<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pattern of network vulnerability scanning coming from all over the world in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pattern-of-network-vulnerability-scanning-coming-from-all-over/m-p/183632#M56421</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43490"&gt;@CTW1983&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Important to remember that unless it's just someone running scripts, most people would run activity through a botnet. This would explain your wide range of IPs coming from different regions.&lt;/P&gt;&lt;P&gt;An additional step to take would be to block the IP for a set period of time.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 25 Oct 2017 13:29:32 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-10-25T13:29:32Z</dc:date>
    <item>
      <title>Pattern of network vulnerability scanning coming from all over the world</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pattern-of-network-vulnerability-scanning-coming-from-all-over/m-p/183531#M56399</link>
      <description>&lt;P&gt;In the last month or so we have seen lots of network vulnerability scanning for the following 3 Threat IDs coming from all over the world.&lt;BR /&gt;&lt;BR /&gt;- MVPower DVR TV Shell Unauthenticated Command Execution Vulnerability(30426)&lt;BR /&gt;- WebUI mainfile.php Arbitrary Command Injection Vulnerability(38836)&lt;BR /&gt;- Wireless IP Camera Pre-Auth Info Leak Vulnerability(33556)&lt;BR /&gt;&lt;BR /&gt;We don't have products that would be vulnerable to these threats. A single scanning interval seems to always look for only these 3 threats all within a few seconds, coming from the same source IP, and attacking the same destination IP. Then several hours later plus or minus a few hours (seems random), another scan interval occurs, but with a different source IP (and likely different region), and attacking a different destination IP from the last time it occurred. Then it repeats.&lt;BR /&gt;&lt;BR /&gt;Our action for these attacks is "reset-both". Should we be doing some thing different?&lt;BR /&gt;&lt;BR /&gt;We find it strange that this is coming from several regions around the world. Are they all part of the same hacking group?&lt;BR /&gt;&lt;BR /&gt;Has anyone else also seen this same pattern?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2017 22:32:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pattern-of-network-vulnerability-scanning-coming-from-all-over/m-p/183531#M56399</guid>
      <dc:creator>CTW1983</dc:creator>
      <dc:date>2017-10-24T22:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: Pattern of network vulnerability scanning coming from all over the world</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pattern-of-network-vulnerability-scanning-coming-from-all-over/m-p/183632#M56421</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43490"&gt;@CTW1983&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Important to remember that unless it's just someone running scripts, most people would run activity through a botnet. This would explain your wide range of IPs coming from different regions.&lt;/P&gt;&lt;P&gt;An additional step to take would be to block the IP for a set period of time.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2017 13:29:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pattern-of-network-vulnerability-scanning-coming-from-all-over/m-p/183632#M56421</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-10-25T13:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: Pattern of network vulnerability scanning coming from all over the world</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pattern-of-network-vulnerability-scanning-coming-from-all-over/m-p/183739#M56436</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;, definitly set the policy to block-ip. The max time is 3600 seconds (1 hour) so at least they would only be able to try once an hour. If they are comming from the smae source IP you could always just put in a rule to block those IP's.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a thought.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2017 21:25:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pattern-of-network-vulnerability-scanning-coming-from-all-over/m-p/183739#M56436</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-10-25T21:25:27Z</dc:date>
    </item>
  </channel>
</rss>

