<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Storm Worm Authors move to Military Theme</title>
	<atom:link href="http://www.sudosecure.net/archives/146/feed" rel="self" type="application/rss+xml" />
	<link>http://www.sudosecure.net/archives/146</link>
	<description>is anything truly secure...</description>
	<pubDate>Tue, 06 Jan 2009 02:06:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: jeremy</title>
		<link>http://www.sudosecure.net/archives/146/comment-page-1#comment-86</link>
		<dc:creator>jeremy</dc:creator>
		<pubDate>Fri, 11 Jul 2008 20:59:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=146#comment-86</guid>
		<description>Thanks for the additional information, and good job.

--jeremy</description>
		<content:encoded><![CDATA[<p>Thanks for the additional information, and good job.</p>
<p>&#8211;jeremy</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marco</title>
		<link>http://www.sudosecure.net/archives/146/comment-page-1#comment-85</link>
		<dc:creator>Marco</dc:creator>
		<pubDate>Fri, 11 Jul 2008 17:49:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=146#comment-85</guid>
		<description>For those who like to look at binary disassembly, I've written an &lt;a href="http://www.cs.ucsb.edu/~marco/blog/2008/07/storms-shellcode.html" title="Storm's shellcode [cs.ucsb.edu]" rel="nofollow"&gt;analysis of the shellcode&lt;/a&gt; used in the 9 browser exploits mentioned by Jeremy.</description>
		<content:encoded><![CDATA[<p>For those who like to look at binary disassembly, I&#8217;ve written an <a href="http://www.cs.ucsb.edu/~marco/blog/2008/07/storms-shellcode.html" title="Storm's shellcode [cs.ucsb.edu]" rel="nofollow">analysis of the shellcode</a> used in the 9 browser exploits mentioned by Jeremy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jeremy</title>
		<link>http://www.sudosecure.net/archives/146/comment-page-1#comment-82</link>
		<dc:creator>jeremy</dc:creator>
		<pubDate>Wed, 09 Jul 2008 04:10:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=146#comment-82</guid>
		<description>Just check your %WINDIR% directory for the following two files: msserv.exe or msserv.config.  If you have them you are infected.  It is possible if your system isn't patched as there is a hidden iframe file "ind.php" with several exploits in it.  Good luck and hope you were lucky.

--jeremy</description>
		<content:encoded><![CDATA[<p>Just check your %WINDIR% directory for the following two files: msserv.exe or msserv.config.  If you have them you are infected.  It is possible if your system isn&#8217;t patched as there is a hidden iframe file &#8220;ind.php&#8221; with several exploits in it.  Good luck and hope you were lucky.</p>
<p>&#8211;jeremy</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JG</title>
		<link>http://www.sudosecure.net/archives/146/comment-page-1#comment-81</link>
		<dc:creator>JG</dc:creator>
		<pubDate>Wed, 09 Jul 2008 03:25:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=146#comment-81</guid>
		<description>So, i just clicked through the link in my email, but quickly realized that i was an idiot and closed the window before the page even loaded. Did i put myself at risk? 

Did anything automatically download??


thanks in advance</description>
		<content:encoded><![CDATA[<p>So, i just clicked through the link in my email, but quickly realized that i was an idiot and closed the window before the page even loaded. Did i put myself at risk? </p>
<p>Did anything automatically download??</p>
<p>thanks in advance</p>
]]></content:encoded>
	</item>
</channel>
</rss>
