<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Suspicious HTTP Response Found (ID 54319) after updated to 8029-4784 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-http-response-found-id-54319-after-updated-to-8029/m-p/217298#M62872</link>
    <description>&lt;P&gt;Try to understand "&lt;SPAN&gt;suspicious HTTP response" means from PAN point of view, it will be nice to have a more descriptive explaination.&amp;nbsp; It is a low&amp;nbsp;severity, but why is it set to alert?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Jun 2018 14:42:13 GMT</pubDate>
    <dc:creator>nextgenhappines</dc:creator>
    <dc:date>2018-06-10T14:42:13Z</dc:date>
    <item>
      <title>Suspicious HTTP Response Found (ID 54319) after updated to 8029-4784</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-http-response-found-id-54319-after-updated-to-8029/m-p/217277#M62870</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone else&amp;nbsp; notices increase amount of&amp;nbsp;&lt;SPAN&gt;Suspicious HTTP Response Found ID 54319 after installed AppID 8029-4784?.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The threat vault description&amp;nbsp;This signature detects a suspicious HTTP response&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Category protocol anomaly&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PANOS Min version 8.0.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Severity low&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Action Alert&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Fire release 785&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Want to see if others are seeing the same thing on their firewall?&amp;nbsp; It looks like it is catching http get file transfer.&amp;nbsp; What makes it suspicious?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="54319.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15441iC29DB06D7964A522/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="54319.png" alt="54319.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Jun 2018 14:52:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-http-response-found-id-54319-after-updated-to-8029/m-p/217277#M62870</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2018-06-09T14:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious HTTP Response Found (ID 54319) after updated to 8029-4784</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-http-response-found-id-54319-after-updated-to-8029/m-p/217284#M62871</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23897"&gt;@nextgenhappines&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I've noticed an uptick, but it's something that I notice quite a lot anyways with our users.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jun 2018 02:04:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-http-response-found-id-54319-after-updated-to-8029/m-p/217284#M62871</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-10T02:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious HTTP Response Found (ID 54319) after updated to 8029-4784</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-http-response-found-id-54319-after-updated-to-8029/m-p/217298#M62872</link>
      <description>&lt;P&gt;Try to understand "&lt;SPAN&gt;suspicious HTTP response" means from PAN point of view, it will be nice to have a more descriptive explaination.&amp;nbsp; It is a low&amp;nbsp;severity, but why is it set to alert?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jun 2018 14:42:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-http-response-found-id-54319-after-updated-to-8029/m-p/217298#M62872</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2018-06-10T14:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious HTTP Response Found (ID 54319) after updated to 8029-4784</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/suspicious-http-response-found-id-54319-after-updated-to-8029/m-p/217510#M62923</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23897"&gt;@nextgenhappines&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Unfortunately they kind of stopped publishing exactly what the signature in question is looking for, however all of the Suspicious HTTP Response Found signatures all focus on looking for different characters in the HTTP response header. For example '40400' looks for "x00". They essentially are looking for a character set that shouldn't actually exist in the response header.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The real issue is that most people don't take the standard seriously and include whatever they want within the response header because generally it doesn't cause any issues. Its set to alert because you can actually use the response header to give commands to infected machines. So if an infected machine reaches out to a CnC server it can put control information within a response header.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll clarify this by saying that there is a&amp;nbsp;&lt;STRONG&gt;lot&lt;/STRONG&gt; of services that don't actually respect RFC 2616 or the further defined RFC 7230. Slack&amp;nbsp;is one that I can think of at the moment that is horribly out of scope and is rightfully identified but is a known application.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 13:06:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/suspicious-http-response-found-id-54319-after-updated-to-8029/m-p/217510#M62923</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-12T13:06:39Z</dc:date>
    </item>
  </channel>
</rss>

