Author Archive

Wireshark Plugin for Mariposa Botnet Command and Control

October 27th, 2009

As a follow up to last week’s post regarding Mariposa infection research, Yamata Li of the Palo Alto Networks Threat Research Team has developed a Wireshark plugin that will allow you to view obfuscated pcaps of traffic from a Mariposa infected client and actually decrypt them within Wireshark. The software is available to all as [...]

Control Applications, Control Threats.

October 22nd, 2009

Over the past month, we’ve been pulled in by customers to analyze various “weird” behavior on the network. One of these instances happened a few weeks ago. A large Fortune 200 customer was reviewing application usage on the network using the Palo Alto Networks devices and discovered that there were a few devices in globally [...]

Who’s the best illusionist?

October 16th, 2009

When asked who’s the best illusionist of all time, you’ll likely hear anything from Harry Houdini to David Copperfield to David Blane, but they don’t have anything on your IPS vendor.
I often hear the question, how big or how good is Palo Alto Networks’ vulnerability research team? If you look at the website or collateral [...]