<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vulnerability and spyware showing in monitor need to check its blocked from PA or not and need more clarity on same in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-and-spyware-showing-in-monitor-need-to-check-its/m-p/426969#M1269</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Please suggest.&lt;/P&gt;&lt;P&gt;DCS-2530L Unauthenticated Information Disclosure Vulnerability&amp;nbsp; :- Action- reset both&lt;/P&gt;&lt;P&gt;ZGrab Application Layer Scanner Detection :-&amp;nbsp;:- Action-&amp;nbsp; alert&lt;/P&gt;&lt;P&gt;name-of-threatid eq 'generic:in-page-push.com :- Action :-&amp;nbsp;sinkhole&lt;/P&gt;&lt;P&gt;Zeroshell Remote Command Execution Vulnerability&amp;nbsp; :- Action- reset both&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Aug 2021 06:29:00 GMT</pubDate>
    <dc:creator>sureshukkalkar</dc:creator>
    <dc:date>2021-08-16T06:29:00Z</dc:date>
    <item>
      <title>vulnerability and spyware showing in monitor need to check its blocked from PA or not and need more clarity on same</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-and-spyware-showing-in-monitor-need-to-check-its/m-p/426908#M1267</link>
      <description>&lt;P&gt;&lt;SPAN&gt;vulnerability and spyware showing in monitor need to check its blocked from PA or not and need more clarity on same&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Aug 2021 10:52:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-and-spyware-showing-in-monitor-need-to-check-its/m-p/426908#M1267</guid>
      <dc:creator>sureshukkalkar</dc:creator>
      <dc:date>2021-08-15T10:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: vulnerability and spyware showing in monitor need to check its blocked from PA or not and need more clarity on same</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-and-spyware-showing-in-monitor-need-to-check-its/m-p/426953#M1268</link>
      <description>&lt;P&gt;The threat logs will show what action has been taken.Can you pls elaborate what your issue is? Do you wish to block the threats?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 05:29:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-and-spyware-showing-in-monitor-need-to-check-its/m-p/426953#M1268</guid>
      <dc:creator>rubber_ducky</dc:creator>
      <dc:date>2021-08-16T05:29:06Z</dc:date>
    </item>
    <item>
      <title>Re: vulnerability and spyware showing in monitor need to check its blocked from PA or not and need more clarity on same</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-and-spyware-showing-in-monitor-need-to-check-its/m-p/426969#M1269</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Please suggest.&lt;/P&gt;&lt;P&gt;DCS-2530L Unauthenticated Information Disclosure Vulnerability&amp;nbsp; :- Action- reset both&lt;/P&gt;&lt;P&gt;ZGrab Application Layer Scanner Detection :-&amp;nbsp;:- Action-&amp;nbsp; alert&lt;/P&gt;&lt;P&gt;name-of-threatid eq 'generic:in-page-push.com :- Action :-&amp;nbsp;sinkhole&lt;/P&gt;&lt;P&gt;Zeroshell Remote Command Execution Vulnerability&amp;nbsp; :- Action- reset both&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 06:29:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-and-spyware-showing-in-monitor-need-to-check-its/m-p/426969#M1269</guid>
      <dc:creator>sureshukkalkar</dc:creator>
      <dc:date>2021-08-16T06:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: vulnerability and spyware showing in monitor need to check its blocked from PA or not and need more clarity on same</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-and-spyware-showing-in-monitor-need-to-check-its/m-p/427044#M1270</link>
      <description>&lt;P&gt;You can check the below url for more clarity on the different actions that Palo Alto takes on a traffic.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-web-interface-help/objects/objects-security-profiles/actions-in-security-profiles.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-web-interface-help/objects/objects-security-profiles/actions-in-security-profiles.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For you to decide if you need to block any threat, you should be able to double check by analysing the Src/Dst IPs to see if the traffic is valid in your environment.&lt;/P&gt;&lt;P&gt;Incase of url, doble check the url.&amp;nbsp; Please DO ALWAYS check if you are seeing any false positves.&lt;/P&gt;&lt;P&gt;You can create security policy to completely block these Ips, if they are really threats. If you feel the src and dst are valid then Palo Alto may be blocking genuine traffic. You may need to exclude the IPs in the threat signature.&lt;/P&gt;&lt;P&gt;Click on the magnifying glass in the threat logs to view more details.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 10:12:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/vulnerability-and-spyware-showing-in-monitor-need-to-check-its/m-p/427044#M1270</guid>
      <dc:creator>rubber_ducky</dc:creator>
      <dc:date>2021-08-16T10:12:13Z</dc:date>
    </item>
  </channel>
</rss>

