<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SQLinjection  not being detected by PA in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/sqlinjection-not-being-detected-by-pa/m-p/63597#M38248</link>
    <description>&lt;P&gt;Yes its matching the correct policy.&lt;/P&gt;</description>
    <pubDate>Tue, 25 Aug 2015 13:35:26 GMT</pubDate>
    <dc:creator>SOC_CSG</dc:creator>
    <dc:date>2015-08-25T13:35:26Z</dc:date>
    <item>
      <title>SQLinjection  not being detected by PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sqlinjection-not-being-detected-by-pa/m-p/63593#M38244</link>
      <description>&lt;P&gt;Hi, we are receiving these tries about SQL injection but our Palo alto is not detecting it. How can we do that PA detect this SQLi????? we have updated the threats signatures.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sql injection&lt;/P&gt;&lt;P&gt;GET /ficha-modelo?id=2&amp;amp;entidad=99999999%27%20oR%20%277%27=%277 HTTP/1.1" 500 59878 "-" "Mozilla/4.0&lt;/P&gt;&lt;P&gt;GET /ficha-modelo?entidad=!S!WCRTESTINPUT000000%3C%3E%3c%3e%253c%253e!E!&amp;amp;id=2 HTTP/1.1" 500 59878 "-" "Mozilla/4.0"&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 13:21:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sqlinjection-not-being-detected-by-pa/m-p/63593#M38244</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2015-08-25T13:21:36Z</dc:date>
    </item>
    <item>
      <title>Re: SQLinjection  not being detected by PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sqlinjection-not-being-detected-by-pa/m-p/63595#M38246</link>
      <description>&lt;P&gt;Have you applied proper security profiles to the concern security policies?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 13:27:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sqlinjection-not-being-detected-by-pa/m-p/63595#M38246</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-08-25T13:27:44Z</dc:date>
    </item>
    <item>
      <title>Re: SQLinjection  not being detected by PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sqlinjection-not-being-detected-by-pa/m-p/63597#M38248</link>
      <description>&lt;P&gt;Yes its matching the correct policy.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 13:35:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sqlinjection-not-being-detected-by-pa/m-p/63597#M38248</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2015-08-25T13:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: SQLinjection  not being detected by PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sqlinjection-not-being-detected-by-pa/m-p/63598#M38249</link>
      <description>&lt;P&gt;No I am talking about the antivirus, antispyware, vulnerabiltiy profile are applied to the security rules?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 14:31:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sqlinjection-not-being-detected-by-pa/m-p/63598#M38249</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-08-25T14:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: SQLinjection  not being detected by PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sqlinjection-not-being-detected-by-pa/m-p/63600#M38251</link>
      <description>&lt;P&gt;we have the 3 security profiles assigned in the default config for this connection. What can we do in order to detect this SQLi???&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 14:44:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sqlinjection-not-being-detected-by-pa/m-p/63600#M38251</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2015-08-25T14:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: SQLinjection  not being detected by PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sqlinjection-not-being-detected-by-pa/m-p/63603#M38253</link>
      <description>&lt;P&gt;typicall something that should be caught by a WAF/ReverseProxy that is fine tuned for specific customer needs, not a firewall or a IPS in my opinion.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 15:11:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sqlinjection-not-being-detected-by-pa/m-p/63603#M38253</guid>
      <dc:creator>cpainchaud</dc:creator>
      <dc:date>2015-08-25T15:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: SQLinjection  not being detected by PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sqlinjection-not-being-detected-by-pa/m-p/63605#M38254</link>
      <description>&lt;P&gt;You have to create security profile and apply them into the security rules&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Objectes&amp;gt; Security profiles&amp;gt; Antivirus&amp;gt; clone default one and modify it accordingly.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Objectes&amp;gt; Security profiles&amp;gt; Anti-Spyware&amp;gt; clone default one and modify it accordingly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Objectes&amp;gt; Security profiles&amp;gt; Vulnerability Profile&amp;gt; clone default one and modify it accordingly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The default profiles are okay but you cannot modify them that'w why we need to clone them.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now go to the Policies&amp;gt; Security&amp;gt; Open the security policy which is allowing the traffic and into that go to action call the above new profiles&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/72iCFCC631BA54B982A/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Security Policy.png" title="Security Policy.png" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 15:39:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sqlinjection-not-being-detected-by-pa/m-p/63605#M38254</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-08-25T15:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: SQLinjection  not being detected by PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sqlinjection-not-being-detected-by-pa/m-p/63609#M38255</link>
      <description>&lt;P&gt;Yes i know but PA doesnt have the specific siganture for this SQLi. We have everything enabled and its not being detected.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 15:56:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sqlinjection-not-being-detected-by-pa/m-p/63609#M38255</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2015-08-25T15:56:44Z</dc:date>
    </item>
    <item>
      <title>Re: SQLinjection  not being detected by PA</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sqlinjection-not-being-detected-by-pa/m-p/63741#M38308</link>
      <description>&lt;P&gt;Hi, COS,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SQLi will be the best effort, it will catch the most common attempts and will not evaluate any string for SQLi. If you really need that, create your own custom threat signature to improve posture, or consider offloading such job to a dedicated web / app firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Great read on creating custom threat signatures can be found in this tech note: &lt;A href="https://live.paloaltonetworks.com/t5/Articles/Creating-Custom-Threat-Signatures/ta-p/58569" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Articles/Creating-Custom-Threat-Signatures/ta-p/58569&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Luciano&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2015 20:42:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sqlinjection-not-being-detected-by-pa/m-p/63741#M38308</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2015-08-27T20:42:47Z</dc:date>
    </item>
  </channel>
</rss>

