<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Unpatched Drive-By Exploit Found On The Web</title>
	<atom:link href="http://blogs.mcafee.com/mcafee-labs/2007/03/28/unpatched-drive-by-exploit-found-on-the-web/feed" rel="self" type="application/rss+xml" />
	<link>http://blogs.mcafee.com/mcafee-labs/unpatched-drive-by-exploit-found-on-the-web</link>
	<description></description>
	<lastBuildDate>Fri, 18 May 2012 09:34:59 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: klimklim</title>
		<link>http://blogs.mcafee.com/mcafee-labs/unpatched-drive-by-exploit-found-on-the-web/comment-page-1#comment-8306</link>
		<dc:creator>klimklim</dc:creator>
		<pubDate>Thu, 24 Sep 2009 09:11:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=230#comment-8306</guid>
		<description>According to this Secunia advisory from today and the Mcafee advisory form March 28 (also found on Microsofts site), the animated cursor found in pretty much any Microsoft OS (XP, VISTa, 2000, 2003), can be used to exploit the machine?</description>
		<content:encoded><![CDATA[<p>According to this Secunia advisory from today and the Mcafee advisory form March 28 (also found on Microsofts site), the animated cursor found in pretty much any Microsoft OS (XP, VISTa, 2000, 2003), can be used to exploit the machine?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christian louboutin</title>
		<link>http://blogs.mcafee.com/mcafee-labs/unpatched-drive-by-exploit-found-on-the-web/comment-page-1#comment-8305</link>
		<dc:creator>Christian louboutin</dc:creator>
		<pubDate>Mon, 31 Aug 2009 08:48:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=230#comment-8305</guid>
		<description>According to this Secunia advisory from today and the Mcafee advisory form March 28 (also found on Microsofts site), the animated cursor found in pretty much any Microsoft OS (XP, VISTa, 2000, 2003), can be used to exploit the machine?</description>
		<content:encoded><![CDATA[<p>According to this Secunia advisory from today and the Mcafee advisory form March 28 (also found on Microsofts site), the animated cursor found in pretty much any Microsoft OS (XP, VISTa, 2000, 2003), can be used to exploit the machine?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nathan Champaigne</title>
		<link>http://blogs.mcafee.com/mcafee-labs/unpatched-drive-by-exploit-found-on-the-web/comment-page-1#comment-8304</link>
		<dc:creator>Nathan Champaigne</dc:creator>
		<pubDate>Thu, 02 Apr 2009 17:12:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=230#comment-8304</guid>
		<description>I think I have discovered a virus behaving as the wga updater. It came up on reboot before the system tray items executed and looked and behaved like Windows Genuine advantage at first and it asked me to initiate it&#039;s procedure. It started the language bar up again which was unusual, and then it halted it&#039;s processes. Since I have my servers and sharing, and even remote registry services shut down, I assume it was a virus plugin which started the Chinese language font up which I have explicitly removed from my system. The false WGA notification program was also was trying to initiate servers and other resident services just before it hung. I canceled and then it then warned me that WGA notification could not be installed, (bullshit) I went to Microsoft&#039;s update site and initiated updates, which worked just fine, else the WGA would have been valid!</description>
		<content:encoded><![CDATA[<p>I think I have discovered a virus behaving as the wga updater. It came up on reboot before the system tray items executed and looked and behaved like Windows Genuine advantage at first and it asked me to initiate it&#8217;s procedure. It started the language bar up again which was unusual, and then it halted it&#8217;s processes. Since I have my servers and sharing, and even remote registry services shut down, I assume it was a virus plugin which started the Chinese language font up which I have explicitly removed from my system. The false WGA notification program was also was trying to initiate servers and other resident services just before it hung. I canceled and then it then warned me that WGA notification could not be installed, (bullshit) I went to Microsoft&#8217;s update site and initiated updates, which worked just fine, else the WGA would have been valid!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim</title>
		<link>http://blogs.mcafee.com/mcafee-labs/unpatched-drive-by-exploit-found-on-the-web/comment-page-1#comment-8303</link>
		<dc:creator>Jim</dc:creator>
		<pubDate>Thu, 12 Feb 2009 06:23:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=230#comment-8303</guid>
		<description>I&#039;m using Firefox but haven&#039;t had this problem, ill be sure to keep a lookout.</description>
		<content:encoded><![CDATA[<p>I&#8217;m using Firefox but haven&#8217;t had this problem, ill be sure to keep a lookout.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Akif</title>
		<link>http://blogs.mcafee.com/mcafee-labs/unpatched-drive-by-exploit-found-on-the-web/comment-page-1#comment-8300</link>
		<dc:creator>Akif</dc:creator>
		<pubDate>Mon, 02 Jun 2008 23:52:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=230#comment-8300</guid>
		<description>While disabling active-scripting would work on some attacks, it would not work on all of them.

http://www.bencehersey.net</description>
		<content:encoded><![CDATA[<p>While disabling active-scripting would work on some attacks, it would not work on all of them.</p>
<p>http://www.bencehersey.net</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jokes</title>
		<link>http://blogs.mcafee.com/mcafee-labs/unpatched-drive-by-exploit-found-on-the-web/comment-page-1#comment-8296</link>
		<dc:creator>jokes</dc:creator>
		<pubDate>Tue, 05 Jun 2007 04:03:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=230#comment-8296</guid>
		<description>Windows XP is not good</description>
		<content:encoded><![CDATA[<p>Windows XP is not good</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Russell Olson</title>
		<link>http://blogs.mcafee.com/mcafee-labs/unpatched-drive-by-exploit-found-on-the-web/comment-page-1#comment-8290</link>
		<dc:creator>Russell Olson</dc:creator>
		<pubDate>Mon, 02 Apr 2007 15:49:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=230#comment-8290</guid>
		<description>I had a problem with my home computer which has McAfee and it said I needed to down load a file from Microsoft to have the McAfee update work.  I went to the web site that looked like a MS site and downloaded a 23 or 24 MB file.  When I did that my cursor locked in the center of the  screen and was unresponsive.   I restarted my computer and the cursor is locked in the center of the screen and the keyboard does nothing.  Is this the ANI?  How do I repair the problem?</description>
		<content:encoded><![CDATA[<p>I had a problem with my home computer which has McAfee and it said I needed to down load a file from Microsoft to have the McAfee update work.  I went to the web site that looked like a MS site and downloaded a 23 or 24 MB file.  When I did that my cursor locked in the center of the  screen and was unresponsive.   I restarted my computer and the cursor is locked in the center of the screen and the keyboard does nothing.  Is this the ANI?  How do I repair the problem?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hilary Ward</title>
		<link>http://blogs.mcafee.com/mcafee-labs/unpatched-drive-by-exploit-found-on-the-web/comment-page-1#comment-8288</link>
		<dc:creator>Hilary Ward</dc:creator>
		<pubDate>Sat, 31 Mar 2007 19:25:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=230#comment-8288</guid>
		<description>Could this be the reason why my hard drive gave up the ghost and was totally corrupted after a McAfee update &amp; restart on Wednesday 28th?</description>
		<content:encoded><![CDATA[<p>Could this be the reason why my hard drive gave up the ghost and was totally corrupted after a McAfee update &amp; restart on Wednesday 28th?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Craig Schmugar</title>
		<link>http://blogs.mcafee.com/mcafee-labs/unpatched-drive-by-exploit-found-on-the-web/comment-page-1#comment-8286</link>
		<dc:creator>Craig Schmugar</dc:creator>
		<pubDate>Fri, 30 Mar 2007 21:48:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=230#comment-8286</guid>
		<description>Re: Ross &amp; disabling active-scripting...

While disabling active-scripting would work on some attacks, it would not work on all of them.  Scripting is not a requirement for this attack to succeed.</description>
		<content:encoded><![CDATA[<p>Re: Ross &#038; disabling active-scripting&#8230;</p>
<p>While disabling active-scripting would work on some attacks, it would not work on all of them.  Scripting is not a requirement for this attack to succeed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Craig Schmugar</title>
		<link>http://blogs.mcafee.com/mcafee-labs/unpatched-drive-by-exploit-found-on-the-web/comment-page-1#comment-8285</link>
		<dc:creator>Craig Schmugar</dc:creator>
		<pubDate>Fri, 30 Mar 2007 21:46:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=230#comment-8285</guid>
		<description>In response to Jeff &amp; VSE &amp; scanning RTF files...

RTF decomposition is handled in the scan engine and has been for as long as I can remember.  Therefore all McAfee products that use the AV scan engine are able to &quot;look inside&quot; such RTFs.</description>
		<content:encoded><![CDATA[<p>In response to Jeff &#038; VSE &#038; scanning RTF files&#8230;</p>
<p>RTF decomposition is handled in the scan engine and has been for as long as I can remember.  Therefore all McAfee products that use the AV scan engine are able to &#8220;look inside&#8221; such RTFs.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

