<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Latest PDF Zero Day Leads to Exploit Egg Hunt</title>
	<atom:link href="http://blogs.mcafee.com/mcafee-labs/2009/10/13/latest-pdf-zero-day-leads-to-exploit-egg-hunt/feed" rel="self" type="application/rss+xml" />
	<link>http://blogs.mcafee.com/mcafee-labs/latest-pdf-zero-day-leads-to-exploit-egg-hunt</link>
	<description></description>
	<lastBuildDate>Wed, 23 May 2012 15:26:06 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blogs.mcafee.com/mcafee-labs/latest-pdf-zero-day-leads-to-exploit-egg-hunt/comment-page-1#comment-25253</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Fri, 16 Oct 2009 12:39:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=2706#comment-25253</guid>
		<description>FYI, I&#039;ve updated my PDFiD tool to detect this 0day: http://blog.didierstevens.com/2009/10/13/update-pdfid-version-0-0-9-to-detect-another-adobe-0day/</description>
		<content:encoded><![CDATA[<p>FYI, I&#8217;ve updated my PDFiD tool to detect this 0day: http://blog.didierstevens.com/2009/10/13/update-pdfid-version-0-0-9-to-detect-another-adobe-0day/</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: user</title>
		<link>http://blogs.mcafee.com/mcafee-labs/latest-pdf-zero-day-leads-to-exploit-egg-hunt/comment-page-1#comment-25252</link>
		<dc:creator>user</dc:creator>
		<pubDate>Thu, 15 Oct 2009 19:05:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=2706#comment-25252</guid>
		<description>Can you guys point out how you guys are actually going about decoding this to make it viewable using your tool fileinsight?

Thanks and love the blog very informational!! :)</description>
		<content:encoded><![CDATA[<p>Can you guys point out how you guys are actually going about decoding this to make it viewable using your tool fileinsight?</p>
<p>Thanks and love the blog very informational!! <img src='http://blogs.mcafee.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: iTinker</title>
		<link>http://blogs.mcafee.com/mcafee-labs/latest-pdf-zero-day-leads-to-exploit-egg-hunt/comment-page-1#comment-25251</link>
		<dc:creator>iTinker</dc:creator>
		<pubDate>Wed, 14 Oct 2009 18:33:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=2706#comment-25251</guid>
		<description>Q: what would be the effect of DEP set to &#039;optOut&#039; or &#039;alwaysOn&#039; on the heap spray attempt? (winXP+)

&quot;The hidden executable ...is written to disk and executed ...&quot;
Q: written where, executed by whom?
If the attacked user is a &quot;normal&quot; user as opposed to an admin is the attack successful?
What happens if a &quot;normal&quot; user is protected by a &quot;line of business&quot; Software Restriction Policy?  Write+Execute should result in a security fault, preventing the attack.  Is there a privilege escalation step?

DEP, &quot;normal&quot; user and SRP are readily available mitigations/defenses against &quot;drive by&quot; attacks.  Testing consistently against them and reporting the results would help to aquaint the non-specialist public with their use.  Hopefully some will be encouraged to investigate and apply these measures, making themselves and the rest of the internet just that little bit safer.</description>
		<content:encoded><![CDATA[<p>Q: what would be the effect of DEP set to &#8216;optOut&#8217; or &#8216;alwaysOn&#8217; on the heap spray attempt? (winXP+)</p>
<p>&#8220;The hidden executable &#8230;is written to disk and executed &#8230;&#8221;<br />
Q: written where, executed by whom?<br />
If the attacked user is a &#8220;normal&#8221; user as opposed to an admin is the attack successful?<br />
What happens if a &#8220;normal&#8221; user is protected by a &#8220;line of business&#8221; Software Restriction Policy?  Write+Execute should result in a security fault, preventing the attack.  Is there a privilege escalation step?</p>
<p>DEP, &#8220;normal&#8221; user and SRP are readily available mitigations/defenses against &#8220;drive by&#8221; attacks.  Testing consistently against them and reporting the results would help to aquaint the non-specialist public with their use.  Hopefully some will be encouraged to investigate and apply these measures, making themselves and the rest of the internet just that little bit safer.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

