<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Access Palo Alto HTML Files in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/access-palo-alto-html-files/m-p/511736#M106364</link>
    <description>&lt;P&gt;Hello, our user want to deploy Palo Alto Firewall 3410 with Os 10.2.2, for security reason then they do the vulnerability assessment but using different device but with same OS 10.2.2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And the result is that they found 2 vulnerabilityissues, low and information.&lt;/P&gt;
&lt;P&gt;i took this VA is on the login page on palo alto firewall.&lt;/P&gt;
&lt;P&gt;The Low vulnerabilityis about&amp;nbsp;'autocomplete' attribute is not disabled on password fields.&lt;/P&gt;
&lt;P&gt;and the Information vulnerabilityis about robots.txt, that they recommed to limit that access to that file.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what i want to ask, is that possible to edit the html files for fix this low&amp;nbsp;vulnerability?&lt;/P&gt;
&lt;P&gt;is there any docs so i can fix this&amp;nbsp;vulnerability?&lt;/P&gt;</description>
    <pubDate>Fri, 12 Aug 2022 16:14:15 GMT</pubDate>
    <dc:creator>DennyChanditya</dc:creator>
    <dc:date>2022-08-12T16:14:15Z</dc:date>
    <item>
      <title>Access Palo Alto HTML Files</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-palo-alto-html-files/m-p/511736#M106364</link>
      <description>&lt;P&gt;Hello, our user want to deploy Palo Alto Firewall 3410 with Os 10.2.2, for security reason then they do the vulnerability assessment but using different device but with same OS 10.2.2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And the result is that they found 2 vulnerabilityissues, low and information.&lt;/P&gt;
&lt;P&gt;i took this VA is on the login page on palo alto firewall.&lt;/P&gt;
&lt;P&gt;The Low vulnerabilityis about&amp;nbsp;'autocomplete' attribute is not disabled on password fields.&lt;/P&gt;
&lt;P&gt;and the Information vulnerabilityis about robots.txt, that they recommed to limit that access to that file.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what i want to ask, is that possible to edit the html files for fix this low&amp;nbsp;vulnerability?&lt;/P&gt;
&lt;P&gt;is there any docs so i can fix this&amp;nbsp;vulnerability?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2022 16:14:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-palo-alto-html-files/m-p/511736#M106364</guid>
      <dc:creator>DennyChanditya</dc:creator>
      <dc:date>2022-08-12T16:14:15Z</dc:date>
    </item>
    <item>
      <title>Re: Access Palo Alto HTML Files</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-palo-alto-html-files/m-p/511863#M106384</link>
      <description>&lt;P&gt;Hello there.&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;The Live Community are volunteers and end users of the product, who come together to assist others.&lt;BR /&gt;I have not heard of any way to modify the "base" html files on the PANOS.&lt;BR /&gt;You would need to submit a feature request through your local PANW SE.&lt;BR /&gt;That is the correct process to follow.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 15:33:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-palo-alto-html-files/m-p/511863#M106384</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2022-08-15T15:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: Access Palo Alto HTML Files</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-palo-alto-html-files/m-p/511975#M106414</link>
      <description>&lt;P&gt;Since i didn't find any docs about how to edit base html files on PanOS/mitigate this problem, so I just open ticket in support portal.&lt;/P&gt;
&lt;P&gt;And they do the checking on html files.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the result for the low vulnerability is It&amp;nbsp;seems&amp;nbsp;false&amp;nbsp;positive&amp;nbsp;if&amp;nbsp;the&amp;nbsp;scanner&amp;nbsp;is&amp;nbsp;detecting&amp;nbsp;it.&amp;nbsp;The&amp;nbsp;browsers&amp;nbsp;can&amp;nbsp;save&amp;nbsp;the&amp;nbsp;password&amp;nbsp;regardless&amp;nbsp;of&amp;nbsp;the&amp;nbsp;autocomplete&amp;nbsp;='off'&amp;nbsp;and&amp;nbsp; o&amp;nbsp;be&amp;nbsp;the&amp;nbsp;scanners.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;and for the information vulnerability with robot.txt is&amp;nbsp;The&amp;nbsp;contents&amp;nbsp;of&amp;nbsp;the&amp;nbsp;robots.txt&amp;nbsp;does&amp;nbsp;not&amp;nbsp;reveal&amp;nbsp;any&amp;nbsp;information&amp;nbsp;about&amp;nbsp;the&amp;nbsp;secret&amp;nbsp;path&amp;nbsp;directories.&amp;nbsp;This&amp;nbsp;hints&amp;nbsp;to&amp;nbsp;disallow&amp;nbsp;everything&amp;nbsp;from&amp;nbsp;the&amp;nbsp;root&amp;nbsp;'/',&amp;nbsp;so&amp;nbsp;no&amp;nbsp;specific&amp;nbsp;directories&amp;nbsp;to&amp;nbsp;allow&amp;nbsp;or&amp;nbsp;disallow.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 08:57:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-palo-alto-html-files/m-p/511975#M106414</guid>
      <dc:creator>DennyChanditya</dc:creator>
      <dc:date>2022-08-16T08:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Access Palo Alto HTML Files</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-palo-alto-html-files/m-p/587832#M117255</link>
      <description>&lt;P&gt;Replying back to this several years late but I do have a fix. Enabling the requirement to force users to accept the banner on login seems to bypass this being reported as a vulnerability. I have successfully verified this across 8.1, 9.1, and 10.1 across 7 devices.&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 21:41:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-palo-alto-html-files/m-p/587832#M117255</guid>
      <dc:creator>Michael.Gossett</dc:creator>
      <dc:date>2024-05-23T21:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: Access Palo Alto HTML Files</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-palo-alto-html-files/m-p/588470#M117324</link>
      <description>&lt;P&gt;Thanks for that information &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 09:19:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-palo-alto-html-files/m-p/588470#M117324</guid>
      <dc:creator>DennyChanditya</dc:creator>
      <dc:date>2024-05-31T09:19:09Z</dc:date>
    </item>
    <item>
      <title>Re: Access Palo Alto HTML Files</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-palo-alto-html-files/m-p/591738#M117833</link>
      <description>&lt;P&gt;This is appears to be fixed in least 10.2.8, you dont even need to login to the device to confirm, inspect the html on the pages the auditors are complaining about:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The portal login form has &lt;SPAN&gt;autocomplete=off&lt;/SPAN&gt; set on the form tag on line 265&lt;/P&gt;
&lt;P&gt;The admin login has &lt;SPAN&gt;autocomplete=off&lt;/SPAN&gt; set on the form tag on line 27&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;According to Tenable(Nessus) having autocomplete set to off on the form is the preferred option&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.tenable.com/plugins/was/98081" target="_blank" rel="noopener"&gt;https://www.tenable.com/plugins/was/98081&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I figured id post this since this was the only thing i found on the internet talking about this nonsense "issue", its a false positive. Maybe next year when it comes up for my audit ill find this post again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 18:33:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-palo-alto-html-files/m-p/591738#M117833</guid>
      <dc:creator>James_V</dc:creator>
      <dc:date>2024-07-11T18:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: Access Palo Alto HTML Files</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-palo-alto-html-files/m-p/1237580#M125096</link>
      <description>&lt;P&gt;Still "showing up" against 10.2.11&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":zipper_mouth_face:"&gt;🤐&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Sep 2025 16:36:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-palo-alto-html-files/m-p/1237580#M125096</guid>
      <dc:creator>AaronWede</dc:creator>
      <dc:date>2025-09-09T16:36:15Z</dc:date>
    </item>
  </channel>
</rss>

