<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Who vets External Dynamic Lists (EDLs) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/who-vets-external-dynamic-lists-edls/m-p/197136#M58625</link>
    <description>&lt;P&gt;I wouldn't expect Palo Alto to vet the lists. I guess the question is, "Is there any entity that double checks any of the lists for invalid entries?" Or, do we have to trust that the list producer got it right?&lt;/P&gt;</description>
    <pubDate>Fri, 26 Jan 2018 16:21:49 GMT</pubDate>
    <dc:creator>LCMember1643</dc:creator>
    <dc:date>2018-01-26T16:21:49Z</dc:date>
    <item>
      <title>Who vets External Dynamic Lists (EDLs)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/who-vets-external-dynamic-lists-edls/m-p/197084#M58614</link>
      <description>&lt;P&gt;The Knowledge article on blocking TOR,&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/How-to-Block-Tor-The-Onion-Router/ta-p/177648" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/How-to-Block-Tor-The-Onion-Router/ta-p/177648&lt;/A&gt;, references a list on&amp;nbsp;panwdbl.appspot.com. This website has a number of lists that can be used to filter traffic, including the list of TOR exit nodes.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What process is used to ensure these lists are accurate? It would be a major problem if, for example, 8.8.8.8 got added to the TOR list by accident or ill intent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The TOR list is&amp;nbsp;&lt;A href="https://panwdbl.appspot.com/lists/ettor.txt&amp;nbsp;" target="_blank"&gt;https://panwdbl.appspot.com/lists/ettor.txt&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 13:52:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/who-vets-external-dynamic-lists-edls/m-p/197084#M58614</guid>
      <dc:creator>LCMember1643</dc:creator>
      <dc:date>2018-01-26T13:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: Who vets External Dynamic Lists (EDLs)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/who-vets-external-dynamic-lists-edls/m-p/197097#M58615</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7784"&gt;@LCMember1643&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;All of the EBLs listed on panwdbl.appspot.com are maintained by their respective publishers. For example the spamhaus DROP and EDROP are all maintained by the spamhaus project. panwdbl was started as a repository for customers to take advantage off, but it simply pulls the indicated lists and feeds them back out in a formate easier to use on a Palo Alto device, these lists are in no way maintained by Palo Alto.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 14:38:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/who-vets-external-dynamic-lists-edls/m-p/197097#M58615</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-01-26T14:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Who vets External Dynamic Lists (EDLs)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/who-vets-external-dynamic-lists-edls/m-p/197136#M58625</link>
      <description>&lt;P&gt;I wouldn't expect Palo Alto to vet the lists. I guess the question is, "Is there any entity that double checks any of the lists for invalid entries?" Or, do we have to trust that the list producer got it right?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 16:21:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/who-vets-external-dynamic-lists-edls/m-p/197136#M58625</guid>
      <dc:creator>LCMember1643</dc:creator>
      <dc:date>2018-01-26T16:21:49Z</dc:date>
    </item>
    <item>
      <title>Re: Who vets External Dynamic Lists (EDLs)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/who-vets-external-dynamic-lists-edls/m-p/197137#M58626</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7784"&gt;@LCMember1643&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You have to trust that the list provider got it right.&amp;nbsp;&lt;/P&gt;&lt;P&gt;An alternative to this would be to install MineMeld. MineMeld is able to mine these lists and merge them into a sole source that is added to your firewall as an External&amp;nbsp;Dynamic List. The advantage here is that MineMeld has the ability to create whitelists that prevent certain addresses from ever showing up on this list, so if you wanted to make sure that 8.8.8.8 wasn't ever included in your EDL and will never be blocked.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 16:27:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/who-vets-external-dynamic-lists-edls/m-p/197137#M58626</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-01-26T16:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: Who vets External Dynamic Lists (EDLs)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/who-vets-external-dynamic-lists-edls/m-p/197188#M58632</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The ones from PAN are pretty good and I havent gotten burned by them in over 5 years. The one that burned me recently was&amp;nbsp;&lt;A href="https://www.abuseipdb.com/" target="_blank"&gt;https://www.abuseipdb.com/&lt;/A&gt;. There was an IP added to it that belonged to Digicert and messed up my users browsing badly. We decided to remove that EBL from our lists. I must say it was the first time in 5+ years of using that list. I did notify DigiCert about it but who knows where it went from there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are the ones I currently use:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The two PAN ones - known malicious and High risk&lt;/P&gt;&lt;P&gt;&lt;A href="http://panwdbl.appspot.com/lists/bruteforceblocker.txt" target="_blank"&gt;http://panwdbl.appspot.com/lists/bruteforceblocker.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://panwdbl.appspot.com/lists/dshieldbl.txt" target="_blank"&gt;http://panwdbl.appspot.com/lists/dshieldbl.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://panwdbl.appspot.com/lists/etcompromised.txt" target="_blank"&gt;http://panwdbl.appspot.com/lists/etcompromised.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://panwdbl.appspot.com/lists/ettor.txt" target="_blank"&gt;http://panwdbl.appspot.com/lists/ettor.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://panwdbl.appspot.com/lists/mdl.txt" target="_blank"&gt;http://panwdbl.appspot.com/lists/mdl.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://panwdbl.appspot.com/lists/openbl.txt" target="_blank"&gt;http://panwdbl.appspot.com/lists/openbl.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://panwdbl.appspot.com/lists/sslabuseiplist.txt" target="_blank"&gt;http://panwdbl.appspot.com/lists/sslabuseiplist.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.spamhaus.org/drop/drop.txt" target="_blank"&gt;http://www.spamhaus.org/drop/drop.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.spamhaus.org/drop/edrop.txt" target="_blank"&gt;http://www.spamhaus.org/drop/edrop.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://panwdbl.appspot.com/lists/zeustrackerbadips.txt" target="_blank"&gt;http://panwdbl.appspot.com/lists/zeustrackerbadips.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Like&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;mentioned, you could have your own and use MindMeld to host it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2018 20:37:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/who-vets-external-dynamic-lists-edls/m-p/197188#M58632</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-01-26T20:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: Who vets External Dynamic Lists (EDLs)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/who-vets-external-dynamic-lists-edls/m-p/218652#M63198</link>
      <description>&lt;P&gt;Any other recommend list?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2018 22:13:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/who-vets-external-dynamic-lists-edls/m-p/218652#M63198</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2018-06-20T22:13:55Z</dc:date>
    </item>
    <item>
      <title>Re: Who vets External Dynamic Lists (EDLs)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/who-vets-external-dynamic-lists-edls/m-p/218656#M63199</link>
      <description>&lt;P&gt;anyone use&amp;nbsp;ransomwaretracker.abuse.ch&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2018 22:39:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/who-vets-external-dynamic-lists-edls/m-p/218656#M63199</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2018-06-20T22:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: Who vets External Dynamic Lists (EDLs)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/who-vets-external-dynamic-lists-edls/m-p/218686#M63201</link>
      <description>&lt;P&gt;I do not. However there is going to be a lot of overlap with what PAN has in their code that we cannot see.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 02:44:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/who-vets-external-dynamic-lists-edls/m-p/218686#M63201</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-06-21T02:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: Who vets External Dynamic Lists (EDLs)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/who-vets-external-dynamic-lists-edls/m-p/218751#M63220</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That's where and why I highly recommend MineMeld if you aren't simply using the built in EDL lists. This ensures that you aren't doubling up indicators and allows you to whitelist any indicator that you for sure don't want to be utilized even if it happens to exist in one of the EDLs you are pulling.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 17:25:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/who-vets-external-dynamic-lists-edls/m-p/218751#M63220</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-21T17:25:58Z</dc:date>
    </item>
  </channel>
</rss>

