<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Frustration with threats from PA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/frustration-with-threats-from-pa/m-p/34057#M24971</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks HULK, that does indeed help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 May 2014 13:43:16 GMT</pubDate>
    <dc:creator>ericgearhart</dc:creator>
    <dc:date>2014-05-06T13:43:16Z</dc:date>
    <item>
      <title>Frustration with threats from PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/frustration-with-threats-from-pa/m-p/34055#M24969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is anyone else frustrated with PA's approach to threats and threat signatures?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Prime example: "Netbios Small Piece Data Evasion Attack Vulnerability" - signature ID 33511, link to the Threat Vault: &lt;A href="https://threatvault.paloaltonetworks.com/Home/ThreatDetail/33511" title="https://threatvault.paloaltonetworks.com/Home/ThreatDetail/33511"&gt;https://threatvault.paloaltonetworks.com/Home/ThreatDetail/33511&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can we please get some kind of an idea of what the heck this is in reference to? A Microsoft KB? Some kind of hint about figuring out if this is a FP or not? Google searches for "Netbios Small Piece Data Evasion Attack Vulnerability" turn up a link to Microsoft KB that's no longer valid.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 May 2014 20:01:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/frustration-with-threats-from-pa/m-p/34055#M24969</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2014-05-05T20:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: Frustration with threats from PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/frustration-with-threats-from-pa/m-p/34056#M24970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The signature 33511 will be triggered if there are two &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;netbios&lt;/SPAN&gt; packets which length is less than 4 bytes in one session. Some evasion techniques will use this method to get rid of detection, but this signature itself is not a vulnerability.&amp;nbsp; &lt;/P&gt;&lt;P&gt;This is just an indicator that PAN find some evasion packet. It &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;not means&lt;/SPAN&gt; it is malicious.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 May 2014 07:38:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/frustration-with-threats-from-pa/m-p/34056#M24970</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-05-06T07:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: Frustration with threats from PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/frustration-with-threats-from-pa/m-p/34057#M24971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks HULK, that does indeed help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 May 2014 13:43:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/frustration-with-threats-from-pa/m-p/34057#M24971</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2014-05-06T13:43:16Z</dc:date>
    </item>
  </channel>
</rss>

