====== Security Profiles ====== ===== Evasion Signatures ===== You can run an evasion test on PAN-OS using a client that accessess [[http://http-evader.semantic-gap.de/|this site]] through the firewall. We find that the following threats are detected and blocked. Notice that a lot of them are //low// and //informational//. ^ Severity ^ Application ^ App Category ^ App Sub Category ^ App Technology ^ Destination Port ^ Threat Category ^ Threat/Content Name ^ ID ^ Direction ^ | informational | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Abnormal HTTP 1.0 Chunked Response Found | 40568 | server-to-client | | informational | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Abnormal Multiple Transfer-Encoding HTTP Response Found | 38302 | server-to-client | | medium | web-browsing | general-internet | internet-utility | browser-based | 80 | code-execution | Eicar File Detected | 39040 | server-to-client | | low | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | HTTP Brotli Encoding | 37778 | server-to-client | | low | web-browsing | general-internet | internet-utility | browser-based | 80 | code-execution | HTTP Response Content Length Too Long | 31370 | server-to-client | | high | web-browsing | general-internet | internet-utility | browser-based | 80 | overflow | Microsoft HTTP Services Chunked Encoding Integer Overflow Vulnerability | 32275 | server-to-client | | informational | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Suspicious Abnormal Chunk-Size in HTTP Response | 40500 | server-to-client | | low | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Suspicious Abnormal HTTP Response Found | 38840 | server-to-client | | low | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Suspicious Abnormal HTTP Response Found | 38839 | server-to-client | | low | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Suspicious Abnormal HTTP Response Found | 38306 | server-to-client | | low | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Suspicious Abnormal HTTP Response Found | 38305 | server-to-client | | low | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Suspicious Abnormal HTTP Response Found | 38304 | server-to-client | | low | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Suspicious Abnormal HTTP Response Found | 38742 | server-to-client | | low | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Suspicious Abnormal HTTP Response Found | 39910 | server-to-client | | low | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Suspicious Abnormal HTTP Response Found | 38824 | server-to-client | | low | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Suspicious Abnormal HTTP Response Found | 38841 | server-to-client | | low | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Suspicious Abnormal HTTP Response Found | 38920 | server-to-client | | low | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Suspicious Abnormal HTTP Response Found | 39041 | server-to-client | | informational | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Suspicious HTTP Evasion Found | 30463 | server-to-client | | low | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Suspicious HTTP Evasion Found | 39819 | server-to-client | | low | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Suspicious HTTP Evasion Found | 30436 | server-to-client | | medium | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Suspicious HTTP Evasion Found | 54622 | server-to-client | | medium | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Suspicious HTTP Evasion Found | 39022 | server-to-client | | medium | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Suspicious HTTP Evasion Found | 39004 | server-to-client | | low | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Suspicious HTTP Response Found | 39869 | server-to-client | | low | web-browsing | general-internet | internet-utility | browser-based | 80 | protocol-anomaly | Suspicious HTTP Response Found | 40400 | server-to-client | | low | shoutcast | media | audio-streaming | client-server | 80 | protocol-anomaly | Suspicious HTTP Response Found | 39860 | server-to-client |