<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Java version detection and blocking old version in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/java-version-detection-and-blocking-old-version/m-p/46367#M34090</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/13014"&gt;Sly_Cooper&lt;/A&gt; : Have you been able to make vulnerability signatures (regex) for this? I'm looking to do the same thing, and if you have something to share, it would be great!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 30 Sep 2014 08:41:31 GMT</pubDate>
    <dc:creator>torm</dc:creator>
    <dc:date>2014-09-30T08:41:31Z</dc:date>
    <item>
      <title>Java version detection and blocking old version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/java-version-detection-and-blocking-old-version/m-p/46363#M34086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With more and more vulnerabilities in Java, I would like to know if there is any way in PAN firewall to identify and blocked non latest Java traffic? The goal is to identify machines and inform owners to update their Java version. If not then block the Java traffic from that host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 May 2014 05:07:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/java-version-detection-and-blocking-old-version/m-p/46363#M34086</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2014-05-14T05:07:30Z</dc:date>
    </item>
    <item>
      <title>Re: Java version detection and blocking old version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/java-version-detection-and-blocking-old-version/m-p/46364#M34087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Hello Sly_Cooper,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;You can create a &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;regex&lt;/SPAN&gt; to match specific &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;java&lt;/SPAN&gt; versions &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;latest) to allow through the PAN firewall. For all other versions, other than the latest one, set the action as "block". So, all the request will be logged into the PAN firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Reference doc: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-5534"&gt;Creating Custom Threat Signatures&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;NOTE: The Java spec is written so that JAR files may look like ZIP files in PAN.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 May 2014 06:01:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/java-version-detection-and-blocking-old-version/m-p/46364#M34087</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-05-14T06:01:42Z</dc:date>
    </item>
    <item>
      <title>Re: Java version detection and blocking old version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/java-version-detection-and-blocking-old-version/m-p/46365#M34088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi HULK,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any example for Java version matching? How requests from java apps will be seen on PAN firewalls?&lt;/P&gt;&lt;P&gt;Thanks in advance. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 May 2014 16:14:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/java-version-detection-and-blocking-old-version/m-p/46365#M34088</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2014-05-22T16:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: Java version detection and blocking old version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/java-version-detection-and-blocking-old-version/m-p/46366#M34089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sly_Cooper,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can take a packet capture on a test machine or PAN firewall from a host, where JAVA update is running. After taking the &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;pcap&lt;/SPAN&gt; file, you have to analyze the header to get the request information i.e "&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;java&lt;/SPAN&gt; version".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 May 2014 16:32:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/java-version-detection-and-blocking-old-version/m-p/46366#M34089</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-05-22T16:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: Java version detection and blocking old version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/java-version-detection-and-blocking-old-version/m-p/46367#M34090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/13014"&gt;Sly_Cooper&lt;/A&gt; : Have you been able to make vulnerability signatures (regex) for this? I'm looking to do the same thing, and if you have something to share, it would be great!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2014 08:41:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/java-version-detection-and-blocking-old-version/m-p/46367#M34090</guid>
      <dc:creator>torm</dc:creator>
      <dc:date>2014-09-30T08:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: Java version detection and blocking old version</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/java-version-detection-and-blocking-old-version/m-p/46368#M34091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/5160"&gt;torm&lt;/A&gt; - Sorry I did not try it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Nov 2014 16:44:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/java-version-detection-and-blocking-old-version/m-p/46368#M34091</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2014-11-11T16:44:20Z</dc:date>
    </item>
  </channel>
</rss>

