<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sipvicious.Gen User-Agent Traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24856#M18132</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://live.paloaltonetworks.com/u1/30719"&gt;martinriveran&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Welcome to forums !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you are talking about threat 13272 Sipvicious.Gen User-Agent traffic, this threat detects SipVicious User-Agent traffic in SIP request headers : &lt;A href="https://threatvault.paloaltonetworks.com/Home/ThreatDetail/13272" title="https://threatvault.paloaltonetworks.com/Home/ThreatDetail/13272"&gt;https://threatvault.paloaltonetworks.com/Home/ThreatDetail/13272&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You might have SIP packets coming in with SipVicious user-agent traffic in the headers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Nov 2014 01:18:29 GMT</pubDate>
    <dc:creator>bat</dc:creator>
    <dc:date>2014-11-14T01:18:29Z</dc:date>
    <item>
      <title>Sipvicious.Gen User-Agent Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24855#M18131</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is my first post here. So i started a new job couple months ago and we have a PA 3050 . The daily reports is showing Sipvicious.Gen User-Agent Traffic coming from IP's all over the world. &lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Nov 2014 01:14:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24855#M18131</guid>
      <dc:creator>martinriveran</dc:creator>
      <dc:date>2014-11-14T01:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: Sipvicious.Gen User-Agent Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24856#M18132</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://live.paloaltonetworks.com/u1/30719"&gt;martinriveran&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Welcome to forums !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you are talking about threat 13272 Sipvicious.Gen User-Agent traffic, this threat detects SipVicious User-Agent traffic in SIP request headers : &lt;A href="https://threatvault.paloaltonetworks.com/Home/ThreatDetail/13272" title="https://threatvault.paloaltonetworks.com/Home/ThreatDetail/13272"&gt;https://threatvault.paloaltonetworks.com/Home/ThreatDetail/13272&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You might have SIP packets coming in with SipVicious user-agent traffic in the headers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Nov 2014 01:18:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24856#M18132</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-11-14T01:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: Sipvicious.Gen User-Agent Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24857#M18133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;STRONG style="font-size: 11.8181819915771px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="30719" data-username="martinriveran" href="https://live.paloaltonetworks.com/people/martinriveran" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;martinriveran&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 11.8181819915771px;"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; ,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please provide some more detail information regarding this threat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can go to Web-UI of the PAN firewall and open Monitor &amp;gt; Logs &amp;gt; Threat. Open the threat and take a snapshot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Nov 2014 01:18:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24857#M18133</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-11-14T01:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: Sipvicious.Gen User-Agent Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24858#M18134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://live.paloaltonetworks.com/u1/30719"&gt;martinriveran&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you trust source and destination of VOIP traffic. If yes, this might be a potential false positive and you can ingore it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Nov 2014 01:22:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24858#M18134</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-11-14T01:22:32Z</dc:date>
    </item>
    <item>
      <title>Re: Sipvicious.Gen User-Agent Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24859#M18135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is the 13272 indeed.&lt;BR /&gt;&lt;IMG alt="sip.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16870_sip.jpg" style="height: 275px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Nov 2014 01:24:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24859#M18135</guid>
      <dc:creator>martinriveran</dc:creator>
      <dc:date>2014-11-14T01:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: Sipvicious.Gen User-Agent Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24860#M18136</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the victim and attacker address is trusted IP addresses on your network...? If so, then it might be a false positive and you can add an "exception" to your vulnerability profile to&amp;nbsp; avoid such logs in future. But, if those addresses are unknown, then you may open a support ticket to verify the traffic/signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Nov 2014 01:28:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24860#M18136</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-11-14T01:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: Sipvicious.Gen User-Agent Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24861#M18137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since, this is SIP traffic, please check address with Call-manager and EPBX address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Nov 2014 01:30:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24861#M18137</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-11-14T01:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: Sipvicious.Gen User-Agent Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24862#M18138</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The attacker IP's are unknown...&lt;BR /&gt;Also this a DC. There should be no SIP traffic at all....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all the help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Nov 2014 01:34:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24862#M18138</guid>
      <dc:creator>martinriveran</dc:creator>
      <dc:date>2014-11-14T01:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: Sipvicious.Gen User-Agent Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24863#M18139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/30719"&gt;martinriveran&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above threat just checks for the User-Agent "friendly-scanner" in the SIP headers. For more information about SipVicious: &lt;A href="http://advantia.ca/weblog/less-than-friendly-scanner--sipvicious" title="http://advantia.ca/weblog/less-than-friendly-scanner--sipvicious"&gt;The Less Than Friendly-scanner, Sipvicious&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again if you do not trust the source of this traffic you can create an exception and change the action from alert to block:&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;&lt;SPAN&gt;To create an exception follow this document:&lt;/SPAN&gt;&lt;A class="jive-link-wiki-small" data-containerid="2027" data-containertype="14" data-objectid="3699" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-3699"&gt;https://live.paloaltonetworks.com/docs/DOC-3699&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Nov 2014 01:35:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24863#M18139</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-11-14T01:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Sipvicious.Gen User-Agent Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24864#M18140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Martin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is Victim a Domain Controller? If you dont expect a SIP traffic on Domain controller than do further investigation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Nov 2014 01:55:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24864#M18140</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-11-14T01:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: Sipvicious.Gen User-Agent Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24865#M18141</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a DC environment where they should be no SIP traffic at all...that is the weird thing....&lt;BR /&gt;The way our PA is setup is only a tab...so not inline.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Agan, i really appreciate everyones help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Nov 2014 02:29:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sipvicious-gen-user-agent-traffic/m-p/24865#M18141</guid>
      <dc:creator>martinriveran</dc:creator>
      <dc:date>2014-11-14T02:29:38Z</dc:date>
    </item>
  </channel>
</rss>

