<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Threat ID 30852 and 35107 - HTTP /etc/passwd Access Attempt in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/threat-id-30852-and-35107-http-etc-passwd-access-attempt/m-p/4701#M3467</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Gafrol and &lt;A href="https://live.paloaltonetworks.com/u1/6808"&gt;cheon&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They both share the same internal bug ID 45996.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to the notes, they found three different variations of this vulnerability and split it into three different threat IDs. 30852 35090 and 35107. This was shipped out with content version 337. Yes, the cover the same threat but cover different variations, apparently. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 Jul 2015 18:57:52 GMT</pubDate>
    <dc:creator>mmmccorkle</dc:creator>
    <dc:date>2015-07-08T18:57:52Z</dc:date>
    <item>
      <title>Threat ID 30852 and 35107 - HTTP /etc/passwd Access Attempt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-id-30852-and-35107-http-etc-passwd-access-attempt/m-p/4699#M3465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is this a duplicate or does anybody know what the difference between those two Threat ID's is ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers Roland&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Apr 2014 08:39:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-id-30852-and-35107-http-etc-passwd-access-attempt/m-p/4699#M3465</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2014-04-09T08:39:53Z</dc:date>
    </item>
    <item>
      <title>Re: Threat ID 30852 and 35107 - HTTP /etc/passwd Access Attempt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-id-30852-and-35107-http-etc-passwd-access-attempt/m-p/4700#M3466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you find it out why there are two threat IDs?&lt;/P&gt;&lt;P&gt;If yes, please let me know it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;KC Lee&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jul 2015 08:20:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-id-30852-and-35107-http-etc-passwd-access-attempt/m-p/4700#M3466</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2015-07-08T08:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: Threat ID 30852 and 35107 - HTTP /etc/passwd Access Attempt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-id-30852-and-35107-http-etc-passwd-access-attempt/m-p/4701#M3467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Gafrol and &lt;A href="https://live.paloaltonetworks.com/u1/6808"&gt;cheon&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They both share the same internal bug ID 45996.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to the notes, they found three different variations of this vulnerability and split it into three different threat IDs. 30852 35090 and 35107. This was shipped out with content version 337. Yes, the cover the same threat but cover different variations, apparently. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jul 2015 18:57:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-id-30852-and-35107-http-etc-passwd-access-attempt/m-p/4701#M3467</guid>
      <dc:creator>mmmccorkle</dc:creator>
      <dc:date>2015-07-08T18:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: Threat ID 30852 and 35107 - HTTP /etc/passwd Access Attempt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-id-30852-and-35107-http-etc-passwd-access-attempt/m-p/4702#M3468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello mmmccorkle,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your kind answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a question more deep.&lt;/P&gt;&lt;P&gt;What about below threats?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 굴림; color: #222222;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10pt; font-family: 돋움;"&gt;1) RIG Exploit Kit Detection (36683, 37561)&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 굴림; color: #222222;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10pt; font-family: 돋움;"&gt;2) WGeneric.Gen Command and Control Traffic (13621, 14210)&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 굴림; color: #222222;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10pt; font-family: 돋움;"&gt;3) Suspicious.Gen Command And Control Traffic (14035, 14137, 14155)&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 굴림; color: #222222;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10pt; font-family: 돋움;"&gt;4) ANGLER Exploit Kit Detection (37744, 37796)&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 굴림; color: #222222;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10pt; font-family: 돋움;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 굴림; color: #222222;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10pt; font-family: 돋움;"&gt;These threat-IDs are also same each other.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 굴림; color: #222222;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10pt; font-family: 돋움;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 굴림; color: #222222;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10pt; font-family: 돋움;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 굴림; color: #222222;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10pt; font-family: 돋움;"&gt;KC Lee&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 굴림; color: #222222;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10pt; font-family: 돋움;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: 굴림; color: #222222;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10pt; font-family: 돋움;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jul 2015 06:40:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-id-30852-and-35107-http-etc-passwd-access-attempt/m-p/4702#M3468</guid>
      <dc:creator>KiCheon.Lee</dc:creator>
      <dc:date>2015-07-17T06:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: Threat ID 30852 and 35107 - HTTP /etc/passwd Access Attempt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-id-30852-and-35107-http-etc-passwd-access-attempt/m-p/525569#M108690</link>
      <description>&lt;P&gt;What about below threats?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1) RIG Exploit Kit Detection (36683, 37561)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2) WGeneric.Gen Command and Control Traffic (13621, 14210)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3) Suspicious.Gen Command And Control Traffic (14035, 14137, 14155)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4) ANGLER Exploit Kit Detection (37744, 37796)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Do you have any of those&amp;nbsp;&lt;STRONG&gt;Threat ID &lt;/STRONG&gt;Guide or Definition, it's will make me easeir to understand the Threat.&lt;/P&gt;</description>
      <pubDate>Sat, 31 Dec 2022 09:24:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-id-30852-and-35107-http-etc-passwd-access-attempt/m-p/525569#M108690</guid>
      <dc:creator>Aryanto</dc:creator>
      <dc:date>2022-12-31T09:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: Threat ID 30852 and 35107 - HTTP /etc/passwd Access Attempt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-id-30852-and-35107-http-etc-passwd-access-attempt/m-p/525721#M108708</link>
      <description>&lt;P&gt;Good day, Men! I'm new to the group and I'll be using this thread to keep tabs on any developments about the creation of duplicate Threat IDs; for the life of me, I can't figure out how to get a second Threat ID.&amp;nbsp;@&lt;A href="https://zinitevi.info/" target="_self"&gt;zinitevi&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Feb 2023 15:46:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-id-30852-and-35107-http-etc-passwd-access-attempt/m-p/525721#M108708</guid>
      <dc:creator>BenHA2D</dc:creator>
      <dc:date>2023-02-19T15:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: Threat ID 30852 and 35107 - HTTP /etc/passwd Access Attempt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threat-id-30852-and-35107-http-etc-passwd-access-attempt/m-p/566530#M114490</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;
&lt;P&gt;I have a query: why was this alert ('HTTP /etc/passwd Access Attempt' generated by PAN NGFW) triggered?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 15:57:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threat-id-30852-and-35107-http-etc-passwd-access-attempt/m-p/566530#M114490</guid>
      <dc:creator>NikhilKulkarni</dc:creator>
      <dc:date>2023-11-21T15:57:56Z</dc:date>
    </item>
  </channel>
</rss>

