<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA File Detection seems not working right in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26406#M19259</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Manni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There shouldn't be a problem with 3.1.8.&amp;nbsp; Can you open a support ticket and include a PCAP and/or a sample of the file in question so we can take a closer look?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Doris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 23 Jun 2011 01:40:53 GMT</pubDate>
    <dc:creator>dyang</dc:creator>
    <dc:date>2011-06-23T01:40:53Z</dc:date>
    <item>
      <title>PA File Detection seems not working right</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26397#M19250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PA claims to detect several DOS and Windows executable filetypes. The following filetypes are partially not really executables, but i am wondering that PA ignores (do not show any log) the types totally. (Nevertheless some of the filetypes are potentially really harmfull).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found the following behaviour of our Palo Alto Firewall (we tested with mail-attachements)&lt;/P&gt;&lt;TABLE border="1" cellpadding="3" cellspacing="0" class="jiveBorder" style="width: 100%; border: 1px solid #000000;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TH align="center" style="background-color:#6690BC;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;Filetype&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color:#6690BC;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;Palo Alto Detection&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;tlb&lt;/TD&gt;&lt;TD&gt;no detection&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;sys&lt;/TD&gt;&lt;TD&gt;no detection&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;wsc&lt;/TD&gt;&lt;TD&gt;no detection&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;bin&lt;/TD&gt;&lt;TD&gt;no detection&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;vxd&lt;/TD&gt;&lt;TD&gt;no detection&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;exe&lt;/TD&gt;&lt;TD&gt;ok&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;scf&lt;/TD&gt;&lt;TD&gt;no detection&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;cmd&lt;/TD&gt;&lt;TD&gt;detection only with file ending ".cmd"&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;drv&lt;/TD&gt;&lt;TD&gt;ok&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;com&lt;/TD&gt;&lt;TD&gt;ok&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;cpl&lt;/TD&gt;&lt;TD&gt;ok&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;vbs&lt;/TD&gt;&lt;TD&gt;no detection&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;scr&lt;/TD&gt;&lt;TD&gt;ok&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;dll&lt;/TD&gt;&lt;TD&gt;ok&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ocx&lt;/TD&gt;&lt;TD&gt;ok&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;reg&lt;/TD&gt;&lt;TD&gt;no detection&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jun 2011 14:42:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26397#M19250</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2011-06-08T14:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: PA File Detection seems not working right</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26398#M19251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm assuming you're referring to the file types that we can block via file filtering, correct?&amp;nbsp; You can find the full list of supported file type signatures here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://live.paloaltonetworks.com/docs/DOC-1783"&gt;https://live.paloaltonetworks.com/docs/DOC-1783&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there is a file type that you'd like to see added, please contact your SE and have them file an enhancement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Doris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jun 2011 20:40:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26398#M19251</guid>
      <dc:creator>dyang</dc:creator>
      <dc:date>2011-06-08T20:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: PA File Detection seems not working right</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26399#M19252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Doris,&lt;/P&gt;&lt;P&gt;PA explicitely declares that they are able to detect the file type "sys" or "reg". But it does not detect this file types, if they are in a mail attachment. Additionally, it should be possible to detect filetypes like "vxd", if PA tries to keep their customer free from potentially harmfull files. Third, it is not a good work, if the PA detects the file type "cmd" only, if the file name ends with ".cmd".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Manfred&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 12:13:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26399#M19252</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2011-06-09T12:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: PA File Detection seems not working right</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26400#M19253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Possibly it would be better to log all the unknown files as "unknown files" than to conceal it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 12:39:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26400#M19253</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2011-06-09T12:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: PA File Detection seems not working right</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26401#M19254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Manfred,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When attempting to detect .sys and .reg files in a mail attachment, did you also have an SSL policy setup to decrypt the traffic?&amp;nbsp; Or are you testing all file types in the same manner and only .sys and .reg files were not being properly detected?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generally speaking, our file signatures are based on the unique characteristics of each file, not just on the file extension itself.&amp;nbsp; If you're experiencing an issue with .cmd files, please open a support case so we can investigate further.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Doris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jun 2011 00:33:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26401#M19254</guid>
      <dc:creator>dyang</dc:creator>
      <dc:date>2011-06-10T00:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: PA File Detection seems not working right</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26402#M19255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Doris,&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0.75pt 0in; text-align: left;"&gt;we tested all the mail attachements with one rule. So in this kind of "file blocking" rule, all executables (so called PE files in PA speek = &lt;SPAN style="font-size: 9pt; color: black; font-family: 'Arial','sans-serif';"&gt;PE -Microsoft Windows Portable Executable (exe, dll, com, scr, ocx, cpl, sys, drv, tlb)) should be detected. The mails were not encrypted, least of all not with SSL. The communication port was tcp 25 = normal emailexchange between a german freemailer and our mailserver. PA detects correctly the application "smtp" in this data exchange. Exe, dll, com, scr, ocx, cpl, drv were detected correctly, sys and tlb were not detected.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0.75pt 0in; text-align: left;"&gt;The relating rule simple says: alert all data files - please look at the attached gif. So a reg or a cmd file should be detected too. But the reg files was detected never, and the cmd file was only detected, if the filename ends with "*.cmd".&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0.75pt 0in; text-align: left;"&gt;What makes me very unhappy is, that there is &lt;STRONG&gt;no&lt;/STRONG&gt; file logging, although we haved &lt;STRONG&gt;attached&lt;/STRONG&gt; some files at an email. In my humble opinion is an attachement very easy to detect, so why did i got no log entry?&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0.75pt 0in; text-align: left;"&gt;The PA art of security seems not to be sufficiently in another point of email communication. If i send an email with javascript in his data body, there is no method in PA to detect and block this code (i tried several data patterns in file blocking or data filtering rules and self designed applications or vulnerabilities). Other security engines like mcafee/webwasher or finjan are able to block such code.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manfred&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0.75pt 0in; text-align: left;"&gt;&lt;IMG src="file:/tmp/moz-screenshot-2.png" /&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0.75pt 0in; text-align: left;"&gt;&lt;IMG src="file:/tmp/moz-screenshot.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jun 2011 11:11:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26402#M19255</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2011-06-10T11:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: PA File Detection seems not working right</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26403#M19256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Manfred,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apologies for the delay.&amp;nbsp; As it turns out, you are correct - our .cmd signature is based on file extension only, as there was no other way for us to create one based on other patterns.&amp;nbsp; As for your issues with .reg files, these should be detected properly.&amp;nbsp; Can you comment on what content and PAN-OS version you're using?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Doris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 00:50:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26403#M19256</guid>
      <dc:creator>dyang</dc:creator>
      <dc:date>2011-06-21T00:50:54Z</dc:date>
    </item>
    <item>
      <title>Re: PA File Detection seems not working right</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26404#M19257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Doris,&lt;/P&gt;&lt;P&gt;we are updating our PAN application knowledgecontent allways shortly after it will be delivered. So the phenome occurs on all content, i guess (if i do understand your question correctly). Our OS is 3.1.8 and will be updated to 4.0.3 next week.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciao&lt;/P&gt;&lt;P&gt;Manni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Jun 2011 16:21:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26404#M19257</guid>
      <dc:creator>mhuels</dc:creator>
      <dc:date>2011-06-22T16:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: PA File Detection seems not working right</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26405#M19258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your continued patience, Manni.&amp;nbsp; I'll see what I can find.&amp;nbsp; &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Jun 2011 18:26:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26405#M19258</guid>
      <dc:creator>dyang</dc:creator>
      <dc:date>2011-06-22T18:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: PA File Detection seems not working right</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26406#M19259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Manni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There shouldn't be a problem with 3.1.8.&amp;nbsp; Can you open a support ticket and include a PCAP and/or a sample of the file in question so we can take a closer look?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Doris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jun 2011 01:40:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-file-detection-seems-not-working-right/m-p/26406#M19259</guid>
      <dc:creator>dyang</dc:creator>
      <dc:date>2011-06-23T01:40:53Z</dc:date>
    </item>
  </channel>
</rss>

