<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Brute force attack in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168751#M53692</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Have you looked at the traffic logs and verified the alert generated correctly? I've had the brute force alerts get screwed up before and once I actually looked at the traffic found out that the source and destination was mixed around. Possibly happened here to?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jul 2017 20:53:36 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-07-27T20:53:36Z</dc:date>
    <item>
      <title>Brute force attack</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168738#M53685</link>
      <description>&lt;P&gt;The PA showed one of the pc's on my network was the source of brute force attack to the Netherlands so I blocked it. Anyone have any ideas what needs to be done to remediate the issues on the PC?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 20:19:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168738#M53685</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-27T20:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: Brute force attack</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168747#M53688</link>
      <description>&lt;P&gt;It was likely compromised and being used as a part of a botnet. Depending on who owns the computer I would either wipe and reimage the machine or if it's a personal machine only allow it back onto the network once a full system scan (virus,malware,spyware) has been run.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 20:41:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168747#M53688</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-27T20:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: Brute force attack</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168750#M53691</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;It must be being used as a relay not sure but it looks like the pc inside our network is trying to brute force something in the netherlands. I was more expecting the attack to be coming in and not going out. &amp;nbsp;I will have the helpdesk check for malware, virus scan and the typical checks and wipe it if it can't be cleaned&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 20:51:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168750#M53691</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-27T20:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: Brute force attack</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168751#M53692</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Have you looked at the traffic logs and verified the alert generated correctly? I've had the brute force alerts get screwed up before and once I actually looked at the traffic found out that the source and destination was mixed around. Possibly happened here to?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 20:53:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168751#M53692</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-27T20:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: Brute force attack</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168752#M53693</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How could you tell that the source and destination were mixed up?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 20:56:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168752#M53693</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-27T20:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: Brute force attack</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168753#M53694</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I you are thinking that the pc was probably being bruted forced and it was reading it wrong? Again how do I find out and how do I fix it and I am also thinking the attack was real but possbile the direction was wrong&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 20:59:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168753#M53694</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-27T20:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: Brute force attack</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168754#M53695</link>
      <description>&lt;P&gt;Take the other IP address that your PC was recorded as attacking, I'm just going to call it&amp;nbsp;&lt;EM&gt;1.1.1.1&amp;nbsp;&lt;/EM&gt;and your internal machine&amp;nbsp;&lt;EM&gt;10.0.0.0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Within the traffic log you can query '( addr in&amp;nbsp;&lt;EM&gt;1.1.1.1&lt;/EM&gt;&amp;nbsp;) and ( addr in&amp;nbsp;&lt;EM&gt;10.0.0.0&lt;/EM&gt; )' and that will show you what direction that traffic was actually going.&amp;nbsp;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2017 21:08:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168754#M53695</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-27T21:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: Brute force attack</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168847#M53708</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Oh you mean in the traffic logs, that is what was telling me that my internal PC &amp;nbsp;(source)is attacking some device or devices in the netherlands ((40.113.123.212)(destination))&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2017 12:43:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168847#M53708</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-28T12:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: Brute force attack</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168848#M53709</link>
      <description>&lt;P&gt;That's a pretty sure sign then that it was your machine that was actually sending the traffic to the netherlands, which likely means that your tech support guys will find something when they run scans against it. Sometimes the threat logs will show the attacker as your internal machines and seems to get the attacker switched around.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2017 12:48:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168848#M53709</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-28T12:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: Brute force attack</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168881#M53726</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yeah it will be interesting to know what is on it to be attacking the netherlands LOL and would be interested to know how it got there but I am not sure they will spend anytime on that&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2017 15:12:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/brute-force-attack/m-p/168881#M53726</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-07-28T15:12:37Z</dc:date>
    </item>
  </channel>
</rss>

