<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for IT Igloo</title>
	<atom:link href="http://itigloo.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://itigloo.com</link>
	<description>Linux for everyone</description>
	<lastBuildDate>Sat, 10 Dec 2011 15:02:41 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>Comment on UK LoCo Christmas Dinner @ Dans Le Noir by Bruno</title>
		<link>http://itigloo.com/2011/12/10/uk-loco-christmas-dinner-dans-le-noir/#comment-371</link>
		<dc:creator><![CDATA[Bruno]]></dc:creator>
		<pubDate>Sat, 10 Dec 2011 15:02:41 +0000</pubDate>
		<guid isPermaLink="false">http://itigloo.com/?p=370#comment-371</guid>
		<description><![CDATA[Indeed, great evening! And glow in the dark scallops too!]]></description>
		<content:encoded><![CDATA[<p>Indeed, great evening! And glow in the dark scallops too!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The Register Hacked (DNS Hijacked) by Expodomain.com &#187; DNS hack attack mutilates multiple Web sites</title>
		<link>http://itigloo.com/2011/09/04/the-register-hacked/#comment-278</link>
		<dc:creator><![CDATA[Expodomain.com &#187; DNS hack attack mutilates multiple Web sites]]></dc:creator>
		<pubDate>Mon, 05 Sep 2011 17:20:42 +0000</pubDate>
		<guid isPermaLink="false">http://itigloo.com/?p=330#comment-278</guid>
		<description><![CDATA[[...] I was doubtful that the site itself had actually been cracked. The first headline I saw read, The Register Hacked. That isn’t what I saw. To me, it looked like a typical Domain Name System (DNS) hijack attack. I [...]]]></description>
		<content:encoded><![CDATA[<p>[...] I was doubtful that the site itself had actually been cracked. The first headline I saw read, The Register Hacked. That isn’t what I saw. To me, it looked like a typical Domain Name System (DNS) hijack attack. I [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The Register Hacked (DNS Hijacked) by anonymous</title>
		<link>http://itigloo.com/2011/09/04/the-register-hacked/#comment-277</link>
		<dc:creator><![CDATA[anonymous]]></dc:creator>
		<pubDate>Mon, 05 Sep 2011 16:49:45 +0000</pubDate>
		<guid isPermaLink="false">http://itigloo.com/?p=330#comment-277</guid>
		<description><![CDATA[http://www.theregister.co.uk/2011/09/05/dns_hijack_service_updated/

So this was real, and as others have said, it was a compromise at the registrar, not at The Register. The probable reason why I did not see it: the co.uk parent domain changes had been reversed before I checked.

This incident is a good example of why I recommend NOT using one&#039;s ISP nameservers. The benefit of cache hits being slightly faster is offset by the TTL being, on average, half of what you would get by doing your own recursion to the authoritative NS. And then you get to share in the cache poisoning with all the other users.

Yes, my recursive resolver could get a poisoned cache as well, but the window of opportunity for mischief is much smaller. And I can flush the cache if I suspect something is amiss.]]></description>
		<content:encoded><![CDATA[<p><a href="http://www.theregister.co.uk/2011/09/05/dns_hijack_service_updated/" rel="nofollow">http://www.theregister.co.uk/2011/09/05/dns_hijack_service_updated/</a></p>
<p>So this was real, and as others have said, it was a compromise at the registrar, not at The Register. The probable reason why I did not see it: the co.uk parent domain changes had been reversed before I checked.</p>
<p>This incident is a good example of why I recommend NOT using one&#8217;s ISP nameservers. The benefit of cache hits being slightly faster is offset by the TTL being, on average, half of what you would get by doing your own recursion to the authoritative NS. And then you get to share in the cache poisoning with all the other users.</p>
<p>Yes, my recursive resolver could get a poisoned cache as well, but the window of opportunity for mischief is much smaller. And I can flush the cache if I suspect something is amiss.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The Register Hacked (DNS Hijacked) by nmcgregor</title>
		<link>http://itigloo.com/2011/09/04/the-register-hacked/#comment-276</link>
		<dc:creator><![CDATA[nmcgregor]]></dc:creator>
		<pubDate>Mon, 05 Sep 2011 13:51:38 +0000</pubDate>
		<guid isPermaLink="false">http://itigloo.com/?p=330#comment-276</guid>
		<description><![CDATA[DNS poses the biggest security risk to any organization]]></description>
		<content:encoded><![CDATA[<p>DNS poses the biggest security risk to any organization</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The perfect job&#8230; Where are you? by Simona</title>
		<link>http://itigloo.com/2011/01/13/the-perfect-job-where-are-you/#comment-273</link>
		<dc:creator><![CDATA[Simona]]></dc:creator>
		<pubDate>Mon, 05 Sep 2011 07:53:01 +0000</pubDate>
		<guid isPermaLink="false">http://itigloo.com/?p=262#comment-273</guid>
		<description><![CDATA[I would really push for it. I would go there arrange a meeting with someone. Make a friend in that company. Send them the CV and a letter to get their attention. I am sure it will work out well for you!]]></description>
		<content:encoded><![CDATA[<p>I would really push for it. I would go there arrange a meeting with someone. Make a friend in that company. Send them the CV and a letter to get their attention. I am sure it will work out well for you!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The Register Hacked (DNS Hijacked) by Chris Woollard</title>
		<link>http://itigloo.com/2011/09/04/the-register-hacked/#comment-272</link>
		<dc:creator><![CDATA[Chris Woollard]]></dc:creator>
		<pubDate>Mon, 05 Sep 2011 07:34:36 +0000</pubDate>
		<guid isPermaLink="false">http://itigloo.com/?p=330#comment-272</guid>
		<description><![CDATA[Thanks. I have now fixed that.]]></description>
		<content:encoded><![CDATA[<p>Thanks. I have now fixed that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The Register Hacked (DNS Hijacked) by bob</title>
		<link>http://itigloo.com/2011/09/04/the-register-hacked/#comment-271</link>
		<dc:creator><![CDATA[bob]]></dc:creator>
		<pubDate>Mon, 05 Sep 2011 07:32:18 +0000</pubDate>
		<guid isPermaLink="false">http://itigloo.com/?p=330#comment-271</guid>
		<description><![CDATA[Guardian link is broken - you&#039;ve got too many mentions of http at the start of the url.]]></description>
		<content:encoded><![CDATA[<p>Guardian link is broken &#8211; you&#8217;ve got too many mentions of http at the start of the url.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The Register Hacked (DNS Hijacked) by Quad</title>
		<link>http://itigloo.com/2011/09/04/the-register-hacked/#comment-270</link>
		<dc:creator><![CDATA[Quad]]></dc:creator>
		<pubDate>Mon, 05 Sep 2011 07:12:34 +0000</pubDate>
		<guid isPermaLink="false">http://itigloo.com/?p=330#comment-270</guid>
		<description><![CDATA[&quot;Gel Babana&quot; translates to &quot;Come to your daddy&quot;]]></description>
		<content:encoded><![CDATA[<p>&#8220;Gel Babana&#8221; translates to &#8220;Come to your daddy&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The Register Hacked (DNS Hijacked) by africasiaeuro</title>
		<link>http://itigloo.com/2011/09/04/the-register-hacked/#comment-269</link>
		<dc:creator><![CDATA[africasiaeuro]]></dc:creator>
		<pubDate>Mon, 05 Sep 2011 06:32:08 +0000</pubDate>
		<guid isPermaLink="false">http://itigloo.com/?p=330#comment-269</guid>
		<description><![CDATA[Turkish hackers target theregister.co.uk perhaps political motive behind it. Site is now down.
&lt;a href=&quot;http://africasiaeuro.com/wordpress&quot; rel=&quot;nofollow&quot;&gt;&lt;b&gt; simply wordpressed&lt;/b&gt;&lt;/a&gt;]]></description>
		<content:encoded><![CDATA[<p>Turkish hackers target theregister.co.uk perhaps political motive behind it. Site is now down.<br />
<a href="http://africasiaeuro.com/wordpress" rel="nofollow"><b> simply wordpressed</b></a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on The Register Hacked (DNS Hijacked) by VPSLIST</title>
		<link>http://itigloo.com/2011/09/04/the-register-hacked/#comment-268</link>
		<dc:creator><![CDATA[VPSLIST]]></dc:creator>
		<pubDate>Mon, 05 Sep 2011 06:19:18 +0000</pubDate>
		<guid isPermaLink="false">http://itigloo.com/?p=330#comment-268</guid>
		<description><![CDATA[Domain name attacks like this can be done via social engineering, such as password recovery or actually tricking somebody at the DNS registrar to disclosing info. This has been around forever, albeit not a full system compromise but ugly as it takes a long time to clear up.]]></description>
		<content:encoded><![CDATA[<p>Domain name attacks like this can be done via social engineering, such as password recovery or actually tricking somebody at the DNS registrar to disclosing info. This has been around forever, albeit not a full system compromise but ugly as it takes a long time to clear up.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

