<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for Practical Tactics</title>
	<atom:link href="http://practical.wordpress.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://practical.wordpress.com</link>
	<description>technology experiences and insights</description>
	<lastBuildDate>Sat, 07 Nov 2009 10:53:16 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Network Zoning &#8211; In the Zone by Mave</title>
		<link>http://practical.wordpress.com/2007/12/06/network-zoning-in-the-zone/#comment-247</link>
		<dc:creator>Mave</dc:creator>
		<pubDate>Sat, 07 Nov 2009 10:53:16 +0000</pubDate>
		<guid isPermaLink="false">http://practical.wordpress.com/2007/12/06/network-zoning-in-the-zone/#comment-247</guid>
		<description>Wow, you have to try this out - Skydur.com - so fast and unblocks every site in China - youtube, twitter, facebook, even hulu ! My best spent $16 bucks (for 3 months of the service). Want throuh the wall ? - go with Skydur http://www.skydur.com</description>
		<content:encoded><![CDATA[<p>Wow, you have to try this out &#8211; Skydur.com &#8211; so fast and unblocks every site in China &#8211; youtube, twitter, facebook, even hulu ! My best spent $16 bucks (for 3 months of the service). Want throuh the wall ? &#8211; go with Skydur <a href="http://www.skydur.com" rel="nofollow">http://www.skydur.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Imperva&#8217;s DIY syslog format by Anonnymous</title>
		<link>http://practical.wordpress.com/2009/06/09/impervas-diy-syslog-format/#comment-246</link>
		<dc:creator>Anonnymous</dc:creator>
		<pubDate>Mon, 14 Sep 2009 00:14:14 +0000</pubDate>
		<guid isPermaLink="false">http://practical.wordpress.com/?p=64#comment-246</guid>
		<description>First of all, good job on this blog, very informational!

Hey where is this document that you have mentioned?
** The document ”Imperva Integration with ARCSight using Common Event Framework” provides a number of examples **
I couldnt find it on google...
Is there any way you could publish it or send me via email?
Thanks!</description>
		<content:encoded><![CDATA[<p>First of all, good job on this blog, very informational!</p>
<p>Hey where is this document that you have mentioned?<br />
** The document ”Imperva Integration with ARCSight using Common Event Framework” provides a number of examples **<br />
I couldnt find it on google&#8230;<br />
Is there any way you could publish it or send me via email?<br />
Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Top 4 WAF Protections by Your INNER WAF &#171; Practical Tactics</title>
		<link>http://practical.wordpress.com/2009/07/01/top-4-waf-protections/#comment-230</link>
		<dc:creator>Your INNER WAF &#171; Practical Tactics</dc:creator>
		<pubDate>Fri, 10 Jul 2009 12:51:54 +0000</pubDate>
		<guid isPermaLink="false">http://practical.wordpress.com/?p=77#comment-230</guid>
		<description>[...] Top 4 WAF&#160;Protections [...]</description>
		<content:encoded><![CDATA[<p>[...] Top 4 WAF&nbsp;Protections [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Network Zoning (The Zone) by Network Zoning &#8211; Be the Zone &#171; Practical Tactics</title>
		<link>http://practical.wordpress.com/2007/10/15/network-zoning-the-zone/#comment-212</link>
		<dc:creator>Network Zoning &#8211; Be the Zone &#171; Practical Tactics</dc:creator>
		<pubDate>Tue, 26 May 2009 17:26:31 +0000</pubDate>
		<guid isPermaLink="false">http://practical.wordpress.com/2007/10/15/network-zoning-the-zone/#comment-212</guid>
		<description>[...] Viewer Database HackingNetwork Zoning - In the ZoneOff to the WAF racesTweaking PLA: Using rsyslogNetwork Zoning (The Zone)PIX Logging Architecture is Back OnlineLog Management 101PIX Parsing (Usable [...]</description>
		<content:encoded><![CDATA[<p>[...] Viewer Database HackingNetwork Zoning &#8211; In the ZoneOff to the WAF racesTweaking PLA: Using rsyslogNetwork Zoning (The Zone)PIX Logging Architecture is Back OnlineLog Management 101PIX Parsing (Usable [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Network Zoning (The Zone) by fathi alwosaibi</title>
		<link>http://practical.wordpress.com/2007/10/15/network-zoning-the-zone/#comment-210</link>
		<dc:creator>fathi alwosaibi</dc:creator>
		<pubDate>Fri, 15 May 2009 05:28:33 +0000</pubDate>
		<guid isPermaLink="false">http://practical.wordpress.com/2007/10/15/network-zoning-the-zone/#comment-210</guid>
		<description>thanx for the reply; 
actually zoning will simplify network administration, and from my experience when you zone you basically lay down the foundation which should be rigid and fixed.  i did add an article in my web site about Zoning Conceptual Design.  Pls. check it out in my web site 

you can get it through this link: http://fathi.fathialwosaibi.net/index.php?option=com_content&amp;view=category&amp;layout=blog&amp;id=1&amp;Itemid=4&amp;lang=en 

good luck;</description>
		<content:encoded><![CDATA[<p>thanx for the reply;<br />
actually zoning will simplify network administration, and from my experience when you zone you basically lay down the foundation which should be rigid and fixed.  i did add an article in my web site about Zoning Conceptual Design.  Pls. check it out in my web site </p>
<p>you can get it through this link: <a href="http://fathi.fathialwosaibi.net/index.php?option=com_content&amp;view=category&amp;layout=blog&amp;id=1&amp;Itemid=4&amp;lang=en" rel="nofollow">http://fathi.fathialwosaibi.net/index.php?option=com_content&amp;view=category&amp;layout=blog&amp;id=1&amp;Itemid=4&amp;lang=en</a> </p>
<p>good luck;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Network Zoning (The Zone) by bmestep</title>
		<link>http://practical.wordpress.com/2007/10/15/network-zoning-the-zone/#comment-209</link>
		<dc:creator>bmestep</dc:creator>
		<pubDate>Thu, 07 May 2009 20:05:23 +0000</pubDate>
		<guid isPermaLink="false">http://practical.wordpress.com/2007/10/15/network-zoning-the-zone/#comment-209</guid>
		<description>Interesting post on your site.

I must apologize I got tied up in so many things I&#039;ve neglected this site and my Web Security sites. I&#039;ll be updating the content here as well as the other sites.

RE: Zoning.
It&#039;s possible to make the zones too complicated to manage, so be sure in any Network Redesign, Security Rebuild, or Risk Management strategy to consider the operational footprint of the end-state on the business. 

Often times Network Zoning will introduce new business processes that can become too rigid to maintain. The end result is the weakening of the zone defenses. The best way to combat such an issue is to consider the maturity of the business and typical operational needs. I would never recommend a rigid, complex security program for a business that is likely to bypass the resulting processes and procedures that Network Zoning introduces.

Cheers!
Brian</description>
		<content:encoded><![CDATA[<p>Interesting post on your site.</p>
<p>I must apologize I got tied up in so many things I&#8217;ve neglected this site and my Web Security sites. I&#8217;ll be updating the content here as well as the other sites.</p>
<p>RE: Zoning.<br />
It&#8217;s possible to make the zones too complicated to manage, so be sure in any Network Redesign, Security Rebuild, or Risk Management strategy to consider the operational footprint of the end-state on the business. </p>
<p>Often times Network Zoning will introduce new business processes that can become too rigid to maintain. The end result is the weakening of the zone defenses. The best way to combat such an issue is to consider the maturity of the business and typical operational needs. I would never recommend a rigid, complex security program for a business that is likely to bypass the resulting processes and procedures that Network Zoning introduces.</p>
<p>Cheers!<br />
Brian</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Network Zoning (The Zone) by fathi alwosaibi</title>
		<link>http://practical.wordpress.com/2007/10/15/network-zoning-the-zone/#comment-208</link>
		<dc:creator>fathi alwosaibi</dc:creator>
		<pubDate>Thu, 07 May 2009 18:46:20 +0000</pubDate>
		<guid isPermaLink="false">http://practical.wordpress.com/2007/10/15/network-zoning-the-zone/#comment-208</guid>
		<description>i also have done some research on network zoning and i will be posting my experience with the concept.  pls. check my web site fathi.fathialwosaibi.net</description>
		<content:encoded><![CDATA[<p>i also have done some research on network zoning and i will be posting my experience with the concept.  pls. check my web site fathi.fathialwosaibi.net</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PIX Parsing (Usable Logs!) by Roberto</title>
		<link>http://practical.wordpress.com/2007/10/22/pix-parsing-usable-logs/#comment-207</link>
		<dc:creator>Roberto</dc:creator>
		<pubDate>Thu, 12 Mar 2009 22:57:34 +0000</pubDate>
		<guid isPermaLink="false">http://practical.wordpress.com/2007/10/22/pix-parsing-usable-logs/#comment-207</guid>
		<description>Hi,
I change the parameters of the firewall and now I am receiving messagess in my DB...
Check the configuration of your FW...</description>
		<content:encoded><![CDATA[<p>Hi,<br />
I change the parameters of the firewall and now I am receiving messagess in my DB&#8230;<br />
Check the configuration of your FW&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Is YOUR HelpDesk hurting you? by Tiffany</title>
		<link>http://practical.wordpress.com/2008/08/06/is-your-helpdesk-hurting-you/#comment-204</link>
		<dc:creator>Tiffany</dc:creator>
		<pubDate>Sun, 22 Feb 2009 11:25:45 +0000</pubDate>
		<guid isPermaLink="false">http://practical.wordpress.com/?p=48#comment-204</guid>
		<description>Well, i had my pc infected by 13 things.
luckily my dad done something in setup.
he deleted all my programs, i&#039;ve got windows XP home edition now, so it runs more faster than it did, i remember my pc having its first scan and there was only 10.. 
Next day i downloaded something and i did&#039;nt know what the hell it was.... 
Scanned, and it came up with 13!!!!
but thats before. god my pc was slow back  then , even though i get tbe same old things, programs going down... getting some lag and it disapeers.. but atleast i scanned and it found nothing Im safe with the web, maybe cause i went on the site named: zango.com before the night it was ruined? ? ? Maybe so... 
-Tiffany</description>
		<content:encoded><![CDATA[<p>Well, i had my pc infected by 13 things.<br />
luckily my dad done something in setup.<br />
he deleted all my programs, i&#8217;ve got windows XP home edition now, so it runs more faster than it did, i remember my pc having its first scan and there was only 10..<br />
Next day i downloaded something and i did&#8217;nt know what the hell it was&#8230;.<br />
Scanned, and it came up with 13!!!!<br />
but thats before. god my pc was slow back  then , even though i get tbe same old things, programs going down&#8230; getting some lag and it disapeers.. but atleast i scanned and it found nothing Im safe with the web, maybe cause i went on the site named: zango.com before the night it was ruined? ? ? Maybe so&#8230;<br />
-Tiffany</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Tweaking PLA: Using rsyslog by RMvP</title>
		<link>http://practical.wordpress.com/2008/03/11/tweaking-pla-using-rsyslog/#comment-203</link>
		<dc:creator>RMvP</dc:creator>
		<pubDate>Fri, 06 Feb 2009 06:39:11 +0000</pubDate>
		<guid isPermaLink="false">http://practical.wordpress.com/?p=39#comment-203</guid>
		<description>Hello,

the result is: 
You supplied the following log message:
     Feb  5 14:08:45 de9cf000 2009 Feb  5 14:08:44

Resulting in these matches using a default regex filter of: 
       (.*):(.*) (.*) (.*) (.*) (.*) (.*:?:?)
_________________________________________________________

]&gt; match 1: Feb  5 14:08
]&gt; match 2: 45 de9cf000
]&gt; match 3: 2009                (default pixhost)
]&gt; match 5:                     (default pixmonth)
]&gt; match 6: 5                   (default pixdate)
]&gt; match 4: Feb                 (default pixyear)
]&gt; match 7: 14:08:44            (default pixtime)
_________________________________________________________

I changed in syslog-ng the datetime to $S_ISODATE and it works
You supplied the following log message:
     Feb  5 14:39:30 de9cf000 2009-02-05T14:39:30+0100

Resulting in these matches using a default regex filter of: 
       (.*):(.*) (.*) (.*)-(.*)-(.*)T(.*)[+-]
_________________________________________________________

]&gt; match 1: Feb  5 14:39
]&gt; match 2: 30
]&gt; match 3: de9cf000                    (default pixhost)
]&gt; match 5: 02                          (default pixmonth)
]&gt; match 6: 05                          (default pixdate)
]&gt; match 4: 2009                        (default pixyear)
]&gt; match 7: 14:39:30                    (default pixtime)
_________________________________________________________

but I must also change ## Calculates correct date
%months = ( from &quot;Jan&quot;,&quot;01&quot;, to &quot;01&quot;,&quot;01&quot;, etc.

thank you for support.</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>the result is:<br />
You supplied the following log message:<br />
     Feb  5 14:08:45 de9cf000 2009 Feb  5 14:08:44</p>
<p>Resulting in these matches using a default regex filter of:<br />
       (.*):(.*) (.*) (.*) (.*) (.*) (.*:?:?)<br />
_________________________________________________________</p>
<p>]&gt; match 1: Feb  5 14:08<br />
]&gt; match 2: 45 de9cf000<br />
]&gt; match 3: 2009                (default pixhost)<br />
]&gt; match 5:                     (default pixmonth)<br />
]&gt; match 6: 5                   (default pixdate)<br />
]&gt; match 4: Feb                 (default pixyear)<br />
]&gt; match 7: 14:08:44            (default pixtime)<br />
_________________________________________________________</p>
<p>I changed in syslog-ng the datetime to $S_ISODATE and it works<br />
You supplied the following log message:<br />
     Feb  5 14:39:30 de9cf000 2009-02-05T14:39:30+0100</p>
<p>Resulting in these matches using a default regex filter of:<br />
       (.*):(.*) (.*) (.*)-(.*)-(.*)T(.*)[+-]<br />
_________________________________________________________</p>
<p>]&gt; match 1: Feb  5 14:39<br />
]&gt; match 2: 30<br />
]&gt; match 3: de9cf000                    (default pixhost)<br />
]&gt; match 5: 02                          (default pixmonth)<br />
]&gt; match 6: 05                          (default pixdate)<br />
]&gt; match 4: 2009                        (default pixyear)<br />
]&gt; match 7: 14:39:30                    (default pixtime)<br />
_________________________________________________________</p>
<p>but I must also change ## Calculates correct date<br />
%months = ( from &#8220;Jan&#8221;,&#8221;01&#8243;, to &#8220;01&#8243;,&#8221;01&#8243;, etc.</p>
<p>thank you for support.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
