<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Creating custom signatures in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/creating-custom-signatures/m-p/45075#M1034</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Lewis and mmarceli,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are partially correct. The pattern match&amp;nbsp; with the context http-req-uri-path should contain only the path after the domain name.&amp;nbsp; In the example above it may be a bit confusing.&amp;nbsp; If you want to block all connections to URLs containing /babykit.html then you probably should have a pattern of&amp;nbsp; /babykit\.html&amp;nbsp;&amp;nbsp; since the "." is a wildcard character the "\" preceding it indicates that we want to match against a period "."&amp;nbsp;&amp;nbsp; The action for the signature would be a reset probably.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Nov 2014 19:23:16 GMT</pubDate>
    <dc:creator>HITSSEC</dc:creator>
    <dc:date>2014-11-13T19:23:16Z</dc:date>
    <item>
      <title>Creating custom signatures</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/creating-custom-signatures/m-p/45073#M1032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a way to create a signature to block or alert as referenced by this website...&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=27208" style="font-size: 10pt; line-height: 1.5em;" title="http://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=27208"&gt;http://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=27208&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The sample url comes from the link below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://l.facebook.com/l/8AQEvKJix/christmasoffers.org/babykit.html" title="http://l.facebook.com/l/8AQEvKJix/christmasoffers.org/babykit.html"&gt;http://l.facebook.com/l/8AQEvKJix/christmasoffers.org/babykit.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this signature is already in the latest updates, please let us know.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Nov 2014 21:23:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/creating-custom-signatures/m-p/45073#M1032</guid>
      <dc:creator>mmarceli</dc:creator>
      <dc:date>2014-11-12T21:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: Creating custom signatures</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/creating-custom-signatures/m-p/45074#M1033</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could create a custom vulnerability signature, in this case for &lt;A href="http://l.facebook.com/l/8AQEvKJix/christmasoffers.org/babykit.html" rel="nofollow" style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #006595;" title="http://l.facebook.com/l/8AQEvKJix/christmasoffers.org/babykit.html"&gt;http://l.facebook.com/l/8AQEvKJix/christmasoffers.org/babykit.html&lt;/A&gt; you could accomplish it by creating a http-req-uri-path signature with christmasoffers.org/babykit.html&lt;/P&gt;&lt;P&gt;&lt;IMG alt="test.PNG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16859_test.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Nov 2014 16:08:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/creating-custom-signatures/m-p/45074#M1033</guid>
      <dc:creator>lewis</dc:creator>
      <dc:date>2014-11-13T16:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: Creating custom signatures</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/creating-custom-signatures/m-p/45075#M1034</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Lewis and mmarceli,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are partially correct. The pattern match&amp;nbsp; with the context http-req-uri-path should contain only the path after the domain name.&amp;nbsp; In the example above it may be a bit confusing.&amp;nbsp; If you want to block all connections to URLs containing /babykit.html then you probably should have a pattern of&amp;nbsp; /babykit\.html&amp;nbsp;&amp;nbsp; since the "." is a wildcard character the "\" preceding it indicates that we want to match against a period "."&amp;nbsp;&amp;nbsp; The action for the signature would be a reset probably.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Nov 2014 19:23:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/creating-custom-signatures/m-p/45075#M1034</guid>
      <dc:creator>HITSSEC</dc:creator>
      <dc:date>2014-11-13T19:23:16Z</dc:date>
    </item>
  </channel>
</rss>

