<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: FWAuto v1.1 &#8211; Firewall Auditing &amp; Ruleset Analyzer Tool</title>
	<atom:link href="http://www.darknet.org.uk/2008/07/fwauto-v11-firewall-auditing-ruleset-analyzer-tool/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2008/07/fwauto-v11-firewall-auditing-ruleset-analyzer-tool/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Sun, 08 Nov 2009 07:15:43 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: zupakomputer</title>
		<link>http://www.darknet.org.uk/2008/07/fwauto-v11-firewall-auditing-ruleset-analyzer-tool/#comment-124079</link>
		<dc:creator>zupakomputer</dc:creator>
		<pubDate>Tue, 22 Jul 2008 11:08:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=889#comment-124079</guid>
		<description>Look who popped up during a scan of the aforementioned B block - and they &#039;just happen&#039; to have exactly the same services running on the same ports,

http://centralops.net/co/DomainDossier.aspx?addr=218.10.111.106&amp;dom_dns=true&amp;dom_whois=true&amp;net_whois=true&amp;go=Submit</description>
		<content:encoded><![CDATA[<p>Look who popped up during a scan of the aforementioned B block &#8211; and they &#8216;just happen&#8217; to have exactly the same services running on the same ports,</p>
<p><a href="http://centralops.net/co/DomainDossier.aspx?addr=218.10.111.106&amp;dom_dns=true&amp;dom_whois=true&amp;net_whois=true&amp;go=Submit" rel="nofollow">http://centralops.net/co/DomainDossier.aspx?addr=218.10.111.106&amp;dom_dns=true&amp;dom_whois=true&amp;net_whois=true&amp;go=Submit</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zupakomputer</title>
		<link>http://www.darknet.org.uk/2008/07/fwauto-v11-firewall-auditing-ruleset-analyzer-tool/#comment-124073</link>
		<dc:creator>zupakomputer</dc:creator>
		<pubDate>Mon, 21 Jul 2008 16:03:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=889#comment-124073</guid>
		<description>Regarding firewalls - found two unrelated websites become unloadable when running a Firestarter config. Other sites were fine. But the interesting part being - the same IP B block showed up as loading alongside the various traffic on those two websites when the firewall was turned off. And it only shows up the first time you try to connect - cache emptying is needed (if the browser saves the pages)to get it to show up again....which made me think &#039;DNS then&#039; - but, why only on pages that can&#039;t get by the firewall?

So of course I had to see who that was, and the router trace won&#039;t go past 15 hops which just gets you the info you had already, that it belongs to a big B block of IPs (24.64.*.*) and only some vague ARIN info on the owner details of that and a bunch of other IP blocks.

What does this smell like - both sites could certainly be having their visitors monitored given what kind of sites they were (hacking, and ecology / green), but it definitely sounds dodgy to me - the same unexact-traceable IP block shows up in both, and both can&#039;t get past a standard firewall config - somones thar is doing some probing and they don&#039;t want to be probed back themselves. I think that calls for some How Not To Be Seen treatment going their way.

Two e-mail providers don&#039;t get past the firewall either, which in some ways sounds ok because you&#039;re logging in - but it&#039;s the login screens that get blocked. And guess what IP block shows up on one of them.

&amp; it just showed up again right before my connection dialed off. Always different host numbers each time it shows up.

And also since I began writing this - the firewall is now blocking all webpages, on the same setting that was fine for them before (see above) - and that IP block 24.64.*.* is showing up again.

What does a high-speed Canadian internet company have to do with my firewall settings? It connects directly to my ISP with ICMP and UDP traffic.</description>
		<content:encoded><![CDATA[<p>Regarding firewalls &#8211; found two unrelated websites become unloadable when running a Firestarter config. Other sites were fine. But the interesting part being &#8211; the same IP B block showed up as loading alongside the various traffic on those two websites when the firewall was turned off. And it only shows up the first time you try to connect &#8211; cache emptying is needed (if the browser saves the pages)to get it to show up again&#8230;.which made me think &#8216;DNS then&#8217; &#8211; but, why only on pages that can&#8217;t get by the firewall?</p>
<p>So of course I had to see who that was, and the router trace won&#8217;t go past 15 hops which just gets you the info you had already, that it belongs to a big B block of IPs (24.64.*.*) and only some vague ARIN info on the owner details of that and a bunch of other IP blocks.</p>
<p>What does this smell like &#8211; both sites could certainly be having their visitors monitored given what kind of sites they were (hacking, and ecology / green), but it definitely sounds dodgy to me &#8211; the same unexact-traceable IP block shows up in both, and both can&#8217;t get past a standard firewall config &#8211; somones thar is doing some probing and they don&#8217;t want to be probed back themselves. I think that calls for some How Not To Be Seen treatment going their way.</p>
<p>Two e-mail providers don&#8217;t get past the firewall either, which in some ways sounds ok because you&#8217;re logging in &#8211; but it&#8217;s the login screens that get blocked. And guess what IP block shows up on one of them.</p>
<p>&amp; it just showed up again right before my connection dialed off. Always different host numbers each time it shows up.</p>
<p>And also since I began writing this &#8211; the firewall is now blocking all webpages, on the same setting that was fine for them before (see above) &#8211; and that IP block 24.64.*.* is showing up again.</p>
<p>What does a high-speed Canadian internet company have to do with my firewall settings? It connects directly to my ISP with ICMP and UDP traffic.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Changlinn</title>
		<link>http://www.darknet.org.uk/2008/07/fwauto-v11-firewall-auditing-ruleset-analyzer-tool/#comment-124064</link>
		<dc:creator>Changlinn</dc:creator>
		<pubDate>Sun, 20 Jul 2008 23:03:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=889#comment-124064</guid>
		<description>Now if only they could do checkpoint too, it is supposedly the most common firewall in enterprise.</description>
		<content:encoded><![CDATA[<p>Now if only they could do checkpoint too, it is supposedly the most common firewall in enterprise.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
