<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Image File Execution Options</title>
	<atom:link href="http://blogs.mcafee.com/mcafee-labs/2008/12/09/image-file-execution-options/feed" rel="self" type="application/rss+xml" />
	<link>http://blogs.mcafee.com/mcafee-labs/image-file-execution-options</link>
	<description></description>
	<lastBuildDate>Wed, 23 May 2012 15:26:06 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: johnny</title>
		<link>http://blogs.mcafee.com/mcafee-labs/image-file-execution-options/comment-page-1#comment-155696</link>
		<dc:creator>johnny</dc:creator>
		<pubDate>Wed, 06 Jul 2011 11:52:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=761#comment-155696</guid>
		<description>Thanks for your detail explanation.
It is so fantastic with screenshot.

Thanks again.</description>
		<content:encoded><![CDATA[<p>Thanks for your detail explanation.<br />
It is so fantastic with screenshot.</p>
<p>Thanks again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ankur</title>
		<link>http://blogs.mcafee.com/mcafee-labs/image-file-execution-options/comment-page-1#comment-20368</link>
		<dc:creator>Ankur</dc:creator>
		<pubDate>Sun, 26 Sep 2010 08:20:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=761#comment-20368</guid>
		<description>Thanks Lokesh..very well explained...
@ken most end users run their machine logged in as admin.</description>
		<content:encoded><![CDATA[<p>Thanks Lokesh..very well explained&#8230;<br />
@ken most end users run their machine logged in as admin.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MySpace Comments</title>
		<link>http://blogs.mcafee.com/mcafee-labs/image-file-execution-options/comment-page-1#comment-20357</link>
		<dc:creator>MySpace Comments</dc:creator>
		<pubDate>Wed, 10 Dec 2008 20:25:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=761#comment-20357</guid>
		<description>Thanks for explaining image file execution stuff.</description>
		<content:encoded><![CDATA[<p>Thanks for explaining image file execution stuff.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tyler</title>
		<link>http://blogs.mcafee.com/mcafee-labs/image-file-execution-options/comment-page-1#comment-20356</link>
		<dc:creator>Tyler</dc:creator>
		<pubDate>Wed, 10 Dec 2008 17:04:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=761#comment-20356</guid>
		<description>Um, Ken/suc - most users run with admin privs.  Thats how malware gets a hold in the first place.

Thanks Lokesh - informative post.</description>
		<content:encoded><![CDATA[<p>Um, Ken/suc &#8211; most users run with admin privs.  Thats how malware gets a hold in the first place.</p>
<p>Thanks Lokesh &#8211; informative post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bruce</title>
		<link>http://blogs.mcafee.com/mcafee-labs/image-file-execution-options/comment-page-1#comment-20355</link>
		<dc:creator>Bruce</dc:creator>
		<pubDate>Wed, 10 Dec 2008 16:10:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=761#comment-20355</guid>
		<description>Ken - the author never said this was a hole.  This is just bringing attention to another technique to autorun something malicious.  Malware authors take advantage of it seems like a dozen or more methods to autorun their programs, and many do require admin rights.  Malware authors also take advantage of uncountable attack vectors that will get at your users PC&#039;s.  And guess what? most shops run with users as admins as do most home users.  but more importantly, IT administrators need to know about these techniques so we can intelligently fight new malware ourselves when our AV vendor&#039;s product does not have an update yet.</description>
		<content:encoded><![CDATA[<p>Ken &#8211; the author never said this was a hole.  This is just bringing attention to another technique to autorun something malicious.  Malware authors take advantage of it seems like a dozen or more methods to autorun their programs, and many do require admin rights.  Malware authors also take advantage of uncountable attack vectors that will get at your users PC&#8217;s.  And guess what? most shops run with users as admins as do most home users.  but more importantly, IT administrators need to know about these techniques so we can intelligently fight new malware ourselves when our AV vendor&#8217;s product does not have an update yet.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: suc</title>
		<link>http://blogs.mcafee.com/mcafee-labs/image-file-execution-options/comment-page-1#comment-20354</link>
		<dc:creator>suc</dc:creator>
		<pubDate>Wed, 10 Dec 2008 13:21:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=761#comment-20354</guid>
		<description>writing in HKey_Local_Machine requires administrative privileges.</description>
		<content:encoded><![CDATA[<p>writing in HKey_Local_Machine requires administrative privileges.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ken Hagan</title>
		<link>http://blogs.mcafee.com/mcafee-labs/image-file-execution-options/comment-page-1#comment-20353</link>
		<dc:creator>Ken Hagan</dc:creator>
		<pubDate>Wed, 10 Dec 2008 13:14:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=761#comment-20353</guid>
		<description>This has been in NT since the outset. Yes, it&#039;s intended as a debugging aid, but it is hardly a malware hole. You need admin rights to tweak it.</description>
		<content:encoded><![CDATA[<p>This has been in NT since the outset. Yes, it&#8217;s intended as a debugging aid, but it is hardly a malware hole. You need admin rights to tweak it.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

