<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to create custom vulnerability signature for SIP packets? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-custom-vulnerability-signature-for-sip-packets/m-p/27603#M20124</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You'll need to contact TAC and ask for them to open up SIP contexts in custom vulnerability signatures.&amp;nbsp; The SIP contexts are not open to the public today, but could be made available through a content update.&amp;nbsp; The "unknown" contexts you refer to are only applicable to "unknown-tcp" and "unknown-udp" App-IDs.&amp;nbsp; Since your traffic is identified as SIP, your existing custom signature will not match.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 Aug 2013 16:48:54 GMT</pubDate>
    <dc:creator>jvalentine</dc:creator>
    <dc:date>2013-08-01T16:48:54Z</dc:date>
    <item>
      <title>How to create custom vulnerability signature for SIP packets?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-custom-vulnerability-signature-for-sip-packets/m-p/27600#M20121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;we are trying to create&amp;nbsp; custom vulnerability signature for triggering on the specific string in the udp packet payload with&amp;nbsp; destination port 5060. Unfortunately there is no context for SIP. We used "Pattern Match" and chose "unknown -req-udp-payload" as a context. We applied a Vulnerability protection profile to the security policy (a rule allowing everything) but for some reason this didn't work as we expected. I mean we didn't receive any alert in the Threat log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to use "unknown -req-udp-payload" context for such purpose or it is intended only for the "unknown-udp" applications? Any other idea for creating such signature?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Leonid&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Aug 2013 10:02:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-custom-vulnerability-signature-for-sip-packets/m-p/27600#M20121</guid>
      <dc:creator>lzolotonos</dc:creator>
      <dc:date>2013-08-01T10:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to create custom vulnerability signature for SIP packets?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-custom-vulnerability-signature-for-sip-packets/m-p/27601#M20122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Following Tech note explains usage a each context for creating a Custom Threat Signature&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5534"&gt;Creating Custom Threat Signatures&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Aug 2013 12:46:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-custom-vulnerability-signature-for-sip-packets/m-p/27601#M20122</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-08-01T12:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to create custom vulnerability signature for SIP packets?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-custom-vulnerability-signature-for-sip-packets/m-p/27602#M20123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good Morning,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have a couple of avenues that you can check for assistance with custom signatures. You can post on the DevCenter (found on our support portal under communities - &lt;/SPAN&gt;&lt;A class="jive-link-community-small" data-containerid="1" data-containertype="14" data-objectid="2010" data-objecttype="14" href="https://live.paloaltonetworks.com/community/devcenter"&gt;https://live.paloaltonetworks.com/community/devcenter&lt;/A&gt;&lt;SPAN&gt;) or you can request that an official signature be made through Applipedia (&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://researchcenter.paloaltonetworks.com/submit-an-application/"&gt;http://researchcenter.paloaltonetworks.com/submit-an-application/&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Karthik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Aug 2013 12:51:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-custom-vulnerability-signature-for-sip-packets/m-p/27602#M20123</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-01T12:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to create custom vulnerability signature for SIP packets?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-custom-vulnerability-signature-for-sip-packets/m-p/27603#M20124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You'll need to contact TAC and ask for them to open up SIP contexts in custom vulnerability signatures.&amp;nbsp; The SIP contexts are not open to the public today, but could be made available through a content update.&amp;nbsp; The "unknown" contexts you refer to are only applicable to "unknown-tcp" and "unknown-udp" App-IDs.&amp;nbsp; Since your traffic is identified as SIP, your existing custom signature will not match.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Aug 2013 16:48:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-custom-vulnerability-signature-for-sip-packets/m-p/27603#M20124</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2013-08-01T16:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to create custom vulnerability signature for SIP packets?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-custom-vulnerability-signature-for-sip-packets/m-p/27604#M20125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By the way, how come that for example the SIP context is closed by default?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems like an neverending stream of feature requests to the SE's &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Aug 2013 19:52:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-custom-vulnerability-signature-for-sip-packets/m-p/27604#M20125</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-08-01T19:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to create custom vulnerability signature for SIP packets?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-custom-vulnerability-signature-for-sip-packets/m-p/27605#M20126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These aren't the same as Feature Requests that have to be rolled-up to your SE and then coded into the next version of PAN-OS.&amp;nbsp; The contexts already exist and just need to be a.) QA'd for public consumption, and then b.) opened to the public via the weekly content update.&amp;nbsp; I hear you, though.&amp;nbsp; I'd love to see all of the contexts opened up.&amp;nbsp; Then again, in my day-to-day I've been able to create all of the custom App-ID and Vulnerability signatures with the contexts that have already been published.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Aug 2013 20:16:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-create-custom-vulnerability-signature-for-sip-packets/m-p/27605#M20126</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2013-08-01T20:16:51Z</dc:date>
    </item>
  </channel>
</rss>

