<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block scanning from shodan in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/93393#M43846</link>
    <description>&lt;P&gt;We are aslo observing the simmilar kind of traffic triggering from the IP's listed in that article.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;blocking individual IP is not good idea but if there is any way that we can block IP's thase resolves to *&lt;SPAN&gt;shodan.io will be best approach.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im not sure how we can do this &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jun 2016 10:50:05 GMT</pubDate>
    <dc:creator>KotreshaMC</dc:creator>
    <dc:date>2016-06-30T10:50:05Z</dc:date>
    <item>
      <title>Block scanning from shodan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/93379#M43835</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone have successfully block scanning from shodan.io? &amp;nbsp; &lt;A href="http://www.shodan.io" target="_blank"&gt;www.shodan.io&lt;/A&gt; &amp;nbsp;?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like Checkpoint has written specific signature to block shodan scanning, &amp;nbsp;&lt;A href="http://blog.checkpoint.com/2016/01/04/check-point-threat-alert-shodan/" target="_blank"&gt;http://blog.checkpoint.com/2016/01/04/check-point-threat-alert-shodan/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-E&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2016 01:21:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/93379#M43835</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2016-06-30T01:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: Block scanning from shodan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/93393#M43846</link>
      <description>&lt;P&gt;We are aslo observing the simmilar kind of traffic triggering from the IP's listed in that article.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;blocking individual IP is not good idea but if there is any way that we can block IP's thase resolves to *&lt;SPAN&gt;shodan.io will be best approach.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im not sure how we can do this &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2016 10:50:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/93393#M43846</guid>
      <dc:creator>KotreshaMC</dc:creator>
      <dc:date>2016-06-30T10:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: Block scanning from shodan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/93394#M43847</link>
      <description>&lt;P&gt;Why would you block scanning from Shodan only?&lt;/P&gt;&lt;P&gt;Set up a zone protection profile which will protect you from all scans. Furthermore make sure that your firewall policy only allows traffic to services which need to be visible from whole internet (web servers, mail server..). And those servers must be hardened in any case so nothing to fear there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2016 11:07:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/93394#M43847</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-06-30T11:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: Block scanning from shodan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/93405#M43853</link>
      <description>&lt;P&gt;Blocking ip may help initally, but I am not going to make it my day job to keep on monitoring if they decided to change ip or add another new scanner. &amp;nbsp; &amp;nbsp;I submit an app-id request to PAN for shodan.io scan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-E&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2016 14:29:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/93405#M43853</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2016-06-30T14:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: Block scanning from shodan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/93406#M43854</link>
      <description>&lt;P&gt;Hi Santonic,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why not block these scanners? &amp;nbsp;I already have zone protection profile configured, shodan is a very slow scanner, it will not get flag by ZP. &amp;nbsp; &amp;nbsp;Sometime you may have some servers that you are just need to open to anyone (with some exceptions). &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-E&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2016 14:32:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/93406#M43854</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2016-06-30T14:32:14Z</dc:date>
    </item>
    <item>
      <title>Re: Block scanning from shodan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/93420#M43860</link>
      <description>&lt;P&gt;Couldn't you just use URL Filtering to disable access to that domain? Wouldn't that be easier then worrying about what IP is accessing that traffic.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2016 17:42:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/93420#M43860</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-06-30T17:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: Block scanning from shodan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/93450#M43864</link>
      <description>It's inbound not outbound traffic.</description>
      <pubDate>Fri, 01 Jul 2016 06:03:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/93450#M43864</guid>
      <dc:creator>KotreshaMC</dc:creator>
      <dc:date>2016-07-01T06:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: Block scanning from shodan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/93452#M43865</link>
      <description>&lt;P&gt;There is one another way i found,&lt;/P&gt;&lt;P&gt;we can create the objets with the FQDN provided in the article and create security policy for it &amp;nbsp;(FQDN initially resolves at commit time. Entries are subsequently refreshed when the firewall performs a check every 30 minutes; all changes in the IP address for the entries are picked up at the refresh cycle) so this might helpful in blocking the IP that resolves to specified shodan domain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2016 07:54:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/93452#M43865</guid>
      <dc:creator>KotreshaMC</dc:creator>
      <dc:date>2016-07-01T07:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Block scanning from shodan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/149280#M49760</link>
      <description>&lt;P&gt;+Bump&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does Palo have simlar IPS sigs as checkpoint?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Shodan.io Internet Of Things Portal&lt;/LI&gt;&lt;LI&gt;Shodan Scanner ISAKMP Request&lt;/LI&gt;&lt;LI&gt;Shodan Scanner SIP Request&lt;BR /&gt;Shodan Scanner BACNET Request&lt;/LI&gt;&lt;LI&gt;Shodan Scanner GTP Request&lt;/LI&gt;&lt;LI&gt;Shodan Scanner ENIP Request&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried looking through Threat Vault but couldn't find anyting.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 03:09:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/149280#M49760</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-03-24T03:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: Block scanning from shodan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/149307#M49771</link>
      <description>&lt;P&gt;I don't exactly see why would there be need for shodan specific signatures.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First of all make sure that all inbound traffic is blocked with firewall policy, except for servers snd services which need to be visible from all interenet (web servers, smtp, IPSEC...).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Services which need to be visible to internet need to be hardened and secured. For these services Shodan is the least of your worries. You want them secured from hackers and malware, not just Shodan. So why specific signature for Shodan traffic? &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 06:56:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/149307#M49771</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-03-24T06:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: Block scanning from shodan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/308373#M80001</link>
      <description>&lt;P&gt;Maybe because the customer asked for it?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2020 21:42:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/308373#M80001</guid>
      <dc:creator>j04nMan</dc:creator>
      <dc:date>2020-01-28T21:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: Block scanning from shodan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/556656#M112989</link>
      <description>&lt;P&gt;correction there: FQDN will refresh in 30 seconds.&lt;BR /&gt;&lt;BR /&gt;I was hoping if we could use domain based EDL in source but that isn't working.&lt;BR /&gt;Is there any way to get the most latest list of shodan.io subdomains/IP addresses&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 05:07:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/556656#M112989</guid>
      <dc:creator>UtkarshB</dc:creator>
      <dc:date>2023-09-06T05:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: Block scanning from shodan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/556658#M112990</link>
      <description>&lt;P&gt;Did that work out!&lt;BR /&gt;&lt;BR /&gt;Is there any app-ID yet for shodan.io&lt;BR /&gt;I don't see&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 05:13:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/556658#M112990</guid>
      <dc:creator>UtkarshB</dc:creator>
      <dc:date>2023-09-06T05:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: Block scanning from shodan</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/588495#M117328</link>
      <description>&lt;P&gt;If you block the known bad actors list, shodan is on that list.&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 12:32:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-scanning-from-shodan/m-p/588495#M117328</guid>
      <dc:creator>m.brewster</dc:creator>
      <dc:date>2024-05-31T12:32:46Z</dc:date>
    </item>
  </channel>
</rss>

