<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Recognize-Security &#187; Articles</title>
	<atom:link href="http://www.rec-sec.com/category/articles/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rec-sec.com</link>
	<description>a non-profit information security web site authored by Moshe Ben Abu (Trancer), focusing on vulnerability research, exploit development (mainly for the Metasploit Framework), web application security, information security and hacking news from around the world.</description>
	<lastBuildDate>Sun, 14 Mar 2010 17:44:35 +0000</lastBuildDate>
	<generator>http://www.rec-sec.com</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='www.rec-sec.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com" />
	<atom:link rel="hub" href="http://superfeedr.com/hubbub" />
			<item>
		<title>Why Bezeq Int SafeNet Service is Useless</title>
		<link>http://www.rec-sec.com/2009/10/16/bezeq-int-safenet-sucks/</link>
		<comments>http://www.rec-sec.com/2009/10/16/bezeq-int-safenet-sucks/#comments</comments>
		<pubDate>Fri, 16 Oct 2009 18:37:08 +0000</pubDate>
		<dc:creator>Trancer</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.rec-sec.com/?p=781</guid>
		<description><![CDATA[Hello readers. In this post I&#8217;d like to talk about Bezeq International SafeNet service. Bezeq Int is the most common ISP in Israel and like most of the ISP&#8217;s out there, Bezeq Int offer their customers a security service called SafeNet, which they recommend users to buy so they could surf the web in a [...]]]></description>
			<content:encoded><![CDATA[<p><img alt="Bezeq International" width="204" height="93" class="left" src="images/bezeqint.png" />Hello readers. In this post I&#8217;d like to talk about Bezeq International SafeNet service. Bezeq Int is the most common <abbr title="Internet Service Provider">ISP</abbr> in Israel and like most of the <abbr title="Internet Service Provider">ISP</abbr>&#8217;s out there, Bezeq Int offer their customers a security service called SafeNet, which they recommend users to buy so they could surf the web in a safer manner.</p>
<p>As stated on <a href="http://www.bezeqint.net/SafeNet.html" title="Bezeq International - SafeNet">Bezeq Int SafeNet page</a> (and <a href="http://www.bezeqint.net/Page.aspx?cc=010101020101" title="Bezeq International - SafeNet details">details</a>), this service cost 13.90 <abbr title="Israeli New Shekel">NIS</abbr> a month and should be some kind of content filtering system, providing users protection from Malware (viruses, worms, trojan horses, spyware), <abbr title="Hyper Text Markup Language">HTML</abbr> exploits, malicious Activ-X and JAVA code, Fishing web sites and more (note I deliberately misspelled the definitions, that&#8217;s how it&#8217;s wrote on the SafeNet service specification page).</p>
<p>Well, after running a series of tests I can surly say Bezeq Int SafeNet service provide non of these protections what so ever. In fact, it doesn&#8217;t provide any sort of active protection. The only protection SafeNet service provides is blocking supposedly malicious web sites using an out-of-date domain names blacklist.</p>
<p>For example, trying to access <a href="http://www.packetstormsecurity.org/" title="packet storm">Packet Storm Security</a> web site will result in a redirection to a Bezeq Int domain, displaying this SafeNet message:<br />
<a href="images/screenshots/safenet.png" title="Bezeq Int SafeNet message" rel="lightbox"><img width="387" height="326" style="border-width:0" src="images/screenshots/safenet.png" alt="Bezeq Int SafeNet message" /></a><br />
<small>Click to enlarge.</small></p>
<p>The SafeNet service blacklist doesn&#8217;t include <a href="http://milw0rm.com/" title="milw0rm - exploits : vulnerabilities : videos : papers : shellcode">milw0rm</a> and other hacking related web sites. I even ran test against active Malware serving pages, Phishing web sites and rouge Anti-Virus sites, non of which have been blocked by Bezeq Int SafeNet service.</p>
<p>Furthermore, the SafeNet service domain blacklist function can be bypassed rather easily. It is possible to access blacklisted domains using their <abbr title="Internet Protocol">IP</abbr> addresses:<br />
<a href="images/screenshots/packetstorm.png" title="Packet Storm Security" rel="lightbox"><img width="387" height="326" style="border-width:0" src="images/screenshots/packetstorm.png" alt="Packet Storm Security" /></a><br />
<small>Click to enlarge.</small></p>
<p>In conclusion, Bezeq Int SafeNat service provide users no affective protection against any kind of threat and Bezeq Int doesn&#8217;t provide their customers any of the promised functions stated on the SafeNet service specification.<br />
In my opinion, Bezeq Int SafeNet service is a total rip-off and if you are registered to it I recommend you&#8217;d cancel the service immediately.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rec-sec.com/2009/10/16/bezeq-int-safenet-sucks/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
	</channel>
</rss>
