<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: TTL Caging: How to Fight Malware Using Reduced TTL Values</title>
	<atom:link href="http://danielmiessler.com/blog/ttl-caging-how-to-fight-malware-using-reduced-ttl-values/feed" rel="self" type="application/rss+xml" />
	<link>http://danielmiessler.com/blog/ttl-caging-how-to-fight-malware-using-reduced-ttl-values</link>
	<description>grep understanding</description>
	<lastBuildDate>Fri, 25 May 2012 02:15:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Daniel Miessler</title>
		<link>http://danielmiessler.com/blog/ttl-caging-how-to-fight-malware-using-reduced-ttl-values/comment-page-1#comment-145389</link>
		<dc:creator>Daniel Miessler</dc:creator>
		<pubDate>Sun, 18 May 2008 19:59:22 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/blog/ttl-caging-how-to-fight-malware-using-reduced-ttl-values#comment-145389</guid>
		<description>&lt;p&gt;Guys,&lt;/p&gt;

&lt;p&gt;I agree that this would just be another layer if one was already doing the blocking at the firewall. That&#039;s a valid point. I just think it&#039;s an interesting and elegant way of approaching the problem.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Guys,</p>

<p>I agree that this would just be another layer if one was already doing the blocking at the firewall. That&#8217;s a valid point. I just think it&#8217;s an interesting and elegant way of approaching the problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Miessler</title>
		<link>http://danielmiessler.com/blog/ttl-caging-how-to-fight-malware-using-reduced-ttl-values/comment-page-1#comment-251665</link>
		<dc:creator>Daniel Miessler</dc:creator>
		<pubDate>Sun, 18 May 2008 19:59:00 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/blog/ttl-caging-how-to-fight-malware-using-reduced-ttl-values#comment-251665</guid>
		<description>&lt;p&gt;Guys,&lt;/p&gt;

&lt;p&gt;I agree that this would just be another layer if one was already doing the blocking at the firewall. That&#039;s a valid point. I just think it&#039;s an interesting and elegant way of approaching the problem.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Guys,</p>

<p>I agree that this would just be another layer if one was already doing the blocking at the firewall. That&#8217;s a valid point. I just think it&#8217;s an interesting and elegant way of approaching the problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kenneth R Swain II</title>
		<link>http://danielmiessler.com/blog/ttl-caging-how-to-fight-malware-using-reduced-ttl-values/comment-page-1#comment-145185</link>
		<dc:creator>Kenneth R Swain II</dc:creator>
		<pubDate>Sun, 18 May 2008 03:43:05 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/blog/ttl-caging-how-to-fight-malware-using-reduced-ttl-values#comment-145185</guid>
		<description>&lt;p&gt;Would not a good egress rule be far more beneficial? I love the way he was thinking, but this would be very hard to maintain. Plus I do not even believe possible in environments that include WAN links such as MPLS or others. One argument that you could use would be that your work place will not let you use good egress rules. If that is they case it seems far fetched that they would let you do this as it would make trouble shooting more difficult.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Would not a good egress rule be far more beneficial? I love the way he was thinking, but this would be very hard to maintain. Plus I do not even believe possible in environments that include WAN links such as MPLS or others. One argument that you could use would be that your work place will not let you use good egress rules. If that is they case it seems far fetched that they would let you do this as it would make trouble shooting more difficult.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kenneth R Swain II</title>
		<link>http://danielmiessler.com/blog/ttl-caging-how-to-fight-malware-using-reduced-ttl-values/comment-page-1#comment-251664</link>
		<dc:creator>Kenneth R Swain II</dc:creator>
		<pubDate>Sun, 18 May 2008 03:43:00 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/blog/ttl-caging-how-to-fight-malware-using-reduced-ttl-values#comment-251664</guid>
		<description>&lt;p&gt;Would not a good egress rule be far more beneficial? I love the way he was thinking, but this would be very hard to maintain. Plus I do not even believe possible in environments that include WAN links such as MPLS or others. One argument that you could use would be that your work place will not let you use good egress rules. If that is they case it seems far fetched that they would let you do this as it would make trouble shooting more difficult.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Would not a good egress rule be far more beneficial? I love the way he was thinking, but this would be very hard to maintain. Plus I do not even believe possible in environments that include WAN links such as MPLS or others. One argument that you could use would be that your work place will not let you use good egress rules. If that is they case it seems far fetched that they would let you do this as it would make trouble shooting more difficult.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kuza55</title>
		<link>http://danielmiessler.com/blog/ttl-caging-how-to-fight-malware-using-reduced-ttl-values/comment-page-1#comment-145167</link>
		<dc:creator>kuza55</dc:creator>
		<pubDate>Sun, 18 May 2008 01:25:58 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/blog/ttl-caging-how-to-fight-malware-using-reduced-ttl-values#comment-145167</guid>
		<description>&lt;p&gt;And the benefit of using this instead of a firewall is what? That anyone who wants to &lt;em&gt;can&lt;/em&gt; circumvent it? That doesn&#039;t seem like a very useful idea to me...Especially since you&#039;re still relying on being able to identify bad traffic going through the proxy.&lt;/p&gt;

&lt;p&gt;P.S. IDS&#039; suck.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>And the benefit of using this instead of a firewall is what? That anyone who wants to <em>can</em> circumvent it? That doesn&#8217;t seem like a very useful idea to me&#8230;Especially since you&#8217;re still relying on being able to identify bad traffic going through the proxy.</p>

<p>P.S. IDS&#8217; suck.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kuza55</title>
		<link>http://danielmiessler.com/blog/ttl-caging-how-to-fight-malware-using-reduced-ttl-values/comment-page-1#comment-251663</link>
		<dc:creator>kuza55</dc:creator>
		<pubDate>Sun, 18 May 2008 01:25:00 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/blog/ttl-caging-how-to-fight-malware-using-reduced-ttl-values#comment-251663</guid>
		<description>&lt;p&gt;And the benefit of using this instead of a firewall is what? That anyone who wants to &lt;em&gt;can&lt;/em&gt; circumvent it? That doesn&#039;t seem like a very useful idea to me...Especially since you&#039;re still relying on being able to identify bad traffic going through the proxy.&lt;/p&gt;

&lt;p&gt;P.S. IDS&#039; suck.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>And the benefit of using this instead of a firewall is what? That anyone who wants to <em>can</em> circumvent it? That doesn&#8217;t seem like a very useful idea to me&#8230;Especially since you&#8217;re still relying on being able to identify bad traffic going through the proxy.</p>

<p>P.S. IDS&#8217; suck.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

