<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I see if my FW has already been exploited by the CVE-2024-3400? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-if-my-fw-has-already-been-exploited-by-the-cve/m-p/583780#M116658</link>
    <description>&lt;P&gt;I have not seen anything yet for IoC in the logs as the exploit package apparently deletes related log entries. If you are syslogging then you may be able to search for something in your external log repository. I suspect there is probably a CLI debug command to show the Python packages loaded, but you would probably have to ask PA support for that. I have been running a script from an external server all weekend, constantly querying and validating the GlobalProtect CSS file, to look for any sign of an installed package.&lt;/P&gt;</description>
    <pubDate>Mon, 15 Apr 2024 19:36:57 GMT</pubDate>
    <dc:creator>Adrian_Jensen</dc:creator>
    <dc:date>2024-04-15T19:36:57Z</dc:date>
    <item>
      <title>How can I see if my FW has already been exploited by the CVE-2024-3400?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-if-my-fw-has-already-been-exploited-by-the-cve/m-p/583729#M116651</link>
      <description>&lt;P&gt;Hello team&lt;/P&gt;
&lt;P&gt;How can we determine if your device logs match the known indicators of compromise (IoC) for this vulnerability?&lt;/P&gt;
&lt;P&gt;I have already fixed the vulnerability and I have the TSF of my device and I want to see if I have been exploited before applying the WK,&lt;/P&gt;
&lt;P&gt;Can anyone help me?&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 13:59:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-if-my-fw-has-already-been-exploited-by-the-cve/m-p/583729#M116651</guid>
      <dc:creator>Alpalo</dc:creator>
      <dc:date>2024-04-15T13:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: How can I see if my FW has already been exploited by the CVE-2024-3400?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-if-my-fw-has-already-been-exploited-by-the-cve/m-p/583780#M116658</link>
      <description>&lt;P&gt;I have not seen anything yet for IoC in the logs as the exploit package apparently deletes related log entries. If you are syslogging then you may be able to search for something in your external log repository. I suspect there is probably a CLI debug command to show the Python packages loaded, but you would probably have to ask PA support for that. I have been running a script from an external server all weekend, constantly querying and validating the GlobalProtect CSS file, to look for any sign of an installed package.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 19:36:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-if-my-fw-has-already-been-exploited-by-the-cve/m-p/583780#M116658</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2024-04-15T19:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: How can I see if my FW has already been exploited by the CVE-2024-3400?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-if-my-fw-has-already-been-exploited-by-the-cve/m-p/584070#M116692</link>
      <description>&lt;P&gt;If you haven't seen it the command from the CLI that can give indicators is in the advisory here:&amp;nbsp;&lt;A href="https://security.paloaltonetworks.com/CVE-2024-3400" target="_blank"&gt;https://security.paloaltonetworks.com/CVE-2024-3400&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;From the advisory though it states this isn't definitive just could indicate a thwarted attempt and not necessarily a breach. We've uploaded tech support logs to Palo and are waiting for their analysis.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 16:41:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-if-my-fw-has-already-been-exploited-by-the-cve/m-p/584070#M116692</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2024-04-17T16:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: How can I see if my FW has already been exploited by the CVE-2024-3400?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-if-my-fw-has-already-been-exploited-by-the-cve/m-p/584073#M116693</link>
      <description>&lt;P&gt;Also when you say FIXED be aware that disabling telemetry is NOT enough now and Palo's Guidance has changed on this as of late yesterday (4/16).&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 16:42:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-if-my-fw-has-already-been-exploited-by-the-cve/m-p/584073#M116693</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2024-04-17T16:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: How can I see if my FW has already been exploited by the CVE-2024-3400?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-if-my-fw-has-already-been-exploited-by-the-cve/m-p/584272#M116717</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;Here is the best writeup I have seen so far.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/" target="_blank"&gt;https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 21:59:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-if-my-fw-has-already-been-exploited-by-the-cve/m-p/584272#M116717</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-04-18T21:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: How can I see if my FW has already been exploited by the CVE-2024-3400?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-if-my-fw-has-already-been-exploited-by-the-cve/m-p/584345#M116722</link>
      <description>&lt;P&gt;IOC's posted i made a new thread for it.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/cve-2024-3400-ioc-s/td-p/584343" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/cve-2024-3400-ioc-s/td-p/584343&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2024 14:47:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-if-my-fw-has-already-been-exploited-by-the-cve/m-p/584345#M116722</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-04-19T14:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: How can I see if my FW has already been exploited by the CVE-2024-3400?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-if-my-fw-has-already-been-exploited-by-the-cve/m-p/584346#M116723</link>
      <description>&lt;P&gt;Also PAN updated their Faq's with a search query.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://security.paloaltonetworks.com/CVE-2024-3400#:~:text=Q.Are%20there%20any%20checks%20I%20can%20run%20on%20my%20device%20to%20look%20for%20evidence%20of%20attempted%20exploit%20activity%3F" target="_blank"&gt;https://security.paloaltonetworks.com/CVE-2024-3400#:~:text=Q.Are%20there%20any%20checks%20I%20can%20run%20on%20my%20device%20to%20look%20for%20evidence%20of%20attempted%20exploit%20activity%3F&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2024 14:58:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-if-my-fw-has-already-been-exploited-by-the-cve/m-p/584346#M116723</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-04-19T14:58:33Z</dc:date>
    </item>
  </channel>
</rss>

