<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fingerprinting Acunetix in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/fingerprinting-acunetix/m-p/19148#M488</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SRA, we tried your suggestion but met with only limited success.&amp;nbsp; Here's the experiment we did:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our firewall guy created a custom application which identified the initial connection attempt by Acunetix based on the signatures that the Acunetix CTO gave us.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I then downloaded a free, community edition of Acunetix, version 8, and ran a scan against a URL which resides behind our firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The result was this: Palo Alto firewall noticed the signature present in the first couple of packets and, so, blocked those packets. Subsequent packets (from the same source IP), which lacked these signatures, were not identified as part of the banned application and were allowed through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Is there some we can create a DDoS trigger that can block the originating IP? Etc. What can we do about this? Please advise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you again,&lt;/P&gt;&lt;P&gt;Dovid&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Jul 2013 19:22:57 GMT</pubDate>
    <dc:creator>wolkenfeld</dc:creator>
    <dc:date>2013-07-24T19:22:57Z</dc:date>
    <item>
      <title>Fingerprinting Acunetix</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/fingerprinting-acunetix/m-p/19145#M485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear PAN Developers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Several times now a developer on our side has reported to us from monitoring tools he manages that people have scanned our critical applications with a freely available Web Application Vulnerability scanner from Acunetix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our CSO contacted the CTO of Acunetix asking how can we could fingerprint their scanner so as to protect our applications from it. Their CTO wrote this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;About blocking the attack: &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I don't know exactly what edition was used to scan your website. &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Some of our editions send the following header with each request: &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Acunetix-Scanning-agreement:Third Party Scanning PROHIBITED &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Check if you can see this header and block based on that.&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;However, if they are using a Consultant edition, this header is not sent.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;All editions are making a request to the following URL before starting the scan: &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;A class="jive-link-external-small" href="http://"&gt;http://&lt;/A&gt;&lt;SPAN&gt;{website}/acunetix-wvs-test-for-some-inexistent-file. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;So, you can also look for that."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Please let me know if, based on this information, you can create for us a method by which to finger print and (dynamically) filter traffic from this scanner in the future. Our current countermeasure - waking up our network engineers and having them manually add the source IP of the scanner (which varies with each attack) - is time consuming...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Thank you so much&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Dovid&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 16:21:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/fingerprinting-acunetix/m-p/19145#M485</guid>
      <dc:creator>wolkenfeld</dc:creator>
      <dc:date>2013-07-23T16:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: Fingerprinting Acunetix</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/fingerprinting-acunetix/m-p/19146#M486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can build a custom vulnerability or app signature to identify this traffic. To match on patterns in http request headers, you can use the http-req-headers context, and for matching patterns in URL you can use http-req-uri-path context.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 20:44:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/fingerprinting-acunetix/m-p/19146#M486</guid>
      <dc:creator>SRA</dc:creator>
      <dc:date>2013-07-23T20:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: Fingerprinting Acunetix</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/fingerprinting-acunetix/m-p/19147#M487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you SRA, I have communicated your response to our firewall manager; we'll be in touch...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 15:09:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/fingerprinting-acunetix/m-p/19147#M487</guid>
      <dc:creator>wolkenfeld</dc:creator>
      <dc:date>2013-07-24T15:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: Fingerprinting Acunetix</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/fingerprinting-acunetix/m-p/19148#M488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SRA, we tried your suggestion but met with only limited success.&amp;nbsp; Here's the experiment we did:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our firewall guy created a custom application which identified the initial connection attempt by Acunetix based on the signatures that the Acunetix CTO gave us.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I then downloaded a free, community edition of Acunetix, version 8, and ran a scan against a URL which resides behind our firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The result was this: Palo Alto firewall noticed the signature present in the first couple of packets and, so, blocked those packets. Subsequent packets (from the same source IP), which lacked these signatures, were not identified as part of the banned application and were allowed through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Is there some we can create a DDoS trigger that can block the originating IP? Etc. What can we do about this? Please advise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you again,&lt;/P&gt;&lt;P&gt;Dovid&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 19:22:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/fingerprinting-acunetix/m-p/19148#M488</guid>
      <dc:creator>wolkenfeld</dc:creator>
      <dc:date>2013-07-24T19:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: Fingerprinting Acunetix</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/fingerprinting-acunetix/m-p/19149#M489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The entire session should be blocked, not just a few packets; unless the remaining packets are part of a different session. Also, from your original post it seems like the patterns don't appear in the session in all the editions of their product. Can you confirm from a packet capture that the patterns (either a header or URI) are indeed present in the session.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 19:40:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/fingerprinting-acunetix/m-p/19149#M489</guid>
      <dc:creator>SRA</dc:creator>
      <dc:date>2013-07-24T19:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: Fingerprinting Acunetix</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/fingerprinting-acunetix/m-p/19150#M490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SRA, thank you for your speedy reply. As the Acunetix CTO stated "&lt;SPAN style="font-size: 10pt; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;STRONG&gt;All&lt;/STRONG&gt; editions are making a request to the following URL before starting the scan:&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;A class="jive-link-external-small" style="color: #316989; font-style: inherit; font-family: inherit;"&gt;http://&lt;/A&gt;&lt;SPAN style="font-style: inherit; font-family: inherit;"&gt;{website}/acunetix-wvs-test-for-some-inexistent-file" &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-style: inherit; background-color: #ffffff; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-style: inherit; background-color: #ffffff; font-family: inherit;"&gt;OK, I re-ran an experiment scan after our firewall guy hit "session" in the rule: same results. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-style: inherit; background-color: #ffffff; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-style: inherit; background-color: #ffffff; font-family: inherit;"&gt;What can we do from here - any ideas?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-style: inherit; background-color: #ffffff; font-family: inherit;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-style: inherit; background-color: #ffffff; font-family: inherit;"&gt;Thanks again,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-style: inherit; background-color: #ffffff; font-family: inherit;"&gt;Dovid&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 20:54:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/fingerprinting-acunetix/m-p/19150#M490</guid>
      <dc:creator>wolkenfeld</dc:creator>
      <dc:date>2013-07-24T20:54:47Z</dc:date>
    </item>
    <item>
      <title>Re: Fingerprinting Acunetix</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/fingerprinting-acunetix/m-p/19151#M491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The session vs. transaction option only matters when you have multiple conditions in the signature, and you want all of those be within a single transaction, or they can occur across transactions in a session. Have you taken a packet capture of the session to check if the patterns are indeed exactly the same as you used in the signature.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 21:49:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/fingerprinting-acunetix/m-p/19151#M491</guid>
      <dc:creator>SRA</dc:creator>
      <dc:date>2013-07-24T21:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: Fingerprinting Acunetix</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/fingerprinting-acunetix/m-p/19152#M492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pardon me for the late reply, please; yes, we took a packet capture and have uploaded this capture to our ticket (ticket #: &lt;SPAN style="color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 10.909090995788574px; background-color: #ffffff;"&gt;00149001&lt;/SPAN&gt;). Please let me know if this will suffice for now, or if there is anything else we can provide you with in helping us develop a filter to test against this scanner.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you so much,&lt;/P&gt;&lt;P&gt;Dovid&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 20:45:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/fingerprinting-acunetix/m-p/19152#M492</guid>
      <dc:creator>wolkenfeld</dc:creator>
      <dc:date>2013-08-06T20:45:39Z</dc:date>
    </item>
  </channel>
</rss>

