<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Storm Worm using a 2 stage attack system</title>
	<atom:link href="http://www.sudosecure.net/archives/67/feed" rel="self" type="application/rss+xml" />
	<link>http://www.sudosecure.net/archives/67</link>
	<description>is anything truly secure...</description>
	<pubDate>Fri, 05 Dec 2008 16:13:15 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>By: jeremy</title>
		<link>http://www.sudosecure.net/archives/67#comment-45</link>
		<dc:creator>jeremy</dc:creator>
		<pubDate>Tue, 20 May 2008 06:02:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=67#comment-45</guid>
		<description>Thanks again, Mark!</description>
		<content:encoded><![CDATA[<p>Thanks again, Mark!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://www.sudosecure.net/archives/67#comment-44</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Tue, 20 May 2008 03:11:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=67#comment-44</guid>
		<description>The A records were removed from the above sites today.
The registrar at 厦门华商盛世网络有限公司 has taken action on them.</description>
		<content:encoded><![CDATA[<p>The A records were removed from the above sites today.<br />
The registrar at 厦门华商盛世网络有限公司 has taken action on them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jeremy</title>
		<link>http://www.sudosecure.net/archives/67#comment-30</link>
		<dc:creator>jeremy</dc:creator>
		<pubDate>Thu, 08 May 2008 02:28:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=67#comment-30</guid>
		<description>Thanks Mark!  I was not aware of cadeaux-avenue.cn and tellicolakerealty.cn.</description>
		<content:encoded><![CDATA[<p>Thanks Mark!  I was not aware of cadeaux-avenue.cn and tellicolakerealty.cn.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://www.sudosecure.net/archives/67#comment-29</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Thu, 08 May 2008 02:22:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=67#comment-29</guid>
		<description>LIVE STORM Domain Names
cadeaux-avenue.cn
polkerdesign.cn
tellicolakerealty.cn

RECENT BUT DEAD
apartment-mall.cn
biggetonething.cn
gasperoblue.cn
giftapplys.cn
gribontruck.cn
ibank-halifax.com
limpodrift.cn
loveinlive.cn
newoneforyou.cn
normocock.cn
orthelike.com
supersameas.com
thingforyoutoo.cn</description>
		<content:encoded><![CDATA[<p>LIVE STORM Domain Names<br />
cadeaux-avenue.cn<br />
polkerdesign.cn<br />
tellicolakerealty.cn</p>
<p>RECENT BUT DEAD<br />
apartment-mall.cn<br />
biggetonething.cn<br />
gasperoblue.cn<br />
giftapplys.cn<br />
gribontruck.cn<br />
ibank-halifax.com<br />
limpodrift.cn<br />
loveinlive.cn<br />
newoneforyou.cn<br />
normocock.cn<br />
orthelike.com<br />
supersameas.com<br />
thingforyoutoo.cn</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jeremy</title>
		<link>http://www.sudosecure.net/archives/67#comment-28</link>
		<dc:creator>jeremy</dc:creator>
		<pubDate>Wed, 07 May 2008 23:49:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=67#comment-28</guid>
		<description>Did you set the User-Agent to "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1921)"?  I am not real sure how I can help without more information about your issue.</description>
		<content:encoded><![CDATA[<p>Did you set the User-Agent to &#8220;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1921)&#8221;?  I am not real sure how I can help without more information about your issue.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jon</title>
		<link>http://www.sudosecure.net/archives/67#comment-27</link>
		<dc:creator>jon</dc:creator>
		<pubDate>Wed, 07 May 2008 21:55:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=67#comment-27</guid>
		<description>i havin a problem  geting a sample of the new load2.php in malzilla

please help</description>
		<content:encoded><![CDATA[<p>i havin a problem  geting a sample of the new load2.php in malzilla</p>
<p>please help</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jeremy</title>
		<link>http://www.sudosecure.net/archives/67#comment-26</link>
		<dc:creator>jeremy</dc:creator>
		<pubDate>Wed, 07 May 2008 21:33:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=67#comment-26</guid>
		<description>Levi your right.  This was a mistake on my part and the Snort rule is correct in that you must have "Windows NT 5.1" in the UA to download the binary.  I will correct it in my post, sorry for the confusion as I was a victim of a bad copy and paste.</description>
		<content:encoded><![CDATA[<p>Levi your right.  This was a mistake on my part and the Snort rule is correct in that you must have &#8220;Windows NT 5.1&#8243; in the UA to download the binary.  I will correct it in my post, sorry for the confusion as I was a victim of a bad copy and paste.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Levi</title>
		<link>http://www.sudosecure.net/archives/67#comment-25</link>
		<dc:creator>Levi</dc:creator>
		<pubDate>Wed, 07 May 2008 20:35:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=67#comment-25</guid>
		<description>I noticed that the User-agent string mentioned in this posting, Mozilla/4.0 (compatible; MSIE 6.0; SV1921), doesn't match the Snort rule Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1921).  The difference is the 'Windows NT 5.1' part.</description>
		<content:encoded><![CDATA[<p>I noticed that the User-agent string mentioned in this posting, Mozilla/4.0 (compatible; MSIE 6.0; SV1921), doesn&#8217;t match the Snort rule Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1921).  The difference is the &#8216;Windows NT 5.1&#8242; part.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Jonkman</title>
		<link>http://www.sudosecure.net/archives/67#comment-24</link>
		<dc:creator>Matt Jonkman</dc:creator>
		<pubDate>Wed, 07 May 2008 12:37:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=67#comment-24</guid>
		<description>Great catch Jeremy! I've actually put this in as a new sig to preserve the previous. New sid is 2008193.</description>
		<content:encoded><![CDATA[<p>Great catch Jeremy! I&#8217;ve actually put this in as a new sig to preserve the previous. New sid is 2008193.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
