<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Responding to DMCA takedown requests in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/responding-to-dmca-takedown-requests/m-p/24250#M17677</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...Maybe you can change the query to match on src or dst port &lt;SPAN style="color: #222222; font-family: arial,sans-serif; background-color: #ffffff;"&gt;( port eq 36028 ).&amp;nbsp; Thanks.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Oct 2012 19:41:59 GMT</pubDate>
    <dc:creator>rmonvon</dc:creator>
    <dc:date>2012-10-24T19:41:59Z</dc:date>
    <item>
      <title>Responding to DMCA takedown requests</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/responding-to-dmca-takedown-requests/m-p/24249#M17676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm a recent Cisco ASA convert. I'm in an academic environment so bittorrent (and P2P in general) is permitted. We get an occasional DMCA takedown request. Finding the culprit in the ASA world was pretty straightforward: grep the syslog for the NATed port and see if there was a match near the alleged infringement time. I'm having a difficult time figuring out how to identify alleged infringers in Palo Alto land.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This sample notice contains the only material I have to work with from the copyright holder:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;INFRINGEMENT DETAIL&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;- ------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;Infringing Work : AVENGERS (2012), THE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;Filename : The Avengers 2012 HQ TS[ [Eng subs when needed P1RAT3-RG&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;First found (UTC): 2012-10-23T11:30:51.56Z&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;Last found (UTC): 2012-10-23T11:33:00.20Z&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;Filesize&amp;nbsp; : 1789259900 bytes&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;IP Address: 64.80.225.13&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;IP Port: 36028&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;Network: BitTorrent&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;Protocol: BitTorrent&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;I was thinking that searching the traffic log for ( port.dst eq 36028 ) and ( time_generated leq '2012/10/23 08:00:00' )&amp;nbsp; (we're GMT -4) would do the trick. Plenty of bittorrent application matches but I haven't found anything close to the time. This has been the case for each takedown notice received since my PA installation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;Ideas of where I'm going wrong?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;Rand&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2012 18:04:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/responding-to-dmca-takedown-requests/m-p/24249#M17676</guid>
      <dc:creator>MCmgt</dc:creator>
      <dc:date>2012-10-24T18:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: Responding to DMCA takedown requests</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/responding-to-dmca-takedown-requests/m-p/24250#M17677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...Maybe you can change the query to match on src or dst port &lt;SPAN style="color: #222222; font-family: arial,sans-serif; background-color: #ffffff;"&gt;( port eq 36028 ).&amp;nbsp; Thanks.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2012 19:41:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/responding-to-dmca-takedown-requests/m-p/24250#M17677</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-10-24T19:41:59Z</dc:date>
    </item>
    <item>
      <title>Re: Responding to DMCA takedown requests</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/responding-to-dmca-takedown-requests/m-p/24251#M17678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Using port.dst and port.src (or just port) will give you the pre-natted information.&amp;nbsp; If you're looking for logs that match up with an entity on the public Internet, then you'll want to use queries like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(natsport eq 36028) and (natdport eq 36028)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generally speaking, most outbound NAT implementations don't modify the destination port - so try it with (natsport eq 36028) and see if that works.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2012 19:55:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/responding-to-dmca-takedown-requests/m-p/24251#M17678</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2012-10-24T19:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: Responding to DMCA takedown requests</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/responding-to-dmca-takedown-requests/m-p/24252#M17679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Respond to that threat by asking for srcip and srcport used on their side (and when they replies with this information you can search for it as dstip and dstport in PA logs).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If they refuse to answer then throw this threat to /dev/null.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2012 20:38:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/responding-to-dmca-takedown-requests/m-p/24252#M17679</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-10-24T20:38:28Z</dc:date>
    </item>
    <item>
      <title>Re: Responding to DMCA takedown requests</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/responding-to-dmca-takedown-requests/m-p/24253#M17680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;(natsport eq 36028) worked great. Thanks!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;IMG alt="Capture.JPG" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4584_Capture.JPG" width="450" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2012 12:16:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/responding-to-dmca-takedown-requests/m-p/24253#M17680</guid>
      <dc:creator>MCmgt</dc:creator>
      <dc:date>2012-10-25T12:16:11Z</dc:date>
    </item>
  </channel>
</rss>

