<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The Old Dog and his Old Tricks (Part I)</title>
	<atom:link href="http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/feed/" rel="self" type="application/rss+xml" />
	<link>http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/</link>
	<description>Thoughts on Security in an Uncivilized World…</description>
	<lastBuildDate>Wed, 08 Sep 2010 02:39:08 -0700</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: sjovan</title>
		<link>http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/comment-page-1/#comment-165</link>
		<dc:creator>sjovan</dc:creator>
		<pubDate>Tue, 25 Sep 2007 23:14:12 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/#comment-165</guid>
		<description>wow.. and that&#039;s how i got that funky mail from @google.com about my banking was insecure and i had to click a realy strange link and stuff.

no, i didn&#039;t bother clicking the link.

realy good articel and you did make a lot of good points :)</description>
		<content:encoded><![CDATA[<p>wow.. and that&#8217;s how i got that funky mail from @google.com about my banking was insecure and i had to click a realy strange link and stuff.</p>
<p>no, i didn&#8217;t bother clicking the link.</p>
<p>realy good articel and you did make a lot of good points <img src='http://xs-sniper.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Awesome AnDrEw</title>
		<link>http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/comment-page-1/#comment-153</link>
		<dc:creator>Awesome AnDrEw</dc:creator>
		<pubDate>Thu, 20 Sep 2007 18:38:56 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/#comment-153</guid>
		<description>EXPN, VRFY, and RCPT TO (as well as the other commands) are classic examples of &quot;questionable&quot; features that exist within the Simple Mail Transfer Protocol. I agree that it&#039;s insecure by design, but it is one of those cases where it&#039;s both a feature and a bug. 99% of the servers I&#039;ve tested for relays have them disabled anyway.</description>
		<content:encoded><![CDATA[<p>EXPN, VRFY, and RCPT TO (as well as the other commands) are classic examples of &#8220;questionable&#8221; features that exist within the Simple Mail Transfer Protocol. I agree that it&#8217;s insecure by design, but it is one of those cases where it&#8217;s both a feature and a bug. 99% of the servers I&#8217;ve tested for relays have them disabled anyway.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nathan McFeters</title>
		<link>http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/comment-page-1/#comment-152</link>
		<dc:creator>Nathan McFeters</dc:creator>
		<pubDate>Thu, 20 Sep 2007 16:57:30 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/#comment-152</guid>
		<description>It&#039;s funny... we&#039;ve gotten so into spam filters and layer 7 firewalls and blah blah, blah blah, blah blah that we&#039;ve forgotten some of these crazy week protocols.</description>
		<content:encoded><![CDATA[<p>It&#8217;s funny&#8230; we&#8217;ve gotten so into spam filters and layer 7 firewalls and blah blah, blah blah, blah blah that we&#8217;ve forgotten some of these crazy week protocols.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: xssniper</title>
		<link>http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/comment-page-1/#comment-151</link>
		<dc:creator>xssniper</dc:creator>
		<pubDate>Thu, 20 Sep 2007 01:35:13 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/#comment-151</guid>
		<description>@ /trash

I couldn&#039;t agree with you more!  This isn&#039;t relay or a vulnerability with Googles SMTP servers, it&#039;s simply the way SMTP was DESIGNED to work.  The whole point of the post was to talk about how SMTP and other protocols are inherently insecure by design... 

BK</description>
		<content:encoded><![CDATA[<p>@ /trash</p>
<p>I couldn&#8217;t agree with you more!  This isn&#8217;t relay or a vulnerability with Googles SMTP servers, it&#8217;s simply the way SMTP was DESIGNED to work.  The whole point of the post was to talk about how SMTP and other protocols are inherently insecure by design&#8230; </p>
<p>BK</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: /trash</title>
		<link>http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/comment-page-1/#comment-150</link>
		<dc:creator>/trash</dc:creator>
		<pubDate>Wed, 19 Sep 2007 19:53:30 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/#comment-150</guid>
		<description>Some Google system with MTA is configured to believe form source address. In fact, they don&#039;t care if the sender address comes from the sender domain. This is not a relaying. This situation is acceptable by new RFCs about SMTP. SMTP protocol MUST be &quot;reviewed&quot; but that is another problem.</description>
		<content:encoded><![CDATA[<p>Some Google system with MTA is configured to believe form source address. In fact, they don&#8217;t care if the sender address comes from the sender domain. This is not a relaying. This situation is acceptable by new RFCs about SMTP. SMTP protocol MUST be &#8220;reviewed&#8221; but that is another problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: /nul</title>
		<link>http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/comment-page-1/#comment-149</link>
		<dc:creator>/nul</dc:creator>
		<pubDate>Tue, 18 Sep 2007 19:42:47 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/#comment-149</guid>
		<description>Billy, I&#039;m *not* begging for the SMTP address at all. It&#039;s just that I thought Google already disabled relaying (since it got public) and then just to make clear not all Google SMTP servers are affected. On a side note: it&#039;s always nice to watch &quot;old school&quot; stuff rising again :)</description>
		<content:encoded><![CDATA[<p>Billy, I&#8217;m *not* begging for the SMTP address at all. It&#8217;s just that I thought Google already disabled relaying (since it got public) and then just to make clear not all Google SMTP servers are affected. On a side note: it&#8217;s always nice to watch &#8220;old school&#8221; stuff rising again <img src='http://xs-sniper.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: xssniper</title>
		<link>http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/comment-page-1/#comment-148</link>
		<dc:creator>xssniper</dc:creator>
		<pubDate>Tue, 18 Sep 2007 19:16:46 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/#comment-148</guid>
		<description>@ /nul - I&#039;m not going to give you the address of the SMTP server I used... but smtp.google.com is NOT it.....</description>
		<content:encoded><![CDATA[<p>@ /nul &#8211; I&#8217;m not going to give you the address of the SMTP server I used&#8230; but smtp.google.com is NOT it&#8230;..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rcarter</title>
		<link>http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/comment-page-1/#comment-147</link>
		<dc:creator>rcarter</dc:creator>
		<pubDate>Tue, 18 Sep 2007 18:27:51 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/#comment-147</guid>
		<description>I guess we always need to keep in mind how protocols work and the &quot;features&quot; they have. Nice find.</description>
		<content:encoded><![CDATA[<p>I guess we always need to keep in mind how protocols work and the &#8220;features&#8221; they have. Nice find.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: /nul</title>
		<link>http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/comment-page-1/#comment-146</link>
		<dc:creator>/nul</dc:creator>
		<pubDate>Tue, 18 Sep 2007 18:09:54 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/#comment-146</guid>
		<description>I&#039;ve tried smtp.google.com. Relaying disabled:

http://shrani.si/f/2T/o2/RggjRFa/smtp.png</description>
		<content:encoded><![CDATA[<p>I&#8217;ve tried smtp.google.com. Relaying disabled:</p>
<p><a href="http://shrani.si/f/2T/o2/RggjRFa/smtp.png" rel="nofollow">http://shrani.si/f/2T/o2/RggjRFa/smtp.png</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: xssniper</title>
		<link>http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/comment-page-1/#comment-145</link>
		<dc:creator>xssniper</dc:creator>
		<pubDate>Tue, 18 Sep 2007 17:49:49 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/18/the-old-dog-and-his-old-tricks-part-i/#comment-145</guid>
		<description>Actually... the SMTP server I used in the example still works....</description>
		<content:encoded><![CDATA[<p>Actually&#8230; the SMTP server I used in the example still works&#8230;.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.875 seconds -->
