<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Shaheen N Abdul Jabbar</title>
	<atom:link href="http://snajsoft.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://snajsoft.com</link>
	<description>Software Engineer &#62; Security Officer &#62; Security Architect</description>
	<lastBuildDate>Mon, 31 Oct 2011 09:00:30 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Comment on Face Recognition Systems For Facility Access by Haider</title>
		<link>http://snajsoft.com/2011/01/03/face-recognition-systems-for-facility-access/comment-page-1/#comment-53</link>
		<dc:creator>Haider</dc:creator>
		<pubDate>Mon, 31 Oct 2011 09:00:30 +0000</pubDate>
		<guid isPermaLink="false">http://snajsoft.com/?p=436#comment-53</guid>
		<description>Is the best</description>
		<content:encoded><![CDATA[<p>Is the best</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Happy Holidays and New Year!! by Al Cronin</title>
		<link>http://snajsoft.com/2010/12/24/happy-holidays-and-new-year-2011/comment-page-1/#comment-52</link>
		<dc:creator>Al Cronin</dc:creator>
		<pubDate>Fri, 21 Jan 2011 02:21:05 +0000</pubDate>
		<guid isPermaLink="false">http://snajsoft.com/?p=430#comment-52</guid>
		<description>Hi Shaheen - Great Website!!!
Happy New Year!!! &amp; best wishes to You and your family!!!</description>
		<content:encoded><![CDATA[<p>Hi Shaheen &#8211; Great Website!!!<br />
Happy New Year!!! &amp; best wishes to You and your family!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Prevent Reverse SSH by Derek Douville</title>
		<link>http://snajsoft.com/2009/02/12/prevent-reverse-ssh/comment-page-1/#comment-51</link>
		<dc:creator>Derek Douville</dc:creator>
		<pubDate>Fri, 07 Jan 2011 22:32:49 +0000</pubDate>
		<guid isPermaLink="false">http://snajsoft.com/?p=26#comment-51</guid>
		<description>Glenn, allowing an outbound SSH connection to be established (eg. allowing TCP  establishment out but not in as suggested above) doesn&#039;t prevent reverse tunnels, which allow the connection to be established to a remote host and subsequently allow traffic in either direction to flow unrestricted.  This is the essence of the problem. 

Since SSH can run on any port, you would have to block TCP connection establishment on all ports for outbound, but since services like FTP, HTTP and HTTPS are often required to remain exposed, SSH can be directed to use port 80 or 21 for its outbound connection.  This is why other respondents mention statefull inspection as a way of detection non-conforming traffic to what is expected on a given port (HTTPS or SSLv3 as Denes Magyar mentions).  SSH tunnels cannot be positively detected because they are encrypted -- the traffic could be anything at all.

I&#039;ve been thinking about how a proxy server could be used to lock it down.  Prevent SSH except to a white-list of hosts and trusted users and then allow other required, well-known services (http, https, ftp, smtp, dns, etc.) via stateful packet inspection.

...thing is, it&#039;s also possible to tunnel over DNS (google for &quot;tunneling over dns&quot;).  It seems he only guaranteed solution is to drop all outbound traffic.</description>
		<content:encoded><![CDATA[<p>Glenn, allowing an outbound SSH connection to be established (eg. allowing TCP  establishment out but not in as suggested above) doesn&#8217;t prevent reverse tunnels, which allow the connection to be established to a remote host and subsequently allow traffic in either direction to flow unrestricted.  This is the essence of the problem. </p>
<p>Since SSH can run on any port, you would have to block TCP connection establishment on all ports for outbound, but since services like FTP, HTTP and HTTPS are often required to remain exposed, SSH can be directed to use port 80 or 21 for its outbound connection.  This is why other respondents mention statefull inspection as a way of detection non-conforming traffic to what is expected on a given port (HTTPS or SSLv3 as Denes Magyar mentions).  SSH tunnels cannot be positively detected because they are encrypted &#8212; the traffic could be anything at all.</p>
<p>I&#8217;ve been thinking about how a proxy server could be used to lock it down.  Prevent SSH except to a white-list of hosts and trusted users and then allow other required, well-known services (http, https, ftp, smtp, dns, etc.) via stateful packet inspection.</p>
<p>&#8230;thing is, it&#8217;s also possible to tunnel over DNS (google for &#8220;tunneling over dns&#8221;).  It seems he only guaranteed solution is to drop all outbound traffic.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Happy Holidays and New Year!! by Heather hynes</title>
		<link>http://snajsoft.com/2010/12/24/happy-holidays-and-new-year-2011/comment-page-1/#comment-50</link>
		<dc:creator>Heather hynes</dc:creator>
		<pubDate>Tue, 04 Jan 2011 14:43:51 +0000</pubDate>
		<guid isPermaLink="false">http://snajsoft.com/?p=430#comment-50</guid>
		<description>Hi Shaheen,

Happy new year to you and your family! May 2011 be good to you all.

P.S. You have your own website? Cool. Looks great. cheers. HH</description>
		<content:encoded><![CDATA[<p>Hi Shaheen,</p>
<p>Happy new year to you and your family! May 2011 be good to you all.</p>
<p>P.S. You have your own website? Cool. Looks great. cheers. HH</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Happy Holidays and New Year!! by Peter Bennett</title>
		<link>http://snajsoft.com/2010/12/24/happy-holidays-and-new-year-2011/comment-page-1/#comment-49</link>
		<dc:creator>Peter Bennett</dc:creator>
		<pubDate>Fri, 31 Dec 2010 14:44:26 +0000</pubDate>
		<guid isPermaLink="false">http://snajsoft.com/?p=430#comment-49</guid>
		<description>Hi Shaheen
Thanks for the greetings. Happy holidays to you. I am doing well at Pegasystems in Cambridge. Have a happy and prosperous new year.
Regards
peter</description>
		<content:encoded><![CDATA[<p>Hi Shaheen<br />
Thanks for the greetings. Happy holidays to you. I am doing well at Pegasystems in Cambridge. Have a happy and prosperous new year.<br />
Regards<br />
peter</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Happy Holidays and New Year!! by Hugh Gerechter</title>
		<link>http://snajsoft.com/2010/12/24/happy-holidays-and-new-year-2011/comment-page-1/#comment-48</link>
		<dc:creator>Hugh Gerechter</dc:creator>
		<pubDate>Wed, 29 Dec 2010 17:49:49 +0000</pubDate>
		<guid isPermaLink="false">http://snajsoft.com/?p=430#comment-48</guid>
		<description>Shaheen and family -- best wishes for a happy and prosperous New Year</description>
		<content:encoded><![CDATA[<p>Shaheen and family &#8212; best wishes for a happy and prosperous New Year</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Happy Holidays and New Year!! by Anita Geerts</title>
		<link>http://snajsoft.com/2010/12/24/happy-holidays-and-new-year-2011/comment-page-1/#comment-47</link>
		<dc:creator>Anita Geerts</dc:creator>
		<pubDate>Mon, 27 Dec 2010 21:57:16 +0000</pubDate>
		<guid isPermaLink="false">http://snajsoft.com/?p=430#comment-47</guid>
		<description>Hi Shaheen,
I&#039;m lovin your website...so interesting.

Are you having a great holiday? I hope so. Have lots of fun, laughter and amazement this Christmas season.

Best wishes to you always,
Anita</description>
		<content:encoded><![CDATA[<p>Hi Shaheen,<br />
I&#8217;m lovin your website&#8230;so interesting.</p>
<p>Are you having a great holiday? I hope so. Have lots of fun, laughter and amazement this Christmas season.</p>
<p>Best wishes to you always,<br />
Anita</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Happy Holidays and New Year!! by Joseph</title>
		<link>http://snajsoft.com/2010/12/24/happy-holidays-and-new-year-2011/comment-page-1/#comment-44</link>
		<dc:creator>Joseph</dc:creator>
		<pubDate>Sat, 25 Dec 2010 09:45:57 +0000</pubDate>
		<guid isPermaLink="false">http://snajsoft.com/?p=430#comment-44</guid>
		<description>Thanks for your Greetings. Wishing you too a very Happy Christmas and Happy New Year.
Regards,
Joseph</description>
		<content:encoded><![CDATA[<p>Thanks for your Greetings. Wishing you too a very Happy Christmas and Happy New Year.<br />
Regards,<br />
Joseph</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Authentication &#8211; Level of Assurance by Tony Pham</title>
		<link>http://snajsoft.com/2010/06/07/authentication-level-of-assurance/comment-page-1/#comment-43</link>
		<dc:creator>Tony Pham</dc:creator>
		<pubDate>Mon, 16 Aug 2010 22:05:57 +0000</pubDate>
		<guid isPermaLink="false">http://snajsoft.com/2010/06/07/authentication-level-of-assurance/#comment-43</guid>
		<description>an emerging opportunity for those who is tracking this space.  There will be a market for Identity Assurance with organizations such as Kantara, Open Identity Exchange, and InCommon Federation which will utilize M-04-04 &amp; NIST SP 800-63 to establish a framework for auditing the Identity Providers.  Watch for this market &quot;Identity Assurance Assessor&quot; to establish next year.</description>
		<content:encoded><![CDATA[<p>an emerging opportunity for those who is tracking this space.  There will be a market for Identity Assurance with organizations such as Kantara, Open Identity Exchange, and InCommon Federation which will utilize M-04-04 &amp; NIST SP 800-63 to establish a framework for auditing the Identity Providers.  Watch for this market &#8220;Identity Assurance Assessor&#8221; to establish next year.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Authentication &#8211; Level of Assurance by Ramesh Nagappan</title>
		<link>http://snajsoft.com/2010/06/07/authentication-level-of-assurance/comment-page-1/#comment-38</link>
		<dc:creator>Ramesh Nagappan</dc:creator>
		<pubDate>Wed, 16 Jun 2010 16:02:20 +0000</pubDate>
		<guid isPermaLink="false">http://snajsoft.com/2010/06/07/authentication-level-of-assurance/#comment-38</guid>
		<description>Nice post, dude ! you may take a look at Kantara initiative - http://kantarainitiative.org/. They are trying to put all the old wine in a new bottle :-)

/R</description>
		<content:encoded><![CDATA[<p>Nice post, dude ! you may take a look at Kantara initiative &#8211; <a href="http://kantarainitiative.org/" rel="nofollow">http://kantarainitiative.org/</a>. They are trying to put all the old wine in a new bottle <img src='http://snajsoft.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>/R</p>
]]></content:encoded>
	</item>
</channel>
</rss>

