg, and the dump file)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The dump it's take from my Desktop (192.168.3.117) when jabber login to remote server (192.168.32.40)&lt;/P&gt;
&lt;P&gt;I send only the first transaction packet because inside the other packet I have in cleartext some reserved information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Max&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2016 15:02:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78230#M72</guid>
      <dc:creator>RepartoSistemi</dc:creator>
      <dc:date>2016-05-17T15:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: Singature for Jabber tcp/2748</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78238#M73</link>
      <description>&lt;P&gt;Thank you. That was a creative work around.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One thing I've noticed is that the data pattern you are matching on is not present in the packet capture (or the excerpt from your initial post).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your pattern is:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;\x 55 43 50 72 6f 76 69 64 65 72 20 31 2e 30 \x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, the pattern in the packet capture and your excerpt is as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;\x 55 43 50 72 6f 76 69 64 65 72 00 31 2e 30 \x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note that the 11th byte in your pattern is 20 (a space). The actual byte is a null byte (00).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This may be a good place to start troubleshooting, if I have not overlooked anything.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Respectfully,&lt;/P&gt;
&lt;P&gt;- rcole&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2016 15:55:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78238#M73</guid>
      <dc:creator>rcole</dc:creator>
      <dc:date>2016-05-17T15:55:43Z</dc:date>
    </item>
    <item>
      <title>Re: Singature for Jabber tcp/2748</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78366#M76</link>
      <description>&lt;P&gt;Ok RCole, I went in deep.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After change the signature Palo Alto recognize logoff process as&amp;nbsp;Cisco Jabber (cti_cisco) application, but for the login process the result is "insufficent-data".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Summary of example transaction:&lt;/P&gt;
&lt;P&gt;CISCO Jabber logoff =&amp;gt; tcp.src 51084 tcp.dst 2748&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;CISCO Jabber login =&amp;gt; tcp.src 51351 tcp.dst 2748&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thake a look of this picture:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="capture03.JPG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4080i3E282542FC4B16EF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="capture03.JPG" alt="capture03.JPG" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="capture03-logoff.JPG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4082i3D6BBE131EE9361D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="capture03-logoff.JPG" alt="capture03-logoff.JPG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="capture03-login.JPG" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4083iC614331ED20657F6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="capture03-login.JPG" alt="capture03-login.JPG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And you know something even stranger?&lt;/P&gt;
&lt;P&gt;Take a look on the logoff/login process from the following tcpdump:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="download.jpg" style="width: 225px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4084i22F2312FC74F5FD7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="download.jpg" alt="download.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;On the logoff process we dont have any byte like our singature, and this is RECOGNISED as&amp;nbsp;cti_cisco, instead on the login process we have some byte equal the singature, and this is NOT&amp;nbsp;recognized, it's insufficend-data.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;?????????&lt;/P&gt;
&lt;P&gt;Crazy!&amp;nbsp;I get hold of the wrong end of the stick ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2016 10:37:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78366#M76</guid>
      <dc:creator>RepartoSistemi</dc:creator>
      <dc:date>2016-05-19T10:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: Singature for Jabber tcp/2748</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78390#M78</link>
      <description>&lt;P&gt;Good morning! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would it be possible for you to export and attach the signature you've created so far so I can inspect it?&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2016 15:23:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78390#M78</guid>
      <dc:creator>rcole</dc:creator>
      <dc:date>2016-05-19T15:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: Singature for Jabber tcp/2748</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78393#M79</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="download.jpg" style="width: 225px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4089i347FB856918B1360/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="download.jpg" alt="download.jpg" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I try combination of:&lt;/P&gt;
&lt;P&gt;-both CONDITION in OR or in AND&lt;/P&gt;
&lt;P&gt;-SCOPE as Transaction or Session&lt;/P&gt;
&lt;P&gt;-Context Unknown-req-tcp-payload or telnet-req-client-data&lt;/P&gt;
&lt;P&gt;-Ordered Condition Match flagged or not flagged.&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2016 15:33:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78393#M79</guid>
      <dc:creator>RepartoSistemi</dc:creator>
      <dc:date>2016-05-19T15:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: Singature for Jabber tcp/2748</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78395#M80</link>
      <description>&lt;P&gt;Thank you for the complete packet capture! However, what I'm hoping for is the actual signature you've written. Can you export it from the firewall and upload it here? Additionally, .RAR and .PCAP formats should no longer require you to obfuscate them to upload.&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2016 17:56:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78395#M80</guid>
      <dc:creator>rcole</dc:creator>
      <dc:date>2016-05-19T17:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: Singature for Jabber tcp/2748</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78411#M81</link>
      <description>&lt;P&gt;Sorry I had atteched a worg file, this is the current signatures xml.&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2016 15:07:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78411#M81</guid>
      <dc:creator>RepartoSistemi</dc:creator>
      <dc:date>2016-05-23T15:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: Singature for Jabber tcp/2748</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78515#M83</link>
      <description>&lt;P&gt;Good morning!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It appears that this may be a limitation of the current custom signature engine. I've confirmed with some peers that unknown-xxx applications require a specific amount of traffic in order to begin&amp;nbsp;matching against custom signatures.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This knowledge base article will assist:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Not-Applicable-Incomplete-Insufficient-Data-in-the-Application/ta-p/65711" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Not-Applicable-Incomplete-Insufficient-Data-in-the-Application/ta-p/65711&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue here appears to be that there is not enough data occurring in the session for the custom signature engine to begin matching against unknown-tcp.&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2016 16:06:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78515#M83</guid>
      <dc:creator>rcole</dc:creator>
      <dc:date>2016-05-23T16:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: Singature for Jabber tcp/2748</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78557#M92</link>
      <description>&lt;P&gt;Ok we hope will a version with a fix.&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 07:27:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/singature-for-jabber-tcp-2748/m-p/78557#M92</guid>
      <dc:creator>RepartoSistemi</dc:creator>
      <dc:date>2016-05-24T07:27:43Z</dc:date>
    </item>
  </channel>
</rss>

