<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authorized file suddenly blocked as threat in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/authorized-file-suddenly-blocked-as-threat/m-p/233810#M422</link>
    <description>&lt;P&gt;There were changes made to signature 31313 in Content version&lt;SPAN&gt;&amp;nbsp;8068-5026.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please work with Support to have&amp;nbsp;this False Positive resolved.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Oct 2018 22:53:26 GMT</pubDate>
    <dc:creator>mivaldi</dc:creator>
    <dc:date>2018-10-03T22:53:26Z</dc:date>
    <item>
      <title>Authorized file suddenly blocked as threat</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/authorized-file-suddenly-blocked-as-threat/m-p/232458#M421</link>
      <description>&lt;P&gt;We came into the office this morning to receive reports from users that they weren't able to access their core application which runs on apache web server.&amp;nbsp; When they login, the internet explorer URL directs the users to www[whatever-url]com/login.jsp .&amp;nbsp; Our clients download the file login.jsp when they access the login portal for the webpage.&amp;nbsp; The firewall is blocking this file in accordance with signature ID 31313 (Oracle single sign on vulnerability).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This behavior has been true since as long as I can remember, but suddenly our PA-3020 running panOS 7.1.1 decided to block this file as a threat.&amp;nbsp; We were able to quickly resolve this issue with a vulnerability protection exemption to allow this threat signature for a specific ip address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I'm now working on is to determine what caused this sudden change in behavior that resulted in the file being blocked.&amp;nbsp; Our firewall did take a&amp;nbsp; app and threats update yesterday around 1:45pm (panupv2-all-contents-8069-5027).&amp;nbsp; However, the vulnerability signature that was being blocked was 31313 which is not mentioned in the latest update release and I know this signature has existed for a long time now.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone ever seen this sort of sudden change of behavior i nthe past?&amp;nbsp; Or any advice on places to check in the palo alto for more clues on what may have occurred?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 14:38:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/authorized-file-suddenly-blocked-as-threat/m-p/232458#M421</guid>
      <dc:creator>Tylerkearns</dc:creator>
      <dc:date>2018-09-26T14:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: Authorized file suddenly blocked as threat</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/authorized-file-suddenly-blocked-as-threat/m-p/233810#M422</link>
      <description>&lt;P&gt;There were changes made to signature 31313 in Content version&lt;SPAN&gt;&amp;nbsp;8068-5026.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please work with Support to have&amp;nbsp;this False Positive resolved.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 22:53:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/authorized-file-suddenly-blocked-as-threat/m-p/233810#M422</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-10-03T22:53:26Z</dc:date>
    </item>
  </channel>
</rss>

