<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Roachys Weblog &#187; Security</title>
	<atom:link href="http://blog.roachy.net/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.roachy.net</link>
	<description>A digital notebook of technical experiences</description>
	<lastBuildDate>Wed, 02 Jun 2010 14:32:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.roachy.net' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/9f441d6d96c5ab0a3564bf350dd9249d?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>Roachys Weblog &#187; Security</title>
		<link>http://blog.roachy.net</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.roachy.net/osd.xml" title="Roachys Weblog" />
	<atom:link rel='hub' href='http://blog.roachy.net/?pushpress=hub'/>
		<item>
		<title>E-Darwin award winner?</title>
		<link>http://blog.roachy.net/2008/09/22/e-darwin-award-winner/</link>
		<comments>http://blog.roachy.net/2008/09/22/e-darwin-award-winner/#comments</comments>
		<pubDate>Mon, 22 Sep 2008 09:28:26 +0000</pubDate>
		<dc:creator>Paul Morgan-Roach</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Kernell]]></category>
		<category><![CDATA[Sarah Palin]]></category>

		<guid isPermaLink="false">http://technicalmumblings.wordpress.com/?p=95</guid>
		<description><![CDATA[To qualify for a Darwin Award, you need to do something achieving suicidal levels of stupidity, thus rendering an abrubt end to your gene pool&#8230;.. It would appear that David Kernell has just achieved that with his &#8220;hack&#8221; of Sarah Palin&#8217;s private Yahoo mail account. The following article is well worth a read, as it [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.roachy.net&amp;blog=2880390&amp;post=95&amp;subd=technicalmumblings&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>To qualify for a Darwin Award, you need to do something achieving suicidal levels of stupidity, thus rendering an abrubt end to your gene pool&#8230;..</p>
<p>It would appear that David Kernell has just achieved that with his &#8220;hack&#8221; of Sarah Palin&#8217;s private Yahoo mail account.</p>
<p>The following article is well worth a read, as it shows that when carrying out a stupid stunt, that level of stupidity is made infinitely less (or more) impressive by broadcasting your act of stupidity and creating a paper trail back to you leaving incriminating evidence of your stupid act&#8230;</p>
<p><a href="http://www.tgdaily.com/html_tmp/content-view-39405-108.html">http://www.tgdaily.com/html_tmp/content-view-39405-108.html</a></p>
<p>To throw into the mix the potential death of the career of said offenders <a href="http://www.legislature.state.tn.us/house/members/h93.htm">father</a> makes this possibly the <em>MOST </em>ridiculous act of self-sabotage I have heard of this year&#8230;</p>
<p><a href="http://blog.wired.com/27bstroke6/2008/09/fbi-raid-apartm.html">http://blog.wired.com/27bstroke6/2008/09/fbi-raid-apartm.html</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technicalmumblings.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technicalmumblings.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technicalmumblings.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technicalmumblings.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technicalmumblings.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technicalmumblings.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technicalmumblings.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technicalmumblings.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technicalmumblings.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technicalmumblings.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technicalmumblings.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technicalmumblings.wordpress.com/95/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technicalmumblings.wordpress.com/95/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technicalmumblings.wordpress.com/95/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.roachy.net&amp;blog=2880390&amp;post=95&amp;subd=technicalmumblings&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.roachy.net/2008/09/22/e-darwin-award-winner/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">roachy1979</media:title>
		</media:content>
	</item>
		<item>
		<title>Out of the frying pan&#8230;..</title>
		<link>http://blog.roachy.net/2008/09/11/out-of-the-frying-pan/</link>
		<comments>http://blog.roachy.net/2008/09/11/out-of-the-frying-pan/#comments</comments>
		<pubDate>Thu, 11 Sep 2008 08:18:02 +0000</pubDate>
		<dc:creator>Paul Morgan-Roach</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Debian]]></category>
		<category><![CDATA[fedora]]></category>

		<guid isPermaLink="false">http://technicalmumblings.wordpress.com/?p=93</guid>
		<description><![CDATA[Following my scathing comments about Ubuntu and the Debian OpenSSL flaw and my subsequent migration to Fedora&#8230;(http://technicalmumblings.wordpress.com/2008/05/23/goodbye-ubuntu/), I was a little concerned when I read the following: https://www.redhat.com/archives/fedora-announce-list/2008-August/msg00012.html This kind of begs the question, which is the lesser of the 2 evils here?  A security breach can occur on any platform and across many platforms&#8230;..mistakes [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.roachy.net&amp;blog=2880390&amp;post=93&amp;subd=technicalmumblings&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Following my scathing comments about Ubuntu and the Debian OpenSSL flaw and my subsequent migration to Fedora&#8230;(<a href="http://technicalmumblings.wordpress.com/2008/05/23/goodbye-ubuntu/">http://technicalmumblings.wordpress.com/2008/05/23/goodbye-ubuntu/</a>), I was a little concerned when I read the following:</p>
<p><a href="https://www.redhat.com/archives/fedora-announce-list/2008-August/msg00012.html">https://www.redhat.com/archives/fedora-announce-list/2008-August/msg00012.html</a></p>
<p>This kind of begs the question, which is the lesser of the 2 evils here?  A security breach can occur on any platform and across many platforms&#8230;..mistakes do happen.  The real trick is how these breaches and vulnerabilities are actually dealt with.  To Debian&#8217;s credit, it dealt with protecting the users as a first priority, whereas in this case Fedora/Red Hat&#8217;s first priority appears to have been covering it&#8217;s own arse, with the users put at risk being the second priority.  Maybe this is the difference between the 2 vendors outlook and corporate responsibilities&#8230;.</p>
<p>There&#8217;s an interesting discussion on Slashdot here:</p>
<p><a href="http://linux.slashdot.org/article.pl?sid=08/09/10/029231">http://linux.slashdot.org/article.pl?sid=08/09/10/029231</a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/technicalmumblings.wordpress.com/93/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/technicalmumblings.wordpress.com/93/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technicalmumblings.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technicalmumblings.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technicalmumblings.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technicalmumblings.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technicalmumblings.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technicalmumblings.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technicalmumblings.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technicalmumblings.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technicalmumblings.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technicalmumblings.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technicalmumblings.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technicalmumblings.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technicalmumblings.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technicalmumblings.wordpress.com/93/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.roachy.net&amp;blog=2880390&amp;post=93&amp;subd=technicalmumblings&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.roachy.net/2008/09/11/out-of-the-frying-pan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">roachy1979</media:title>
		</media:content>
	</item>
		<item>
		<title>Google vs. Cuil as a Password cracker</title>
		<link>http://blog.roachy.net/2008/07/31/google-vs-cuil-as-a-password-cracker/</link>
		<comments>http://blog.roachy.net/2008/07/31/google-vs-cuil-as-a-password-cracker/#comments</comments>
		<pubDate>Thu, 31 Jul 2008 14:54:23 +0000</pubDate>
		<dc:creator>Paul Morgan-Roach</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Cuil]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google vs. Cuil]]></category>
		<category><![CDATA[hash]]></category>
		<category><![CDATA[md5]]></category>

		<guid isPermaLink="false">http://technicalmumblings.wordpress.com/?p=73</guid>
		<description><![CDATA[Well, Google is effectively an amazingly powerful data gatherer and indexing tool &#8211; check out this article on how Google can be used to check for previously indexed MD5 hashes: http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/ I thought I&#8217;d put Cuil to the test, to see whether they can offer the same &#8220;service&#8221;&#8230;.given their bold claims about their number of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.roachy.net&amp;blog=2880390&amp;post=73&amp;subd=technicalmumblings&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Well, Google is effectively an amazingly powerful data gatherer and indexing tool &#8211; check out this article on how Google can be used to check for previously indexed MD5 hashes:</p>
<p><a href="http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/">http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/</a></p>
<p>I thought I&#8217;d put Cuil to the test, to see whether they can offer the same &#8220;service&#8221;&#8230;.given their bold claims about their number of indexed pages <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Step 1 &#8211; think of a password &#8211; for the sake of this test I&#8217;ll choose the weak password, gringo</p>
<p>Step 2 &#8211; hash the password (if you&#8217;re lazy, like me, this can be done <a href="http://utilitymill.com/utility/Goog_Your_Hash">here</a>)</p>
<p>Step 3 &#8211; <a href="http://www.google.com/search?q=eeda31dbc9833b93c4c592af68d7f8e6">Google it! </a></p>
<p>Step 4 &#8211; <a href="http://www.cuil.com/search?q=eeda31dbc9833b93c4c592af68d7f8e6">Cuil it!</a></p>
<div class="mceTemp">
<dl class="wp-caption alignnone">
<dt class="wp-caption-dt"><a href="http://technicalmumblings.files.wordpress.com/2008/07/screenshot-1.png"><img class="size-medium wp-image-75" src="http://technicalmumblings.files.wordpress.com/2008/07/screenshot-1.png?w=300&#038;h=129" alt="Cuils MD5 Search...." width="300" height="129" /></a></dt>
</dl>
</div>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/technicalmumblings.wordpress.com/73/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/technicalmumblings.wordpress.com/73/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technicalmumblings.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technicalmumblings.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technicalmumblings.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technicalmumblings.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technicalmumblings.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technicalmumblings.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technicalmumblings.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technicalmumblings.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technicalmumblings.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technicalmumblings.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technicalmumblings.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technicalmumblings.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technicalmumblings.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technicalmumblings.wordpress.com/73/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.roachy.net&amp;blog=2880390&amp;post=73&amp;subd=technicalmumblings&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.roachy.net/2008/07/31/google-vs-cuil-as-a-password-cracker/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">roachy1979</media:title>
		</media:content>

		<media:content url="http://technicalmumblings.files.wordpress.com/2008/07/screenshot-1.png?w=300" medium="image">
			<media:title type="html">Cuils MD5 Search....</media:title>
		</media:content>
	</item>
		<item>
		<title>First DNS Hijacks reported</title>
		<link>http://blog.roachy.net/2008/07/29/first-dns-hijacks-reported/</link>
		<comments>http://blog.roachy.net/2008/07/29/first-dns-hijacks-reported/#comments</comments>
		<pubDate>Tue, 29 Jul 2008 07:34:55 +0000</pubDate>
		<dc:creator>Paul Morgan-Roach</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[BIND]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[Kaminsky]]></category>
		<category><![CDATA[Patch]]></category>

		<guid isPermaLink="false">http://technicalmumblings.wordpress.com/?p=66</guid>
		<description><![CDATA[It looks like following Dan Kaminsky&#8217;s exploit being made public the first attacks have been reported on DNS servers: http://www.techcentral.ie/article.aspx?id=12375 I can&#8217;t believe that there are many people out there who haven&#8217;t yet patched their DNS servers&#8230;&#8230;but it&#8217;s worth checking on the Doxpara site (http://www.doxpara.com/) &#8230;that is, of course unless you&#8217;re DNS has been hijacked [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.roachy.net&amp;blog=2880390&amp;post=66&amp;subd=technicalmumblings&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>It looks like following Dan Kaminsky&#8217;s exploit being made public the first attacks have been reported on DNS servers:</p>
<p><a href="http://http://www.techcentral.ie/article.aspx?id=12375">http://www.techcentral.ie/article.aspx?id=12375</a></p>
<p>I can&#8217;t believe that there are many people out there who haven&#8217;t yet patched their DNS servers&#8230;&#8230;but it&#8217;s worth checking on the Doxpara site (<a href="http://www.doxpara.com/">http://www.doxpara.com/</a>)</p>
<p>&#8230;that is, of course unless you&#8217;re DNS has been hijacked and you are being sent to a spoofed doxpara site <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Still bad news for those running Mac DNS servers as Apple still haven&#8217;t released a patch, although apparently the Bind team have stated that the BSD version of the patch can be ported&#8230;.</p>
<p>Further info here:</p>
<p><a href="http://xforce.iss.net/xforce/xfdb/35575">http://xforce.iss.net/xforce/xfdb/35575</a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/technicalmumblings.wordpress.com/66/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/technicalmumblings.wordpress.com/66/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technicalmumblings.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technicalmumblings.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technicalmumblings.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technicalmumblings.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technicalmumblings.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technicalmumblings.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technicalmumblings.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technicalmumblings.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technicalmumblings.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technicalmumblings.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technicalmumblings.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technicalmumblings.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technicalmumblings.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technicalmumblings.wordpress.com/66/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.roachy.net&amp;blog=2880390&amp;post=66&amp;subd=technicalmumblings&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.roachy.net/2008/07/29/first-dns-hijacks-reported/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">roachy1979</media:title>
		</media:content>
	</item>
		<item>
		<title>Insecure email</title>
		<link>http://blog.roachy.net/2008/04/14/insecure-email/</link>
		<comments>http://blog.roachy.net/2008/04/14/insecure-email/#comments</comments>
		<pubDate>Mon, 14 Apr 2008 12:30:31 +0000</pubDate>
		<dc:creator>Paul Morgan-Roach</dc:creator>
				<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[gnupg]]></category>

		<guid isPermaLink="false">http://technicalmumblings.wordpress.com/?p=34</guid>
		<description><![CDATA[Working for a number of clients, it&#8217;s surprising how many people assume that an email sent is secure by default.  The number of people (including e-commerce providers) who feel comfortable sending (and requesting) credit card information via email is quite shocking&#8230; It&#8217;s worth clarifying that sending an email is the digital equivalent of sending a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.roachy.net&amp;blog=2880390&amp;post=34&amp;subd=technicalmumblings&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Working for a number of clients, it&#8217;s surprising how many people assume that an email sent is secure by default.  The number of people (including e-commerce providers) who feel comfortable sending (and requesting) credit card information via email is quite shocking&#8230;</p>
<p>It&#8217;s worth clarifying that sending an email is the digital equivalent of sending a postcard&#8230;.anyone, on any number of the hops between the sender and the recipient, could read the contents of that email with relative ease, in the same way that if you sent a postcard, anyone en route between the sender and the recipient who handles that card could read the contents.  Worse yet, there are methods of spoofing (pretending to be) the recipient mail server &#8211; causing all emails that are destined for the recipient to be captured then forwarded on without the recipient even knowing that this has happened&#8230;.</p>
<p>There are methods of securing email, however &#8211; one of these is worth noting as a free solution &#8211; GNUPG http://www.gnupg.org/ and it is worth considering if you need to send any information that you feel is sensitive.  GNUPG can be used for digital signing of emails (proving that the email is really from you) and also for the encryption of emails using a private key pair.</p>
<p>There are resources on the use of GNUPG on the site, and it can be used on a variety of platforms (Windows, Linux, Mac) etc.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/technicalmumblings.wordpress.com/34/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/technicalmumblings.wordpress.com/34/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technicalmumblings.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technicalmumblings.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technicalmumblings.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technicalmumblings.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technicalmumblings.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technicalmumblings.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technicalmumblings.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technicalmumblings.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technicalmumblings.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technicalmumblings.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technicalmumblings.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technicalmumblings.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technicalmumblings.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technicalmumblings.wordpress.com/34/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.roachy.net&amp;blog=2880390&amp;post=34&amp;subd=technicalmumblings&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.roachy.net/2008/04/14/insecure-email/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">roachy1979</media:title>
		</media:content>
	</item>
		<item>
		<title>SSH Port Forwarding again&#8230;.</title>
		<link>http://blog.roachy.net/2008/03/18/ssh-port-forwarding-again/</link>
		<comments>http://blog.roachy.net/2008/03/18/ssh-port-forwarding-again/#comments</comments>
		<pubDate>Tue, 18 Mar 2008 08:53:00 +0000</pubDate>
		<dc:creator>Paul Morgan-Roach</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[firewalls]]></category>
		<category><![CDATA[Port Forwarding]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SSH]]></category>
		<category><![CDATA[Wiindows]]></category>

		<guid isPermaLink="false">http://technicalmumblings.wordpress.com/?p=28</guid>
		<description><![CDATA[Another cool article on SSH port forwarding: http://www.cmready.com/polyoperable/?p=7 theres more info on using SSH to proxy outbound connections here: http://www.debuntu.org/2006/04/08/22-ssh-and-port-forwarding-or-how-to-get-through-a-firewall and on creating transparent socks proxys and reverse tunnels here: http://www.linuxlogin.com/linux/admin/sshtunnels.php<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.roachy.net&amp;blog=2880390&amp;post=28&amp;subd=technicalmumblings&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Another cool article on SSH port forwarding:</p>
<p><a title="http://www.cmready.com/polyoperable/?p=7" href="http://www.cmready.com/polyoperable/?p=7">http://www.cmready.com/polyoperable/?p=7</a></p>
<p>theres more info on using SSH to proxy outbound connections here:</p>
<p><a href="http://www.debuntu.org/2006/04/08/22-ssh-and-port-forwarding-or-how-to-get-through-a-firewall" target="_blank">http://www.debuntu.org/2006/04/08/22-ssh-and-port-forwarding-or-how-to-get-through-a-firewall</a></p>
<p>and on creating transparent socks proxys and reverse tunnels here:</p>
<p><a href="http://www.linuxlogin.com/linux/admin/sshtunnels.php" target="_blank">http://www.linuxlogin.com/linux/admin/sshtunnels.php</a></p>
<p> <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/technicalmumblings.wordpress.com/28/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/technicalmumblings.wordpress.com/28/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technicalmumblings.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technicalmumblings.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technicalmumblings.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technicalmumblings.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technicalmumblings.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technicalmumblings.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technicalmumblings.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technicalmumblings.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technicalmumblings.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technicalmumblings.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technicalmumblings.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technicalmumblings.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technicalmumblings.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technicalmumblings.wordpress.com/28/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.roachy.net&amp;blog=2880390&amp;post=28&amp;subd=technicalmumblings&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.roachy.net/2008/03/18/ssh-port-forwarding-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">roachy1979</media:title>
		</media:content>
	</item>
		<item>
		<title>Breaking Firewalls with OpenSSH and Putty</title>
		<link>http://blog.roachy.net/2008/03/06/breaking-firewalls-with-openssh-and-putty/</link>
		<comments>http://blog.roachy.net/2008/03/06/breaking-firewalls-with-openssh-and-putty/#comments</comments>
		<pubDate>Thu, 06 Mar 2008 14:36:13 +0000</pubDate>
		<dc:creator>Paul Morgan-Roach</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SSH]]></category>

		<guid isPermaLink="false">http://technicalmumblings.wordpress.com/?p=27</guid>
		<description><![CDATA[Just found this interesting article http://souptonuts.sourceforge.net/sshtips.htm<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.roachy.net&amp;blog=2880390&amp;post=27&amp;subd=technicalmumblings&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Just found this interesting article <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><a href="http://souptonuts.sourceforge.net/sshtips.htm" title="http://souptonuts.sourceforge.net/sshtips.htm">http://souptonuts.sourceforge.net/sshtips.htm</a></p>
<p> <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/technicalmumblings.wordpress.com/27/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/technicalmumblings.wordpress.com/27/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technicalmumblings.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technicalmumblings.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technicalmumblings.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technicalmumblings.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technicalmumblings.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technicalmumblings.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technicalmumblings.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technicalmumblings.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technicalmumblings.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technicalmumblings.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technicalmumblings.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technicalmumblings.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technicalmumblings.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technicalmumblings.wordpress.com/27/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.roachy.net&amp;blog=2880390&amp;post=27&amp;subd=technicalmumblings&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.roachy.net/2008/03/06/breaking-firewalls-with-openssh-and-putty/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">roachy1979</media:title>
		</media:content>
	</item>
		<item>
		<title>IPtables in Ubuntu Gutsy</title>
		<link>http://blog.roachy.net/2008/02/29/iptables-in-ubuntu-gutsy/</link>
		<comments>http://blog.roachy.net/2008/02/29/iptables-in-ubuntu-gutsy/#comments</comments>
		<pubDate>Fri, 29 Feb 2008 23:02:44 +0000</pubDate>
		<dc:creator>Paul Morgan-Roach</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[IPtables]]></category>

		<guid isPermaLink="false">http://technicalmumblings.wordpress.com/?p=23</guid>
		<description><![CDATA[Ok, well I&#8217;ve just had my first unpleasant surprise with Ubuntu Gutsy. Just checked my IPtables rules as i&#8217;m at home effectively outside my firewall just testing my security, and it seems that by default, the ruleset is set to allow all traffic&#8230;..I&#8217;m pretty shocked&#8230;.. when stacked side by side with Fedora, which i&#8217;ve been [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.roachy.net&amp;blog=2880390&amp;post=23&amp;subd=technicalmumblings&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Ok, well I&#8217;ve just had my first unpleasant surprise with Ubuntu Gutsy.  Just checked my IPtables rules as i&#8217;m at home effectively outside my firewall just testing my security, and it seems that by default, the ruleset is set to allow all traffic&#8230;..I&#8217;m pretty shocked&#8230;..  when stacked side by side with Fedora, which i&#8217;ve been using at work, which is downright agressive about security from the word go.  Ubuntu by it&#8217;s very nature is aimed at making Linux more accessible, and from reading the Ubuntu forums the majority of new users wouldn&#8217;t even consider checking&#8230;</p>
<p>I appreciate that most people seem to think that a firewall is unnecessary on a Linux box, as no daemons are running on a default install &#8211; but suppose (as I do) you then install an SSH server, and you want Windows machines on your network to access files&#8230;.and a plethora of other bits and pieces &#8211; eventually you end up with loads of holes.  I&#8217;d rather find out an application doesn&#8217;t work until I open corresponding ports than have data visible from the public internet&#8230;</p>
<p>My untouched IPtables config looked like this:</p>
<blockquote><p>roachy@roachy-laptop:~$ sudo iptables &#8211;list<br />
Chain INPUT (policy ACCEPT)<br />
target     prot opt source               destination</p>
<p>Chain FORWARD (policy ACCEPT)<br />
target     prot opt source               destination</p>
<p>Chain OUTPUT (policy ACCEPT)<br />
target     prot opt source               destination</p></blockquote>
<p>Then after modification (yes I cheated and used Firestarter!)</p>
<blockquote><p>roachy@roachy-laptop:~$ sudo iptables &#8211;list<br />
Chain INPUT (policy DROP)<br />
target     prot opt source               destination<br />
ACCEPT     tcp  &#8212;  192.168.2.1          anywhere            tcp flags:!FIN,SYN,RST,ACK/SYN<br />
ACCEPT     udp  &#8212;  192.168.2.1          anywhere<br />
ACCEPT     0    &#8212;  anywhere             anywhere<br />
ACCEPT     icmp &#8212;  anywhere             anywhere            limit: avg 10/sec burst 5<br />
DROP       0    &#8212;  anywhere             255.255.255.255<br />
DROP       0    &#8212;  anywhere             192.168.2.255<br />
DROP       0    &#8212;  BASE-ADDRESS.MCAST.NET/8  anywhere<br />
DROP       0    &#8212;  anywhere             224.0.0.0/8<br />
DROP       0    &#8212;  255.255.255.255      anywhere<br />
DROP       0    &#8212;  anywhere             0.0.0.0<br />
DROP       0    &#8212;  anywhere             anywhere            state INVALID<br />
LSI        0    -f  anywhere             anywhere            limit: avg 10/min burst 5<br />
INBOUND    0    &#8212;  anywhere             anywhere<br />
LOG_FILTER  0    &#8212;  anywhere             anywhere<br />
LOG        0    &#8212;  anywhere             anywhere            LOG level info prefix `Unknown Input&#8217;</p>
<p>Chain FORWARD (policy DROP)<br />
target     prot opt source               destination<br />
ACCEPT     icmp &#8212;  anywhere             anywhere            limit: avg 10/sec burst 5<br />
LOG_FILTER  0    &#8212;  anywhere             anywhere<br />
LOG        0    &#8212;  anywhere             anywhere            LOG level info prefix `Unknown Forward&#8217;</p>
<p>Chain OUTPUT (policy DROP)<br />
target     prot opt source               destination<br />
ACCEPT     tcp  &#8212;  192.168.2.11         192.168.2.1         tcp dpt:domain<br />
ACCEPT     udp  &#8212;  192.168.2.11         192.168.2.1         udp dpt:domain<br />
ACCEPT     0    &#8212;  anywhere             anywhere<br />
DROP       0    &#8212;  224.0.0.0/8          anywhere<br />
DROP       0    &#8212;  anywhere             BASE-ADDRESS.MCAST.NET/8<br />
DROP       0    &#8212;  255.255.255.255      anywhere<br />
DROP       0    &#8212;  anywhere             0.0.0.0<br />
DROP       0    &#8212;  anywhere             anywhere            state INVALID<br />
OUTBOUND   0    &#8212;  anywhere             anywhere<br />
LOG_FILTER  0    &#8212;  anywhere             anywhere<br />
LOG        0    &#8212;  anywhere             anywhere            LOG level info prefix `Unknown Output&#8217;</p>
<p>Chain INBOUND (1 references)<br />
target     prot opt source               destination<br />
ACCEPT     tcp  &#8212;  anywhere             anywhere            state RELATED,ESTABLISHED<br />
ACCEPT     udp  &#8212;  anywhere             anywhere            state RELATED,ESTABLISHED<br />
LSI        0    &#8212;  anywhere             anywhere</p>
<p>Chain LOG_FILTER (5 references)<br />
target     prot opt source               destination</p>
<p>Chain LSI (2 references)<br />
target     prot opt source               destination<br />
LOG_FILTER  0    &#8212;  anywhere             anywhere<br />
LOG        tcp  &#8212;  anywhere             anywhere            tcp flags:FIN,SYN,RST,ACK/SYN limit: avg 1/sec burst 5 LOG level info prefix `Inbound &#8216;<br />
DROP       tcp  &#8212;  anywhere             anywhere            tcp flags:FIN,SYN,RST,ACK/SYN<br />
LOG        tcp  &#8212;  anywhere             anywhere            tcp flags:FIN,SYN,RST,ACK/RST limit: avg 1/sec burst 5 LOG level info prefix `Inbound &#8216;<br />
DROP       tcp  &#8212;  anywhere             anywhere            tcp flags:FIN,SYN,RST,ACK/RST<br />
LOG        icmp &#8212;  anywhere             anywhere            icmp echo-request limit: avg 1/sec burst 5 LOG level info prefix `Inbound &#8216;<br />
DROP       icmp &#8212;  anywhere             anywhere            icmp echo-request<br />
LOG        0    &#8212;  anywhere             anywhere            limit: avg 5/sec burst 5 LOG level info prefix `Inbound &#8216;<br />
DROP       0    &#8212;  anywhere             anywhere</p>
<p>Chain LSO (1 references)<br />
target     prot opt source               destination<br />
LOG_FILTER  0    &#8212;  anywhere             anywhere<br />
LOG        0    &#8212;  anywhere             anywhere            limit: avg 5/sec burst 5 LOG level info prefix `Outbound &#8216;<br />
REJECT     0    &#8212;  anywhere             anywhere            reject-with icmp-port-unreachable</p>
<p>Chain OUTBOUND (1 references)<br />
target     prot opt source               destination<br />
ACCEPT     icmp &#8212;  anywhere             anywhere<br />
ACCEPT     tcp  &#8212;  anywhere             anywhere            state RELATED,ESTABLISHED<br />
ACCEPT     udp  &#8212;  anywhere             anywhere            state RELATED,ESTABLISHED<br />
ACCEPT     tcp  &#8212;  192.168.2.11         anywhere            tcp dpt:www<br />
ACCEPT     udp  &#8212;  192.168.2.11         anywhere            udp dpt:www<br />
ACCEPT     tcp  &#8212;  192.168.2.11         anywhere            tcp dpts:netbios-ns:netbios-ssn<br />
ACCEPT     udp  &#8212;  192.168.2.11         anywhere            udp dpts:netbios-ns:netbios-ssn<br />
ACCEPT     tcp  &#8212;  192.168.2.11         anywhere            tcp dpt:microsoft-ds<br />
ACCEPT     udp  &#8212;  192.168.2.11         anywhere            udp dpt:microsoft-ds<br />
ACCEPT     tcp  &#8212;  192.168.2.11         anywhere            tcp dpt:https<br />
ACCEPT     udp  &#8212;  192.168.2.11         anywhere            udp dpt:https<br />
LSO        0    &#8212;  anywhere             anywhere</p></blockquote>
<p>Quite  a significant difference&#8230;..</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/technicalmumblings.wordpress.com/23/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/technicalmumblings.wordpress.com/23/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technicalmumblings.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technicalmumblings.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technicalmumblings.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technicalmumblings.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technicalmumblings.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technicalmumblings.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technicalmumblings.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technicalmumblings.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technicalmumblings.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technicalmumblings.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technicalmumblings.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technicalmumblings.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technicalmumblings.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technicalmumblings.wordpress.com/23/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.roachy.net&amp;blog=2880390&amp;post=23&amp;subd=technicalmumblings&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.roachy.net/2008/02/29/iptables-in-ubuntu-gutsy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">roachy1979</media:title>
		</media:content>
	</item>
		<item>
		<title>How to test for Open Mail Relays</title>
		<link>http://blog.roachy.net/2008/02/18/how-to-test-for-open-mail-relays/</link>
		<comments>http://blog.roachy.net/2008/02/18/how-to-test-for-open-mail-relays/#comments</comments>
		<pubDate>Mon, 18 Feb 2008 16:41:33 +0000</pubDate>
		<dc:creator>Paul Morgan-Roach</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Mail relays]]></category>

		<guid isPermaLink="false">http://technicalmumblings.wordpress.com/?p=11</guid>
		<description><![CDATA[Previously I knew how to test for traditional Open Relays on mail servers &#8211; but was looking for some more extensive testing and stumbled across this site: http://www.dsbl.org/relay-methods Among the list is methods of testing against double bounce and webmail relaying&#8230;. In addition to this the base-64 encoding and decoding tool can be used to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.roachy.net&amp;blog=2880390&amp;post=11&amp;subd=technicalmumblings&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Previously I knew how to test for traditional Open Relays on mail servers &#8211; but was looking for some more extensive testing and stumbled across this site:</p>
<p><a title="http://www.dsbl.org/relay-methods" href="http://www.dsbl.org/relay-methods" target="_blank">http://www.dsbl.org/relay-methods</a></p>
<p>Among the list is methods of testing against double bounce and webmail relaying&#8230;.</p>
<p>In addition to this the base-64 encoding and decoding tool can be used to test SMTP Auth on servers:</p>
<p><a href="http://legacy.dillfrog.com/tools/base-64_encode/">http://legacy.dillfrog.com/tools/base-64_encode/</a></p>
<p>Very useful <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/technicalmumblings.wordpress.com/11/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/technicalmumblings.wordpress.com/11/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technicalmumblings.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technicalmumblings.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technicalmumblings.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technicalmumblings.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technicalmumblings.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technicalmumblings.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technicalmumblings.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technicalmumblings.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technicalmumblings.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technicalmumblings.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technicalmumblings.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technicalmumblings.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technicalmumblings.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technicalmumblings.wordpress.com/11/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.roachy.net&amp;blog=2880390&amp;post=11&amp;subd=technicalmumblings&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.roachy.net/2008/02/18/how-to-test-for-open-mail-relays/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">roachy1979</media:title>
		</media:content>
	</item>
	</channel>
</rss>