<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: A chink in the AirPort armor?</title>
	<atom:link href="http://gigaom.com/2007/10/04/a-chink-in-the-airport-armor/feed/" rel="self" type="application/rss+xml" />
	<link>http://gigaom.com/2007/10/04/a-chink-in-the-airport-armor/</link>
	<description></description>
	<lastBuildDate>Mon, 20 May 2013 11:28:32 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Airport Finder</title>
		<link>http://gigaom.com/2007/10/04/a-chink-in-the-airport-armor/#comment-324357</link>
		<dc:creator><![CDATA[Airport Finder]]></dc:creator>
		<pubDate>Fri, 26 Jun 2009 10:02:33 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/2007/10/04/a-chink-in-the-airport-armor/#comment-324357</guid>
		<description><![CDATA[Thanks for sharing...real good one.]]></description>
		<content:encoded><![CDATA[<p>Thanks for sharing&#8230;real good one.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Billy Halsey</title>
		<link>http://gigaom.com/2007/10/04/a-chink-in-the-airport-armor/#comment-324351</link>
		<dc:creator><![CDATA[Billy Halsey]]></dc:creator>
		<pubDate>Sun, 07 Oct 2007 21:27:02 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/2007/10/04/a-chink-in-the-airport-armor/#comment-324351</guid>
		<description><![CDATA[Thanks for the suggestion, Kim. I&#039;ve been using netstat for a long time as well on various systems. Unfortunately it doesn&#039;t do much good when you discover the attempt in your logs two days later. I can&#039;t see what ports were actually open at the time on my MBP, or what application(s) were serving which ports at the time which would have caused NAT-PMP to open the firewall ports in question.]]></description>
		<content:encoded><![CDATA[<p>Thanks for the suggestion, Kim. I&#8217;ve been using netstat for a long time as well on various systems. Unfortunately it doesn&#8217;t do much good when you discover the attempt in your logs two days later. I can&#8217;t see what ports were actually open at the time on my MBP, or what application(s) were serving which ports at the time which would have caused NAT-PMP to open the firewall ports in question.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kim Fairlane</title>
		<link>http://gigaom.com/2007/10/04/a-chink-in-the-airport-armor/#comment-324350</link>
		<dc:creator><![CDATA[Kim Fairlane]]></dc:creator>
		<pubDate>Sun, 07 Oct 2007 16:30:23 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/2007/10/04/a-chink-in-the-airport-armor/#comment-324350</guid>
		<description><![CDATA[Have you tried netstat from a command line prompt?
netstat is used to see what ports are being listened on and which have established connections.
I usually use this in windows and linux environments for debugging network related issues. However, I googled the netstat command for mac os x, and I think these commands can show information that might shed a light as to which app is opening these ports:
netstat -a (-A ;couldn&#039;t understand what the difference is)
netstat -np  (shows all protocols and which ports they use, without doing a namelookup on IP&#039;s)
Here&#039;s a link to where I found the information:
http://www.osxfaq.com/man/1/netstat.ws

BR, Kim]]></description>
		<content:encoded><![CDATA[<p>Have you tried netstat from a command line prompt?<br />
netstat is used to see what ports are being listened on and which have established connections.<br />
I usually use this in windows and linux environments for debugging network related issues. However, I googled the netstat command for mac os x, and I think these commands can show information that might shed a light as to which app is opening these ports:<br />
netstat -a (-A ;couldn&#8217;t understand what the difference is)<br />
netstat -np  (shows all protocols and which ports they use, without doing a namelookup on IP&#8217;s)<br />
Here&#8217;s a link to where I found the information:<br />
<a href="http://www.osxfaq.com/man/1/netstat.ws" rel="nofollow">http://www.osxfaq.com/man/1/netstat.ws</a></p>
<p>BR, Kim</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://gigaom.com/2007/10/04/a-chink-in-the-airport-armor/#comment-324356</link>
		<dc:creator><![CDATA[Rob]]></dc:creator>
		<pubDate>Fri, 05 Oct 2007 00:04:18 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/2007/10/04/a-chink-in-the-airport-armor/#comment-324356</guid>
		<description><![CDATA[This is exactly why we use &quot;Defense in Depth&quot;.]]></description>
		<content:encoded><![CDATA[<p>This is exactly why we use &#8220;Defense in Depth&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Billy Halsey</title>
		<link>http://gigaom.com/2007/10/04/a-chink-in-the-airport-armor/#comment-324355</link>
		<dc:creator><![CDATA[Billy Halsey]]></dc:creator>
		<pubDate>Thu, 04 Oct 2007 23:52:42 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/2007/10/04/a-chink-in-the-airport-armor/#comment-324355</guid>
		<description><![CDATA[@ Twist -- The logs are showing up on my MBP, which means that these attempts are making it through my AirPort Extreme base station. That&#039;s the problem. The MBP &lt;em&gt;is&lt;/em&gt; blocking them, but the base station &lt;em&gt;should&lt;/em&gt; be and I shouldn&#039;t be seeing them in my log file at all.

@ Rob -- &#039;Enable NAT Port Mapping Protocol&#039; is checked. I suppose that would do it, then! I&#039;m still going to fault Apple for this one, because even a techie like me turns it on thinking it necessary for &lt;em&gt;any&lt;/em&gt; port mapping, not realizing that it&#039;s actually the NAT-PMP alternative to uPNP. I&#039;ve turned it off and we&#039;ll see what happens.

False alarm or coincidence? Like I said, I don&#039;t have any apps that I&#039;m aware of that run on those ports. That it lasted two hours and a few odd seconds seems extra fishy.

Thanks for your help, everyone.]]></description>
		<content:encoded><![CDATA[<p>@ Twist &#8212; The logs are showing up on my MBP, which means that these attempts are making it through my AirPort Extreme base station. That&#8217;s the problem. The MBP <em>is</em> blocking them, but the base station <em>should</em> be and I shouldn&#8217;t be seeing them in my log file at all.</p>
<p>@ Rob &#8212; &#8216;Enable NAT Port Mapping Protocol&#8217; is checked. I suppose that would do it, then! I&#8217;m still going to fault Apple for this one, because even a techie like me turns it on thinking it necessary for <em>any</em> port mapping, not realizing that it&#8217;s actually the NAT-PMP alternative to uPNP. I&#8217;ve turned it off and we&#8217;ll see what happens.</p>
<p>False alarm or coincidence? Like I said, I don&#8217;t have any apps that I&#8217;m aware of that run on those ports. That it lasted two hours and a few odd seconds seems extra fishy.</p>
<p>Thanks for your help, everyone.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://gigaom.com/2007/10/04/a-chink-in-the-airport-armor/#comment-324354</link>
		<dc:creator><![CDATA[Rob]]></dc:creator>
		<pubDate>Thu, 04 Oct 2007 23:17:13 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/2007/10/04/a-chink-in-the-airport-armor/#comment-324354</guid>
		<description><![CDATA[Do you have &quot;Enable NAT Port Mapping Protocol&quot; enabled in the base station?]]></description>
		<content:encoded><![CDATA[<p>Do you have &#8220;Enable NAT Port Mapping Protocol&#8221; enabled in the base station?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Twist</title>
		<link>http://gigaom.com/2007/10/04/a-chink-in-the-airport-armor/#comment-324349</link>
		<dc:creator><![CDATA[Twist]]></dc:creator>
		<pubDate>Thu, 04 Oct 2007 22:41:01 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/2007/10/04/a-chink-in-the-airport-armor/#comment-324349</guid>
		<description><![CDATA[&lt;b&gt;Blocked attempts&lt;/b&gt; normally means that there was an &lt;b&gt;attempt&lt;/b&gt; to access your network via that port and it was &lt;b&gt;blocked&lt;/b&gt; by your firewall. Means it was doing its job and you shouldn&#039;t have anything to worry about.]]></description>
		<content:encoded><![CDATA[<p><b>Blocked attempts</b> normally means that there was an <b>attempt</b> to access your network via that port and it was <b>blocked</b> by your firewall. Means it was doing its job and you shouldn&#8217;t have anything to worry about.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Billy Halsey</title>
		<link>http://gigaom.com/2007/10/04/a-chink-in-the-airport-armor/#comment-324353</link>
		<dc:creator><![CDATA[Billy Halsey]]></dc:creator>
		<pubDate>Thu, 04 Oct 2007 22:18:05 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/2007/10/04/a-chink-in-the-airport-armor/#comment-324353</guid>
		<description><![CDATA[@rob -- I&#039;ve got the full log at &lt;a href=&quot;http://paxoo.com/tab/ipfw.log&quot; rel=&quot;nofollow&quot;&gt;my website&lt;/a&gt;. (The hostname &amp; IP in the logs are fake.)

@max -- I run Little Snitch 2.0b7, but it didn&#039;t show me anything relevant.]]></description>
		<content:encoded><![CDATA[<p>@rob &#8212; I&#8217;ve got the full log at <a href="http://paxoo.com/tab/ipfw.log" rel="nofollow">my website</a>. (The hostname &amp; IP in the logs are fake.)</p>
<p>@max &#8212; I run Little Snitch 2.0b7, but it didn&#8217;t show me anything relevant.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: max</title>
		<link>http://gigaom.com/2007/10/04/a-chink-in-the-airport-armor/#comment-324352</link>
		<dc:creator><![CDATA[max]]></dc:creator>
		<pubDate>Thu, 04 Oct 2007 16:59:33 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/2007/10/04/a-chink-in-the-airport-armor/#comment-324352</guid>
		<description><![CDATA[Lil&#039; snitch will inform you about which ports are in use by which apps on your mac.]]></description>
		<content:encoded><![CDATA[<p>Lil&#8217; snitch will inform you about which ports are in use by which apps on your mac.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://gigaom.com/2007/10/04/a-chink-in-the-airport-armor/#comment-324347</link>
		<dc:creator><![CDATA[Rob]]></dc:creator>
		<pubDate>Thu, 04 Oct 2007 14:43:27 +0000</pubDate>
		<guid isPermaLink="false">http://theappleblog.com/2007/10/04/a-chink-in-the-airport-armor/#comment-324347</guid>
		<description><![CDATA[can you post a couple of lines from your ipfw.log?]]></description>
		<content:encoded><![CDATA[<p>can you post a couple of lines from your ipfw.log?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
