<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Need response on some VAPT points in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/need-response-on-some-vapt-points/m-p/274816#M75194</link>
    <description>&lt;P&gt;There are some VAPT points of one of our customer which is attached with the email.&lt;/P&gt;&lt;P&gt;My response on these vulnerability point are as follow:-&lt;/P&gt;&lt;P&gt;1)&amp;nbsp;SSL/TLS Server supports TLSv1.0 :-&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We can enable TLSv1.2 in SSL/TLS profile under Device -SSL/TLS profile and use these profile wherever required.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;2)&amp;nbsp;Birthday attacks against TLS ciphers with 64bit block size vulnerability (Sweet32) :-&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We can enhance block size of cipher and generate certificate for firewall access.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;3)&amp;nbsp;SSL Certificate&amp;nbsp; Expired :-&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We can renew certificate with vaild start and end date.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;4)&amp;nbsp;SSL Certificate - Self-Signed Certificate:-&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Trusted third party certificate can be installed for this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;5)&amp;nbsp;SSL Certificate - Improper Usage Vulnerability:-&amp;nbsp;&lt;/P&gt;&lt;P&gt;6)&amp;nbsp;SSL Certificate - Signature Verification Failed Vulnerability:-&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Trusted third party certificate can be installed for this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;7)&amp;nbsp;HTTP Security Header Not Detected:- Need your response on this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; Deprecated SSH Cryptographic Settings:-&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;we can enable strong cipher for ssh access of firewall i.e ctr,gcm.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check and share your response on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Karthikeyan&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jul 2019 06:46:32 GMT</pubDate>
    <dc:creator>karthikeyanB</dc:creator>
    <dc:date>2019-07-04T06:46:32Z</dc:date>
    <item>
      <title>Need response on some VAPT points</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-response-on-some-vapt-points/m-p/274816#M75194</link>
      <description>&lt;P&gt;There are some VAPT points of one of our customer which is attached with the email.&lt;/P&gt;&lt;P&gt;My response on these vulnerability point are as follow:-&lt;/P&gt;&lt;P&gt;1)&amp;nbsp;SSL/TLS Server supports TLSv1.0 :-&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We can enable TLSv1.2 in SSL/TLS profile under Device -SSL/TLS profile and use these profile wherever required.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;2)&amp;nbsp;Birthday attacks against TLS ciphers with 64bit block size vulnerability (Sweet32) :-&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We can enhance block size of cipher and generate certificate for firewall access.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;3)&amp;nbsp;SSL Certificate&amp;nbsp; Expired :-&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We can renew certificate with vaild start and end date.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;4)&amp;nbsp;SSL Certificate - Self-Signed Certificate:-&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Trusted third party certificate can be installed for this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;5)&amp;nbsp;SSL Certificate - Improper Usage Vulnerability:-&amp;nbsp;&lt;/P&gt;&lt;P&gt;6)&amp;nbsp;SSL Certificate - Signature Verification Failed Vulnerability:-&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Trusted third party certificate can be installed for this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;7)&amp;nbsp;HTTP Security Header Not Detected:- Need your response on this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; Deprecated SSH Cryptographic Settings:-&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;we can enable strong cipher for ssh access of firewall i.e ctr,gcm.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check and share your response on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Karthikeyan&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 06:46:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-response-on-some-vapt-points/m-p/274816#M75194</guid>
      <dc:creator>karthikeyanB</dc:creator>
      <dc:date>2019-07-04T06:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: Need response on some VAPT points</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/need-response-on-some-vapt-points/m-p/275131#M75234</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Not sure what the question is, but the points are correct from what I can tell.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 17:01:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/need-response-on-some-vapt-points/m-p/275131#M75234</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-07-05T17:01:04Z</dc:date>
    </item>
  </channel>
</rss>

