<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Temporary disable Miner / Malwaredomainlist offline in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/temporary-disable-miner-malwaredomainlist-offline/m-p/361878#M95494</link>
    <description>&lt;P&gt;Hello!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anybody know how to temporary disabel a miner without deleting it from config ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Problem is, that currently &lt;A href="http://www.malwaredomainlist.com" target="_blank" rel="noopener"&gt;www.malwaredomainlist.com&lt;/A&gt; gets resolved to 127.0.0.1 and the miner alerts in the log files with&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="display: inline !important; float: none; background-color: #ffffff; color: #222222; font-family: Helvetica,Arial,sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; overflow-wrap: break-word; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;basepoller._poll ERROR: Exception in polling loop for Malwaredomain_IPs: HTTPSConnectionPool(host=&lt;/SPAN&gt;&lt;A style="color: #003399; font-family: Helvetica,Arial,sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; overflow-wrap: break-word; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px; padding: 0px; margin: 0px;" href="http://www.malwaredomainlist.com/" target="_blank" rel="noopener noreferrer"&gt;www.malwaredomainlist.com&lt;/A&gt;&lt;SPAN style="display: inline !important; float: none; background-color: #ffffff; color: #222222; font-family: Helvetica,Arial,sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; overflow-wrap: break-word; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;, port=443): Max retries exceeded with url: /hostslist/ip.txt (Caused by SSLError(SSLError(1, u[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:590)),)))&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Any suggestions about the malwaredomainlist or disabling ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for help&lt;/P&gt;</description>
    <pubDate>Tue, 10 Nov 2020 09:51:03 GMT</pubDate>
    <dc:creator>Fuerdauer</dc:creator>
    <dc:date>2020-11-10T09:51:03Z</dc:date>
    <item>
      <title>Temporary disable Miner / Malwaredomainlist offline</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/temporary-disable-miner-malwaredomainlist-offline/m-p/361878#M95494</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anybody know how to temporary disabel a miner without deleting it from config ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Problem is, that currently &lt;A href="http://www.malwaredomainlist.com" target="_blank" rel="noopener"&gt;www.malwaredomainlist.com&lt;/A&gt; gets resolved to 127.0.0.1 and the miner alerts in the log files with&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="display: inline !important; float: none; background-color: #ffffff; color: #222222; font-family: Helvetica,Arial,sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; overflow-wrap: break-word; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;basepoller._poll ERROR: Exception in polling loop for Malwaredomain_IPs: HTTPSConnectionPool(host=&lt;/SPAN&gt;&lt;A style="color: #003399; font-family: Helvetica,Arial,sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; overflow-wrap: break-word; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px; padding: 0px; margin: 0px;" href="http://www.malwaredomainlist.com/" target="_blank" rel="noopener noreferrer"&gt;www.malwaredomainlist.com&lt;/A&gt;&lt;SPAN style="display: inline !important; float: none; background-color: #ffffff; color: #222222; font-family: Helvetica,Arial,sans-serif; font-size: 12px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; overflow-wrap: break-word; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;, port=443): Max retries exceeded with url: /hostslist/ip.txt (Caused by SSLError(SSLError(1, u[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:590)),)))&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Any suggestions about the malwaredomainlist or disabling ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for help&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 09:51:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/temporary-disable-miner-malwaredomainlist-offline/m-p/361878#M95494</guid>
      <dc:creator>Fuerdauer</dc:creator>
      <dc:date>2020-11-10T09:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: Temporary disable Miner / Malwaredomainlist offline</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/temporary-disable-miner-malwaredomainlist-offline/m-p/361925#M95495</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/120672"&gt;@Fuerdauer&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I noticed the MalwareDomainList miner issue as well. Haven't been able to find a reason for the localhost DNS answer. Anyone know what happened?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can remove the miner from your processor input(s) if you don't want the indicators in your list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 15:31:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/temporary-disable-miner-malwaredomainlist-offline/m-p/361925#M95495</guid>
      <dc:creator>fwmike2</dc:creator>
      <dc:date>2020-11-10T15:31:03Z</dc:date>
    </item>
  </channel>
</rss>

