attacking site and PAN

cancel
Showing results for 
Search instead for 
Did you mean: 

attacking site and PAN

L4 Transporter

Hello

Few days ago I discovered site with some information about VMware Update Manager. I had a problem with it and I was searching for solution.

This site is www.bourgelat.net/cannot-patch-definitions-vmware-19988

I have PA with all licences but PAN software doesnt detect any bad traffic Smiley Sad

I asked PAN to change categorization to malware site, but today I got email : New category: computer-and-internet-info

This site still trying to hurt Your computer, and PAN doesnt responds to it - is it OK?

I have security policy with thread prevention/av - but it doesnt stops it, hopefully my Symnatec Endpoint protection detecting it and blocking.

You can try to open www.bourgelat.net - this isn't https so in my opinion PAN should react in some way to this traffic.

Do You agree with me?

How it's possible when IE 10 with default configuration recomends to not enter to this site while PAN recategorization is computer-and-internet-info ?

Regards

Slawek

13 REPLIES 13

L4 Transporter

small update, www.bourgelat.net is classified as malware site by BightCloud Service, and it's blocked if You are blocking access by url filter (block malware sites) but if you are using PA url database you are under risk!

L5 Sessionator

Hi slv,

Can you provide more details about why you feel this site is malicious? 

--Doris

My symantec endpoint pretection is detecting that this site try to attact my computer using "red export kit redirect" now.

Are you referring to this threat Web Attack: Red Exploit Kit Redirect: Attack Signature - Symantec Corp. ?

If yes then --> CVE-2009-4324

CVE-2009-4324 is covered with nine Threat ID's

Capture.JPG.jpg

Are these nine Threat ID's all covered in your Vuln. Protection Profile ?

BTW, www.bourgelat.net/cannot-patch-definitions-vmware-19988 does not seem to be accessible at all

Capture.JPG.jpg

L4 Transporter

I can't verify it now, but probably - yes.

Today "www.bourgelat.net/cannot-patch-definitions-vmware-19988" isn't accessable but please try with www.bourgelat.net  Please try with it.

I will check my security rules, but I'm sure that I blocing medium and critical threats.

Regards

SLawek

I don't see anything threatening on www.bourgelat.net

Although a google search for "www.bourgelat.net malware" shows very suspicious results...

Here You are report from today (SEP):

Wykryto zagrożenie
Czas zdarzenia:
Czas rozpoczęcia:
Czas zakończenia:
Wystąpienie:
Nazwa sygnatury:
Identyfikator sygnatury:
Podidentyfikator sygnatury:
Adres URL włamania:
Adres URL zawartości włamania:
Opis zdarzenia:
Typ zdarzenia:
Typ hakingu:
Istotność:
Nazwa aplikacji:
Protokół sieciowy:
Kierunek ruchu sieciowego:
Adres IP komputera zdalnego:
Zdalny adres MAC:
Nazwa hosta zdalnego:
Alert:
Port lokalny:
Port zdalny:

is it a false positive?

Regards

Slawek

L4 Transporter

Slawek,


We deal with situation by having two custom URL categories:


1. Temporary-Blocked = this allows you to immediately block it while you wait for a reclassification request to be processed by Palo Alto.

2. Custom-Blocked = This allows you to override the Pan-DB or Brightcloud category.  Additionally you can use it to block parts of an otherwise good website.


Hope this provides a way to react quicker.  It works quite well for us.


Phil

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!