<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does Palo Alto issue security advisories for security related fixes in patches/updates? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/does-palo-alto-issue-security-advisories-for-security-related/m-p/39029#M28609</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But that doesnt matter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The firewall (specially if its a modern NGFW from the 21th century) should be able to protect itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is force authentication before you can do anything remotely close to management of the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is default deny which all PA slides talk about regarding PA's security policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would be great if a PA representative could add some info in this thread regarding why 46728 doesnt show up on the &lt;A href="http://securityadvisories.paloaltonetworks.com/" title="http://securityadvisories.paloaltonetworks.com/"&gt;Submit Form&lt;/A&gt; list?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This security hole is as bad as the backdoor in DLINK equipment described in:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.devttys0.com/wp-content/uploads/2010/12/dlink_php_vulnerability.pdf"&gt;http://www.devttys0.com/wp-content/uploads/2010/12/dlink_php_vulnerability.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or for that matter the nice backdoor into TP-LINK equipment:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://sekurak.pl/tp-link-httptftp-backdoor/" title="http://sekurak.pl/tp-link-httptftp-backdoor/"&gt;http://sekurak.pl/tp-link-httptftp-backdoor/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://sekurak.pl/more-information-about-tp-link-backdoor/" title="http://sekurak.pl/more-information-about-tp-link-backdoor/"&gt; More information about TP-Link backdoor&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 13 Apr 2013 08:17:48 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2013-04-13T08:17:48Z</dc:date>
    <item>
      <title>Does Palo Alto issue security advisories for security related fixes in patches/updates?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-palo-alto-issue-security-advisories-for-security-related/m-p/39024#M28604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I noticed that in the release notes for PANOS 5.0.4, there was a reasonably serious security issue pointed out:&lt;/P&gt;&lt;P data-canvas-width="44.64" data-font-name="g_font_p0_1" dir="ltr" style="font-size: 16px; font-family: serif;"&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;46728 -&amp;nbsp; A Tech Support file generated on the firewall could be &lt;SPAN class="highlight selected"&gt;downloaded&lt;/SPAN&gt; without the admin being prompted for user authentication. The issue is now fixed.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To me this is kind of a big deal... being able to download the equivalent of a 'show tech' could reveal at the very least the entire firewall's configuration, right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's what led me to creating this thread... does PA issue security advisories for their products? I wouldn't have even noticed this issue existed or was fixed in 5.0.4 if I hadn't pulled down and read the release notes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 20:25:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-palo-alto-issue-security-advisories-for-security-related/m-p/39024#M28604</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-04-12T20:25:35Z</dc:date>
    </item>
    <item>
      <title>Re: Does Palo Alto issue security advisories for security related fixes in patches/updates?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-palo-alto-issue-security-advisories-for-security-related/m-p/39025#M28605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you can find them here: &lt;A href="http://securityadvisories.paloaltonetworks.com"&gt;http://securityadvisories.paloaltonetworks.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would probably be best to consult your local Palo Alto SE about that ticket and the details. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 20:48:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-palo-alto-issue-security-advisories-for-security-related/m-p/39025#M28605</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2013-04-12T20:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: Does Palo Alto issue security advisories for security related fixes in patches/updates?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-palo-alto-issue-security-advisories-for-security-related/m-p/39026#M28606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The interesting thing is that 46728 isn't listed at &lt;A href="http://securityadvisories.paloaltonetworks.com/" title="http://securityadvisories.paloaltonetworks.com/"&gt;http://securityadvisories.paloaltonetworks.com/&lt;/A&gt; ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 20:55:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-palo-alto-issue-security-advisories-for-security-related/m-p/39026#M28606</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-04-12T20:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: Does Palo Alto issue security advisories for security related fixes in patches/updates?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-palo-alto-issue-security-advisories-for-security-related/m-p/39027#M28607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P&gt;umphmharding wrote:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It would probably be best to consult your local Palo Alto SE about that ticket and the details.&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see the details myself!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If I do a 'wget &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://my-PA-firewall/device/export.file.php"&gt;https://my-PA-firewall/device/export.file.php&lt;/A&gt;&lt;SPAN&gt;' I can pull a generated tech support file without being authenticated!&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Apr 2013 21:25:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-palo-alto-issue-security-advisories-for-security-related/m-p/39027#M28607</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-04-12T21:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: Does Palo Alto issue security advisories for security related fixes in patches/updates?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-palo-alto-issue-security-advisories-for-security-related/m-p/39028#M28608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is an issue, and it was fixed, but best practice is to lock down your management interface to a few select IP addresses belonging to your administrators. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Apr 2013 00:37:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-palo-alto-issue-security-advisories-for-security-related/m-p/39028#M28608</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2013-04-13T00:37:58Z</dc:date>
    </item>
    <item>
      <title>Re: Does Palo Alto issue security advisories for security related fixes in patches/updates?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/does-palo-alto-issue-security-advisories-for-security-related/m-p/39029#M28609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But that doesnt matter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The firewall (specially if its a modern NGFW from the 21th century) should be able to protect itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is force authentication before you can do anything remotely close to management of the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is default deny which all PA slides talk about regarding PA's security policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would be great if a PA representative could add some info in this thread regarding why 46728 doesnt show up on the &lt;A href="http://securityadvisories.paloaltonetworks.com/" title="http://securityadvisories.paloaltonetworks.com/"&gt;Submit Form&lt;/A&gt; list?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This security hole is as bad as the backdoor in DLINK equipment described in:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.devttys0.com/wp-content/uploads/2010/12/dlink_php_vulnerability.pdf"&gt;http://www.devttys0.com/wp-content/uploads/2010/12/dlink_php_vulnerability.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or for that matter the nice backdoor into TP-LINK equipment:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://sekurak.pl/tp-link-httptftp-backdoor/" title="http://sekurak.pl/tp-link-httptftp-backdoor/"&gt;http://sekurak.pl/tp-link-httptftp-backdoor/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://sekurak.pl/more-information-about-tp-link-backdoor/" title="http://sekurak.pl/more-information-about-tp-link-backdoor/"&gt; More information about TP-Link backdoor&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Apr 2013 08:17:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/does-palo-alto-issue-security-advisories-for-security-related/m-p/39029#M28609</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-04-13T08:17:48Z</dc:date>
    </item>
  </channel>
</rss>

