<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: update.newinfoclientstack.com in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/update-newinfoclientstack-com/m-p/166590#M53362</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;We were able to add it to our exisiting MISP list so we are good to go, But it is good to know that I could create a a seperate rule and profile&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Jul 2017 14:44:55 GMT</pubDate>
    <dc:creator>jdprovine</dc:creator>
    <dc:date>2017-07-14T14:44:55Z</dc:date>
    <item>
      <title>update.newinfoclientstack.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/update-newinfoclientstack-com/m-p/166544#M53350</link>
      <description>&lt;P&gt;I looked in the threat database and PA classifies this URL&amp;nbsp;Inbox &amp;nbsp;update.newinfoclientstack.com as maleware. Is there a way to know if this is covered by the threat prevention subscription? There were no details in how to deal with it in the database&lt;/P&gt;&lt;DIV&gt;&lt;DIV class="nH"&gt;&lt;DIV class="nH"&gt;&lt;DIV class="nH bkL"&gt;&lt;DIV class="no"&gt;&lt;DIV class="nH bkK nn"&gt;&lt;DIV class="nH"&gt;&lt;DIV class="nH"&gt;&lt;DIV class="nH ar4 z"&gt;&lt;DIV class="AO"&gt;&lt;DIV class="Tm"&gt;&lt;DIV class="aeF"&gt;&lt;DIV class="nH"&gt;&lt;DIV class="BltHke nH oy8Mbf"&gt;&lt;DIV class="aia"&gt;&lt;DIV class="nH apg UI vm2QI"&gt;&lt;DIV class="nH"&gt;&lt;DIV class="nH aNW apk"&gt;&lt;DIV class="nH age apN aZ6"&gt;&lt;DIV class="nH ao8"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 14 Jul 2017 13:33:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/update-newinfoclientstack-com/m-p/166544#M53350</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-14T13:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: update.newinfoclientstack.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/update-newinfoclientstack-com/m-p/166575#M53354</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The&amp;nbsp;&lt;SPAN&gt;newinfoclientstack.com domain is only listed as malware because of the listing in PAN-DB URL Classifications and therefore isn't covered with the threat prevention subscription. The only thing that the threat prevention license is going to cover is antivirus, anti-spyware, and vulnerability proctection updates.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Keep in mind that you still have access to URL filtering by the devices Base db; in this case it doesn't do you much good as the Base db is listing it as a content-delivery-network while the Cloud db is listing it as Malware.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2017 14:13:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/update-newinfoclientstack-com/m-p/166575#M53354</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-14T14:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: update.newinfoclientstack.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/update-newinfoclientstack-com/m-p/166582#M53355</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;This is the URL that was requested to be blocked, but i see no evidence it has ever tried on the firewall. Just trying to figure out the best way to deal with these issues and not make excessive work&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2017 14:19:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/update-newinfoclientstack-com/m-p/166582#M53355</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-14T14:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: update.newinfoclientstack.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/update-newinfoclientstack-com/m-p/166585#M53358</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Do you have an active 'blacklist' so to speak? You could build an EBL that was only for addresses that were going to be blocked and then put any such request like this in that 'blacklist' policy. If you utilize MineMeld you could even build in an age-out limit so that entries are automatically removed after x amount of time. That's how I deal with requests such as this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2017 14:24:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/update-newinfoclientstack-com/m-p/166585#M53358</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-14T14:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: update.newinfoclientstack.com</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/update-newinfoclientstack-com/m-p/166590#M53362</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;We were able to add it to our exisiting MISP list so we are good to go, But it is good to know that I could create a a seperate rule and profile&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2017 14:44:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/update-newinfoclientstack-com/m-p/166590#M53362</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-14T14:44:55Z</dc:date>
    </item>
  </channel>
</rss>

