<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: tunneling through hotspot firewall</title>
	<atom:link href="http://sechero.com/tunneling-through-hotspot-firewall/feed/" rel="self" type="application/rss+xml" />
	<link>http://sechero.com/tunneling-through-hotspot-firewall/</link>
	<description>If it's about security, you heard it here first</description>
	<lastBuildDate>Sat, 30 May 2009 10:40:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: "Penetration Testing (pen-test) Mailing List" </title>
		<link>http://sechero.com/tunneling-through-hotspot-firewall/comment-page-1/#comment-251</link>
		<dc:creator>"Penetration Testing (pen-test) Mailing List" </dc:creator>
		<pubDate>Sun, 26 Apr 2009 22:16:53 +0000</pubDate>
		<guid isPermaLink="false">http://sechero.com/tunneling-through-hotspot-firewall/#comment-251</guid>
		<description>&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;h1&gt;&lt;a href=&quot;http://seclists.org/pen-test/2009/Apr/0165.html&quot;&gt;Re: tunneling through hotspot firewall&lt;/a&gt;&lt;/h1&gt;&lt;/p&gt;
&lt;p&gt;Posted by Paul Melson on Apr 26&lt;p&gt;&lt;/p&gt;
&lt;p&gt; &lt;p&gt; On Fri, Apr 24, 2009 at 3:01 PM, Daniel Gultsch &lt;daniel_at_gultsch&#046;de&gt; wrote: &lt;br /&gt; &gt; I read a paper that the sequence numbers could be checked but usually &lt;br /&gt; &gt; aren&#039;t. I could google it again but it was something with &quot;mac spoofing &lt;br /&gt; &gt; detection sequence numbers&quot; &lt;br /&gt; &lt;p&gt;I&#039;ve read...&lt;p&gt;URL: &lt;a href=&quot;http://seclists.org/pen-test/2009/Apr/0165.html&quot;&gt;http://seclists.org/pen-test/2009/Apr/0165.html&lt;/a&gt;&lt;/p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;

</description>
		<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://seclists.org/pen-test/2009/Apr/0165.html">Re: tunneling through hotspot firewall</a></h1>
</p>
<p>Posted by Paul Melson on Apr 26</p>
</p>
<p> On Fri, Apr 24, 2009 at 3:01 PM, Daniel Gultsch &lt;daniel_at_gultsch&#46;de&gt; wrote: <br /> &gt; I read a paper that the sequence numbers could be checked but usually <br /> &gt; aren&#8217;t. I could google it again but it was something with &quot;mac spoofing <br /> &gt; detection sequence numbers&quot;  </p>
<p>I&#8217;ve read&#8230;</p>
<p>URL: <a href="http://seclists.org/pen-test/2009/Apr/0165.html">http://seclists.org/pen-test/2009/Apr/0165.html</a></p></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: "Penetration Testing (pen-test) Mailing List" </title>
		<link>http://sechero.com/tunneling-through-hotspot-firewall/comment-page-1/#comment-244</link>
		<dc:creator>"Penetration Testing (pen-test) Mailing List" </dc:creator>
		<pubDate>Fri, 24 Apr 2009 19:01:39 +0000</pubDate>
		<guid isPermaLink="false">http://sechero.com/tunneling-through-hotspot-firewall/#comment-244</guid>
		<description>&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;h1&gt;&lt;a href=&quot;http://seclists.org/pen-test/2009/Apr/0159.html&quot;&gt;Re: tunneling through hotspot firewall&lt;/a&gt;&lt;/h1&gt;&lt;/p&gt;
&lt;p&gt;Posted by Daniel Gultsch on Apr 24&lt;p&gt;&lt;/p&gt;
&lt;p&gt; &lt;p&gt; On Fri, 24 Apr 2009 00:17:13 -0400 &lt;br /&gt; Paul Melson &lt;pmelson_at_gmail&#046;com&gt; wrote: &lt;br /&gt; &gt; You will run into issues with sequence numbers in the 802.11 frames. &lt;br /&gt; &lt;p&gt;I read a paper that the sequence numbers could be checked but usually &lt;br /&gt; aren&#039;t. I could google it again but it was something with...&lt;p&gt;URL: &lt;a href=&quot;http://seclists.org/pen-test/2009/Apr/0159.html&quot;&gt;http://seclists.org/pen-test/2009/Apr/0159.html&lt;/a&gt;&lt;/p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;

</description>
		<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://seclists.org/pen-test/2009/Apr/0159.html">Re: tunneling through hotspot firewall</a></h1>
</p>
<p>Posted by Daniel Gultsch on Apr 24</p>
</p>
<p> On Fri, 24 Apr 2009 00:17:13 -0400 <br /> Paul Melson &lt;pmelson_at_gmail&#46;com&gt; wrote: <br /> &gt; You will run into issues with sequence numbers in the 802.11 frames.  </p>
<p>I read a paper that the sequence numbers could be checked but usually <br /> aren&#8217;t. I could google it again but it was something with&#8230;</p>
<p>URL: <a href="http://seclists.org/pen-test/2009/Apr/0159.html">http://seclists.org/pen-test/2009/Apr/0159.html</a></p></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: "Penetration Testing (pen-test) Mailing List" </title>
		<link>http://sechero.com/tunneling-through-hotspot-firewall/comment-page-1/#comment-243</link>
		<dc:creator>"Penetration Testing (pen-test) Mailing List" </dc:creator>
		<pubDate>Fri, 24 Apr 2009 18:49:18 +0000</pubDate>
		<guid isPermaLink="false">http://sechero.com/tunneling-through-hotspot-firewall/#comment-243</guid>
		<description>&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;h1&gt;&lt;a href=&quot;http://seclists.org/pen-test/2009/Apr/0158.html&quot;&gt;Re: tunneling through hotspot firewall&lt;/a&gt;&lt;/h1&gt;&lt;/p&gt;
&lt;p&gt;Posted by Daniel Gultsch on Apr 24&lt;p&gt;&lt;/p&gt;
&lt;p&gt; &lt;p&gt; On Fri, 24 Apr 2009 11:41:30 -0430 &lt;br /&gt; Aarón Mizrachi &lt;unmanarc_at_gmail&#046;com&gt; wrote:  &lt;br /&gt; &gt; It could work... but, some wireless hotspot blocks UDP traffic and &lt;br /&gt; &gt; only allow 80 and 443 TCP... With TCP, the clone computer will emit &lt;br /&gt; &gt; an ICMP or RST closing your connection. &lt;br /&gt; &lt;p&gt;well yeah....&lt;p&gt;URL: &lt;a href=&quot;http://seclists.org/pen-test/2009/Apr/0158.html&quot;&gt;http://seclists.org/pen-test/2009/Apr/0158.html&lt;/a&gt;&lt;/p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;

</description>
		<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://seclists.org/pen-test/2009/Apr/0158.html">Re: tunneling through hotspot firewall</a></h1>
</p>
<p>Posted by Daniel Gultsch on Apr 24</p>
</p>
<p> On Fri, 24 Apr 2009 11:41:30 -0430 <br /> Aarón Mizrachi &lt;unmanarc_at_gmail&#46;com&gt; wrote:  <br /> &gt; It could work&#8230; but, some wireless hotspot blocks UDP traffic and <br /> &gt; only allow 80 and 443 TCP&#8230; With TCP, the clone computer will emit <br /> &gt; an ICMP or RST closing your connection.  </p>
<p>well yeah&#8230;.</p>
<p>URL: <a href="http://seclists.org/pen-test/2009/Apr/0158.html">http://seclists.org/pen-test/2009/Apr/0158.html</a></p></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: "Penetration Testing (pen-test) Mailing List" </title>
		<link>http://sechero.com/tunneling-through-hotspot-firewall/comment-page-1/#comment-242</link>
		<dc:creator>"Penetration Testing (pen-test) Mailing List" </dc:creator>
		<pubDate>Fri, 24 Apr 2009 16:11:30 +0000</pubDate>
		<guid isPermaLink="false">http://sechero.com/tunneling-through-hotspot-firewall/#comment-242</guid>
		<description>&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;h1&gt;&lt;a href=&quot;http://seclists.org/pen-test/2009/Apr/0157.html&quot;&gt;Re: tunneling through hotspot firewall&lt;/a&gt;&lt;/h1&gt;&lt;/p&gt;
&lt;p&gt;Posted by Aarón Mizrachi on Apr 24&lt;p&gt;&lt;/p&gt;
&lt;p&gt; &lt;p&gt; On Miércoles 22 Abril 2009 07:05:51 Daniel Gultsch escribió: &lt;br /&gt; &gt; Hey guys, &lt;br /&gt; &gt; &lt;br /&gt; &gt; this is my first posting on this mailling list. I kinda hope this is &lt;br /&gt; &gt; the right place. However lets get to the point. &lt;br /&gt; &gt; &lt;br /&gt; &gt; Suppose I&#039;d have an unencrypted  wireless lan with an dhcp server and a &lt;br /&gt; ...&lt;p&gt;URL: &lt;a href=&quot;http://seclists.org/pen-test/2009/Apr/0157.html&quot;&gt;http://seclists.org/pen-test/2009/Apr/0157.html&lt;/a&gt;&lt;/p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;

</description>
		<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://seclists.org/pen-test/2009/Apr/0157.html">Re: tunneling through hotspot firewall</a></h1>
</p>
<p>Posted by Aarón Mizrachi on Apr 24</p>
</p>
<p> On Miércoles 22 Abril 2009 07:05:51 Daniel Gultsch escribió: <br /> &gt; Hey guys, <br /> &gt; <br /> &gt; this is my first posting on this mailling list. I kinda hope this is <br /> &gt; the right place. However lets get to the point. <br /> &gt; <br /> &gt; Suppose I&#8217;d have an unencrypted  wireless lan with an dhcp server and a <br /> &#8230;</p>
<p>URL: <a href="http://seclists.org/pen-test/2009/Apr/0157.html">http://seclists.org/pen-test/2009/Apr/0157.html</a></p></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: "Penetration Testing (pen-test) Mailing List" </title>
		<link>http://sechero.com/tunneling-through-hotspot-firewall/comment-page-1/#comment-232</link>
		<dc:creator>"Penetration Testing (pen-test) Mailing List" </dc:creator>
		<pubDate>Fri, 24 Apr 2009 04:17:13 +0000</pubDate>
		<guid isPermaLink="false">http://sechero.com/tunneling-through-hotspot-firewall/#comment-232</guid>
		<description>&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;h1&gt;&lt;a href=&quot;http://seclists.org/pen-test/2009/Apr/0145.html&quot;&gt;Re: tunneling through hotspot firewall&lt;/a&gt;&lt;/h1&gt;&lt;/p&gt;
&lt;p&gt;Posted by Paul Melson on Apr 24&lt;p&gt;&lt;/p&gt;
&lt;p&gt; &lt;p&gt; On Wed, Apr 22, 2009 at 7:35 AM, Daniel Gultsch &lt;daniel_at_gultsch&#046;de&gt; wrote: &lt;br /&gt; &gt; Ok, lets further suppose I&#039;d have on succesfully logged in (and &lt;br /&gt; &gt; whitelisted) client). An evil attackers joins the notework as well - &lt;br /&gt; &gt; not beeing able to connect to the outside world (because...&lt;p&gt;URL: &lt;a href=&quot;http://seclists.org/pen-test/2009/Apr/0145.html&quot;&gt;http://seclists.org/pen-test/2009/Apr/0145.html&lt;/a&gt;&lt;/p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;

</description>
		<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://seclists.org/pen-test/2009/Apr/0145.html">Re: tunneling through hotspot firewall</a></h1>
</p>
<p>Posted by Paul Melson on Apr 24</p>
</p>
<p> On Wed, Apr 22, 2009 at 7:35 AM, Daniel Gultsch &lt;daniel_at_gultsch&#46;de&gt; wrote: <br /> &gt; Ok, lets further suppose I&#8217;d have on succesfully logged in (and <br /> &gt; whitelisted) client). An evil attackers joins the notework as well &#8211; <br /> &gt; not beeing able to connect to the outside world (because&#8230;</p>
<p>URL: <a href="http://seclists.org/pen-test/2009/Apr/0145.html">http://seclists.org/pen-test/2009/Apr/0145.html</a></p></p>
]]></content:encoded>
	</item>
</channel>
</rss>

