<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Avoid scanning threat vulnerabilities in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/avoid-scanning-threat-vulnerabilities/m-p/30879#M22600</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First you can activate on the security rule the DSRI which will prevent analyse on your server answer.&lt;/P&gt;&lt;P&gt;Or you can create a custom profile for this rule&lt;/P&gt;&lt;P&gt;At the end on your global profile you can disable some alert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 28 May 2014 12:36:37 GMT</pubDate>
    <dc:creator>VinceM</dc:creator>
    <dc:date>2014-05-28T12:36:37Z</dc:date>
    <item>
      <title>Avoid scanning threat vulnerabilities</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/avoid-scanning-threat-vulnerabilities/m-p/30878#M22599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I have in my firewall logs events detected as a threat of this IP:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: courier new,courier;"&gt;Source IP:&amp;nbsp;&amp;nbsp;&amp;nbsp; 84.88.91.1&amp;nbsp;&amp;nbsp;&amp;nbsp; Spain&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;From Zone: Untrust&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: arial,helvetica,sans-serif;"&gt;to my web server:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;Destination IP:&amp;nbsp;&amp;nbsp;&amp;nbsp; 195.77.XX.XX&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;Destination Port:&amp;nbsp;&amp;nbsp;&amp;nbsp; 80&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: courier new,courier;"&gt;To Zone: DMZ&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Multiple Vulnerabilities Types Targeting a Single Source&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: courier new,courier;"&gt;Acunetix Web Vulnerability Scanner Detection&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;Microsoft IIS Escaped Characters Decoding Command Execution Vulnerability&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;HTTP Directory Traversal Vulnerabilit&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;Microsoft Windows win.ini access attempt&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;Generic HTTP Cross Site Scripting Attempt&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 8pt;"&gt;HTTP Cross Site Scripting Attempt&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: courier new,courier;"&gt;Microsoft SharePoint scriptresx.ashx Cross-site Scripting Vulnerability&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I avoid or prevent this type of vulnerability scanning? or what recommendations do you suggest me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dicu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 May 2014 11:49:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/avoid-scanning-threat-vulnerabilities/m-p/30878#M22599</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2014-05-28T11:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: Avoid scanning threat vulnerabilities</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/avoid-scanning-threat-vulnerabilities/m-p/30879#M22600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First you can activate on the security rule the DSRI which will prevent analyse on your server answer.&lt;/P&gt;&lt;P&gt;Or you can create a custom profile for this rule&lt;/P&gt;&lt;P&gt;At the end on your global profile you can disable some alert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 May 2014 12:36:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/avoid-scanning-threat-vulnerabilities/m-p/30879#M22600</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2014-05-28T12:36:37Z</dc:date>
    </item>
    <item>
      <title>Re: Avoid scanning threat vulnerabilities</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/avoid-scanning-threat-vulnerabilities/m-p/30880#M22601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is a doc that explains on how to exempt an ip address from threat profile&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5235"&gt;How To Add Exempt IP Addresses From the Threat Monitor Logs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can use the above doc so it will not scan that.&lt;/P&gt;&lt;P&gt;Here is another useful doc regarding threat prevention.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3094"&gt;Threat Prevention Deployment Tech Note&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Let us know if this helps.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 May 2014 15:45:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/avoid-scanning-threat-vulnerabilities/m-p/30880#M22601</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2014-05-29T15:45:21Z</dc:date>
    </item>
  </channel>
</rss>

