<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Testing Sinkhole DNS in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/testing-sinkhole-dns/m-p/239072#M68475</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97840"&gt;@aaobuhov&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;While namecha.in is present in the PAN-DB URL Classifications it doesn't look like it currently actually has an active DNS Signature in place, which is what the Sinkhole process would trigger on. It was first released in 2732, but it's not showing as being active in a current release. The other domain has the same issue, it isn't showing as having a current active signature.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Nov 2018 14:52:23 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-11-08T14:52:23Z</dc:date>
    <item>
      <title>Testing Sinkhole DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/testing-sinkhole-dns/m-p/239039#M68463</link>
      <description>&lt;P&gt;Hello, all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am testing Anti-Spyware DNS sinkhole. I set:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sinkhole.png" style="width: 624px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17470iEC23C5551C0D196A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Sinkhole.png" alt="Sinkhole.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I make policy with this profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For most DNS-names in category&amp;nbsp;“Malware” и “Command and Control” (&lt;A href="https://threatvault.paloaltonetworks.com/" target="_blank"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt;) i see nslookup answer, for example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Addresses: ::1&lt;BR /&gt;127.0.0.1&lt;/P&gt;&lt;P&gt;And it is good.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But for two DNS-names: namecha.in,&amp;nbsp;4cdf1kuvlgl5zpb9.pmr.cc&amp;nbsp;(Malware category too) sinkhole is not working and i see ip-adresses in nslookup answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What can be wrong? I need advice.&lt;/P&gt;&lt;P&gt;Yes, i can make my own external dynamic list, but why standart not working for malware?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2018 09:34:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/testing-sinkhole-dns/m-p/239039#M68463</guid>
      <dc:creator>aaobuhov</dc:creator>
      <dc:date>2018-11-08T09:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: Testing Sinkhole DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/testing-sinkhole-dns/m-p/239072#M68475</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/97840"&gt;@aaobuhov&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;While namecha.in is present in the PAN-DB URL Classifications it doesn't look like it currently actually has an active DNS Signature in place, which is what the Sinkhole process would trigger on. It was first released in 2732, but it's not showing as being active in a current release. The other domain has the same issue, it isn't showing as having a current active signature.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2018 14:52:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/testing-sinkhole-dns/m-p/239072#M68475</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-11-08T14:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: Testing Sinkhole DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/testing-sinkhole-dns/m-p/239242#M68506</link>
      <description>&lt;P&gt;Hello, BPy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is clear for me now, what&amp;nbsp;&lt;SPAN&gt;PAN-DB URL&amp;nbsp;database is not same as PA DNS Signature database.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2018 05:18:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/testing-sinkhole-dns/m-p/239242#M68506</guid>
      <dc:creator>aaobuhov</dc:creator>
      <dc:date>2018-11-09T05:18:37Z</dc:date>
    </item>
  </channel>
</rss>

