<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to detect DNS TXT messages in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-detect-dns-txt-messages/m-p/16096#M11750</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Stefan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should be able to block it.&lt;/P&gt;&lt;P&gt;I was able to search in this vulnerability signature in the threat DB.&amp;nbsp;&amp;nbsp; Threat Id:- &lt;SPAN style="color: #252525; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;31941&lt;/SPAN&gt;&amp;nbsp; CVE:&lt;SPAN style="color: #252525; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;-2008-2469&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://threatvault.paloaltonetworks.com/" title="https://threatvault.paloaltonetworks.com/"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="4298" alt="dns-txt.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4298_dns-txt.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 03 Oct 2012 07:44:00 GMT</pubDate>
    <dc:creator>ppatel</dc:creator>
    <dc:date>2012-10-03T07:44:00Z</dc:date>
    <item>
      <title>How to detect DNS TXT messages</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-detect-dns-txt-messages/m-p/16095#M11749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;is it possible to detect and furthermore block DNS TXT messages via a Threat Signature? &lt;/P&gt;&lt;P&gt;The goal is to disable DNS Queries regarding TXT resource records.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure if the context &lt;EM&gt;dns-req-section&lt;/EM&gt; does the job...&lt;/P&gt;&lt;P&gt;Did anyone ever try this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2012 07:33:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-detect-dns-txt-messages/m-p/16095#M11749</guid>
      <dc:creator>IG-Support</dc:creator>
      <dc:date>2012-10-03T07:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to detect DNS TXT messages</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-detect-dns-txt-messages/m-p/16096#M11750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Stefan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should be able to block it.&lt;/P&gt;&lt;P&gt;I was able to search in this vulnerability signature in the threat DB.&amp;nbsp;&amp;nbsp; Threat Id:- &lt;SPAN style="color: #252525; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;31941&lt;/SPAN&gt;&amp;nbsp; CVE:&lt;SPAN style="color: #252525; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;-2008-2469&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://threatvault.paloaltonetworks.com/" title="https://threatvault.paloaltonetworks.com/"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="4298" alt="dns-txt.PNG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4298_dns-txt.PNG" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2012 07:44:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-detect-dns-txt-messages/m-p/16096#M11750</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-10-03T07:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to detect DNS TXT messages</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-detect-dns-txt-messages/m-p/16097#M11751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the quick reply! Unfortunately, this signature is not a generic TXT signature but rather addresses a specific threat which works by means of TXT records. Or at least thats my experience, otherwise I would have seen it in the threat logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nevertheless, while this signature does not match, chances are that there is the possibility to write a generic signature. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2012 07:50:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-detect-dns-txt-messages/m-p/16097#M11751</guid>
      <dc:creator>IG-Support</dc:creator>
      <dc:date>2012-10-03T07:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to detect DNS TXT messages</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-detect-dns-txt-messages/m-p/16098#M11752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think Parth meant since there is a signature regarding DNS TXT you should be able to create a custom one aswell.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2012 07:53:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-detect-dns-txt-messages/m-p/16098#M11752</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-10-03T07:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to detect DNS TXT messages</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-detect-dns-txt-messages/m-p/16099#M11753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct. A custom threat signatures can be created.&lt;/P&gt;&lt;P&gt;Or if you think the firewall did not capture a valid threat, you can submit a pcap from the client PC and the related traffic logs by opening a support ticket and we can hand it over to threat team for validation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2012 07:59:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-detect-dns-txt-messages/m-p/16099#M11753</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-10-03T07:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to detect DNS TXT messages</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-detect-dns-txt-messages/m-p/16100#M11754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see, makes sense... I prefer a generic solution which effectively matches all DNS TXT messages, no specific threat as such. If it helps, I can still submit a capture though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to create a custom signature, do you have a working signature already or shall I submit a new case via support?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;S&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2012 08:14:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-detect-dns-txt-messages/m-p/16100#M11754</guid>
      <dc:creator>IG-Support</dc:creator>
      <dc:date>2012-10-03T08:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to detect DNS TXT messages</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-detect-dns-txt-messages/m-p/16101#M11755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stefan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Support would not be able to assist you with the creation of custom signatures.&lt;/P&gt;&lt;P&gt;In order to build a signature, I would highly recommend you put your requests/inputs to dev-center of Palo Alto Networks.&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/community/devcenter"&gt;https://live.paloaltonetworks.com/community/devcenter&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you think the traffic passing through the firewall is a threat and the threat signatures are not triggered that is when you want to contact support with the pcaps and other relevant data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2012 08:21:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-detect-dns-txt-messages/m-p/16101#M11755</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-10-03T08:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to detect DNS TXT messages</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-detect-dns-txt-messages/m-p/16102#M11756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;However you should be able to contact local support (the company you bought the PA stuff from) or your sales engineer at PA to get assisted.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2012 08:43:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-detect-dns-txt-messages/m-p/16102#M11756</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-10-03T08:43:27Z</dc:date>
    </item>
  </channel>
</rss>

