<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CVE-2014-6271 Shellshock rules blocking Sharepoint traffic? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/73260#M41385</link>
    <description>&lt;P&gt;It's also vulnerable to injection and execution of shell code&lt;/P&gt;</description>
    <pubDate>Mon, 22 Feb 2016 16:13:34 GMT</pubDate>
    <dc:creator>vkalal</dc:creator>
    <dc:date>2016-02-22T16:13:34Z</dc:date>
    <item>
      <title>CVE-2014-6271 Shellshock rules blocking Sharepoint traffic?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/73257#M41382</link>
      <description>&lt;P&gt;This morning our PAs began blocking internal Sharepoint document access with App-ID&amp;nbsp;&lt;SPAN&gt;36995. The traffic that is blocked is coming from IE11 + Windows 7 clients.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I'm not sure why this bash vulnerability is being flagged as affecting Windows servers + clients in this case. Anyone have ideas?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2016 16:06:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/73257#M41382</guid>
      <dc:creator>Khang_Than-Trong</dc:creator>
      <dc:date>2016-02-22T16:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2014-6271 Shellshock rules blocking Sharepoint traffic?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/73259#M41384</link>
      <description>&lt;P&gt;It's blocking it because of a&amp;nbsp;vulnerability called an arbitrary code execution exploit. Most of these vulnerabilities allow the&amp;nbsp;execution of machine code which may allow the attacker to run arbitary commands.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2016 16:12:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/73259#M41384</guid>
      <dc:creator>vkalal</dc:creator>
      <dc:date>2016-02-22T16:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2014-6271 Shellshock rules blocking Sharepoint traffic?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/73260#M41385</link>
      <description>&lt;P&gt;It's also vulnerable to injection and execution of shell code&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2016 16:13:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/73260#M41385</guid>
      <dc:creator>vkalal</dc:creator>
      <dc:date>2016-02-22T16:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2014-6271 Shellshock rules blocking Sharepoint traffic?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/73262#M41386</link>
      <description>&lt;P&gt;Thanks for the reply. Any ideas how to mitigate/address this? Admittedly, I'm not sure what can be done on the client-side to allow for the traffic/access to be non-exploitable.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2016 16:26:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/73262#M41386</guid>
      <dc:creator>Khang_Than-Trong</dc:creator>
      <dc:date>2016-02-22T16:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2014-6271 Shellshock rules blocking Sharepoint traffic?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/73265#M41389</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The default action is set to Alert to allow administrators to choose their desired action.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2016 16:39:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/73265#M41389</guid>
      <dc:creator>vkalal</dc:creator>
      <dc:date>2016-02-22T16:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2014-6271 Shellshock rules blocking Sharepoint traffic?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/73268#M41391</link>
      <description>&lt;P&gt;Thanks. Looks like it may be unpatched Office clients triggering this from my inspection/testing.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2016 17:06:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/73268#M41391</guid>
      <dc:creator>Khang_Than-Trong</dc:creator>
      <dc:date>2016-02-22T17:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2014-6271 Shellshock rules blocking Sharepoint traffic?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/73292#M41398</link>
      <description>&lt;P&gt;Hi Khang,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Shellshock is a fancy name for specially crafted packets in client-to-server communication that are trying to exploit bash and could lead to execution of arbitrary commands on the server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have your own trusted hosts on the originating side (if this is from your own network as you are suggesting) I would definitely open a case with TAC and see if this is a false positive or you might have compromised hosts in your network that are trying to enumerate / exploit servers within. If it is False Positive - PAN needs to solve it; if it is not False Positive than some probes for vulnerable bash inside of your network would be considered indicators of compromise.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;BR /&gt;&lt;BR /&gt;Luciano&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2016 12:40:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/73292#M41398</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2016-02-23T12:40:22Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2014-6271 Shellshock rules blocking Sharepoint traffic?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/73636#M41480</link>
      <description>&lt;P&gt;Thanks for the reply. I did some testing with the Sharepoint document access traffic from patched Windows workstations and they're not triggering the PA alerts/blocking so I chalk this up to the desktops not being patched yet.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2016 22:17:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/73636#M41480</guid>
      <dc:creator>Khang_Than-Trong</dc:creator>
      <dc:date>2016-02-25T22:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2014-6271 Shellshock rules blocking Sharepoint traffic?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/73762#M41526</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What components were unpatched? Windows, IE or Office?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have several clients alerting on this in morning. Destination is 2 sharepoint servers on the LAN and 1 residning in one-drive.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Upgraded our HA to 7.0.5h2 two days ago.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Feb 2016 09:11:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/73762#M41526</guid>
      <dc:creator>superture</dc:creator>
      <dc:date>2016-02-29T09:11:33Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2014-6271 Shellshock rules blocking Sharepoint traffic?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/74604#M41736</link>
      <description>&lt;P&gt;Office components weren't updated.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2016 21:13:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cve-2014-6271-shellshock-rules-blocking-sharepoint-traffic/m-p/74604#M41736</guid>
      <dc:creator>Khang_Than-Trong</dc:creator>
      <dc:date>2016-03-11T21:13:21Z</dc:date>
    </item>
  </channel>
</rss>

