<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Uptick in RFC2397 Data URL Scheme Usage Detected (30419) ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/uptick-in-rfc2397-data-url-scheme-usage-detected-30419/m-p/66603#M39244</link>
    <description>&lt;P&gt;let us know what the outcome is, we're getting these daily whereas we've never had them prior to about a month or so ago&lt;/P&gt;</description>
    <pubDate>Wed, 14 Oct 2015 17:35:35 GMT</pubDate>
    <dc:creator>ulti</dc:creator>
    <dc:date>2015-10-14T17:35:35Z</dc:date>
    <item>
      <title>Uptick in RFC2397 Data URL Scheme Usage Detected (30419) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uptick-in-rfc2397-data-url-scheme-usage-detected-30419/m-p/65104#M38922</link>
      <description>&lt;P&gt;Before I go on a wild goose chase, has anyone seen an increase in threat 30419 (RFC2397 Data URL Scheme Usage Detected)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems like these things trip for a while until PA figures out someone's using something novel in a new App. A new application sig comes out and the alerts go away...&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2015 13:29:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uptick-in-rfc2397-data-url-scheme-usage-detected-30419/m-p/65104#M38922</guid>
      <dc:creator>MCmgt</dc:creator>
      <dc:date>2015-09-25T13:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: Uptick in RFC2397 Data URL Scheme Usage Detected (30419) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uptick-in-rfc2397-data-url-scheme-usage-detected-30419/m-p/65127#M38936</link>
      <description>&lt;P&gt;thank goodness - its not just me. yes, we've seen a huge increase in these and wasn't sure if we should negate these in the policy or if Palo's threat team jacked with the settings in a recent db update. (known to happen)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2015 21:16:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uptick-in-rfc2397-data-url-scheme-usage-detected-30419/m-p/65127#M38936</guid>
      <dc:creator>ulti</dc:creator>
      <dc:date>2015-09-25T21:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: Uptick in RFC2397 Data URL Scheme Usage Detected (30419) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uptick-in-rfc2397-data-url-scheme-usage-detected-30419/m-p/66355#M39173</link>
      <description>&lt;P&gt;anyone have thoughts on this? seems noisy for us. Can't tell if Palo changed it in threat db or if there's just a huge increase of it on net.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2015 15:51:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uptick-in-rfc2397-data-url-scheme-usage-detected-30419/m-p/66355#M39173</guid>
      <dc:creator>ulti</dc:creator>
      <dc:date>2015-10-09T15:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: Uptick in RFC2397 Data URL Scheme Usage Detected (30419) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uptick-in-rfc2397-data-url-scheme-usage-detected-30419/m-p/66602#M39243</link>
      <description>&lt;P&gt;I opened a case (&lt;SPAN&gt;00389881) yesterday. They've heard rumblings from customers but hadn't received any pcaps yet.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;By chance, I stumbled across someone tripping the sig and called them. They got red-faced when I asked them what they had just done...visited okmagazine.com. Sure enough, I was able to reproduce it and support has a pcap to look at.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2015 17:28:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uptick-in-rfc2397-data-url-scheme-usage-detected-30419/m-p/66602#M39243</guid>
      <dc:creator>MCmgt</dc:creator>
      <dc:date>2015-10-14T17:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: Uptick in RFC2397 Data URL Scheme Usage Detected (30419) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uptick-in-rfc2397-data-url-scheme-usage-detected-30419/m-p/66603#M39244</link>
      <description>&lt;P&gt;let us know what the outcome is, we're getting these daily whereas we've never had them prior to about a month or so ago&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2015 17:35:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uptick-in-rfc2397-data-url-scheme-usage-detected-30419/m-p/66603#M39244</guid>
      <dc:creator>ulti</dc:creator>
      <dc:date>2015-10-14T17:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: Uptick in RFC2397 Data URL Scheme Usage Detected (30419) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uptick-in-rfc2397-data-url-scheme-usage-detected-30419/m-p/66604#M39245</link>
      <description>&lt;P&gt;This particular instance was &lt;SPAN&gt;a TTF (TrueType Font) file, and that the purpose of the javascript containing it looked to be css/style/ad delivery using JWPLAYER.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Advertising...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;YMMV.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2015 18:56:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uptick-in-rfc2397-data-url-scheme-usage-detected-30419/m-p/66604#M39245</guid>
      <dc:creator>MCmgt</dc:creator>
      <dc:date>2015-10-14T18:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: Uptick in RFC2397 Data URL Scheme Usage Detected (30419) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uptick-in-rfc2397-data-url-scheme-usage-detected-30419/m-p/67604#M39610</link>
      <description>&lt;P&gt;Did you mark it as exception and allow or are you still alerting on it?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2015 16:35:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uptick-in-rfc2397-data-url-scheme-usage-detected-30419/m-p/67604#M39610</guid>
      <dc:creator>ulti</dc:creator>
      <dc:date>2015-11-03T16:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: Uptick in RFC2397 Data URL Scheme Usage Detected (30419) ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uptick-in-rfc2397-data-url-scheme-usage-detected-30419/m-p/68354#M39881</link>
      <description>&lt;P&gt;We've been getting a lot of hits on this Threat ID as well. &amp;nbsp;I think if anything, this ID should be set to Informational or Low.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2015 22:05:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uptick-in-rfc2397-data-url-scheme-usage-detected-30419/m-p/68354#M39881</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2015-11-18T22:05:24Z</dc:date>
    </item>
  </channel>
</rss>

