<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How would I create a custom threat signature that looks for a server's &amp;quot;invalid username&amp;quot; response to a failed login attempt? in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-would-i-create-a-custom-threat-signature-that-looks-for-a/m-p/10949#M300</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="p1"&gt;Hi,&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;I'm new to Palo Alto and custom threat signatures. I'm trying to detect invalid login attempts to a web site and apply a time rate. When the user enters an invalid username in the login, the site returns the text "invalid username". Which context would I use to search for this pattern match? I read the "Creating Custom Signatures" document, but it created more questions and I can't seem to find any deeper documentation. By using that document, I was able to use the wordpress brute force combination signature they included (monitoring http POST to wp-login.php), but I have some users that trip those thresholds often because they log into many blogs simultaneously on one server. I'm looking for something a little more granular (not just login attempts (good or bad), but bad attempts based on the site returning the text "bad password", or "invalid username". Is this possible? I don't mind reading more documentation regarding custom signatures if it's available, I've just not seen any other documents yet that give an example like this.&lt;/P&gt;&lt;P class="p2"&gt;&lt;/P&gt;&lt;P class="p1"&gt;I did take a pcap of the exchange between client and server. I see the text in the pcap, but still not sure which context to use to search for the string. The client sends an http POST to wp-login.php, and then the server issues an http 200 response and then the "Invalid username" text comes a few packets later. Below is the TCP stream from the pcap that contains the "Invalid username" text. I've tried the http_rsp_headers and file_html_body contexts, but still unable to match the text in the exchange.&lt;/P&gt;&lt;P class="p2"&gt;&lt;/P&gt;&lt;P class="p1"&gt;Thanks! &lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;POST /login/ HTTP/1.1&lt;/P&gt;&lt;P class="p1"&gt;Host: www.mysite.com&lt;/P&gt;&lt;P class="p1"&gt;Connection: keep-alive&lt;/P&gt;&lt;P class="p1"&gt;Content-Length: 164&lt;/P&gt;&lt;P class="p1"&gt;Cache-Control: max-age=0&lt;/P&gt;&lt;P class="p1"&gt;Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8&lt;/P&gt;&lt;P class="p3"&gt;&lt;SPAN class="s1"&gt;Origin: &lt;A href="http://www.mysite.com/"&gt;&lt;SPAN class="s2"&gt;http://www.mysite.com&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.146 Safari/537.36&lt;/P&gt;&lt;P class="p1"&gt;Content-Type: application/x-www-form-urlencoded&lt;/P&gt;&lt;P class="p3"&gt;&lt;SPAN class="s1"&gt;Referer: &lt;A href="http://www.mysite.com/login/"&gt;&lt;SPAN class="s2"&gt;http://www.mysite.com/login/&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;Accept-Encoding: gzip,deflate,sdch&lt;/P&gt;&lt;P class="p1"&gt;Accept-Language: en-US,en;q=0.8&lt;/P&gt;&lt;P class="p1"&gt;Cookie: wlp_post_protection=1; PHPSESSID=gh0pdah82shb6les906pc5n4u7; __utma=74238163.586482511.1393824836.1393824836.1393824836.1; __utmc=74238163; __utmz=74238163.1393824836.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=217530694.1368975606.1393822044.1393822044.1393886113.2; __utmc=217530694; __utmz=217530694.1393822044.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wfvt_345498598=531583af83045; wordpress_test_cookie=WP+Cookie+check&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;log=ed&amp;amp;pwd=ed&amp;amp;cptch_result=87Q%3D&amp;amp;cptch_time=1393918888&amp;amp;cptch_number=6&amp;amp;wp-submit=Log+In&amp;amp;redirect_to=http%3A%2F%2Fwww.mysite.com%2Fwp-admin%2F&amp;amp;testcookie=1HTTP/1.1 200 OK&lt;/P&gt;&lt;P class="p1"&gt;Date: Tue, 04 Mar 2014 07:44:02 GMT&lt;/P&gt;&lt;P class="p1"&gt;Server: Apache/2.2.15 (CentOS)&lt;/P&gt;&lt;P class="p1"&gt;X-Powered-By: PHP/5.3.3&lt;/P&gt;&lt;P class="p1"&gt;Set-Cookie: wfvt_345498598=5315844284ba8; expires=Tue, 04-Mar-2014 08:14:02 GMT; path=/&lt;/P&gt;&lt;P class="p1"&gt;Expires: Thu, 19 Nov 1981 08:52:00 GMT&lt;/P&gt;&lt;P class="p1"&gt;Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0&lt;/P&gt;&lt;P class="p1"&gt;Pragma: no-cache&lt;/P&gt;&lt;P class="p1"&gt;Set-Cookie: wordpress_test_cookie=WP+Cookie+check; path=/&lt;/P&gt;&lt;P class="p1"&gt;X-Frame-Options: SAMEORIGIN&lt;/P&gt;&lt;P class="p1"&gt;Content-Length: 4373&lt;/P&gt;&lt;P class="p1"&gt;Connection: close&lt;/P&gt;&lt;P class="p1"&gt;Content-Type: text/html; charset=UTF-8&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;!DOCTYPE html&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;!--[if IE 8]&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;html xmlns="&lt;A href="http://www.w3.org/1999/xhtml"&gt;http://www.w3.org/1999/xhtml&lt;/A&gt;" class="ie8" lang="en-US"&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;![endif]--&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;!--[if !(IE &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; ]&amp;gt;&amp;lt;!--&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;html xmlns="&lt;A href="http://www.w3.org/1999/xhtml"&gt;http://www.w3.org/1999/xhtml&lt;/A&gt;" lang="en-US"&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;!--&amp;lt;![endif]--&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;head&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;title&amp;gt;mysite www &amp;amp;rsaquo; Log In&amp;lt;/title&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;link rel='stylesheet' id='open-sans-css'&amp;nbsp; href='//fonts.googleapis.com/css?family=Open+Sans%3A300italic%2C400italic%2C600italic%2C300%2C400%2C600&amp;amp;#038;subset=latin%2Clatin-ext&amp;amp;#038;ver=3.8.1' type='text/css' media='all' /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;link rel='stylesheet' id='dashicons-css'&amp;nbsp; href='&lt;A href="http://www.mysite.com/wp-includes/css/dashicons.min.css?ver=3.8.1"&gt;http://www.mysite.com/wp-includes/css/dashicons.min.css?ver=3.8.1&lt;/A&gt;' type='text/css' media='all' /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;link rel='stylesheet' id='wp-admin-css'&amp;nbsp; href='&lt;A href="http://www.mysite.com/wp-admin/css/wp-admin.min.css?ver=3.8.1"&gt;http://www.mysite.com/wp-admin/css/wp-admin.min.css?ver=3.8.1&lt;/A&gt;' type='text/css' media='all' /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;link rel='stylesheet' id='buttons-css'&amp;nbsp; href='&lt;A href="http://www.mysite.com/wp-includes/css/buttons.min.css?ver=3.8.1"&gt;http://www.mysite.com/wp-includes/css/buttons.min.css?ver=3.8.1&lt;/A&gt;' type='text/css' media='all' /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;link rel='stylesheet' id='colors-fresh-css'&amp;nbsp; href='&lt;A href="http://www.mysite.com/wp-admin/css/colors.min.css?ver=3.8.1"&gt;http://www.mysite.com/wp-admin/css/colors.min.css?ver=3.8.1&lt;/A&gt;' type='text/css' media='all' /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;!--[if lte IE 7]&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;link rel='stylesheet' id='ie-css'&amp;nbsp; href='&lt;A href="http://www.mysite.com/wp-admin/css/ie.min.css?ver=3.8.1"&gt;http://www.mysite.com/wp-admin/css/ie.min.css?ver=3.8.1&lt;/A&gt;' type='text/css' media='all' /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;![endif]--&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;meta name='robots' content='noindex,follow' /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;script type="text/javascript"&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;addLoadEvent = function(func){if(typeof jQuery!="undefined")jQuery(document).ready(func);else if(typeof wpOnload!='function'){wpOnload=func;}else{var oldonload=wpOnload;wpOnload=function(){oldonload();func();}}};&lt;/P&gt;&lt;P class="p1"&gt;function s(id,pos){g(id).left=pos+'px';}&lt;/P&gt;&lt;P class="p1"&gt;function g(id){return document.getElementById(id).style;}&lt;/P&gt;&lt;P class="p1"&gt;function shake(id,a,d){c=a.shift();s(id,c);if(a.length&amp;gt;0){setTimeout(function(){shake(id,a,d);},d);}else{try{g(id).position='static';wp_attempt_focus();}catch(e){}}}&lt;/P&gt;&lt;P class="p1"&gt;addLoadEvent(function(){ var p=new Array(15,30,15,0,-15,-30,-15,0);p=p.concat(p.concat(p));var i=document.forms[0].id;g(i).position='relative';shake(i,p,20);});&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;/script&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;/head&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;body class="login login-action-login wp-core-ui"&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;div id="login"&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;h1&amp;gt;&amp;lt;a href="&lt;A href="http://wordpress.org/"&gt;http://wordpress.org/&lt;/A&gt;" title="Powered by WordPress"&amp;gt;mysite www&amp;lt;/a&amp;gt;&amp;lt;/h1&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;div id="login_error"&amp;gt; &amp;lt;strong&amp;gt;ERROR&amp;lt;/strong&amp;gt;: Invalid username. &amp;lt;a href="&lt;A href="http://www.mysite.com/login/?action=lostpassword"&gt;http://www.mysite.com/login/?action=lostpassword&lt;/A&gt;" title="Password Lost and Found"&amp;gt;Lost your password&amp;lt;/a&amp;gt;?&amp;lt;br /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;/div&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;form name="loginform" id="loginform" action="&lt;A href="http://www.mysite.com/login/"&gt;http://www.mysite.com/login/&lt;/A&gt;" method="post"&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;p&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;label for="user_login"&amp;gt;Username&amp;lt;br /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;input type="text" name="log" id="user_login" class="input" value="" size="20" /&amp;gt;&amp;lt;/label&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;/p&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;p&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;label for="user_pass"&amp;gt;Password&amp;lt;br /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;input type="password" name="pwd" id="user_pass" class="input" value="" size="20" /&amp;gt;&amp;lt;/label&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;/p&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;p class="cptch_block"&amp;gt;&amp;lt;br /&amp;gt; &amp;lt;input type="hidden" name="cptch_result" value="hIE=" /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;input type="hidden" name="cptch_time" value="1393919042" /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;input type="hidden" value="Version: 2.4" /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; 1 &amp;amp;#43; on&amp;amp;#101; =&amp;nbsp; &amp;lt;input id="cptch_input" type="text" autocomplete="off" name="cptch_number" value="" maxlength="2" size="2" aria-required="true" required="required" style="margin-bottom:0;display:inline;font-size: 12px;width: 40px;" /&amp;gt; &amp;lt;/p&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;br /&amp;gt; &amp;lt;p class="forgetmenot"&amp;gt;&amp;lt;label for="rememberme"&amp;gt;&amp;lt;input name="rememberme" type="checkbox" id="rememberme" value="forever"&amp;nbsp; /&amp;gt; Remember Me&amp;lt;/label&amp;gt;&amp;lt;/p&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;p class="submit"&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;input type="submit" name="wp-submit" id="wp-submit" class="button button-primary button-large" value="Log In" /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;input type="hidden" name="redirect_to" value="&lt;A href="http://www.mysite.com/wp-admin/"&gt;http://www.mysite.com/wp-admin/&lt;/A&gt;" /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;input type="hidden" name="testcookie" value="1" /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;/p&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;/form&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;p id="nav"&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;a href="&lt;A href="http://www.mysite.com/login/?action=lostpassword"&gt;http://www.mysite.com/login/?action=lostpassword&lt;/A&gt;" title="Password Lost and Found"&amp;gt;Lost your password?&amp;lt;/a&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;/p&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;script type="text/javascript"&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;function wp_attempt_focus(){&lt;/P&gt;&lt;P class="p1"&gt;setTimeout( function(){ try{&lt;/P&gt;&lt;P class="p1"&gt;d = document.getElementById('user_login');&lt;/P&gt;&lt;P class="p1"&gt;if( d.value != '' )&lt;/P&gt;&lt;P class="p1"&gt;d.value = '';&lt;/P&gt;&lt;P class="p1"&gt;d.focus();&lt;/P&gt;&lt;P class="p1"&gt;d.select();&lt;/P&gt;&lt;P class="p1"&gt;} catch(e){}&lt;/P&gt;&lt;P class="p1"&gt;}, 200);&lt;/P&gt;&lt;P class="p1"&gt;}&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;if(typeof wpOnload=='function')wpOnload();&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;/script&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;p id="backtoblog"&amp;gt;&amp;lt;a href="&lt;A href="http://www.mysite.com/"&gt;http://www.mysite.com/&lt;/A&gt;" title="Are you lost?"&amp;gt;&amp;amp;larr; Back to mysite www&amp;lt;/a&amp;gt;&amp;lt;/p&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;/div&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;div class="clear"&amp;gt;&amp;lt;/div&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;/body&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;/html&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 Mar 2014 19:47:35 GMT</pubDate>
    <dc:creator>itmgr</dc:creator>
    <dc:date>2014-03-04T19:47:35Z</dc:date>
    <item>
      <title>How would I create a custom threat signature that looks for a server's "invalid username" response to a failed login attempt?</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-would-i-create-a-custom-threat-signature-that-looks-for-a/m-p/10949#M300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="p1"&gt;Hi,&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;I'm new to Palo Alto and custom threat signatures. I'm trying to detect invalid login attempts to a web site and apply a time rate. When the user enters an invalid username in the login, the site returns the text "invalid username". Which context would I use to search for this pattern match? I read the "Creating Custom Signatures" document, but it created more questions and I can't seem to find any deeper documentation. By using that document, I was able to use the wordpress brute force combination signature they included (monitoring http POST to wp-login.php), but I have some users that trip those thresholds often because they log into many blogs simultaneously on one server. I'm looking for something a little more granular (not just login attempts (good or bad), but bad attempts based on the site returning the text "bad password", or "invalid username". Is this possible? I don't mind reading more documentation regarding custom signatures if it's available, I've just not seen any other documents yet that give an example like this.&lt;/P&gt;&lt;P class="p2"&gt;&lt;/P&gt;&lt;P class="p1"&gt;I did take a pcap of the exchange between client and server. I see the text in the pcap, but still not sure which context to use to search for the string. The client sends an http POST to wp-login.php, and then the server issues an http 200 response and then the "Invalid username" text comes a few packets later. Below is the TCP stream from the pcap that contains the "Invalid username" text. I've tried the http_rsp_headers and file_html_body contexts, but still unable to match the text in the exchange.&lt;/P&gt;&lt;P class="p2"&gt;&lt;/P&gt;&lt;P class="p1"&gt;Thanks! &lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;POST /login/ HTTP/1.1&lt;/P&gt;&lt;P class="p1"&gt;Host: www.mysite.com&lt;/P&gt;&lt;P class="p1"&gt;Connection: keep-alive&lt;/P&gt;&lt;P class="p1"&gt;Content-Length: 164&lt;/P&gt;&lt;P class="p1"&gt;Cache-Control: max-age=0&lt;/P&gt;&lt;P class="p1"&gt;Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8&lt;/P&gt;&lt;P class="p3"&gt;&lt;SPAN class="s1"&gt;Origin: &lt;A href="http://www.mysite.com/"&gt;&lt;SPAN class="s2"&gt;http://www.mysite.com&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.146 Safari/537.36&lt;/P&gt;&lt;P class="p1"&gt;Content-Type: application/x-www-form-urlencoded&lt;/P&gt;&lt;P class="p3"&gt;&lt;SPAN class="s1"&gt;Referer: &lt;A href="http://www.mysite.com/login/"&gt;&lt;SPAN class="s2"&gt;http://www.mysite.com/login/&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;Accept-Encoding: gzip,deflate,sdch&lt;/P&gt;&lt;P class="p1"&gt;Accept-Language: en-US,en;q=0.8&lt;/P&gt;&lt;P class="p1"&gt;Cookie: wlp_post_protection=1; PHPSESSID=gh0pdah82shb6les906pc5n4u7; __utma=74238163.586482511.1393824836.1393824836.1393824836.1; __utmc=74238163; __utmz=74238163.1393824836.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=217530694.1368975606.1393822044.1393822044.1393886113.2; __utmc=217530694; __utmz=217530694.1393822044.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); wfvt_345498598=531583af83045; wordpress_test_cookie=WP+Cookie+check&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;log=ed&amp;amp;pwd=ed&amp;amp;cptch_result=87Q%3D&amp;amp;cptch_time=1393918888&amp;amp;cptch_number=6&amp;amp;wp-submit=Log+In&amp;amp;redirect_to=http%3A%2F%2Fwww.mysite.com%2Fwp-admin%2F&amp;amp;testcookie=1HTTP/1.1 200 OK&lt;/P&gt;&lt;P class="p1"&gt;Date: Tue, 04 Mar 2014 07:44:02 GMT&lt;/P&gt;&lt;P class="p1"&gt;Server: Apache/2.2.15 (CentOS)&lt;/P&gt;&lt;P class="p1"&gt;X-Powered-By: PHP/5.3.3&lt;/P&gt;&lt;P class="p1"&gt;Set-Cookie: wfvt_345498598=5315844284ba8; expires=Tue, 04-Mar-2014 08:14:02 GMT; path=/&lt;/P&gt;&lt;P class="p1"&gt;Expires: Thu, 19 Nov 1981 08:52:00 GMT&lt;/P&gt;&lt;P class="p1"&gt;Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0&lt;/P&gt;&lt;P class="p1"&gt;Pragma: no-cache&lt;/P&gt;&lt;P class="p1"&gt;Set-Cookie: wordpress_test_cookie=WP+Cookie+check; path=/&lt;/P&gt;&lt;P class="p1"&gt;X-Frame-Options: SAMEORIGIN&lt;/P&gt;&lt;P class="p1"&gt;Content-Length: 4373&lt;/P&gt;&lt;P class="p1"&gt;Connection: close&lt;/P&gt;&lt;P class="p1"&gt;Content-Type: text/html; charset=UTF-8&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;!DOCTYPE html&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;!--[if IE 8]&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;html xmlns="&lt;A href="http://www.w3.org/1999/xhtml"&gt;http://www.w3.org/1999/xhtml&lt;/A&gt;" class="ie8" lang="en-US"&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;![endif]--&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;!--[if !(IE &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; ]&amp;gt;&amp;lt;!--&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;html xmlns="&lt;A href="http://www.w3.org/1999/xhtml"&gt;http://www.w3.org/1999/xhtml&lt;/A&gt;" lang="en-US"&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;!--&amp;lt;![endif]--&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;head&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;title&amp;gt;mysite www &amp;amp;rsaquo; Log In&amp;lt;/title&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;link rel='stylesheet' id='open-sans-css'&amp;nbsp; href='//fonts.googleapis.com/css?family=Open+Sans%3A300italic%2C400italic%2C600italic%2C300%2C400%2C600&amp;amp;#038;subset=latin%2Clatin-ext&amp;amp;#038;ver=3.8.1' type='text/css' media='all' /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;link rel='stylesheet' id='dashicons-css'&amp;nbsp; href='&lt;A href="http://www.mysite.com/wp-includes/css/dashicons.min.css?ver=3.8.1"&gt;http://www.mysite.com/wp-includes/css/dashicons.min.css?ver=3.8.1&lt;/A&gt;' type='text/css' media='all' /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;link rel='stylesheet' id='wp-admin-css'&amp;nbsp; href='&lt;A href="http://www.mysite.com/wp-admin/css/wp-admin.min.css?ver=3.8.1"&gt;http://www.mysite.com/wp-admin/css/wp-admin.min.css?ver=3.8.1&lt;/A&gt;' type='text/css' media='all' /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;link rel='stylesheet' id='buttons-css'&amp;nbsp; href='&lt;A href="http://www.mysite.com/wp-includes/css/buttons.min.css?ver=3.8.1"&gt;http://www.mysite.com/wp-includes/css/buttons.min.css?ver=3.8.1&lt;/A&gt;' type='text/css' media='all' /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;link rel='stylesheet' id='colors-fresh-css'&amp;nbsp; href='&lt;A href="http://www.mysite.com/wp-admin/css/colors.min.css?ver=3.8.1"&gt;http://www.mysite.com/wp-admin/css/colors.min.css?ver=3.8.1&lt;/A&gt;' type='text/css' media='all' /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;!--[if lte IE 7]&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;link rel='stylesheet' id='ie-css'&amp;nbsp; href='&lt;A href="http://www.mysite.com/wp-admin/css/ie.min.css?ver=3.8.1"&gt;http://www.mysite.com/wp-admin/css/ie.min.css?ver=3.8.1&lt;/A&gt;' type='text/css' media='all' /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;![endif]--&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;meta name='robots' content='noindex,follow' /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;script type="text/javascript"&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;addLoadEvent = function(func){if(typeof jQuery!="undefined")jQuery(document).ready(func);else if(typeof wpOnload!='function'){wpOnload=func;}else{var oldonload=wpOnload;wpOnload=function(){oldonload();func();}}};&lt;/P&gt;&lt;P class="p1"&gt;function s(id,pos){g(id).left=pos+'px';}&lt;/P&gt;&lt;P class="p1"&gt;function g(id){return document.getElementById(id).style;}&lt;/P&gt;&lt;P class="p1"&gt;function shake(id,a,d){c=a.shift();s(id,c);if(a.length&amp;gt;0){setTimeout(function(){shake(id,a,d);},d);}else{try{g(id).position='static';wp_attempt_focus();}catch(e){}}}&lt;/P&gt;&lt;P class="p1"&gt;addLoadEvent(function(){ var p=new Array(15,30,15,0,-15,-30,-15,0);p=p.concat(p.concat(p));var i=document.forms[0].id;g(i).position='relative';shake(i,p,20);});&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;/script&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;/head&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;body class="login login-action-login wp-core-ui"&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;div id="login"&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;h1&amp;gt;&amp;lt;a href="&lt;A href="http://wordpress.org/"&gt;http://wordpress.org/&lt;/A&gt;" title="Powered by WordPress"&amp;gt;mysite www&amp;lt;/a&amp;gt;&amp;lt;/h1&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;div id="login_error"&amp;gt; &amp;lt;strong&amp;gt;ERROR&amp;lt;/strong&amp;gt;: Invalid username. &amp;lt;a href="&lt;A href="http://www.mysite.com/login/?action=lostpassword"&gt;http://www.mysite.com/login/?action=lostpassword&lt;/A&gt;" title="Password Lost and Found"&amp;gt;Lost your password&amp;lt;/a&amp;gt;?&amp;lt;br /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;/div&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;form name="loginform" id="loginform" action="&lt;A href="http://www.mysite.com/login/"&gt;http://www.mysite.com/login/&lt;/A&gt;" method="post"&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;p&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;label for="user_login"&amp;gt;Username&amp;lt;br /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;input type="text" name="log" id="user_login" class="input" value="" size="20" /&amp;gt;&amp;lt;/label&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;/p&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;p&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;label for="user_pass"&amp;gt;Password&amp;lt;br /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;input type="password" name="pwd" id="user_pass" class="input" value="" size="20" /&amp;gt;&amp;lt;/label&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;/p&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;p class="cptch_block"&amp;gt;&amp;lt;br /&amp;gt; &amp;lt;input type="hidden" name="cptch_result" value="hIE=" /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;input type="hidden" name="cptch_time" value="1393919042" /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;input type="hidden" value="Version: 2.4" /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; 1 &amp;amp;#43; on&amp;amp;#101; =&amp;nbsp; &amp;lt;input id="cptch_input" type="text" autocomplete="off" name="cptch_number" value="" maxlength="2" size="2" aria-required="true" required="required" style="margin-bottom:0;display:inline;font-size: 12px;width: 40px;" /&amp;gt; &amp;lt;/p&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;br /&amp;gt; &amp;lt;p class="forgetmenot"&amp;gt;&amp;lt;label for="rememberme"&amp;gt;&amp;lt;input name="rememberme" type="checkbox" id="rememberme" value="forever"&amp;nbsp; /&amp;gt; Remember Me&amp;lt;/label&amp;gt;&amp;lt;/p&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;p class="submit"&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;input type="submit" name="wp-submit" id="wp-submit" class="button button-primary button-large" value="Log In" /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;input type="hidden" name="redirect_to" value="&lt;A href="http://www.mysite.com/wp-admin/"&gt;http://www.mysite.com/wp-admin/&lt;/A&gt;" /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;input type="hidden" name="testcookie" value="1" /&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;/p&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;/form&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;p id="nav"&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;a href="&lt;A href="http://www.mysite.com/login/?action=lostpassword"&gt;http://www.mysite.com/login/?action=lostpassword&lt;/A&gt;" title="Password Lost and Found"&amp;gt;Lost your password?&amp;lt;/a&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;/p&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;script type="text/javascript"&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;function wp_attempt_focus(){&lt;/P&gt;&lt;P class="p1"&gt;setTimeout( function(){ try{&lt;/P&gt;&lt;P class="p1"&gt;d = document.getElementById('user_login');&lt;/P&gt;&lt;P class="p1"&gt;if( d.value != '' )&lt;/P&gt;&lt;P class="p1"&gt;d.value = '';&lt;/P&gt;&lt;P class="p1"&gt;d.focus();&lt;/P&gt;&lt;P class="p1"&gt;d.select();&lt;/P&gt;&lt;P class="p1"&gt;} catch(e){}&lt;/P&gt;&lt;P class="p1"&gt;}, 200);&lt;/P&gt;&lt;P class="p1"&gt;}&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;if(typeof wpOnload=='function')wpOnload();&lt;/P&gt;&lt;P class="p1"&gt;&amp;lt;/script&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;p id="backtoblog"&amp;gt;&amp;lt;a href="&lt;A href="http://www.mysite.com/"&gt;http://www.mysite.com/&lt;/A&gt;" title="Are you lost?"&amp;gt;&amp;amp;larr; Back to mysite www&amp;lt;/a&amp;gt;&amp;lt;/p&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;/div&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;div class="clear"&amp;gt;&amp;lt;/div&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;/body&amp;gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp; &amp;lt;/html&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Mar 2014 19:47:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/how-would-i-create-a-custom-threat-signature-that-looks-for-a/m-p/10949#M300</guid>
      <dc:creator>itmgr</dc:creator>
      <dc:date>2014-03-04T19:47:35Z</dc:date>
    </item>
  </channel>
</rss>

