<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Remove a site from  from Palo Alto's blacklist in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/remove-a-site-from-from-palo-alto-s-blacklist/m-p/494866#M105065</link>
    <description>&lt;P&gt;My client's site, a Canadian site that prepares school supply kits, edupac.ca was hacked badly a few months ago. But we manually removed all malware files. We abandoned the original infected file base, restoring from backups, and now the code base is a clean version from before the hacks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EduPac is an established company for over 20 years. I am their web developer, and I have been working with them for at least eight years. Being ranked "High Risk"&amp;nbsp; hurts them, since they deal with schools using the service.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found some old posts from 2018 and 2019 about this, but they are giving links to pages that no longer offer any option to request removal. I tried to phone, but you need a serial number to get through their call system. I can't find any support email, and, since I am not a customer, I can't log into their support system to enter a ticket.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These are really nice people who are no threat, and had the bad luck to get hacked for and have their site taken over for a couple of days a few months ago. It doesn't seem right that they should be punished when their site is now no threat.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help, or information you can give me will be really appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;</description>
    <pubDate>Mon, 30 May 2022 20:10:23 GMT</pubDate>
    <dc:creator>canadacoder</dc:creator>
    <dc:date>2022-05-30T20:10:23Z</dc:date>
    <item>
      <title>Remove a site from  from Palo Alto's blacklist</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remove-a-site-from-from-palo-alto-s-blacklist/m-p/494866#M105065</link>
      <description>&lt;P&gt;My client's site, a Canadian site that prepares school supply kits, edupac.ca was hacked badly a few months ago. But we manually removed all malware files. We abandoned the original infected file base, restoring from backups, and now the code base is a clean version from before the hacks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EduPac is an established company for over 20 years. I am their web developer, and I have been working with them for at least eight years. Being ranked "High Risk"&amp;nbsp; hurts them, since they deal with schools using the service.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found some old posts from 2018 and 2019 about this, but they are giving links to pages that no longer offer any option to request removal. I tried to phone, but you need a serial number to get through their call system. I can't find any support email, and, since I am not a customer, I can't log into their support system to enter a ticket.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These are really nice people who are no threat, and had the bad luck to get hacked for and have their site taken over for a couple of days a few months ago. It doesn't seem right that they should be punished when their site is now no threat.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help, or information you can give me will be really appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 20:10:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remove-a-site-from-from-palo-alto-s-blacklist/m-p/494866#M105065</guid>
      <dc:creator>canadacoder</dc:creator>
      <dc:date>2022-05-30T20:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: Remove a site from  from Palo Alto's blacklist</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remove-a-site-from-from-palo-alto-s-blacklist/m-p/494909#M105069</link>
      <description>&lt;P&gt;You can query your site's status here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://urlfiltering.paloaltonetworks.com/query/" target="_blank"&gt;https://urlfiltering.paloaltonetworks.com/query/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the bottom of the page click the "Request Change" button and fill out with as much information as possible to request a re-evaluation.&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 00:47:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remove-a-site-from-from-palo-alto-s-blacklist/m-p/494909#M105069</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-05-31T00:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: Remove a site from  from Palo Alto's blacklist</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remove-a-site-from-from-palo-alto-s-blacklist/m-p/495958#M105103</link>
      <description>&lt;P&gt;I had previously tried that, which was recommended in a previous post. But when I did, I got this message:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"This URL already has the requested categorization. If you intended to submit a different categorization, please try again. If you are trying to change the Risk rating, this cannot be done via Change Request. If the Risk rating is incorrect, please contact support."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But they give no way to actually contact support.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 17:12:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remove-a-site-from-from-palo-alto-s-blacklist/m-p/495958#M105103</guid>
      <dc:creator>canadacoder</dc:creator>
      <dc:date>2022-05-31T17:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: Remove a site from  from Palo Alto's blacklist</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remove-a-site-from-from-palo-alto-s-blacklist/m-p/496462#M105109</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/221588"&gt;@canadacoder&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The High Risk category isn't something that you can request removal from outside of a support ticket. Since your schools apparently have Palo-Alto Networks equipment, could you ask one of them to open a ticket on your behalf if you have a working relationship with them?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Outside of that, what the schools are doing actually&amp;nbsp;&lt;EM&gt;isn't&amp;nbsp;&lt;/EM&gt;best practice per PAN. The recommended, and default, policy action is Alert and not Block. The name of that category trips people up and gets people to want to set it to block, but high-risk is used&amp;nbsp;&lt;EM&gt;after&amp;nbsp;&lt;/EM&gt;the site is caught under malware, phishing, or C2. This will go down to medium risk after 60 days.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you fixed this months ago and you're still running into issues, I'd actually look at your hosting provider. High-Risk is used for bulletproof ISP-hosting and sites hosts on known bad ASNs as well. You may be able to resolve this issue by just moving to a more reputable hosting partner.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 01:24:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remove-a-site-from-from-palo-alto-s-blacklist/m-p/496462#M105109</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-06-01T01:24:59Z</dc:date>
    </item>
  </channel>
</rss>

