<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can PA block Web shell or shell script? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-pa-block-web-shell-or-shell-script/m-p/48412#M35625</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, guys~&lt;/P&gt;&lt;P&gt;One of my customer want to know whether the Pan block web shell or shell script. In my opinion, there's no ips which can block those attacks 100%. &lt;/P&gt;&lt;P&gt;Threat prevention of the PA is signature base also, which means if it detects well-known web shell, it might block it. If not, it can't.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's sure that web shell is based on web server application vulnerability or miss configuration. So the basic method to block those attack is secure cording or secure configuration of the web server.&lt;/P&gt;&lt;P&gt;But I need to tell the customer the exact information about PA's function.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please don't mention custom signature, there's not so much customer who can make custom signature :smileygrin:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Mar 2014 04:45:04 GMT</pubDate>
    <dc:creator>JTR</dc:creator>
    <dc:date>2014-03-18T04:45:04Z</dc:date>
    <item>
      <title>Can PA block Web shell or shell script?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-pa-block-web-shell-or-shell-script/m-p/48412#M35625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, guys~&lt;/P&gt;&lt;P&gt;One of my customer want to know whether the Pan block web shell or shell script. In my opinion, there's no ips which can block those attacks 100%. &lt;/P&gt;&lt;P&gt;Threat prevention of the PA is signature base also, which means if it detects well-known web shell, it might block it. If not, it can't.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's sure that web shell is based on web server application vulnerability or miss configuration. So the basic method to block those attack is secure cording or secure configuration of the web server.&lt;/P&gt;&lt;P&gt;But I need to tell the customer the exact information about PA's function.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please don't mention custom signature, there's not so much customer who can make custom signature :smileygrin:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Mar 2014 04:45:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-pa-block-web-shell-or-shell-script/m-p/48412#M35625</guid>
      <dc:creator>JTR</dc:creator>
      <dc:date>2014-03-18T04:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: Can PA block Web shell or shell script?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-pa-block-web-shell-or-shell-script/m-p/48413#M35626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Palo Alto Networks can help protect a great many things. &lt;SPAN style="line-height: 1.5em; font-size: 10pt;"&gt;We can block file types, viruses, threats, &lt;/SPAN&gt;vulnerability&lt;SPAN style="line-height: 1.5em; font-size: 10pt;"&gt; etc. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the shell script that is being executed is part of a known threat/vulnerability, then we should be able to detect that and stop it (if configured to do so).&lt;/P&gt;&lt;P&gt;Otherwise we do not block shell scripts. Unless you want to create a regex (Regular Expression) and create a custom signature.. I am sorry, you told me not to say that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the record, here are instructions on creating Custom Signatures:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5534"&gt;Creating Custom Threat Signatures&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does that help answer your question?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Mar 2014 15:29:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-pa-block-web-shell-or-shell-script/m-p/48413#M35626</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2014-03-21T15:29:30Z</dc:date>
    </item>
  </channel>
</rss>

