<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom Vulnerability Signature. Is this limitation correct or is a fail? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-vulnerability-signature-is-this-limitation-correct-or-is/m-p/66657#M39279</link>
    <description>&lt;P&gt;The signature can have multiple sets of patterns.&amp;nbsp; Each set of patterns (max 16) can be "or" conditions.&amp;nbsp; The pattern string can be for specific&amp;nbsp;purposes such as misuse of access to PHP related resources.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does this&amp;nbsp;add any clarity or am I missing something.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Phil&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 15 Oct 2015 14:48:02 GMT</pubDate>
    <dc:creator>HITSSEC</dc:creator>
    <dc:date>2015-10-15T14:48:02Z</dc:date>
    <item>
      <title>Custom Vulnerability Signature. Is this limitation correct or is a fail?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-vulnerability-signature-is-this-limitation-correct-or-is/m-p/64993#M38870</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I've been trying to create a custom vulnerability and I have encountered this limitation:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/444i57581BB8DCAFB6B2/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="vulnerability 41003.jpg" title="vulnerability 41003.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Currently in Threat Database Vault 529 version there are 50 signatures for PHP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I'm trying to add all PHP signatures and this message appears when it exceeds 17 signatures.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is this limitation correct or is a fail?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;A few days ago we suffer multiple PHP vulnerability scanning in our web servers:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/445iEE6A1C4F56EC54B3/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="SIEM scan vulnerability.jpg" title="SIEM scan vulnerability.jpg" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The source IP 188.78.195.67&amp;nbsp;is in many blacklists.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to create a custom signature for IP auto-block attacker for 1 hour, if 10 times in 10 seconds any PHP Scan Vulnerability.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks and regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;dicu&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2015 09:21:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-vulnerability-signature-is-this-limitation-correct-or-is/m-p/64993#M38870</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2015-09-23T09:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Vulnerability Signature. Is this limitation correct or is a fail?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-vulnerability-signature-is-this-limitation-correct-or-is/m-p/65004#M38879</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm not sure on the custom Vulnerabilities issue, perhaps a support case is in order? However if the IP is on many lists, have you considered Dynamic Block Lists?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://isc.sans.edu/forums/diary/Subscribing+to+the+DShield+Top+20+on+a+Palo+Alto+Networks+Firewall/19365/" target="_blank"&gt;https://isc.sans.edu/forums/diary/Subscribing+to+the+DShield+Top+20+on+a+Palo+Alto+Networks+Firewall/19365/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Dynamic-Block-List-DBL-or-External-Block-List/ta-p/53414" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Dynamic-Block-List-DBL-or-External-Block-List/ta-p/53414&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a thought.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2015 14:36:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-vulnerability-signature-is-this-limitation-correct-or-is/m-p/65004#M38879</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-09-23T14:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Vulnerability Signature. Is this limitation correct or is a fail?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-vulnerability-signature-is-this-limitation-correct-or-is/m-p/66399#M39183</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To address the limit of 16 patterns you just need to add another signature as shown below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;IMG title="Capture-Signature-Details.PNG" alt="Capture-Signature-Details.PNG" src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/613iB644D05D70DB0702/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Each signature can have 16 "or" &amp;nbsp;values.&amp;nbsp;&amp;nbsp; I have signatures that have +50 string patterns&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2015 01:34:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-vulnerability-signature-is-this-limitation-correct-or-is/m-p/66399#M39183</guid>
      <dc:creator>HITSSEC</dc:creator>
      <dc:date>2015-10-12T01:34:13Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Vulnerability Signature. Is this limitation correct or is a fail?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-vulnerability-signature-is-this-limitation-correct-or-is/m-p/66467#M39213</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First of all thanks for your answer Otakar.Klier.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: 20px;"&gt;About &lt;/SPAN&gt;&lt;SPAN style="line-height: 20px;"&gt;"Dynamic Block List" I already knew&amp;nbsp;and I already had put to work this in any of our clients.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: 20px;"&gt;I think it is a correct answer.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: 20px;"&gt;But first I would like to try every option that gives the IPS Palo Alto and&amp;nbsp;one of these are the "Custom Vulnerability Signature".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: 20px;"&gt;It is a way to demonstrate the potential of Palo Alto firewalls.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: 20px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: 20px;"&gt;dicu&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2015 07:49:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-vulnerability-signature-is-this-limitation-correct-or-is/m-p/66467#M39213</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2015-10-13T07:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Vulnerability Signature. Is this limitation correct or is a fail?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-vulnerability-signature-is-this-limitation-correct-or-is/m-p/66471#M39214</link>
      <description>&lt;P&gt;Hello&amp;nbsp;HITSSEC&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't understand.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think you mean to use patterns instead of signatures.&lt;/P&gt;
&lt;P&gt;I think it might work but what are the patterns of each firm?&amp;nbsp;or where can I find them?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://threatvault.paloaltonetworks.com/" target="_blank"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Note that currently in Threat Database Vault 529 version there are 50 signatures for PHP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks and regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;dicu&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2015 08:17:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-vulnerability-signature-is-this-limitation-correct-or-is/m-p/66471#M39214</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2015-10-13T08:17:47Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Vulnerability Signature. Is this limitation correct or is a fail?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-vulnerability-signature-is-this-limitation-correct-or-is/m-p/66657#M39279</link>
      <description>&lt;P&gt;The signature can have multiple sets of patterns.&amp;nbsp; Each set of patterns (max 16) can be "or" conditions.&amp;nbsp; The pattern string can be for specific&amp;nbsp;purposes such as misuse of access to PHP related resources.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does this&amp;nbsp;add any clarity or am I missing something.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Phil&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 14:48:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-vulnerability-signature-is-this-limitation-correct-or-is/m-p/66657#M39279</guid>
      <dc:creator>HITSSEC</dc:creator>
      <dc:date>2015-10-15T14:48:02Z</dc:date>
    </item>
  </channel>
</rss>

