PA doesn't cover DROWN Attack?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

PA doesn't cover DROWN Attack?

L5 Sessionator

A customer has been warned about DROWN attack (https://drownattack.com/) on one of its servers. As a server is behind PA I thought there was no risk. But searching through signature database I didn't find anything about DROWN attack. I've also checked all CVEs connected with attack (CVE-2015-3197, CVE-2016-0703, CVE-2016-0800) and PA doesn't have signature for any of them! 

 

Anyone knows about if PA covers this attack? Anyone contacted PA about this already?

 

8 REPLIES 8

Would the PAN be able to detet this if it was performing reverse proxy ssl decryption?

 

Just a thought

Hi,

 

decryption would not really help, as Dulle explained intercepting communication over long time is sufficient to exploit this. Decryption can't help if someone is somewhere allowing (knowingly or unknowingly) copying of your traffic as it passes along the way.

 

And there came Application and Threat Content Release Notes Version 567, and proved me wrong....

Not really Dulle. The signature doesn't detect any exploit. It just detects use of SSLv2. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!