<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Compromised or commonly used username found in HTTP Basic Authentication in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/compromised-or-commonly-used-username-found-in-http-basic/m-p/581396#M2137</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What are you looking to obtain this information for?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would assume Palo Alto is not going to release exactly what triggers there vulnerability signatures. If they were to provide this information you would probably have to open a TAC case to get an official response, but again my assumption is they wouldnt give you this.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the information listed in the threat vault:&lt;/P&gt;
&lt;HEADER id="header" data-reactid=".0.0"&gt;
&lt;DIV class="form-inline" data-reactid=".0.0.1"&gt;
&lt;DIV id="share-buttonModal" class="modal fade in" tabindex="-1" role="dialog" data-reactid=".0.0.1.3.1"&gt;
&lt;DIV class="modal-dialog share-modal-style" data-reactid=".0.0.1.3.1.0"&gt;
&lt;DIV class="modal-content" data-reactid=".0.0.1.3.1.0.0"&gt;
&lt;DIV class="modal-body" data-reactid=".0.0.1.3.1.0.0.1"&gt;
&lt;P data-reactid=".0.0.1.3.1.0.0.1.0"&gt;&lt;A href="https://threatvault.paloaltonetworks.com/?query=Compromised" target="_blank"&gt;https://threatvault.paloaltonetworks.com/?query=Compromised&lt;/A&gt; or commonly used username found in HTTP Basic Authentication&amp;amp;type=&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="recaptcha-parent" data-reactid=".0.0.1.4"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/HEADER&gt;</description>
    <pubDate>Fri, 22 Mar 2024 20:30:10 GMT</pubDate>
    <dc:creator>Claw4609</dc:creator>
    <dc:date>2024-03-22T20:30:10Z</dc:date>
    <item>
      <title>Compromised or commonly used username found in HTTP Basic Authentication</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/compromised-or-commonly-used-username-found-in-http-basic/m-p/581155#M2134</link>
      <description>&lt;P&gt;Hi, can i get common username patterns that are getting matched with the PA signature "Compromised or commonly used username found in HTTP Basic Authentication" ??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any links where i can get the usernames that are mapped with this signature which are designated as compromised or commonly used ??&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 07:30:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/compromised-or-commonly-used-username-found-in-http-basic/m-p/581155#M2134</guid>
      <dc:creator>PAuserIM</dc:creator>
      <dc:date>2024-03-21T07:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: Compromised or commonly used username found in HTTP Basic Authentication</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/compromised-or-commonly-used-username-found-in-http-basic/m-p/581396#M2137</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What are you looking to obtain this information for?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would assume Palo Alto is not going to release exactly what triggers there vulnerability signatures. If they were to provide this information you would probably have to open a TAC case to get an official response, but again my assumption is they wouldnt give you this.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the information listed in the threat vault:&lt;/P&gt;
&lt;HEADER id="header" data-reactid=".0.0"&gt;
&lt;DIV class="form-inline" data-reactid=".0.0.1"&gt;
&lt;DIV id="share-buttonModal" class="modal fade in" tabindex="-1" role="dialog" data-reactid=".0.0.1.3.1"&gt;
&lt;DIV class="modal-dialog share-modal-style" data-reactid=".0.0.1.3.1.0"&gt;
&lt;DIV class="modal-content" data-reactid=".0.0.1.3.1.0.0"&gt;
&lt;DIV class="modal-body" data-reactid=".0.0.1.3.1.0.0.1"&gt;
&lt;P data-reactid=".0.0.1.3.1.0.0.1.0"&gt;&lt;A href="https://threatvault.paloaltonetworks.com/?query=Compromised" target="_blank"&gt;https://threatvault.paloaltonetworks.com/?query=Compromised&lt;/A&gt; or commonly used username found in HTTP Basic Authentication&amp;amp;type=&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="recaptcha-parent" data-reactid=".0.0.1.4"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/HEADER&gt;</description>
      <pubDate>Fri, 22 Mar 2024 20:30:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/compromised-or-commonly-used-username-found-in-http-basic/m-p/581396#M2137</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-03-22T20:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: Compromised or commonly used username found in HTTP Basic Authentication</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/compromised-or-commonly-used-username-found-in-http-basic/m-p/581671#M2140</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There was a particular traffic between 2 servers which got identified with this IPS signature but when checked with the respective server owner there was no generic/common usernames found in the server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So would like to know what kind of key parameters(usernames) considered for this IPS signature.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 07:00:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/compromised-or-commonly-used-username-found-in-http-basic/m-p/581671#M2140</guid>
      <dc:creator>PAuserIM</dc:creator>
      <dc:date>2024-03-26T07:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: Compromised or commonly used username found in HTTP Basic Authentication</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/compromised-or-commonly-used-username-found-in-http-basic/m-p/581676#M2141</link>
      <description>&lt;P&gt;As the signature name indicates, the common username was found in HTTP Basic Authentication, in other words, it was found in the traffic that the firewall saw. It doesn't mean that the common username exists on the server.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;If you collect the threat pcap, you should be able to see what username is used in the traffic.&lt;/P&gt;
&lt;P&gt;Reference:&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/take-packet-captures/take-a-threat-packet-capture" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/take-packet-captures/take-a-threat-packet-capture&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 08:03:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/compromised-or-commonly-used-username-found-in-http-basic/m-p/581676#M2141</guid>
      <dc:creator>ymiyashita</dc:creator>
      <dc:date>2024-03-26T08:03:27Z</dc:date>
    </item>
  </channel>
</rss>

