<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Detecting Flame exploit in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/detecting-flame-exploit/m-p/6961#M5132</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My answer to that question is currently - "Unless we have offices in the Middle East I'm unaware of, are politically active in Middle Eastern politics, or could otherwise be the target for 3 letter acronym Western intelligence agencies, I do not believe Flame is a present threat - unless/until the code is re-worked by cyber-criminals and deployed for other means"...!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 May 2012 12:30:16 GMT</pubDate>
    <dc:creator>apackard</dc:creator>
    <dc:date>2012-05-30T12:30:16Z</dc:date>
    <item>
      <title>Detecting Flame exploit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/detecting-flame-exploit/m-p/6960#M5131</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It looks like the Snort folks have a signature for Flame, does PAN?&amp;nbsp; If not, when is it coming?&amp;nbsp; The CTOs will be asking if we are safe...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://vrt-blog.snort.org/2012/05/flame-malware-targeted-attacks-and-you.html"&gt;http://vrt-blog.snort.org/2012/05/flame-malware-targeted-attacks-and-you.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 May 2012 22:00:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/detecting-flame-exploit/m-p/6960#M5131</guid>
      <dc:creator>grant_sturgis</dc:creator>
      <dc:date>2012-05-29T22:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: Detecting Flame exploit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/detecting-flame-exploit/m-p/6961#M5132</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My answer to that question is currently - "Unless we have offices in the Middle East I'm unaware of, are politically active in Middle Eastern politics, or could otherwise be the target for 3 letter acronym Western intelligence agencies, I do not believe Flame is a present threat - unless/until the code is re-worked by cyber-criminals and deployed for other means"...!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2012 12:30:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/detecting-flame-exploit/m-p/6961#M5132</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2012-05-30T12:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: Detecting Flame exploit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/detecting-flame-exploit/m-p/6962#M5133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You prefer to wait until a threat is eminent before protecting yourself?&amp;nbsp; That seems less than prudent.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2012 14:36:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/detecting-flame-exploit/m-p/6962#M5133</guid>
      <dc:creator>grant_sturgis</dc:creator>
      <dc:date>2012-05-30T14:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: Detecting Flame exploit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/detecting-flame-exploit/m-p/6963#M5134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Isnt that much more fun? Like using Microsoft products in your network - every day is a suprise when it comes to security &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree with thread starter - since snort have announced a bunch of ips-rules (which I assume also means that their commercial sourcefire IPS can already detect this) hopefully PA could do the same...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried threat vault to search for both flame and skywiper but no hits, hopefully someone from PA could inform the community whats going on (like which db update and date will have ips-rules to detect this)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And dont say "contact your SE" ffs &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2012 19:50:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/detecting-flame-exploit/m-p/6963#M5134</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-05-30T19:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: Detecting Flame exploit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/detecting-flame-exploit/m-p/6964#M5135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...We will have an AV update for the flame exploits later today.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2012 19:57:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/detecting-flame-exploit/m-p/6964#M5135</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-05-30T19:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: Detecting Flame exploit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/detecting-flame-exploit/m-p/6965#M5136</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for this, specially we have now a variant Shamoon.&lt;/P&gt;&lt;P&gt;IS AV now also updated for Shamoon?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Aug 2012 05:45:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/detecting-flame-exploit/m-p/6965#M5136</guid>
      <dc:creator>sandro</dc:creator>
      <dc:date>2012-08-30T05:45:27Z</dc:date>
    </item>
    <item>
      <title>Re: Detecting Flame exploit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/detecting-flame-exploit/m-p/6966#M5137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I cant find anything right now about shamoon in &lt;A href="https://threatvault.paloaltonetworks.com/" title="https://threatvault.paloaltonetworks.com/"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt; searching for vuln, spyware and virus (dont forget to change that dropdown to the right).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However plenty of flame variants when searching for flame in the virus container along with two generic signatures in spyware. Perhaps shamoon is already covered by one of the flame variants?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tricky part of all these names is that the AV community tends to create their own name for each virus which means something that Kaspersky has named could be the very same thing but different name when looking in Symantec db's and so on.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Aug 2012 08:53:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/detecting-flame-exploit/m-p/6966#M5137</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-08-30T08:53:58Z</dc:date>
    </item>
  </channel>
</rss>

