<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IMAP long tag anomaly in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/imap-long-tag-anomaly/m-p/70442#M40513</link>
    <description>&lt;P&gt;I know this was kind of asked here, and I was wondering if the best option would be to create a rule like the one mentioned in this post..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/SMTP-long-MAIL-anomaly-Vulnerability-30392/m-p/2327#M1718" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/SMTP-long-MAIL-anomaly-Vulnerability-30392/m-p/2327#M1718&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since I am getting these almost everyday, and they seem to be always from one user account, and they happen to use gmail.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also use gmail but I never seem to see my account as the "attacker" which I'm not sure why his account keep showing up as the attacker.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Should I just create the block rule and see if his email still works? He says he uses teh Windows Mail app with all gmail accounts.&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jan 2016 17:06:14 GMT</pubDate>
    <dc:creator>Zewwy</dc:creator>
    <dc:date>2016-01-06T17:06:14Z</dc:date>
    <item>
      <title>IMAP long tag anomaly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/imap-long-tag-anomaly/m-p/70442#M40513</link>
      <description>&lt;P&gt;I know this was kind of asked here, and I was wondering if the best option would be to create a rule like the one mentioned in this post..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/SMTP-long-MAIL-anomaly-Vulnerability-30392/m-p/2327#M1718" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/SMTP-long-MAIL-anomaly-Vulnerability-30392/m-p/2327#M1718&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since I am getting these almost everyday, and they seem to be always from one user account, and they happen to use gmail.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also use gmail but I never seem to see my account as the "attacker" which I'm not sure why his account keep showing up as the attacker.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Should I just create the block rule and see if his email still works? He says he uses teh Windows Mail app with all gmail accounts.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jan 2016 17:06:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/imap-long-tag-anomaly/m-p/70442#M40513</guid>
      <dc:creator>Zewwy</dc:creator>
      <dc:date>2016-01-06T17:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: IMAP long tag anomaly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/imap-long-tag-anomaly/m-p/74311#M41657</link>
      <description>&lt;P&gt;A very smart network engineer&amp;nbsp;I know informed me this is due to the way google changed the way their email system worked, and is caused when users who particularly use gmail with multiple folders will cause this Threat to be triggered.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;He provided one of two options to help correct it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) get my colleague to clean up his gmail. reduce folder, etc (not likly to happen)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) adjust the profile monitor and change it so that particular vulnerability isn't alerted on, this leave it open to exploitation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both options are not great, thus at this point I'll simply have to ingore in.. *Sticks head in the sand*&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for all the replies *Cough none*&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2016 19:50:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/imap-long-tag-anomaly/m-p/74311#M41657</guid>
      <dc:creator>Zewwy</dc:creator>
      <dc:date>2016-03-07T19:50:14Z</dc:date>
    </item>
  </channel>
</rss>

