<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block FTP Brute Force Attemps - Threat ID 40001 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-ftp-brute-force-attemps-threat-id-40001/m-p/20626#M15058</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the actual signature that is being enabled behind that exception rule? Is it a custom sig or the Palo Alto Networks ftp brute force sig?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Jul 2012 19:05:34 GMT</pubDate>
    <dc:creator>fredallee</dc:creator>
    <dc:date>2012-07-05T19:05:34Z</dc:date>
    <item>
      <title>Block FTP Brute Force Attemps - Threat ID 40001</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ftp-brute-force-attemps-threat-id-40001/m-p/20624#M15056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to block Block FTP Brute Force Attemps.&lt;/P&gt;&lt;P&gt;The default rule in the PA alert only in theThreat log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I added a new Vulnerabolity Protection Rule:&lt;/P&gt;&lt;P&gt;Action: Block&lt;/P&gt;&lt;P&gt;Host type: Any (also tried Server)&lt;/P&gt;&lt;P&gt;Category: brute-force&lt;/P&gt;&lt;P&gt;Severity: Any&lt;/P&gt;&lt;P&gt;CVE: Any&lt;/P&gt;&lt;P&gt;Vendor ID: Any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I placed the rule above al the default rules (see attachment).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I simulate a ftp brute force attack I only see a alert message in the Threat log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance for your reply,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hans&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 16:49:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ftp-brute-force-attemps-threat-id-40001/m-p/20624#M15056</guid>
      <dc:creator>hnederstigt</dc:creator>
      <dc:date>2012-07-05T16:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: Block FTP Brute Force Attemps - Threat ID 40001</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ftp-brute-force-attemps-threat-id-40001/m-p/20625#M15057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try changing the action to 'block-ip'.&amp;nbsp; Block will only block the packet/session related to the violation, which doesn't work very well for attacks based on cumulative attempts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="dektop.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3198_dektop.png" width="450" /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 18:55:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ftp-brute-force-attemps-threat-id-40001/m-p/20625#M15057</guid>
      <dc:creator>drogers</dc:creator>
      <dc:date>2012-07-05T18:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: Block FTP Brute Force Attemps - Threat ID 40001</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-ftp-brute-force-attemps-threat-id-40001/m-p/20626#M15058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the actual signature that is being enabled behind that exception rule? Is it a custom sig or the Palo Alto Networks ftp brute force sig?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 19:05:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-ftp-brute-force-attemps-threat-id-40001/m-p/20626#M15058</guid>
      <dc:creator>fredallee</dc:creator>
      <dc:date>2012-07-05T19:05:34Z</dc:date>
    </item>
  </channel>
</rss>

