Re: Linked-in and its Phishing-like contacts option!
<[email protected]> Wed, 1 May 2013 15:20:09 -0400
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
This is a multipart message in MIME format. --===============0366399472== Content-Type: multipart/alternative; boundary="----=_NextPart_000_0004_01CE467F.5EDC2640" Content-Language: en-us This is a multipart message in MIME format. ------=_NextPart_000_0004_01CE467F.5EDC2640 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Yeah, I was trying to make this non-product specific, but most vendors = can actually do this to some degree or another. Here's how we do it on my product: https://mcafee.box.com/MWG7-FeatureDemo-Part2 =20 The problem with doing it at a network layer with an IDS is the SSL = decryption. Almost everything nowadays is HTTPS, so it's game over if = you cannot open up the encryption. =20 =20 e=C2=B2 _____________________________________ =20 From: [email protected] = [mailto:[email protected]] On Behalf Of Jon = Robinson Sent: Wednesday, May 01, 2013 12:45 PM To: Firewall Wizards Security Mailing List Subject: Re: [fw-wiz] Linked-in and its Phishing-like contacts option! =20 It's not free but Palo Alto Networks does this.You can search here to = see which applications/sites they can control: = http://apps.paloaltonetworks.com/applipedia/ =20 Jon Robinson Digital Scepter desk (951) 461-7868 mobile (562) 682-0821 [email protected] =20 =20 On Tue, Apr 30, 2013 at 10:50 PM, Mathew Want <[email protected]> wrote: Read only access to the sites. I like that idea a lot. Has anyone else come across this requirement or found a good way to do = it at a control point level? Perhaps at the IDS layer? M@=20 =20 On 1 May 2013 02:20, <[email protected]> wrote: > I'm honestly not sure how we could block this stuff in a web-proxy, or = be > alerted by an IDS rule short of just blocking the sites. > (Maybe this will start more discussion. How would one try this?) I have a lot of requests from customers to try to make the web = read-only. The main use cases are for social network, blogs/wikis, and = commenting on posts. The fundamental ways to do this are to 1) have MITM = SSL decryption, and 2) block the POST method for specific sites. Most = commercial proxies can do this and even squid does SSL MITM. By blocking POST to certain categories of sites and only allowing the = POST for the */logon pages, users can view all the = facebook/twitter/youtube they want, but can't write anything outbound to = the site. It's pretty effective. e=C2=B2 _____________________________________ From: [email protected] = [mailto:[email protected]] On Behalf Of = Bruce Platt Sent: Friday, April 26, 2013 7:41 AM To: Firewall Wizards Security Mailing List Subject: Re: [fw-wiz] Linked-in and its Phishing-like contacts option! I have a love/hate relationship with these as well. I was only tempted = down this perfidious path a few years ago when a set of my Grandchildren = asked me to get a Facebook account so we could interact that way as they = live on the other coast from me. I started disliking it within five = minutes when a former employer sent me a request to "friend" him. Then = it became an issue of who can I not be "friends" with among my = contemporaries. Same with Linked-In, same with Twitter. Up to this point I'm just addressing the personal inconvenience aspect = of it, which is why I chose Crispan's post to which to reply. But, the larger issue is really the risk of exposing all sorts of = personal / corporate information in a variety of unwitting ways. This = is the part I hate. We've had many discussions about the risks of = allowing people to use social media web sites from work. It's a losing = battle. Entering one's email password is just one, and Linked-In is not = the only villain. I just made some flight reservations yesterday. The = airline website offered to add the reservation to my Calendar. Not let = me download a .cal file, but to directly insert it into my calendar. = Uh, no. Not today. But, this now get's added to our list of worst practices and meet's = Paul's criteria of being part of overall operational security. I'm = honestly not sure how we could block this stuff in a web-proxy, or be = alerted by an IDS rule short of just blocking the sites. (Maybe this = will start more discussion. How would one try this?) Mix these with BYOD, and it makes a daunting task indeed. Cheers -- +------------------------------------+ Bruce B. Platt, Ph.D. V.P. Research ei3 Corporation 136 Summit Avenue Montvale, NJ 07645 Phone: +1-201-802-9080 ext. 404 <tel:%2B1-201-802-9080%20ext.%20404>=20 Facsimile: +1-201-802-9099 <tel:%2B1-201-802-9099>=20 On Fri, Apr 26, 2013 at 12:53 AM, Crispin Cowan = <[email protected]> wrote: I boycott all social media. I=E2=80=99m not opposed to social = networking, but I am opposed to some dot.com monetizing my = relationships; I do all my social networking via open protocols like = e-mail, and having a beer with a friend =F0=9F=98=8A I broke this rule once, joining LinkedIn 5 years ago, because I needed a = job. LinkedIn was a total failure at getting a job, but attending = ToorCon and having a beer with someone I met there worked. I deleted my = LinkedIn account when I got tired of the =E2=80=9CFoo wants to connect = with you=E2=80=9D spam. I=E2=80=99m still getting LinkedIn spam. Screw social networking web sites. I don=E2=80=99t have a FaceBook page = or a Twitter account, and never will. Funny, I never envisioned myself as Clint Eastwood yelling at kids to = get off my lawn, but here I am =F0=9F=98=8A Sent from Windows Mail From: Gautier . Rich Sent: =E2=80=8EThursday=E2=80=8E, =E2=80=8EApril=E2=80=8E = =E2=80=8E25=E2=80=8E, =E2=80=8E2013 = =E2=80=8E9=E2=80=8E:=E2=80=8E28=E2=80=8E =E2=80=8EPM To: Firewall Wizards Security Mailing List Thoughts? I=E2=80=99m wondering why User Operational Security falls = under the realm of Firewall Wizards.. Other than that, I=E2=80=99d say = =E2=80=93 They=E2=80=99re not alone by any stretch of the imagination, = and plenty of users seem to be perfectly willing to accept the risk (or = be unaware of it). However, not much you can do on the firewall side = other than turning off webmail access... Richard Gautier, CISSP Enterprise Architect, Federal Group 650 Massachusetts Avenue NW Suite 510 Washington, DC 20001 Office: (571) 226-8828 <tel:%28571%29%20226-8828> | Cell: (703) = 231-2156 <tel:%28703%29%20231-2156>=20 [email protected] | www.drc.com From: [email protected] = [mailto:[email protected]] On Behalf Of = Mathew Want Sent: Monday, April 22, 2013 7:30 PM To: Firewall Wizards Security Mailing List Subject: [fw-wiz] Linked-in and its Phishing-like contacts option! Hiya all. Has anyone else noticed the option to see who else they know is = connected on Linked-in? Have you noticed that if you click on the = outlook button it asks you for your WORK EMAIL PASSWORD!!!!! Bloody hell! It's not like the job of getting users to not submit this = information to other sites isn't already hard enough without this!!! The = "can't put brains in pumpkins " department must be having a field day = over this. Am I the only one that think this is a touch negligent on the part of = Linked-in? Or should I just accept that it is corporate facebook, = accepts that they have the dame moral fibre and move on? Maybe I am expecting too much? Thoughts? -- Regards, M@ -- "Some things are eternal by nature, others by consequence" ________________________________________ This electronic message transmission and any attachments that accompany = it contain information from DRC=C2=AE (Dynamics Research Corporation) or = its subsidiaries, or the intended recipient, which is privileged, = proprietary, business confidential, or otherwise protected from = disclosure and is the exclusive property of DRC and/or the intended = recipient. The information in this email is solely intended for the use = of the individual or entity that is the intended recipient. If you are = not the intended recipient, any use, dissemination, distribution, = retention, or copying of this communication, attachments, or substance = is prohibited. If you have received this electronic transmission in = error, please immediately reply to the author via email that you = received the message by mistake and also promptly and permanently delete = this message and all copies of this email and any attachments. We thank = you for your assistance and apologize for any inconvenience. _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards --=20 "Some things are eternal by nature, others by consequence" _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards =20 ------=_NextPart_000_0004_01CE467F.5EDC2640 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <html xmlns:v=3D"urn:schemas-microsoft-com:vml" = xmlns:o=3D"urn:schemas-microsoft-com:office:office" = xmlns:w=3D"urn:schemas-microsoft-com:office:word" = xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" = xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta = http-equiv=3DContent-Type content=3D"text/html; charset=3Dutf-8"><meta = name=3DGenerator content=3D"Microsoft Word 14 (filtered = medium)"><style><!-- /* Font Definitions */ @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} @font-face {font-family:Tahoma; panose-1:2 11 6 4 3 5 4 4 2 4;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0in; margin-bottom:.0001pt; font-size:12.0pt; font-family:"Times New Roman","serif";} a:link, span.MsoHyperlink {mso-style-priority:99; color:blue; text-decoration:underline;} a:visited, span.MsoHyperlinkFollowed {mso-style-priority:99; color:purple; text-decoration:underline;} span.hoenzb {mso-style-name:hoenzb;} span.EmailStyle18 {mso-style-type:personal-reply; font-family:"Courier New"; color:#1F497D;} .MsoChpDefault {mso-style-type:export-only; font-family:"Calibri","sans-serif";} @page WordSection1 {size:8.5in 11.0in; margin:1.0in 1.0in 1.0in 1.0in;} div.WordSection1 {page:WordSection1;} --></style><!--[if gte mso 9]><xml> <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" /> </xml><![endif]--><!--[if gte mso 9]><xml> <o:shapelayout v:ext=3D"edit"> <o:idmap v:ext=3D"edit" data=3D"1" /> </o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue = vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span = style=3D'font-size:10.0pt;font-family:"Courier New";color:#1F497D'>Yeah, = I was trying to make this non-product specific, but most vendors can = actually do this to some degree or another.<o:p></o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:10.0pt;font-family:"Courier = New";color:#1F497D'>Here's how we do it on my = product:<o:p></o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:10.0pt;font-family:"Courier = New";color:#1F497D'>https://mcafee.box.com/MWG7-FeatureDemo-Part2<o:p></o= :p></span></p><p class=3DMsoNormal><span = style=3D'font-size:10.0pt;font-family:"Courier = New";color:#1F497D'><o:p> </o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:10.0pt;font-family:"Courier = New";color:#1F497D'>The problem with doing it at a network layer with an = IDS is the SSL decryption. Almost everything nowadays is HTTPS, so it's = game over if you cannot open up the encryption.<o:p></o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:10.0pt;font-family:"Courier = New";color:#1F497D'><o:p> </o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:10.0pt;font-family:"Courier = New";color:#1F497D'><o:p> </o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:10.0pt;font-family:"Courier = New";color:#1F497D'>e=C2=B2<o:p></o:p></span></p><p = class=3DMsoNormal><span style=3D'font-size:10.0pt;font-family:"Courier = New";color:#1F497D'>_____________________________________<o:p></o:p></spa= n></p><p class=3DMsoNormal><span = style=3D'font-size:10.0pt;font-family:"Courier = New";color:#1F497D'><o:p> </o:p></span></p><p = class=3DMsoNormal><b><span = style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span>= </b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'> = [email protected] = [mailto:[email protected]] <b>On Behalf Of = </b>Jon Robinson<br><b>Sent:</b> Wednesday, May 01, 2013 12:45 = PM<br><b>To:</b> Firewall Wizards Security Mailing = List<br><b>Subject:</b> Re: [fw-wiz] Linked-in and its Phishing-like = contacts option!<o:p></o:p></span></p><p = class=3DMsoNormal><o:p> </o:p></p><div><p class=3DMsoNormal>It's = not free but Palo Alto Networks does this.You can search here to see = which applications/sites they can control: <a = href=3D"http://apps.paloaltonetworks.com/applipedia/">http://apps.paloalt= onetworks.com/applipedia/</a><o:p></o:p></p><div><p = class=3DMsoNormal><br clear=3Dall><o:p></o:p></p><div><div><div><p = class=3DMsoNormal><o:p> </o:p></p></div><div><p = class=3DMsoNormal>Jon Robinson<o:p></o:p></p></div><div><p = class=3DMsoNormal>Digital Scepter<o:p></o:p></p></div><div><p = class=3DMsoNormal>desk (951) 461-7868<o:p></o:p></p></div><div><p = class=3DMsoNormal>mobile (562) 682-0821<o:p></o:p></p></div><div><p = class=3DMsoNormal><a href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a><o:p></o:p></p></div><div><p = class=3DMsoNormal><o:p> </o:p></p></div></div></div><p = class=3DMsoNormal = style=3D'margin-bottom:12.0pt'><o:p> </o:p></p><div><p = class=3DMsoNormal>On Tue, Apr 30, 2013 at 10:50 PM, Mathew Want <<a = href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a>> = wrote:<o:p></o:p></p><div><div><p class=3DMsoNormal = style=3D'margin-bottom:12.0pt'>Read only access to the sites. I like = that idea a lot.<br><br>Has anyone else come across this requirement or = found a good way to do it at a control point level? Perhaps at the IDS = layer?<o:p></o:p></p></div><p class=3DMsoNormal><span = class=3Dhoenzb><span style=3D'color:#888888'>M@ = </span></span><o:p></o:p></p></div><div><div><div><p class=3DMsoNormal = style=3D'margin-bottom:12.0pt'><o:p> </o:p></p><div><p = class=3DMsoNormal>On 1 May 2013 02:20, <<a = href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a>> = wrote:<o:p></o:p></p><div><p class=3DMsoNormal = style=3D'margin-bottom:12.0pt'>> I'm honestly not sure how we could = block this stuff in a web-proxy, or be<br>> alerted by an IDS rule = short of just blocking the sites.<br>> (Maybe this will start more = discussion. How would one try this?)<o:p></o:p></p></div><p = class=3DMsoNormal>I have a lot of requests from customers to try to make = the web read-only. The main use cases are for social network, = blogs/wikis, and commenting on posts. The fundamental ways to do this = are to 1) have MITM SSL decryption, and 2) block the POST method for = specific sites. Most commercial proxies can do this and even squid does = SSL MITM.<br><br>By blocking POST to certain categories of sites and = only allowing the POST for the */logon pages, users can view all the = facebook/twitter/youtube they want, but can't write anything outbound to = the site. It's pretty = effective.<br><br>e=C2=B2<br>_____________________________________<br><br= >From: <a href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a> = [mailto:<a = href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a>] On = Behalf Of Bruce Platt<br>Sent: Friday, April 26, 2013 7:41 = AM<o:p></o:p></p><div><p class=3DMsoNormal>To: Firewall Wizards Security = Mailing List<o:p></o:p></p></div><p class=3DMsoNormal>Subject: Re: = [fw-wiz] Linked-in and its Phishing-like contacts = option!<o:p></o:p></p><div><div><p class=3DMsoNormal><br>I have a = love/hate relationship with these as well. I was only tempted down = this perfidious path a few years ago when a set of my Grandchildren = asked me to get a Facebook account so we could interact that way as they = live on the other coast from me. I started disliking it within = five minutes when a former employer sent me a request to = "friend" him. Then it became an issue of who can I not = be "friends" with among my contemporaries.<br><br>Same with = Linked-In, same with Twitter.<br><br>Up to this point I'm just = addressing the personal inconvenience aspect of it, which is why I chose = Crispan's post to which to reply.<br><br>But, the larger issue is really = the risk of exposing all sorts of personal / corporate information = in a variety of unwitting ways. This is the part I hate. = We've had many discussions about the risks of allowing people to = use social media web sites from work. It's a losing battle. = Entering one's email password is just one, and Linked-In is not = the only villain. I just made some flight reservations yesterday. = The airline website offered to add the reservation to my Calendar. = Not let me download a .cal file, but to directly insert it into my = calendar. Uh, no. Not today.<br><br>But, this now get's = added to our list of worst practices and meet's Paul's criteria of being = part of overall operational security. I'm honestly not sure how we = could block this stuff in a web-proxy, or be alerted by an IDS rule = short of just blocking the sites. (Maybe this will start more = discussion. How would one try this?)<br><br>Mix these with BYOD, = and it makes a daunting task = indeed.<br><br>Cheers<br><br>--<br>+------------------------------------+= <br>Bruce B. Platt, Ph.D.<br>V.P. Research<br>ei3 Corporation<br>136 = Summit Avenue<br>Montvale, NJ 07645<br>Phone: <a = href=3D"tel:%2B1-201-802-9080%20ext.%20404" = target=3D"_blank">+1-201-802-9080 ext. 404</a><br>Facsimile: <a = href=3D"tel:%2B1-201-802-9099" = target=3D"_blank">+1-201-802-9099</a><br><br>On Fri, Apr 26, 2013 at = 12:53 AM, Crispin Cowan <<a href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a>> wrote:<br>I boycott = all social media. I=E2=80=99m not opposed to social networking, but I am = opposed to some <a href=3D"http://dot.com" target=3D"_blank">dot.com</a> = monetizing my relationships; I do all my social networking via open = protocols like e-mail, and having a beer with a friend = 😊<br><br>I broke this rule once, joining LinkedIn 5 years ago, = because I needed a job. LinkedIn was a total failure at getting a job, = but attending ToorCon and having a beer with someone I met there worked. = I deleted my LinkedIn account when I got tired of the =E2=80=9CFoo wants = to connect with you=E2=80=9D spam. I=E2=80=99m still getting LinkedIn = spam.<br><br>Screw social networking web sites. I don=E2=80=99t have a = FaceBook page or a Twitter account, and never will.<br><br>Funny, I = never envisioned myself as Clint Eastwood yelling at kids to get off my = lawn, but here I am 😊<br><br>Sent from Windows Mail<br><br>From: = Gautier . Rich<br>Sent: =E2=80=8EThursday=E2=80=8E, = =E2=80=8EApril=E2=80=8E =E2=80=8E25=E2=80=8E, =E2=80=8E2013 = =E2=80=8E9=E2=80=8E:=E2=80=8E28=E2=80=8E =E2=80=8EPM<br>To: Firewall = Wizards Security Mailing List<br><br>Thoughts? I=E2=80=99m wondering why = User Operational Security falls under the realm of Firewall Wizards.. = Other than that, I=E2=80=99d say =E2=80=93 They=E2=80=99re not = alone by any stretch of the imagination, and plenty of users seem to be = perfectly willing to accept the risk (or be unaware of it). = However, not much you can do on the firewall side other than = turning off webmail access...<br><br>Richard Gautier, = CISSP<br>Enterprise Architect, Federal = Group<o:p></o:p></p></div></div><div><p class=3DMsoNormal>650 = Massachusetts Avenue NW<br>Suite 510<br>Washington, DC 20001<br>Office: = <a href=3D"tel:%28571%29%20226-8828" target=3D"_blank">(571) = 226-8828</a> | Cell: <a href=3D"tel:%28703%29%20231-2156" = target=3D"_blank">(703) 231-2156</a><br><a = href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a> = | <a href=3D"http://www.drc.com" = target=3D"_blank">www.drc.com</a><br><br>From: <a = href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a> = [mailto:<a = href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a>] On = Behalf Of Mathew Want<br>Sent: Monday, April 22, 2013 7:30 PM<br>To: = Firewall Wizards Security Mailing List<br>Subject: [fw-wiz] Linked-in = and its Phishing-like contacts option!<br><br>Hiya all.<br><br>Has = anyone else noticed the option to see who else they know is connected on = Linked-in? Have you noticed that if you click on the outlook button it = asks you for your WORK EMAIL PASSWORD!!!!!<br>Bloody hell! It's not like = the job of getting users to not submit this information to other sites = isn't already hard enough without this!!! The "can't put brains in = pumpkins " department must be having a field day over this.<br>Am I = the only one that think this is a touch negligent on the part of = Linked-in? Or should I just accept that it is corporate facebook, = accepts that they have the dame moral fibre and move on?<br>Maybe I am = expecting too much? = Thoughts?<br>--<br>Regards,<br>M@<br>--<br>"Some things are eternal = by nature,<br>others by consequence"<o:p></o:p></p></div><p = class=3DMsoNormal>________________________________________<o:p></o:p></p>= <div><div><p class=3DMsoNormal>This electronic message transmission and = any attachments that accompany it contain information from DRC=C2=AE = (Dynamics Research Corporation) or its subsidiaries, or the intended = recipient, which is privileged, proprietary, business confidential, or = otherwise protected from disclosure and is the exclusive property of DRC = and/or the intended recipient. The information in this email is solely = intended for the use of the individual or entity that is the intended = recipient. If you are not the intended recipient, any use, = dissemination, distribution, retention, or copying of this = communication, attachments, or substance is prohibited. If you have = received this electronic transmission in error, please immediately reply = to the author via email that you received the message by mistake and = also promptly and permanently delete this message and all copies of this = email and any attachments. We thank you for your assistance and = apologize for any = inconvenience.<br><br>_______________________________________________<br>= firewall-wizards mailing list<br><a = href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a><br><a = href=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards" = target=3D"_blank">https://listserv.icsalabs.com/mailman/listinfo/firewall= -wizards</a><br><br><br>_______________________________________________<b= r>firewall-wizards mailing list<br><a = href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a><br><a = href=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards" = target=3D"_blank">https://listserv.icsalabs.com/mailman/listinfo/firewall= -wizards</a><o:p></o:p></p></div></div></div><p = class=3DMsoNormal><br><br clear=3Dall><br>-- <br>"Some things are = eternal by nature,<br>others by = consequence"<o:p></o:p></p></div></div></div><p class=3DMsoNormal = style=3D'margin-bottom:12.0pt'><br>______________________________________= _________<br>firewall-wizards mailing list<br><a = href=3D"mailto:[email protected]">firewall-wizards@l= istserv.icsalabs.com</a><br><a = href=3D"https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards" = target=3D"_blank">https://listserv.icsalabs.com/mailman/listinfo/firewall= -wizards</a><o:p></o:p></p></div><p = class=3DMsoNormal><o:p> </o:p></p></div></div></div></body></html> ------=_NextPart_000_0004_01CE467F.5EDC2640-- --===============0366399472== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards --===============0366399472==--