<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Analyzing PDF files and Shellcode</title>
	<atom:link href="http://www.sudosecure.net/archives/313/feed" rel="self" type="application/rss+xml" />
	<link>http://www.sudosecure.net/archives/313</link>
	<description>is anything truly secure...</description>
	<lastBuildDate>Sat, 20 Mar 2010 20:29:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Dave</title>
		<link>http://www.sudosecure.net/archives/313/comment-page-1#comment-156</link>
		<dc:creator>Dave</dc:creator>
		<pubDate>Fri, 14 Nov 2008 13:58:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=313#comment-156</guid>
		<description>This comment actually involves several of your recent articles.

There is a new drive-by Storm attack!

This attack now includes an additional attack method, a compromised Adobe Acrobat (pdf) file, as described in this article.

It also includes a new, updated two-stage multi-vector attack similar to what was reported here in early May (now includes code to download &amp; execute two different payload files from different locations - is Storm subletting? - as well as a new, very irritating combination of AV evasion/obfuscation techniques).

It also now includes a third attack method, based on a Microsoft Office SnapShot Viewer ActiveX exploit.

This attack is also serving-up files directly by an IP address, which also happens to be right next store to the IPs you mentioned being used by flora.pl and the spewing spambots in your Comment Spam &amp; PPC Redirection article!  I have confirmed that these virus files are being served-up from the same &quot;bulletproof&quot; Panamanian hosting service you mentioned!

The scariest part, however, it how they appear to be spreading this.  From what I can tell, it appears this may be being spread via infected banner ads displayed on legit sites and served-up from affiliate ad services!  Yikes!

I am E-MAILing you the details, but wanted to make sure that you saw this right away!</description>
		<content:encoded><![CDATA[<p>This comment actually involves several of your recent articles.</p>
<p>There is a new drive-by Storm attack!</p>
<p>This attack now includes an additional attack method, a compromised Adobe Acrobat (pdf) file, as described in this article.</p>
<p>It also includes a new, updated two-stage multi-vector attack similar to what was reported here in early May (now includes code to download &amp; execute two different payload files from different locations &#8211; is Storm subletting? &#8211; as well as a new, very irritating combination of AV evasion/obfuscation techniques).</p>
<p>It also now includes a third attack method, based on a Microsoft Office SnapShot Viewer ActiveX exploit.</p>
<p>This attack is also serving-up files directly by an IP address, which also happens to be right next store to the IPs you mentioned being used by flora.pl and the spewing spambots in your Comment Spam &amp; PPC Redirection article!  I have confirmed that these virus files are being served-up from the same &#8220;bulletproof&#8221; Panamanian hosting service you mentioned!</p>
<p>The scariest part, however, it how they appear to be spreading this.  From what I can tell, it appears this may be being spread via infected banner ads displayed on legit sites and served-up from affiliate ad services!  Yikes!</p>
<p>I am E-MAILing you the details, but wanted to make sure that you saw this right away!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
