<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ThreatID 33542 and Facebook in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/threatid-33542-and-facebook/m-p/8106#M5982</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Some more info:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://wwapps.paloaltonetworks.com/ThreatVault/"&gt;http://wwapps.paloaltonetworks.com/ThreatVault/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://wwapps.paloaltonetworks.com/ThreatVault/Home.aspx/ThreatDetail/33542"&gt;http://wwapps.paloaltonetworks.com/ThreatVault/Home.aspx/ThreatDetail/33542&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attack Name: Mozilla Firefox GeckoActiveXObject Method Denial of Service Vulnerability&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Description: Mozilla Firefox is prone to a denial of service vulnerability while parsing certain crafted HTTP responses.The vulnerability is due to the lack of proper checks on GeckoActiveXObject Method in the HTTP response, leading to an exploitable denial of service vulnerability. An attacker could exploit the vulnerability by sending a crafted HTTP response. A successful attack could lead to denial of service with the privileges of the current logged-in user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Threat ID: 36871&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;References: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3803"&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3803&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Severity: high&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Category: dos&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 May 2012 19:00:55 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-05-11T19:00:55Z</dc:date>
    <item>
      <title>ThreatID 33542 and Facebook</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threatid-33542-and-facebook/m-p/8104#M5980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm seeing a lot of alerts in the last couple days for threatID 33542 when users are visiting facebook via &lt;A href="http://www.facebook.com/"&gt;http://www.facebook.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could this be a false positive?&amp;nbsp; Anyone else seeing a jump in this threat?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tnx, Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2012 17:35:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threatid-33542-and-facebook/m-p/8104#M5980</guid>
      <dc:creator>TomS</dc:creator>
      <dc:date>2012-05-11T17:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: ThreatID 33542 and Facebook</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threatid-33542-and-facebook/m-p/8105#M5981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal"&gt;We are seeing the same thing over here. Every source IP seems to be Akami CDN servers that serve Facebook from our ISP, so I'm really thinking this is a false positive.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;app: facebook-base&lt;BR /&gt;proto: tcp&lt;BR /&gt;threatid: Mozilla Firefox GeckoActiveXObject Method Denial of Service Vulnerability(33542)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2012 17:38:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threatid-33542-and-facebook/m-p/8105#M5981</guid>
      <dc:creator>Braden</dc:creator>
      <dc:date>2012-05-11T17:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: ThreatID 33542 and Facebook</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threatid-33542-and-facebook/m-p/8106#M5982</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Some more info:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://wwapps.paloaltonetworks.com/ThreatVault/"&gt;http://wwapps.paloaltonetworks.com/ThreatVault/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://wwapps.paloaltonetworks.com/ThreatVault/Home.aspx/ThreatDetail/33542"&gt;http://wwapps.paloaltonetworks.com/ThreatVault/Home.aspx/ThreatDetail/33542&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attack Name: Mozilla Firefox GeckoActiveXObject Method Denial of Service Vulnerability&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Description: Mozilla Firefox is prone to a denial of service vulnerability while parsing certain crafted HTTP responses.The vulnerability is due to the lack of proper checks on GeckoActiveXObject Method in the HTTP response, leading to an exploitable denial of service vulnerability. An attacker could exploit the vulnerability by sending a crafted HTTP response. A successful attack could lead to denial of service with the privileges of the current logged-in user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Threat ID: 36871&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;References: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3803"&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3803&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Severity: high&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Category: dos&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2012 19:00:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threatid-33542-and-facebook/m-p/8106#M5982</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-05-11T19:00:55Z</dc:date>
    </item>
    <item>
      <title>Re: ThreatID 33542 and Facebook</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threatid-33542-and-facebook/m-p/8107#M5983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also seeing the same high count of events.&amp;nbsp; Not all events are stemming from workstations that have Firefox installed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2012 19:09:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threatid-33542-and-facebook/m-p/8107#M5983</guid>
      <dc:creator>MGoodnow</dc:creator>
      <dc:date>2012-05-11T19:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: ThreatID 33542 and Facebook</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threatid-33542-and-facebook/m-p/8108#M5984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There have been some changes made to Facebook code that is causing some false positives to be triggered for this ThreatID. We are working to address this issue in next week's update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2012 19:12:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threatid-33542-and-facebook/m-p/8108#M5984</guid>
      <dc:creator>sspringer</dc:creator>
      <dc:date>2012-05-11T19:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: ThreatID 33542 and Facebook</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threatid-33542-and-facebook/m-p/8109#M5985</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there an ETA on the patch / update?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 14:54:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threatid-33542-and-facebook/m-p/8109#M5985</guid>
      <dc:creator>bmaslakovic</dc:creator>
      <dc:date>2012-05-14T14:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: ThreatID 33542 and Facebook</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threatid-33542-and-facebook/m-p/8110#M5986</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would think/hope that it would be fixed in the weekly content (wednesday AM CET, tuesday PM USA) Update. Cheers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 16:03:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threatid-33542-and-facebook/m-p/8110#M5986</guid>
      <dc:creator>KP</dc:creator>
      <dc:date>2012-05-14T16:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: ThreatID 33542 and Facebook</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threatid-33542-and-facebook/m-p/8111#M5987</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to the result of our lab test,&lt;/P&gt;&lt;P&gt;it may be fixed with the latest content ver.308-1390.&lt;/P&gt;&lt;P&gt;- there is not this fix on release note though...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tomoyuki Komure&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2012 04:54:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threatid-33542-and-facebook/m-p/8111#M5987</guid>
      <dc:creator>komure</dc:creator>
      <dc:date>2012-05-16T04:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: ThreatID 33542 and Facebook</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/threatid-33542-and-facebook/m-p/8112#M5988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, we also have updated the content to 308-1390, and the alerts have stopped. Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2012 14:00:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/threatid-33542-and-facebook/m-p/8112#M5988</guid>
      <dc:creator>bmaslakovic</dc:creator>
      <dc:date>2012-05-16T14:00:41Z</dc:date>
    </item>
  </channel>
</rss>

