<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule"	>
<channel>
	<title>Comments on: Ike-scan 1.8 Information Seepage</title>
	<atom:link href="http://www.cutawaysecurity.com/blog/archives/125/feed" rel="self" type="application/rss+xml" />
	<link>http://www.cutawaysecurity.com/blog/archives/125</link>
	<description>Cutaway's Observations, Opinions, Rants, Raves, Tantrums, and Tirades</description>
	<lastBuildDate>Wed, 02 Jun 2010 22:30:56 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Roy Hills</title>
		<link>http://www.cutawaysecurity.com/blog/archives/125/comment-page-1#comment-9107</link>
		<dc:creator>Roy Hills</dc:creator>
		<pubDate>Tue, 27 Mar 2007 09:01:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/archives/125#comment-9107</guid>
		<description>The offending code has been totally removed from version 1.9, and I would suggest that everyone upgrade to version 1.9 anyway because it&#039;s got lots of additional features.

There&#039;s also an ike-scan wiki, which I hope gives some useful information.  If you&#039;re interested in ike-scan, I&#039;d suggest visiting it at http://www.nta-monitor.com/wiki (select the ike-scan link).  If you register you can also contribute to the documentation, and add your comments to the talk pages.  I&#039;d really like to hear about any problems, new feature requests, strange responses Etc.

Anyway, here is some historical information on this issue, for anyone who is interested:

This issue was first reported by this Debian bug report against ike-scan 1.7:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=327220

The code had been in every ike-scan version from 1.0 to 1.7 inclusive, although for 1.7 there was a workaround where using the --nodns option prevented the lookup.  The &quot;--disable-lookup&quot; option was added in version 1.8, which caused the offending code to be #ifdef&#039;ed out; and the code was removed entirely in version 1.9.

I used to use the code for ike-scan testing, but it was never of any use outside my own test environment, and it was superseded by the autoconf &quot;make check&quot; tests around version 1.7 anyway.

If anyone has additional questions or comments about ike-scan, you can contact me at:
ike-scan (at) nta-monitor (dot) com
or leave a comment on the appropriate wiki talk page.

Roy Hills</description>
		<content:encoded><![CDATA[<p>The offending code has been totally removed from version 1.9, and I would suggest that everyone upgrade to version 1.9 anyway because it&#8217;s got lots of additional features.</p>
<p>There&#8217;s also an ike-scan wiki, which I hope gives some useful information.  If you&#8217;re interested in ike-scan, I&#8217;d suggest visiting it at <a href="http://www.nta-monitor.com/wiki" rel="nofollow">http://www.nta-monitor.com/wiki</a> (select the ike-scan link).  If you register you can also contribute to the documentation, and add your comments to the talk pages.  I&#8217;d really like to hear about any problems, new feature requests, strange responses Etc.</p>
<p>Anyway, here is some historical information on this issue, for anyone who is interested:</p>
<p>This issue was first reported by this Debian bug report against ike-scan 1.7:<br />
<a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=327220" rel="nofollow">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=327220</a></p>
<p>The code had been in every ike-scan version from 1.0 to 1.7 inclusive, although for 1.7 there was a workaround where using the &#8211;nodns option prevented the lookup.  The &#8220;&#8211;disable-lookup&#8221; option was added in version 1.8, which caused the offending code to be #ifdef&#8217;ed out; and the code was removed entirely in version 1.9.</p>
<p>I used to use the code for ike-scan testing, but it was never of any use outside my own test environment, and it was superseded by the autoconf &#8220;make check&#8221; tests around version 1.7 anyway.</p>
<p>If anyone has additional questions or comments about ike-scan, you can contact me at:<br />
ike-scan (at) nta-monitor (dot) com<br />
or leave a comment on the appropriate wiki talk page.</p>
<p>Roy Hills</p>
]]></content:encoded>
	</item>
</channel>
</rss>
