<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom Vulnerability (.DMG) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-vulnerability-dmg/m-p/34741#M25496</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think it would be best if you post the same thread in &lt;A href="https://live.paloaltonetworks.com/space/2010"&gt;DevCenter&lt;/A&gt; as developer and other users expert in this answer on that community.&lt;/P&gt;&lt;P&gt;Hope this helps you find the answer.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Mar 2014 21:53:22 GMT</pubDate>
    <dc:creator>mbutt</dc:creator>
    <dc:date>2014-03-06T21:53:22Z</dc:date>
    <item>
      <title>Custom Vulnerability (.DMG)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-vulnerability-dmg/m-p/34739#M25494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PanOSS 5.0.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following site (amongst others) hosts a malicious file that I want to block: &lt;A href="http://free-mac-download.net/" title="http://free-mac-download.net/"&gt;Download Genieo&lt;/A&gt;. The file is a .dmg and I want it blocked to my Mac user estate. Rather than block the URL I thought I would give Custom Signatures &amp;gt; Vulnerability a go. I am following the document Creating_Custom_Signatures-RevA (page 43).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;File name is InstallGenieo.dmg with Hex of&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="p1"&gt;0000000: 789c 730d 6262 6060 883f cf30 0a46 2400&amp;nbsp; x.s.bb``.?.0.F$.&lt;/P&gt;&lt;P class="p1"&gt;0000010: 0087 f401 c878 9ced d43b 0ac2 4010 06e0&amp;nbsp; .....x...;..@...&lt;/P&gt;&lt;P class="p1"&gt;0000020: 8885 d7f0 0e1e 20da 888d 10f0 004b c020&amp;nbsp; ...... ......K.&lt;/P&gt;&lt;P class="p1"&gt;0000030: 8baf&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;I have created a custom vulnerability Configuration like so:&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;IMG __jive_id="12008" alt="Screen Shot 2014-03-06 at 15.53.53.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/12008_Screen Shot 2014-03-06 at 15.53.53.png" /&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;and Standard Signature, And Condition (Transaction) like so:&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;IMG __jive_id="12009" alt="Screen Shot 2014-03-06 at 15.55.13.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/12009_Screen Shot 2014-03-06 at 15.55.13.png" style="width: 620px; height: 187px;" /&gt;&lt;/P&gt;&lt;P class="p1"&gt;Once pushed from Panorama to my devices I don't see it in the logs as Alerting. I'm sure I'm missing something but being my first attempt, I'm not sure where. Should I add it to the Vulnerability Protection under Security Profiles or something..? Or am I doing this incorrectly in the first place...?:)&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;Any hints would be great,&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Mar 2014 15:58:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-vulnerability-dmg/m-p/34739#M25494</guid>
      <dc:creator>nickcx1</dc:creator>
      <dc:date>2014-03-06T15:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Vulnerability (.DMG)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-vulnerability-dmg/m-p/34740#M25495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not an expert to say if the definition is correct.&lt;/P&gt;&lt;P&gt;Nonetheless you need the security profile in the security policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Mar 2014 21:12:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-vulnerability-dmg/m-p/34740#M25495</guid>
      <dc:creator>prb</dc:creator>
      <dc:date>2014-03-06T21:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Vulnerability (.DMG)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-vulnerability-dmg/m-p/34741#M25496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think it would be best if you post the same thread in &lt;A href="https://live.paloaltonetworks.com/space/2010"&gt;DevCenter&lt;/A&gt; as developer and other users expert in this answer on that community.&lt;/P&gt;&lt;P&gt;Hope this helps you find the answer.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Mar 2014 21:53:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-vulnerability-dmg/m-p/34741#M25496</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2014-03-06T21:53:22Z</dc:date>
    </item>
  </channel>
</rss>

