<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Insinuator</title>
	<atom:link href="http://www.insinuator.net/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.insinuator.net</link>
	<description>Some outright rants from a bunch of infosec practitioners.</description>
	<lastBuildDate>Fri, 23 Dec 2011 16:58:58 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Comment on Liferay Portlet Shell by Nicob</title>
		<link>http://www.insinuator.net/2011/12/liferay-portlet-shell/comment-page-1/#comment-762</link>
		<dc:creator>Nicob</dc:creator>
		<pubDate>Fri, 23 Dec 2011 16:58:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.insinuator.net/?p=811#comment-762</guid>
		<description>I&#039;ll demo my own Liferay Java Shell next week at BerlinSides. It doesn&#039;t need an additional portlet, &quot;XSLT Content&quot; is enough ...</description>
		<content:encoded><![CDATA[<p>I&#8217;ll demo my own Liferay Java Shell next week at BerlinSides. It doesn&#8217;t need an additional portlet, &#8220;XSLT Content&#8221; is enough &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on (Auditing) Remote Access Security in 2011 by erey</title>
		<link>http://www.insinuator.net/2011/08/auditing-remote-access-security-in-2011/comment-page-1/#comment-681</link>
		<dc:creator>erey</dc:creator>
		<pubDate>Tue, 20 Sep 2011 19:41:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.insinuator.net/?p=564#comment-681</guid>
		<description>David,

thanks for the comment. Point is, you usually can&#039;t (establish the endpoint&#039;s trustworthy state) in an operationally feasible way, due to a number of reasons (heterogeneity of endpoints, speed and sprawl of their deployment, technical hurdles etc.). That&#039;s why good governance incl. reasonable AUPs (ideally with some element of liability in those) is so important. or just not allowing any local data processing on endpoints.
That said, in general we like the certificate approach (being quite aware of the operational side of it), and we&#039;ll publish an ERNW newsletter on &quot;Certificate based authentication with iPads&quot; within the next two weeks.

Have a good one &amp; thanks again for the comment, Enno</description>
		<content:encoded><![CDATA[<p>David,</p>
<p>thanks for the comment. Point is, you usually can&#8217;t (establish the endpoint&#8217;s trustworthy state) in an operationally feasible way, due to a number of reasons (heterogeneity of endpoints, speed and sprawl of their deployment, technical hurdles etc.). That&#8217;s why good governance incl. reasonable AUPs (ideally with some element of liability in those) is so important. or just not allowing any local data processing on endpoints.<br />
That said, in general we like the certificate approach (being quite aware of the operational side of it), and we&#8217;ll publish an ERNW newsletter on &#8220;Certificate based authentication with iPads&#8221; within the next two weeks.</p>
<p>Have a good one &amp; thanks again for the comment, Enno</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on (Auditing) Remote Access Security in 2011 by David</title>
		<link>http://www.insinuator.net/2011/08/auditing-remote-access-security-in-2011/comment-page-1/#comment-639</link>
		<dc:creator>David</dc:creator>
		<pubDate>Tue, 16 Aug 2011 09:25:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.insinuator.net/?p=564#comment-639</guid>
		<description>That Matrix is really interesting, it&#039;s very good to have such a reference when dealing with mobile device management and remote access. However, it raises one question in my mind : during a connection, how do you establish that the endpoint is company-managed or trustworthy ?

I have some ideas about this (certificate, serial numbers, application installed on the endpoint, mac address), but have you benchmarked some of those, or others ?</description>
		<content:encoded><![CDATA[<p>That Matrix is really interesting, it&#8217;s very good to have such a reference when dealing with mobile device management and remote access. However, it raises one question in my mind : during a connection, how do you establish that the endpoint is company-managed or trustworthy ?</p>
<p>I have some ideas about this (certificate, serial numbers, application installed on the endpoint, mac address), but have you benchmarked some of those, or others ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Week of releases &#8211; gtp_scan-0.7 by al</title>
		<link>http://www.insinuator.net/2011/07/week-of-releases-gtp_scan-0-7/comment-page-1/#comment-634</link>
		<dc:creator>al</dc:creator>
		<pubDate>Tue, 02 Aug 2011 06:17:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.insinuator.net/?p=513#comment-634</guid>
		<description>Does this have documentation for proper on how to use?</description>
		<content:encoded><![CDATA[<p>Does this have documentation for proper on how to use?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Week of releases &#8211; gtp_scan-0.7 by dmende</title>
		<link>http://www.insinuator.net/2011/07/week-of-releases-gtp_scan-0-7/comment-page-1/#comment-619</link>
		<dc:creator>dmende</dc:creator>
		<pubDate>Wed, 13 Jul 2011 15:37:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.insinuator.net/?p=513#comment-619</guid>
		<description>Hi, Im not sure what you mean. Can you please elaborate? thanks</description>
		<content:encoded><![CDATA[<p>Hi, Im not sure what you mean. Can you please elaborate? thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Week of releases &#8211; gtp_scan-0.7 by joinbaijun</title>
		<link>http://www.insinuator.net/2011/07/week-of-releases-gtp_scan-0-7/comment-page-1/#comment-618</link>
		<dc:creator>joinbaijun</dc:creator>
		<pubDate>Wed, 13 Jul 2011 15:09:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.insinuator.net/?p=513#comment-618</guid>
		<description>i guess you know vul on GGSN during attachment too，do you？</description>
		<content:encoded><![CDATA[<p>i guess you know vul on GGSN during attachment too，do you？</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on IPv6 Security Part 2, RA Guard – Let&#8217;s get practical by erey</title>
		<link>http://www.insinuator.net/2011/03/ipv6-security-part-2-ra-guard-%e2%80%93-lets-get-practical/comment-page-1/#comment-587</link>
		<dc:creator>erey</dc:creator>
		<pubDate>Mon, 13 Jun 2011 18:35:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.insinuator.net/?p=325#comment-587</guid>
		<description>Bruno,

thanks for your mail. Unfortunately the RA guard feature (even though described in the - &quot;informational&quot; - RFC 6105) is currently only available on very few platforms. As for Cisco devices the configuration can be found in our presentation from the IPv6 Kongress. We have not yet extensively researched other vendors. What kind of hardware (vendor/model[s]) are you actually willing to configure RA guard on?
Feel free to contact us directly (erey@ernw.de, cwerny@ernw.de) to discuss this further/in more detail.

all the best for your research project, thanks

Enno</description>
		<content:encoded><![CDATA[<p>Bruno,</p>
<p>thanks for your mail. Unfortunately the RA guard feature (even though described in the &#8211; &#8220;informational&#8221; &#8211; RFC 6105) is currently only available on very few platforms. As for Cisco devices the configuration can be found in our presentation from the IPv6 Kongress. We have not yet extensively researched other vendors. What kind of hardware (vendor/model[s]) are you actually willing to configure RA guard on?<br />
Feel free to contact us directly (erey@ernw.de, <a href="mailto:cwerny@ernw.de">cwerny@ernw.de</a>) to discuss this further/in more detail.</p>
<p>all the best for your research project, thanks</p>
<p>Enno</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Yet another update on IPv6 security &#8211; Some notes from the IPv6-Kongress in Frankfurt by erey</title>
		<link>http://www.insinuator.net/2011/05/yet-another-update-on-ipv6-security-some-notes-from-the-ipv6-kongress-in-frankfurt/comment-page-1/#comment-586</link>
		<dc:creator>erey</dc:creator>
		<pubDate>Mon, 13 Jun 2011 18:25:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.insinuator.net/?p=402#comment-586</guid>
		<description>Hi,

sorry for the late reply, life kept me (too) busy. As for your questions:

a) I think Wireshark complains as it does not expect to see an IPv6 packet without an actual upper layer payload. As, obviously, the RA guard implementation on the Cisco device in question (a 4948-E) doesn&#039;t either (expect this). Still the packets are not malformed, it&#039;s just Wireshark not fully understanding them.
b) the screenshots are from a litte session in the break right before Marc&#039;s talk. We (he &amp; us) gathered and did some testing with his tool and our device. Did he give a live demo of this one? I&#039;d expect this not to have happened (lacking a RA guard capable device) but I changed rooms at noon to follow Eric&#039;s talk so couldn&#039;t see Marc&#039;s talk in full.

Feel free to contact us directly (erey@ernw.de, cwerny@ernw.de) to discuss this further.

thanks

Enno</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>sorry for the late reply, life kept me (too) busy. As for your questions:</p>
<p>a) I think Wireshark complains as it does not expect to see an IPv6 packet without an actual upper layer payload. As, obviously, the RA guard implementation on the Cisco device in question (a 4948-E) doesn&#8217;t either (expect this). Still the packets are not malformed, it&#8217;s just Wireshark not fully understanding them.<br />
b) the screenshots are from a litte session in the break right before Marc&#8217;s talk. We (he &amp; us) gathered and did some testing with his tool and our device. Did he give a live demo of this one? I&#8217;d expect this not to have happened (lacking a RA guard capable device) but I changed rooms at noon to follow Eric&#8217;s talk so couldn&#8217;t see Marc&#8217;s talk in full.</p>
<p>Feel free to contact us directly (erey@ernw.de, <a href="mailto:cwerny@ernw.de">cwerny@ernw.de</a>) to discuss this further.</p>
<p>thanks</p>
<p>Enno</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on HITB Aftermath by erey</title>
		<link>http://www.insinuator.net/2011/05/hitb-aftermath/comment-page-1/#comment-585</link>
		<dc:creator>erey</dc:creator>
		<pubDate>Mon, 13 Jun 2011 18:16:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.insinuator.net/?p=454#comment-585</guid>
		<description>thanks man! ;-)</description>
		<content:encoded><![CDATA[<p>thanks man! <img src='http://www.insinuator.net/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on IPv6 Security Part 2, RA Guard – Let&#8217;s get practical by Bruno</title>
		<link>http://www.insinuator.net/2011/03/ipv6-security-part-2-ra-guard-%e2%80%93-lets-get-practical/comment-page-1/#comment-517</link>
		<dc:creator>Bruno</dc:creator>
		<pubDate>Thu, 09 Jun 2011 21:11:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.insinuator.net/?p=325#comment-517</guid>
		<description>Dear Enno,
I found your articles very interesting regarding IPv6 security.

I am currently developping an IPv6 project study for University purposes in order to deploy a secure Wireless IPv6 Network.

After reading the RFC-6105 (IPv6 Router Advertisement Guard), it seems being possible to configure Stateles Router Guard.

I would like to know how to configure Stateless Router Guard in order to examines incoming RAs and decides whether to forward or block them based solely on information found in the message or in the L2-device configuration ??
Which commands shoud we use in the L2 device ?

Sincerely thanks in advance,
Bruno</description>
		<content:encoded><![CDATA[<p>Dear Enno,<br />
I found your articles very interesting regarding IPv6 security.</p>
<p>I am currently developping an IPv6 project study for University purposes in order to deploy a secure Wireless IPv6 Network.</p>
<p>After reading the RFC-6105 (IPv6 Router Advertisement Guard), it seems being possible to configure Stateles Router Guard.</p>
<p>I would like to know how to configure Stateless Router Guard in order to examines incoming RAs and decides whether to forward or block them based solely on information found in the message or in the L2-device configuration ??<br />
Which commands shoud we use in the L2 device ?</p>
<p>Sincerely thanks in advance,<br />
Bruno</p>
]]></content:encoded>
	</item>
</channel>
</rss>

