<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Re: Skype false positive in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48564#M35759</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;The URL log as below is generated by accessing to secure.skype.com from IE10.&lt;/P&gt;&lt;P&gt;Do you mean you can't figure out this is actual skype session or just https session from browser?&lt;/P&gt;&lt;P&gt;If my understanding is correct, I guess there is no clue to figure out which pattern is it because the session is encrypted by ssl and PaloAlto device could not see the payload.&lt;/P&gt;&lt;P&gt;However, skype client send out skype-probe session, if you can see skype and skype-probe from one source address, you might be able to say that user is using skype client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="WS000003.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7823_WS000003.jpg" style="width: 620px; height: 38px;" /&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Aug 2013 09:56:27 GMT</pubDate>
    <dc:creator>emr_1</dc:creator>
    <dc:date>2013-08-22T09:56:27Z</dc:date>
    <item>
      <title>Skype false positive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48560#M35755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;About skype: how to know, when users realy use skype and when PA detects only false positive? Because now i have lot of log with "secure.skype.com" URL and PA detects it as skype application.. I would be grateful for an explanation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Aug 2013 06:44:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48560#M35755</guid>
      <dc:creator>Interface</dc:creator>
      <dc:date>2013-08-22T06:44:43Z</dc:date>
    </item>
    <item>
      <title>Re: Skype false positive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48561#M35756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ignas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users are using any other video/audio calling application into their machine...? Please follow below mentioned documents for more information about SKYPE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1505"&gt;Controlling Skype&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/23221"&gt;Re: Skype IM Problem&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I would recommend you to open a case with support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Aug 2013 07:31:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48561#M35756</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2013-08-22T07:31:12Z</dc:date>
    </item>
    <item>
      <title>Re: Skype false positive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48562#M35757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Skype not installed on users' computers. We checked this. But PA detects skype application. Detailed log shows &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; "secure.skype.com" URL&lt;/SPAN&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Aug 2013 09:07:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48562#M35757</guid>
      <dc:creator>Interface</dc:creator>
      <dc:date>2013-08-22T09:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: Skype false positive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48563#M35758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could be a false positive. Is the firewall on the latest dynamic updates ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Aug 2013 09:13:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48563#M35758</guid>
      <dc:creator>harshanatarajan</dc:creator>
      <dc:date>2013-08-22T09:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Skype false positive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48564#M35759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;The URL log as below is generated by accessing to secure.skype.com from IE10.&lt;/P&gt;&lt;P&gt;Do you mean you can't figure out this is actual skype session or just https session from browser?&lt;/P&gt;&lt;P&gt;If my understanding is correct, I guess there is no clue to figure out which pattern is it because the session is encrypted by ssl and PaloAlto device could not see the payload.&lt;/P&gt;&lt;P&gt;However, skype client send out skype-probe session, if you can see skype and skype-probe from one source address, you might be able to say that user is using skype client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="WS000003.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7823_WS000003.jpg" style="width: 620px; height: 38px;" /&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Aug 2013 09:56:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48564#M35759</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2013-08-22T09:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: Skype false positive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48565#M35760</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi emr,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks for your answer. I can't find skype-probe. So no skype client is being used. I think that users are redirected to a &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt; &lt;/SPAN&gt;&lt;SPAN style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;"secure.skype.com"&lt;/SPAN&gt; page from some other page or something like that, though I can't say exactly. Because when I type in a web browser &lt;SPAN style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;"secure.skype.com"&lt;/SPAN&gt;, i'm redirected to "login.skype.com" and PA log shows few records &lt;SPAN style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;"secure.skype.com",&lt;/SPAN&gt; "login.skype.com" and "apps.skypeassets.com".&amp;nbsp; And when I look at users log, I only see &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;"secure.skype.com"&lt;/SPAN&gt; records. I'm trying to figure out how this happens.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Aug 2013 11:12:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48565#M35760</guid>
      <dc:creator>Interface</dc:creator>
      <dc:date>2013-08-22T11:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: Re: Skype false positive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48566#M35761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the user is using skype client, you can find skype-probe in traffic log as below:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="WS000004.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7825_WS000004.jpg" style="width: 620px; height: 62px;" /&gt;&lt;/P&gt;&lt;P&gt;I can see all URLs you mentioned. (URL category name might be different from you because I'm using PAN-DB instead of BrightCloud)&lt;/P&gt;&lt;P&gt;What is 'users log' you are pointing to?&lt;/P&gt;&lt;P&gt;Do you mean detail log for 'secure.skype.com'?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="WS000005.jpg" class="jive-image jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/7824_WS000005.jpg" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Aug 2013 11:35:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48566#M35761</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2013-08-22T11:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: Skype false positive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48567#M35762</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;URL log. I use filter: (url contains skype).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Untitled.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7826_Untitled.png" style="width: 620px; height: 157px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Aug 2013 12:07:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48567#M35762</guid>
      <dc:creator>Interface</dc:creator>
      <dc:date>2013-08-22T12:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: Skype false positive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48568#M35763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, it looks like your PaloAlto device places between client PC and proxy server.&lt;/P&gt;&lt;P&gt;I'm not using proxy. This might causes different result.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Aug 2013 12:48:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48568#M35763</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2013-08-22T12:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: Skype false positive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48569#M35764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe. Anyway thank you for help &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Aug 2013 13:31:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48569#M35764</guid>
      <dc:creator>Interface</dc:creator>
      <dc:date>2013-08-22T13:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: Skype false positive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48570#M35765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Explanation:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if the webpage contains a java script "detection_as3.swf", wich redirects to webpage "&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://secure.skype.com"&gt;https://secure.skype.com&lt;/A&gt;&lt;SPAN&gt;", PA firewall this connection consider as a "skype" application. Case closed.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Aug 2013 11:11:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/skype-false-positive/m-p/48570#M35765</guid>
      <dc:creator>Interface</dc:creator>
      <dc:date>2013-08-23T11:11:49Z</dc:date>
    </item>
  </channel>
</rss>

