<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Exploit-MS08-067 Bundled in Commercial Malware Kit</title>
	<atom:link href="http://blogs.mcafee.com/mcafee-labs/2008/11/14/exploit-ms08-067-bundled-in-commercial-malware-kit/feed" rel="self" type="application/rss+xml" />
	<link>http://blogs.mcafee.com/mcafee-labs/exploit-ms08-067-bundled-in-commercial-malware-kit</link>
	<description></description>
	<lastBuildDate>Tue, 29 Nov 2011 07:51:20 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Trackback - Cheap Internation Call &#62;&#62; How to make cheap international call</title>
		<link>http://blogs.mcafee.com/mcafee-labs/exploit-ms08-067-bundled-in-commercial-malware-kit/comment-page-1#comment-19582</link>
		<dc:creator>Trackback - Cheap Internation Call &#62;&#62; How to make cheap international call</dc:creator>
		<pubDate>Thu, 19 Nov 2009 21:56:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=746#comment-19582</guid>
		<description>,..] www.labs.com is one interesting source of information on this subject,..]</description>
		<content:encoded><![CDATA[<p>,..] www.labs.com is one interesting source of information on this subject,..]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://blogs.mcafee.com/mcafee-labs/exploit-ms08-067-bundled-in-commercial-malware-kit/comment-page-1#comment-19581</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Wed, 11 Nov 2009 16:08:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=746#comment-19581</guid>
		<description>So the Chinese are now just publicly selling &lt;a href=&quot;http://www.sophos.net/&quot; rel=&quot;nofollow&quot;&gt;malware&lt;/a&gt; kits...amazing. In response to #8, not sure if you are kidding or not, but just in case....No, there is absolutely zero chance that this kit was used to make or implement Conficker.</description>
		<content:encoded><![CDATA[<p>So the Chinese are now just publicly selling <a href="http://www.sophos.net/" rel="nofollow">malware</a> kits&#8230;amazing. In response to #8, not sure if you are kidding or not, but just in case&#8230;.No, there is absolutely zero chance that this kit was used to make or implement Conficker.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John N</title>
		<link>http://blogs.mcafee.com/mcafee-labs/exploit-ms08-067-bundled-in-commercial-malware-kit/comment-page-1#comment-19570</link>
		<dc:creator>John N</dc:creator>
		<pubDate>Mon, 23 Mar 2009 17:19:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=746#comment-19570</guid>
		<description>Any indications this package was used to create Conficker?</description>
		<content:encoded><![CDATA[<p>Any indications this package was used to create Conficker?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matthew Wollenweber</title>
		<link>http://blogs.mcafee.com/mcafee-labs/exploit-ms08-067-bundled-in-commercial-malware-kit/comment-page-1#comment-19563</link>
		<dc:creator>Matthew Wollenweber</dc:creator>
		<pubDate>Sun, 16 Nov 2008 21:06:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=746#comment-19563</guid>
		<description>Did you guys look into the commercial version of the app? From what I see above, it looks like they probably just re-packaged code existing elsewhere (Milw0rm/Metasploit/CANVAS). Are they using the exact same code? Do they alter any of the encoding to bypass signatures?

Likewise with the toolkit version, what software are they dropping on the target box? Do the tools match known signatures?</description>
		<content:encoded><![CDATA[<p>Did you guys look into the commercial version of the app? From what I see above, it looks like they probably just re-packaged code existing elsewhere (Milw0rm/Metasploit/CANVAS). Are they using the exact same code? Do they alter any of the encoding to bypass signatures?</p>
<p>Likewise with the toolkit version, what software are they dropping on the target box? Do the tools match known signatures?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

