<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Signature for Clash of Clans game in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/signature-for-clash-of-clans-game/m-p/78983#M98</link>
    <description>&lt;P&gt;I use this signature to positively identify the application as&amp;nbsp;the firewall policy is configured to&amp;nbsp;block all unknown-tcp and unknown-udp.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-David&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Jun 2016 22:37:44 GMT</pubDate>
    <dc:creator>david3</dc:creator>
    <dc:date>2016-06-01T22:37:44Z</dc:date>
    <item>
      <title>Signature for Clash of Clans game</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/signature-for-clash-of-clans-game/m-p/78827#M93</link>
      <description>&lt;P&gt;I built the attached&amp;nbsp;custom application signature for the Clash of Clans game (previously identified as unknown-tcp) based on taking multiple pcaps and finding the first 7 bytes of the first 4 data packets appear to be constant across sessions. However, I have a rather limited test bed of one iPad accessing one clan at this time. Comments and refinements welcome.&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2016 15:49:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/signature-for-clash-of-clans-game/m-p/78827#M93</guid>
      <dc:creator>david3</dc:creator>
      <dc:date>2016-05-31T15:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: Signature for Clash of Clans game</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/signature-for-clash-of-clans-game/m-p/78980#M97</link>
      <description>&lt;P&gt;are you trying to identify and block this app? or.... ?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2016 22:16:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/signature-for-clash-of-clans-game/m-p/78980#M97</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2016-06-01T22:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: Signature for Clash of Clans game</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/signature-for-clash-of-clans-game/m-p/78983#M98</link>
      <description>&lt;P&gt;I use this signature to positively identify the application as&amp;nbsp;the firewall policy is configured to&amp;nbsp;block all unknown-tcp and unknown-udp.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-David&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2016 22:37:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/signature-for-clash-of-clans-game/m-p/78983#M98</guid>
      <dc:creator>david3</dc:creator>
      <dc:date>2016-06-01T22:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: Signature for Clash of Clans game</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/signature-for-clash-of-clans-game/m-p/79039#M102</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also recently created a signature to identify that game. First, the protocol used is common to all Supercell games, not just Clash of Clans. I haven't seen a way yet to differentiate between the different games (not that I care about that). My signature was pretty similar to yours at first, but sometimes it would not match, like when an Android user needs to install an update for the game. I also sometimes&amp;nbsp;see UDP traffic on the same port, after the game connects using TCP. I haven't been able to reproduce that traffic on my iPhone though. I suspect the UDP traffic is only used on Android clients. Also, I don't see any repeating pattern in it, probably because the negotiation happens in the TCP stream. I will try to get my hands on an Android device to reproduce the traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2016 20:33:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/signature-for-clash-of-clans-game/m-p/79039#M102</guid>
      <dc:creator>BenjAudy.MTL</dc:creator>
      <dc:date>2016-06-02T20:33:54Z</dc:date>
    </item>
  </channel>
</rss>

