<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo alto can detect SPAM in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2939#M2180</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Thanks for your answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I limit number of concurrent smtp in PA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 19 Jun 2013 19:11:50 GMT</pubDate>
    <dc:creator>soporteseguridad</dc:creator>
    <dc:date>2013-06-19T19:11:50Z</dc:date>
    <item>
      <title>Palo alto can detect SPAM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2935#M2176</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN id="result_box" lang="en"&gt;Hi i have a doubt about Palo Alto. Y&lt;SPAN class="hps"&gt;esterday&lt;/SPAN&gt; we realised that there was a massive spam &lt;SPAN class="hps"&gt;&lt;/SPAN&gt;&lt;SPAN class="hps"&gt;&lt;/SPAN&gt;&lt;SPAN class="hps"&gt;sending &lt;/SPAN&gt;&lt;SPAN class="hps"&gt;&lt;/SPAN&gt;&lt;SPAN class="hps"&gt;from&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;our&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;email servers.&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;This is the second&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;incident&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;of its kind in&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;recent days.&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;The question is whether&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;Paloalto&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;can&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;do some kind of&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;test to&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;detect this&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;type of behavior,&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;is able to examine&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;headers or something like that&lt;/SPAN&gt;&lt;SPAN&gt;?&lt;/SPAN&gt;, &lt;SPAN class="hps"&gt;There is some kind&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;of&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;filter&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;on that? What is the best solution that i could take??&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;&lt;SPAN class="hps"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps"&gt;Thanks so much.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 12:43:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2935#M2176</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2013-06-19T12:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto can detect SPAM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2936#M2177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Paloalto don't help you for that &lt;/P&gt;&lt;P&gt;refer to &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/12044#12044"&gt;https://live.paloaltonetworks.com/message/12044#12044&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 13:31:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2936#M2177</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2013-06-19T13:31:18Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto can detect SPAM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2937#M2178</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Network monitoring of you SMTP gateway outbound queue is a start (not a PA solution).&amp;nbsp; The other options PA based include:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Using the ACC monitoring SMTP connections from the inside SMTP gateways to show # of connections, destination countries, etc...&lt;BR /&gt;2) Using Session Browser (under Monitor tab) to monitor the number of active outbound SMTP connections from your SMTP gateway(s)&lt;/P&gt;&lt;P&gt;3) Once you know your baseline you can use resource protection (part of DOS protection ) to limit number of concurrent smtp connections you will allow outbound from your SMTP gateway.&amp;nbsp; Logging will tell you when it is actived.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 14:19:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2937#M2178</guid>
      <dc:creator>HITSSEC</dc:creator>
      <dc:date>2013-06-19T14:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto can detect SPAM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2938#M2179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could also create a custom IPS signature to get a alert when mails are being sent that contains a specific term or terms.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other than that get a proper antispam solution is the way to block both inbound aswell as any outbound spam attempts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Popular solutions seems to be Ironport and Halon among others...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 19:10:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2938#M2179</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-06-19T19:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto can detect SPAM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2939#M2180</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Thanks for your answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I limit number of concurrent smtp in PA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 19:11:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2939#M2180</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2013-06-19T19:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto can detect SPAM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2940#M2181</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take a look at the following threads:&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1746"&gt;https://live.paloaltonetworks.com/docs/DOC-1746&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-4574"&gt;https://live.paloaltonetworks.com/docs/DOC-4574&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured it for inbound smtp traffic but you can easily change it for outbound traffic.&amp;nbsp; The DOS rule you create would just apply to outbound SMTP traffic based on your situation. Hope this helps?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 21:44:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2940#M2181</guid>
      <dc:creator>HITSSEC</dc:creator>
      <dc:date>2013-06-19T21:44:29Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto can detect SPAM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2941#M2182</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello soporteseguridad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have had quite a few questions on this topic recently and have tried lots of things.&amp;nbsp; Unfortunately none have been very helpful.&amp;nbsp; The problem with most spam is that it is valid email (not malware), just lots of it, and unsolicited.&amp;nbsp; Here are a few options that may or may not help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.) The answer given by HITSSEC was one that it thought would be a great idea, though I tried it, and had very weak results.&amp;nbsp; The problem was, that even when metering SMTP traffic down to something like 2pps, I was still able to pass out 80+ emails out of 100 in a couple of seconds..Not very helpful.&amp;nbsp; In addition, if your spamming from an SMTP(postfix) type server, the server will just keep trying to deliver the messages.&amp;nbsp; It will eventually succeed after your DoS rule timeout happens.&amp;nbsp; I tested this with a postfix server running on my Mac (and a handy spam script), behind my PA-200 with a DoS policy.&amp;nbsp; It didn't matter how much I decreased the allowed pps, the policy did not prevent spamming - just slowed it down some.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.) Dynamic block lists.&amp;nbsp; This is an option available in 5.x and could be useful if you are trying to block email being sent to known relay servers, or from known IPs.&amp;nbsp; If you were so inclined, I imagine you could pull a list with a script (curl or wget) from a site that tracks spammers and make that file available on a webserver that your firewall has access to.&amp;nbsp; Then, add that path to your security rule as a dynamic block list.&amp;nbsp; This will of course not be helpful if the spam is being sent from dynamic (changing) IPs.&lt;/P&gt;&lt;P&gt;See KB here: &lt;A __default_attr="4724" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.) Dynamic address objects. Also in 5.x, you can have a dynamic address object in your security rule which can be updated via a script using the XML API on the firewall.&amp;nbsp; This could be an option if you had a method (external to the firewall) to detect and identify spammer IPs.&amp;nbsp; I have seen people use this feature to great success in conjunction with Splunk and the PaloAlto app for splunk (which contains a python script for updating dynamic address objects).&amp;nbsp; See KB here for info on dynamic address objects: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-4121"&gt;Dynamic Address Objects&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-chadd.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 03:44:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2941#M2182</guid>
      <dc:creator>cchristiansen</dc:creator>
      <dc:date>2013-06-20T03:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto can detect SPAM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2942#M2183</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Hello soporteseguridad,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;I realized that DOS protection will only limit the flow of outbound spam as the SMTP gateway will retry later.&amp;nbsp; Other than a spam filtering solution or a lot of custom SMTP related signatures, your best bet may be a monitoring approach.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Phil&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 13:04:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2942#M2183</guid>
      <dc:creator>HITSSEC</dc:creator>
      <dc:date>2013-06-20T13:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto can detect SPAM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2943#M2184</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another variant could be to whitelist destinations. That will of course doesnt help if the spam goes to a specific domain which already is whitelisted but still... a variant of this could be to also use geoip as dstip's (but again, wont help if the spam goes out to these you have already whitelisted).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 16:47:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2943#M2184</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-06-20T16:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: Palo alto can detect SPAM</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2944#M2185</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Re: ineffectiveness of DoS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the point is not to &lt;EM&gt;prevent&lt;/EM&gt; sending spam but to be alerted that you &lt;EM&gt;are&lt;/EM&gt; sending spam. Once you know you have a compromised machine you can take care of the real problem. The spam is just a symptom of a bigger problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Apr 2014 13:59:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-can-detect-spam/m-p/2944#M2185</guid>
      <dc:creator>MCmgt</dc:creator>
      <dc:date>2014-04-02T13:59:54Z</dc:date>
    </item>
  </channel>
</rss>

