<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disabled Vulnerability Signatures in App+Threat Update 335 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/disabled-vulnerability-signatures-in-app-threat-update-335/m-p/47712#M35093</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In signature 335 there was only disabled vulnerability signature 30793 Microsoft Internet Explorer Content-Type Denial Of Service Vulnerability.&amp;nbsp; This signature should no longer trigger as the signature is disabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reasons behind this are:&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; The signature is being reviewed for improvements&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; The vulnerability does not exist anymore&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 29 Oct 2012 21:32:29 GMT</pubDate>
    <dc:creator>nayubi</dc:creator>
    <dc:date>2012-10-29T21:32:29Z</dc:date>
    <item>
      <title>Disabled Vulnerability Signatures in App+Threat Update 335</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disabled-vulnerability-signatures-in-app-threat-update-335/m-p/47711#M35092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can someone please explain why a high severity vulnerability signature has been disabled in update 335?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this mean that this vulnerability will no longer be detected?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What happens if we encounter this vulnerability, will it be allowed through?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The same question also about the disabled spyware signature in the update 335 as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2012 08:50:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disabled-vulnerability-signatures-in-app-threat-update-335/m-p/47711#M35092</guid>
      <dc:creator>ERIKS</dc:creator>
      <dc:date>2012-10-24T08:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: Disabled Vulnerability Signatures in App+Threat Update 335</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disabled-vulnerability-signatures-in-app-threat-update-335/m-p/47712#M35093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In signature 335 there was only disabled vulnerability signature 30793 Microsoft Internet Explorer Content-Type Denial Of Service Vulnerability.&amp;nbsp; This signature should no longer trigger as the signature is disabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reasons behind this are:&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; The signature is being reviewed for improvements&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; The vulnerability does not exist anymore&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Oct 2012 21:32:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disabled-vulnerability-signatures-in-app-threat-update-335/m-p/47712#M35093</guid>
      <dc:creator>nayubi</dc:creator>
      <dc:date>2012-10-29T21:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: Disabled Vulnerability Signatures in App+Threat Update 335</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disabled-vulnerability-signatures-in-app-threat-update-335/m-p/47713#M35094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Im a bit curious about "2.&amp;nbsp; The vulnerability does not exist anymore"...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is PA thinking that there shouldnt be old clients out there or that the attack itself is no longer available like through metasploit etc?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2012 06:42:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disabled-vulnerability-signatures-in-app-threat-update-335/m-p/47713#M35094</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-10-30T06:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: Disabled Vulnerability Signatures in App+Threat Update 335</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disabled-vulnerability-signatures-in-app-threat-update-335/m-p/47714#M35095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These are reasons why they could be disabled, but yes if they believe it is no longer a threat or if it is combined in another signature that identifies it with better accuracy. Or if the application is obsolete.&amp;nbsp; If you feel this threat is still an issue and should be a part of the Palo Alto database please contact support and open a ticket for review.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2012 18:31:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disabled-vulnerability-signatures-in-app-threat-update-335/m-p/47714#M35095</guid>
      <dc:creator>nayubi</dc:creator>
      <dc:date>2012-10-30T18:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: Disabled Vulnerability Signatures in App+Threat Update 335</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disabled-vulnerability-signatures-in-app-threat-update-335/m-p/47715#M35096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Im a bit uncomfortible with signatures disappearing due to the application or threat being obsolete.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I totally agree if the signature is removed because it misfires (false-positives) or is taken care of by another signature (then perhaps the release notes should inform about this?) but I think its wrong when signatures are removed just because the threat might no longer be an issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean one of the points of using an IPS is to protect devices which cannot protect themselfs - otherwise we wont need IPS capabilities in the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Specially on the appliance side there are many devices which for one or another reason just cannot be updated to the latest version of the operating system or other softwares being runned on them.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2012 19:00:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disabled-vulnerability-signatures-in-app-threat-update-335/m-p/47715#M35096</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-10-30T19:00:51Z</dc:date>
    </item>
  </channel>
</rss>

