<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for exploring software and hardware security</title>
	<atom:link href="http://securityblog.astida.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://securityblog.astida.com</link>
	<description>articles about secure systems, secure protocols, tamperproofing, obfuscation, authentication, attack vectors...</description>
	<lastBuildDate>Thu, 12 Nov 2009 16:07:15 -0600</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on How the crackers crack code? by Spyware Blockers</title>
		<link>http://securityblog.astida.com/2009/10/11/how-the-crackers-crack-code/#comment-27</link>
		<dc:creator>Spyware Blockers</dc:creator>
		<pubDate>Thu, 12 Nov 2009 16:07:15 +0000</pubDate>
		<guid isPermaLink="false">http://securityblog.astida.com/?p=119#comment-27</guid>
		<description>I have been reading your posts lately, just want to say thanks for all informative stuff i have found here, helped me learn alot lately.

Much Regards, Mark</description>
		<content:encoded><![CDATA[<p>I have been reading your posts lately, just want to say thanks for all informative stuff i have found here, helped me learn alot lately.</p>
<p>Much Regards, Mark</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to design secure systems? Key Concepts in Information Security by Amaris</title>
		<link>http://securityblog.astida.com/2009/10/28/key-concepts-in-information-security/#comment-24</link>
		<dc:creator>Amaris</dc:creator>
		<pubDate>Mon, 09 Nov 2009 18:52:07 +0000</pubDate>
		<guid isPermaLink="false">http://securityblog.astida.com/?p=258#comment-24</guid>
		<description>Great blog. Can&#039;t wait to start my own blog.</description>
		<content:encoded><![CDATA[<p>Great blog. Can&#8217;t wait to start my own blog.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to design secure systems? Security Analysis by business security systems</title>
		<link>http://securityblog.astida.com/2009/10/19/how-to-design-security-systems-security-analysis/#comment-14</link>
		<dc:creator>business security systems</dc:creator>
		<pubDate>Wed, 04 Nov 2009 08:22:25 +0000</pubDate>
		<guid isPermaLink="false">http://securityblog.astida.com/?p=152#comment-14</guid>
		<description>&lt;strong&gt;business security systems...&lt;/strong&gt;

I like this!...</description>
		<content:encoded><![CDATA[<p><strong>business security systems&#8230;</strong></p>
<p>I like this!&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Conventional website authentication model, its weaknesses and alternatives by davitb</title>
		<link>http://securityblog.astida.com/2009/09/27/conventional-website-authentication-model-and-its-weaknesses/#comment-12</link>
		<dc:creator>davitb</dc:creator>
		<pubDate>Mon, 02 Nov 2009 19:29:28 +0000</pubDate>
		<guid isPermaLink="false">http://securebox.wordpress.com/?p=77#comment-12</guid>
		<description>Lemnainomek, what you mean by saying other variant?</description>
		<content:encoded><![CDATA[<p>Lemnainomek, what you mean by saying other variant?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Conventional website authentication model, its weaknesses and alternatives by Lemnainomek</title>
		<link>http://securityblog.astida.com/2009/09/27/conventional-website-authentication-model-and-its-weaknesses/#comment-11</link>
		<dc:creator>Lemnainomek</dc:creator>
		<pubDate>Mon, 02 Nov 2009 00:51:55 +0000</pubDate>
		<guid isPermaLink="false">http://securebox.wordpress.com/?p=77#comment-11</guid>
		<description>Other variant is possible also</description>
		<content:encoded><![CDATA[<p>Other variant is possible also</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Conventional website authentication model, its weaknesses and alternatives by JimmyBean</title>
		<link>http://securityblog.astida.com/2009/09/27/conventional-website-authentication-model-and-its-weaknesses/#comment-5</link>
		<dc:creator>JimmyBean</dc:creator>
		<pubDate>Thu, 01 Oct 2009 12:44:28 +0000</pubDate>
		<guid isPermaLink="false">http://securebox.wordpress.com/?p=77#comment-5</guid>
		<description>I don&#039;t know If I said it already but ...Hey good stuff...keep up the good work! :) I read a lot of blogs on a daily basis and for the most part, people lack substance but, I just wanted to make a quick comment to say I&#039;m glad I found your blog.  Thanks,)

A definite great read..Jim Bean</description>
		<content:encoded><![CDATA[<p>I don&#8217;t know If I said it already but &#8230;Hey good stuff&#8230;keep up the good work! :) I read a lot of blogs on a daily basis and for the most part, people lack substance but, I just wanted to make a quick comment to say I&#8217;m glad I found your blog.  Thanks,)</p>
<p>A definite great read..Jim Bean</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About by Narek</title>
		<link>http://securityblog.astida.com/about/#comment-2</link>
		<dc:creator>Narek</dc:creator>
		<pubDate>Mon, 28 Sep 2009 14:08:57 +0000</pubDate>
		<guid isPermaLink="false">http://securebox.wordpress.com/about/#comment-2</guid>
		<description>Bonne continuation !</description>
		<content:encoded><![CDATA[<p>Bonne continuation !</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Conventional website authentication model, its weaknesses and alternatives by davitb</title>
		<link>http://securityblog.astida.com/2009/09/27/conventional-website-authentication-model-and-its-weaknesses/#comment-4</link>
		<dc:creator>davitb</dc:creator>
		<pubDate>Sun, 27 Sep 2009 20:16:48 +0000</pubDate>
		<guid isPermaLink="false">http://securebox.wordpress.com/?p=77#comment-4</guid>
		<description>Hi Ruben, good question.
Actually the attack vector you described has a similar concept as phishing but falls into another category - called pharming.
You can find lot of interesting information about pharming and anti-pharming in the following resources:
&lt;a href=&quot;http://en.wikipedia.org/wiki/Pharming&quot; title=&quot;&quot; rel=&quot;nofollow&quot;&gt;Wikipedia: Pharming
&lt;a href=&quot;http://en.wikipedia.org/wiki/Anti-pharming&quot; title=&quot;&quot; rel=&quot;nofollow&quot;&gt;Wikipedia: Anti-Pharming</description>
		<content:encoded><![CDATA[<p>Hi Ruben, good question.<br />
Actually the attack vector you described has a similar concept as phishing but falls into another category &#8211; called pharming.<br />
You can find lot of interesting information about pharming and anti-pharming in the following resources:<br />
<a href="http://en.wikipedia.org/wiki/Pharming" title="" rel="nofollow">Wikipedia: Pharming<br />
</a><a href="http://en.wikipedia.org/wiki/Anti-pharming" title="" rel="nofollow">Wikipedia: Anti-Pharming</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Conventional website authentication model, its weaknesses and alternatives by Ruben</title>
		<link>http://securityblog.astida.com/2009/09/27/conventional-website-authentication-model-and-its-weaknesses/#comment-3</link>
		<dc:creator>Ruben</dc:creator>
		<pubDate>Sun, 27 Sep 2009 18:34:24 +0000</pubDate>
		<guid isPermaLink="false">http://securebox.wordpress.com/?p=77#comment-3</guid>
		<description>Hi, I was interested in phishing. Can it be the case that somebody in your stays in your private network and tweaks the local gateway/dns server so when you browser requests to open the http://www.paypal.com instead of navigating to the real ip of paypal service it navigates to some phony IP, which has a web site with very similar interface as the real one(just like in your example).
Do you know any ways to identify such kid of attacks?</description>
		<content:encoded><![CDATA[<p>Hi, I was interested in phishing. Can it be the case that somebody in your stays in your private network and tweaks the local gateway/dns server so when you browser requests to open the <a href="http://www.paypal.com" rel="nofollow">http://www.paypal.com</a> instead of navigating to the real ip of paypal service it navigates to some phony IP, which has a web site with very similar interface as the real one(just like in your example).<br />
Do you know any ways to identify such kid of attacks?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
