<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA identifying traffic from AKAMAI as BruteForce. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-identifying-traffic-from-akamai-as-bruteforce/m-p/90078#M43555</link>
    <description>&lt;P&gt;Negative, still experiencing this issue on my end.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jun 2016 00:15:49 GMT</pubDate>
    <dc:creator>MIGAS</dc:creator>
    <dc:date>2016-06-21T00:15:49Z</dc:date>
    <item>
      <title>PA identifying traffic from AKAMAI as BruteForce.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-identifying-traffic-from-akamai-as-bruteforce/m-p/88281#M43489</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Context: For the past 24 hours we've had constant reports of a Brute force attack on our servers originating from the Akamai CDN's.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm unsure whether this is simply a false positive, or if there something to&amp;nbsp;actually worry about.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've submitted a ticket to ccare@akamai.com with the same information - hoping for a response.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below is a direct log from our firewalls, but obviously - I've removed some the more 'sensitive' information.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS, there are a total of 2 originating address causing us issues, these are:&amp;nbsp;104.95.121.227 and &amp;nbsp;104.74.58.4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;domain: 1&lt;BR /&gt;receive_time: 2016/06/17 09:14:50&lt;BR /&gt;serial: 001606021465&lt;BR /&gt;seqno: 741569&lt;BR /&gt;actionflags: 0x0&lt;BR /&gt;type: THREAT&lt;BR /&gt;subtype: vulnerability&lt;BR /&gt;config_ver: 1&lt;BR /&gt;time_generated: 2016/06/17 09:14:50&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;src: 104.74.58.4&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;dst: x.x.x.x &lt;BR /&gt;natsrc: 104.74.58.4&lt;BR /&gt;natdst: x.x.x.x&lt;BR /&gt;rule: Allow - General Internet&lt;BR /&gt;srcuser:&lt;/P&gt;
&lt;P&gt;srcloc: US&lt;/P&gt;
&lt;P&gt;app: soap&lt;BR /&gt;vsys: vsys1&lt;/P&gt;
&lt;P&gt;inbound_if: ethernet1/1&lt;BR /&gt;outbound_if: ethernet1/3&lt;/P&gt;
&lt;P&gt;time_received: 2016/06/17 09:14:50&lt;BR /&gt;sessionid: 9902&lt;BR /&gt;repeatcnt: 15&lt;BR /&gt;sport: 80&lt;BR /&gt;dport: 63873&lt;BR /&gt;natsport: 80&lt;BR /&gt;natdport: 18570&lt;BR /&gt;flags: 0x404000&lt;BR /&gt;proto: tcp&lt;BR /&gt;action: reset-both&lt;BR /&gt;cpadding: 0&lt;BR /&gt;dg_hier_level_1: 0&lt;BR /&gt;dg_hier_level_2: 0&lt;BR /&gt;dg_hier_level_3: 0&lt;BR /&gt;dg_hier_level_4: 0&lt;BR /&gt;vsys_name:&lt;/P&gt;
&lt;P&gt;vsys_id: 1&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;threatid: HTTP Request Brute Force Attack(40059)&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;reportid: 0&lt;BR /&gt;category: not-resolved&lt;BR /&gt;contenttype:&lt;BR /&gt;severity: high&lt;BR /&gt;direction: server-to-client&lt;BR /&gt;url_idx: 1&lt;BR /&gt;padding: 0&lt;BR /&gt;pcap_id: 0&lt;BR /&gt;filedigest:&lt;BR /&gt;user_agent:&lt;BR /&gt;filetype:&lt;BR /&gt;misc:&lt;BR /&gt;cloud:&lt;BR /&gt;xff:&lt;BR /&gt;referer:&lt;BR /&gt;sender:&lt;BR /&gt;subject:&lt;BR /&gt;recipient:&lt;BR /&gt;file_url:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2016 23:52:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-identifying-traffic-from-akamai-as-bruteforce/m-p/88281#M43489</guid>
      <dc:creator>MIGAS</dc:creator>
      <dc:date>2016-06-16T23:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: PA identifying traffic from AKAMAI as BruteForce.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-identifying-traffic-from-akamai-as-bruteforce/m-p/88361#M43491</link>
      <description>&lt;P&gt;A couple of my customers are also facing exactly same issue.&lt;/P&gt;
&lt;P&gt;Application 'soap' is same, and IP address is also AKAMAI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm currently suggest them to tune threshold of signature id 40059.&lt;/P&gt;
&lt;P&gt;The default&amp;nbsp;threshold is 10 hits per 6 seconds.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2016 03:02:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-identifying-traffic-from-akamai-as-bruteforce/m-p/88361#M43491</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2016-06-17T03:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: PA identifying traffic from AKAMAI as BruteForce.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-identifying-traffic-from-akamai-as-bruteforce/m-p/88712#M43505</link>
      <description>&lt;P&gt;this is getting real annoying, so many alerts due to this. is this something PAN can fix for us or we have to wait on Akamai&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2016 16:08:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-identifying-traffic-from-akamai-as-bruteforce/m-p/88712#M43505</guid>
      <dc:creator>googol</dc:creator>
      <dc:date>2016-06-17T16:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: PA identifying traffic from AKAMAI as BruteForce.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-identifying-traffic-from-akamai-as-bruteforce/m-p/88715#M43508</link>
      <description>&lt;P&gt;I would think that Palo Alto will address the issue and tune the threshold or whitelist Akamai in the threat signature. What annoys me is you can't tell me they didn't see this issue in internal testing.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2016 16:14:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-identifying-traffic-from-akamai-as-bruteforce/m-p/88715#M43508</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-06-17T16:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: PA identifying traffic from AKAMAI as BruteForce.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-identifying-traffic-from-akamai-as-bruteforce/m-p/89331#M43535</link>
      <description>&lt;P&gt;Has anyone received an update regarding these?&lt;BR /&gt;&lt;BR /&gt;We're getting way too many messages, and I'm assuming this is a false positive.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2016 02:54:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-identifying-traffic-from-akamai-as-bruteforce/m-p/89331#M43535</guid>
      <dc:creator>MIGAS</dc:creator>
      <dc:date>2016-06-20T02:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: PA identifying traffic from AKAMAI as BruteForce.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-identifying-traffic-from-akamai-as-bruteforce/m-p/89983#M43553</link>
      <description>&lt;P&gt;Is this resolved yet? &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2016 21:36:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-identifying-traffic-from-akamai-as-bruteforce/m-p/89983#M43553</guid>
      <dc:creator>ajrockn</dc:creator>
      <dc:date>2016-06-20T21:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: PA identifying traffic from AKAMAI as BruteForce.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-identifying-traffic-from-akamai-as-bruteforce/m-p/90078#M43555</link>
      <description>&lt;P&gt;Negative, still experiencing this issue on my end.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2016 00:15:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-identifying-traffic-from-akamai-as-bruteforce/m-p/90078#M43555</guid>
      <dc:creator>MIGAS</dc:creator>
      <dc:date>2016-06-21T00:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: PA identifying traffic from AKAMAI as BruteForce.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-identifying-traffic-from-akamai-as-bruteforce/m-p/90360#M43565</link>
      <description>&lt;P&gt;Me too.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2016 10:30:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-identifying-traffic-from-akamai-as-bruteforce/m-p/90360#M43565</guid>
      <dc:creator>KotreshaMC</dc:creator>
      <dc:date>2016-06-21T10:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: PA identifying traffic from AKAMAI as BruteForce.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-identifying-traffic-from-akamai-as-bruteforce/m-p/90394#M43567</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The upcoming content version (590) should handle&amp;nbsp;this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2016 11:51:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-identifying-traffic-from-akamai-as-bruteforce/m-p/90394#M43567</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2016-06-21T11:51:49Z</dc:date>
    </item>
  </channel>
</rss>

