<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Many threats for DNS blocklists fresh.fmb.la and support-intelligence.net in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/many-threats-for-dns-blocklists-fresh-fmb-la-and-support/m-p/595350#M2261</link>
    <description>&lt;P&gt;Two DNS blocklists used by standard SpamAssassin 4.0 have many Palo Alto threat IDs for wildfire, malware and phishing. Blocklists are not phishing sites but give back DNS values to decide if should be blocked by mailservers or not. Especially needed for evaluation of URIs in mails.&lt;/P&gt;
&lt;P&gt;/var/lib/spamassassin/4.000000/updates_spamassassin_org/72_active.cf:urirhssub URIBL_RHS_DOB&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dob.sibl.support-intelligence.net&amp;nbsp; A&amp;nbsp;&amp;nbsp; 2&lt;/P&gt;
&lt;P&gt;/var/lib/spamassassin/4.000000/updates_spamassassin_org/72_active.cf:askdns&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; __FROM_FMBLA_NEWDOM&amp;nbsp;&amp;nbsp;&amp;nbsp; _AUTHORDOMAIN_.fresh.fmb.la. A /^127\.2\.0\.2$/&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have submitted quite a few change request for subdomains, e.g. com[.]fresh[.]fmb[.]la, org[.]dob[.]sibl[.]support-intelligence[.]net, netwrix[.]com[.]dob[.]sibl[.]support-intelligence[.]net, telekom[.]de[.]dob[.]sibl[.]support-intelligence[.]net&lt;/P&gt;
&lt;P&gt;but there are problably many more. Is it possible to get a recursive cleanup of the threat database?&lt;/P&gt;</description>
    <pubDate>Tue, 20 Aug 2024 11:08:32 GMT</pubDate>
    <dc:creator>kivory</dc:creator>
    <dc:date>2024-08-20T11:08:32Z</dc:date>
    <item>
      <title>Many threats for DNS blocklists fresh.fmb.la and support-intelligence.net</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/many-threats-for-dns-blocklists-fresh-fmb-la-and-support/m-p/595350#M2261</link>
      <description>&lt;P&gt;Two DNS blocklists used by standard SpamAssassin 4.0 have many Palo Alto threat IDs for wildfire, malware and phishing. Blocklists are not phishing sites but give back DNS values to decide if should be blocked by mailservers or not. Especially needed for evaluation of URIs in mails.&lt;/P&gt;
&lt;P&gt;/var/lib/spamassassin/4.000000/updates_spamassassin_org/72_active.cf:urirhssub URIBL_RHS_DOB&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dob.sibl.support-intelligence.net&amp;nbsp; A&amp;nbsp;&amp;nbsp; 2&lt;/P&gt;
&lt;P&gt;/var/lib/spamassassin/4.000000/updates_spamassassin_org/72_active.cf:askdns&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; __FROM_FMBLA_NEWDOM&amp;nbsp;&amp;nbsp;&amp;nbsp; _AUTHORDOMAIN_.fresh.fmb.la. A /^127\.2\.0\.2$/&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have submitted quite a few change request for subdomains, e.g. com[.]fresh[.]fmb[.]la, org[.]dob[.]sibl[.]support-intelligence[.]net, netwrix[.]com[.]dob[.]sibl[.]support-intelligence[.]net, telekom[.]de[.]dob[.]sibl[.]support-intelligence[.]net&lt;/P&gt;
&lt;P&gt;but there are problably many more. Is it possible to get a recursive cleanup of the threat database?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 11:08:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/many-threats-for-dns-blocklists-fresh-fmb-la-and-support/m-p/595350#M2261</guid>
      <dc:creator>kivory</dc:creator>
      <dc:date>2024-08-20T11:08:32Z</dc:date>
    </item>
  </channel>
</rss>

