<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>shellprompt's blog</title>
	<atom:link href="http://unixlabs.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://unixlabs.wordpress.com</link>
	<description>ramblings of someone interested in security</description>
	<lastBuildDate>Mon, 29 Dec 2008 16:25:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='unixlabs.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/afa2465f25194d801abd49953b86829b?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>shellprompt's blog</title>
		<link>http://unixlabs.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://unixlabs.wordpress.com/osd.xml" title="shellprompt&#039;s blog" />
	<atom:link rel='hub' href='http://unixlabs.wordpress.com/?pushpress=hub'/>
		<item>
		<title>McDonalds Phishing</title>
		<link>http://unixlabs.wordpress.com/2008/12/29/mcdonalds-phishing/</link>
		<comments>http://unixlabs.wordpress.com/2008/12/29/mcdonalds-phishing/#comments</comments>
		<pubDate>Mon, 29 Dec 2008 16:24:10 +0000</pubDate>
		<dc:creator>unixlabs</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://unixlabs.wordpress.com/2008/12/29/mcdonalds-phishing/</guid>
		<description><![CDATA[The research guys at trend have found a gem &#8211; A phishing McDonalds survey with $75 &#8220;cash back&#8221;. Getting a Taste of McDonald’s Phish Fillet &#124; TrendLabs &#124; Malware Blog &#8211; by Trend Micro<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=unixlabs.wordpress.com&amp;blog=5659244&amp;post=36&amp;subd=unixlabs&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The research guys at trend have found a gem &#8211; A phishing McDonalds survey with $75 &#8220;cash back&#8221;.</p>
<p><a href="http://blog.trendmicro.com/getting-a-taste-of-mcdonalds-phish-fillet/">Getting a Taste of McDonald’s Phish Fillet | TrendLabs | Malware Blog &#8211; by Trend Micro</a></p>
<blockquote></blockquote>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/unixlabs.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/unixlabs.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/unixlabs.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/unixlabs.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/unixlabs.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/unixlabs.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/unixlabs.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/unixlabs.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/unixlabs.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/unixlabs.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/unixlabs.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/unixlabs.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/unixlabs.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/unixlabs.wordpress.com/36/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=unixlabs.wordpress.com&amp;blog=5659244&amp;post=36&amp;subd=unixlabs&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://unixlabs.wordpress.com/2008/12/29/mcdonalds-phishing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/11a21b5bc3bc634d438d41214831052b?s=96&#38;d=identicon" medium="image">
			<media:title type="html">shellprompt</media:title>
		</media:content>
	</item>
		<item>
		<title>MagpieRSS &#8211; vulnerable to XSS</title>
		<link>http://unixlabs.wordpress.com/2008/12/29/magpierss-vulnerable-to-xss/</link>
		<comments>http://unixlabs.wordpress.com/2008/12/29/magpierss-vulnerable-to-xss/#comments</comments>
		<pubDate>Mon, 29 Dec 2008 16:23:58 +0000</pubDate>
		<dc:creator>unixlabs</dc:creator>
				<category><![CDATA[0-day]]></category>
		<category><![CDATA[Malware and Exploits]]></category>

		<guid isPermaLink="false">http://unixlabs.wordpress.com/2008/12/29/magpierss-vulnerable-to-xss/</guid>
		<description><![CDATA[I found this post interesting on the XSS forums.  MagieRSS does not sanitise the XML as it is being parsed.  more information to be found here PoC here.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=unixlabs.wordpress.com&amp;blog=5659244&amp;post=35&amp;subd=unixlabs&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I found this post interesting on the XSS forums.  MagieRSS does not sanitise the XML as it is being parsed.  more information to be found <a href="http://sla.ckers.org/forum/read.php?3,25775,25775#msg-25775">here</a> PoC <a href="http://www.elites0ft.com/poc.xml">here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/unixlabs.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/unixlabs.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/unixlabs.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/unixlabs.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/unixlabs.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/unixlabs.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/unixlabs.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/unixlabs.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/unixlabs.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/unixlabs.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/unixlabs.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/unixlabs.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/unixlabs.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/unixlabs.wordpress.com/35/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=unixlabs.wordpress.com&amp;blog=5659244&amp;post=35&amp;subd=unixlabs&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://unixlabs.wordpress.com/2008/12/29/magpierss-vulnerable-to-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/11a21b5bc3bc634d438d41214831052b?s=96&#38;d=identicon" medium="image">
			<media:title type="html">shellprompt</media:title>
		</media:content>
	</item>
		<item>
		<title>another variant of the IE7 exploit&#8230;.</title>
		<link>http://unixlabs.wordpress.com/2008/12/19/another-variant-of-the-ie7-exploit/</link>
		<comments>http://unixlabs.wordpress.com/2008/12/19/another-variant-of-the-ie7-exploit/#comments</comments>
		<pubDate>Fri, 19 Dec 2008 19:35:06 +0000</pubDate>
		<dc:creator>unixlabs</dc:creator>
				<category><![CDATA[0-day]]></category>
		<category><![CDATA[Malware and Exploits]]></category>

		<guid isPermaLink="false">http://unixlabs.wordpress.com/2008/12/19/another-variant-of-the-ie7-exploit/</guid>
		<description><![CDATA[here is another variant of the IE7 zero day.&#160; I work in security, but I know how to use the spellchecker.&#160;&#160; link.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=unixlabs.wordpress.com&amp;blog=5659244&amp;post=31&amp;subd=unixlabs&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>here is another variant of the IE7 zero day.&nbsp; I work in security, but I know how to use the spellchecker.&nbsp;&nbsp; <a href="http://www.milw0rm.com/exploits/7477">link</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/unixlabs.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/unixlabs.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/unixlabs.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/unixlabs.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/unixlabs.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/unixlabs.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/unixlabs.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/unixlabs.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/unixlabs.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/unixlabs.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/unixlabs.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/unixlabs.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/unixlabs.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/unixlabs.wordpress.com/31/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=unixlabs.wordpress.com&amp;blog=5659244&amp;post=31&amp;subd=unixlabs&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://unixlabs.wordpress.com/2008/12/19/another-variant-of-the-ie7-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/11a21b5bc3bc634d438d41214831052b?s=96&#38;d=identicon" medium="image">
			<media:title type="html">shellprompt</media:title>
		</media:content>
	</item>
		<item>
		<title>IE 7 Exploit write ups.</title>
		<link>http://unixlabs.wordpress.com/2008/12/19/ie-7-exploit-write-ups/</link>
		<comments>http://unixlabs.wordpress.com/2008/12/19/ie-7-exploit-write-ups/#comments</comments>
		<pubDate>Fri, 19 Dec 2008 19:31:49 +0000</pubDate>
		<dc:creator>unixlabs</dc:creator>
				<category><![CDATA[0-day]]></category>
		<category><![CDATA[Malware and Exploits]]></category>

		<guid isPermaLink="false">http://unixlabs.wordpress.com/2008/12/19/ie-7-exploit-write-ups/</guid>
		<description><![CDATA[Good write ups by Websense and HDM<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=unixlabs.wordpress.com&amp;blog=5659244&amp;post=27&amp;subd=unixlabs&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Good write ups by <a href="http://securitylabs.websense.com/content/Blogs/3263.aspx#">Websense</a> and <a href="http://www.breakingpointsystems.com/community/blog/patch-tuesdays-and-drive-by-sundays">HDM</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/unixlabs.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/unixlabs.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/unixlabs.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/unixlabs.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/unixlabs.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/unixlabs.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/unixlabs.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/unixlabs.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/unixlabs.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/unixlabs.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/unixlabs.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/unixlabs.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/unixlabs.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/unixlabs.wordpress.com/27/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=unixlabs.wordpress.com&amp;blog=5659244&amp;post=27&amp;subd=unixlabs&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://unixlabs.wordpress.com/2008/12/19/ie-7-exploit-write-ups/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/11a21b5bc3bc634d438d41214831052b?s=96&#38;d=identicon" medium="image">
			<media:title type="html">shellprompt</media:title>
		</media:content>
	</item>
		<item>
		<title>Browser Security Handbook.</title>
		<link>http://unixlabs.wordpress.com/2008/12/16/browser-security-handbook/</link>
		<comments>http://unixlabs.wordpress.com/2008/12/16/browser-security-handbook/#comments</comments>
		<pubDate>Tue, 16 Dec 2008 22:43:54 +0000</pubDate>
		<dc:creator>unixlabs</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://unixlabs.wordpress.com/2008/12/16/browser-security-handbook/</guid>
		<description><![CDATA[Google produced the browser security handbook for general release &#8211; here<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=unixlabs.wordpress.com&amp;blog=5659244&amp;post=21&amp;subd=unixlabs&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Google produced the browser security handbook for general release &#8211; <a href="http://code.google.com/p/browsersec/wiki/Main">here</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/unixlabs.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/unixlabs.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/unixlabs.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/unixlabs.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/unixlabs.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/unixlabs.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/unixlabs.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/unixlabs.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/unixlabs.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/unixlabs.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/unixlabs.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/unixlabs.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/unixlabs.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/unixlabs.wordpress.com/21/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=unixlabs.wordpress.com&amp;blog=5659244&amp;post=21&amp;subd=unixlabs&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://unixlabs.wordpress.com/2008/12/16/browser-security-handbook/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/11a21b5bc3bc634d438d41214831052b?s=96&#38;d=identicon" medium="image">
			<media:title type="html">shellprompt</media:title>
		</media:content>
	</item>
		<item>
		<title>Bit9 vulnerable applications of 2008 report.</title>
		<link>http://unixlabs.wordpress.com/2008/12/15/bit9-vulnerable-applications-of-2008-report/</link>
		<comments>http://unixlabs.wordpress.com/2008/12/15/bit9-vulnerable-applications-of-2008-report/#comments</comments>
		<pubDate>Mon, 15 Dec 2008 20:49:57 +0000</pubDate>
		<dc:creator>unixlabs</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://unixlabs.wordpress.com/2008/12/15/bit9-vulnerable-applications-of-2008-report/</guid>
		<description><![CDATA[see here for what Bit9 Considers to be the vulnerable apps of 2008.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=unixlabs.wordpress.com&amp;blog=5659244&amp;post=19&amp;subd=unixlabs&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>see <a href="http://www.bit9.com/files/Vulnerable_Apps_DEC_08.pdf">here </a>for what Bit9 Considers to be the vulnerable apps of 2008.</p>
<p></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/unixlabs.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/unixlabs.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/unixlabs.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/unixlabs.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/unixlabs.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/unixlabs.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/unixlabs.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/unixlabs.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/unixlabs.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/unixlabs.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/unixlabs.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/unixlabs.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/unixlabs.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/unixlabs.wordpress.com/19/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=unixlabs.wordpress.com&amp;blog=5659244&amp;post=19&amp;subd=unixlabs&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://unixlabs.wordpress.com/2008/12/15/bit9-vulnerable-applications-of-2008-report/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/11a21b5bc3bc634d438d41214831052b?s=96&#38;d=identicon" medium="image">
			<media:title type="html">shellprompt</media:title>
		</media:content>
	</item>
		<item>
		<title>more discussion on the zero day IE exploit.</title>
		<link>http://unixlabs.wordpress.com/2008/12/13/more-discussion-on-the-zero-day-ie-exploit/</link>
		<comments>http://unixlabs.wordpress.com/2008/12/13/more-discussion-on-the-zero-day-ie-exploit/#comments</comments>
		<pubDate>Sat, 13 Dec 2008 14:57:39 +0000</pubDate>
		<dc:creator>unixlabs</dc:creator>
				<category><![CDATA[0-day]]></category>

		<guid isPermaLink="false">http://unixlabs.wordpress.com/2008/12/13/more-discussion-on-the-zero-day-ie-exploit/</guid>
		<description><![CDATA[More interesting data on the IE zero day exploit(now thought to effect IE5 and 6) &#8211; this time from the team at secunia post here .&#160; Microsoft&#8217;s current recommendations are still weak &#8211; IE Enhanced security mode (Server), restrict user permissions and use the high internet zone are poor solutions to this problem.&#160; &#8211; full [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=unixlabs.wordpress.com&amp;blog=5659244&amp;post=15&amp;subd=unixlabs&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>More interesting data on the IE zero day exploit(now thought to effect IE5 and 6) &#8211; this time from the team at secunia <a href="http://secunia.com/blog/38/">post here</a> .&nbsp; Microsoft&#8217;s current recommendations are still weak &#8211; IE Enhanced security mode (Server), restrict user permissions and use the high internet zone are poor solutions to this problem.&nbsp; &#8211; <a href="http://www.microsoft.com/technet/security/advisory/961051.mspx">full article here</a></p>
<p>ZDNET have put together screenshots on how to configure the browser settings to limit this attack <a href="http://content.zdnet.com/2346-12691_22-87874-1.html">here</a></p>
<p>UPDATE: &#8211; Microsoft are releasing a out of band patch &#8211; details <a href="http://www.microsoft.com/technet/security/bulletin/ms08-dec.mspx">here</a></p>
<p></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/unixlabs.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/unixlabs.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/unixlabs.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/unixlabs.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/unixlabs.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/unixlabs.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/unixlabs.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/unixlabs.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/unixlabs.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/unixlabs.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/unixlabs.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/unixlabs.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/unixlabs.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/unixlabs.wordpress.com/15/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=unixlabs.wordpress.com&amp;blog=5659244&amp;post=15&amp;subd=unixlabs&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://unixlabs.wordpress.com/2008/12/13/more-discussion-on-the-zero-day-ie-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/11a21b5bc3bc634d438d41214831052b?s=96&#38;d=identicon" medium="image">
			<media:title type="html">shellprompt</media:title>
		</media:content>
	</item>
		<item>
		<title>Prevx report on Fiesta malware toolkit statistics.</title>
		<link>http://unixlabs.wordpress.com/2008/12/12/prevx-report-on-fiesta-malware-toolkit-statistics/</link>
		<comments>http://unixlabs.wordpress.com/2008/12/12/prevx-report-on-fiesta-malware-toolkit-statistics/#comments</comments>
		<pubDate>Fri, 12 Dec 2008 09:15:58 +0000</pubDate>
		<dc:creator>unixlabs</dc:creator>
				<category><![CDATA[Malware and Exploits]]></category>

		<guid isPermaLink="false">http://unixlabs.wordpress.com/2008/12/12/prevx-report-on-fiesta-malware-toolkit-statistics/</guid>
		<description><![CDATA[The analysis guys at Prevx have monitored the latest version of the Fiesta malware toolkit which currently offers 25 different exploits to the unknowning visitor. They have gathered some statistics &#8211; showing that IE 6 is still an important attack vector.&#160; MSIE6.0 &#8211; 1422 possible victims &#8211; 427 Infections &#8211; 30.0% Target to Infection Ratio [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=unixlabs.wordpress.com&amp;blog=5659244&amp;post=12&amp;subd=unixlabs&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The analysis guys at Prevx have monitored the latest version of the Fiesta malware toolkit which currently offers 25 different exploits to the unknowning visitor. </p>
<p><img style="max-width:800px;" src="http://pxnow.prevx.com/content/blog/fiesta1.8.jpg" width="477" height="1912" /></p>
<p>They have gathered some statistics &#8211; showing that IE 6 is still an important attack vector.&nbsp; </p>
<p>MSIE6.0 &#8211; 1422 possible victims &#8211; 427 Infections &#8211; 30.0% Target to Infection <br />Ratio</p>
<p>
<p>MSIE7.0 &#8211; 1547 possible victims &#8211; 103 Infections &#8211; 06.65% Target to Infection <br />Ratio</p>
<p>
<p>MSIE8.0 &#8211; 13 possible victims &#8211; 1 Infection</p>
<p></p>
<p><a target="_blank" href="http://www.prevx.com/blog/107/Fiesta---Monitoring-ITW-exploit.html">Full Prevx Post here<br /></a></p>
<p></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/unixlabs.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/unixlabs.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/unixlabs.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/unixlabs.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/unixlabs.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/unixlabs.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/unixlabs.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/unixlabs.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/unixlabs.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/unixlabs.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/unixlabs.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/unixlabs.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/unixlabs.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/unixlabs.wordpress.com/12/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=unixlabs.wordpress.com&amp;blog=5659244&amp;post=12&amp;subd=unixlabs&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://unixlabs.wordpress.com/2008/12/12/prevx-report-on-fiesta-malware-toolkit-statistics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/11a21b5bc3bc634d438d41214831052b?s=96&#38;d=identicon" medium="image">
			<media:title type="html">shellprompt</media:title>
		</media:content>

		<media:content url="http://pxnow.prevx.com/content/blog/fiesta1.8.jpg" medium="image" />
	</item>
		<item>
		<title>restoring machines after malware infection have removed the safeboot option</title>
		<link>http://unixlabs.wordpress.com/2008/12/12/restoring-machines-after-malware-infection-have-removed-the-safeboot-option/</link>
		<comments>http://unixlabs.wordpress.com/2008/12/12/restoring-machines-after-malware-infection-have-removed-the-safeboot-option/#comments</comments>
		<pubDate>Fri, 12 Dec 2008 09:11:22 +0000</pubDate>
		<dc:creator>unixlabs</dc:creator>
				<category><![CDATA[Malware and Exploits]]></category>

		<guid isPermaLink="false">http://unixlabs.wordpress.com/2008/12/12/restoring-machines-after-malware-infection-have-removed-the-safeboot-option/</guid>
		<description><![CDATA[Update: Restoring Safe Mode with a .REG file, and a Live CD « Didier Stevens useful blog on how to recover that damaged machine.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=unixlabs.wordpress.com&amp;blog=5659244&amp;post=8&amp;subd=unixlabs&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.didierstevens.com/2008/11/26/update-restoring-safe-mode-with-a-reg-file-and-a-live-cd/">Update: Restoring Safe Mode with a .REG file, and a Live CD « Didier Stevens</a></p>
<p>useful blog on how to recover that damaged machine.<br />
<blockquote></blockquote>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/unixlabs.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/unixlabs.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/unixlabs.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/unixlabs.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/unixlabs.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/unixlabs.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/unixlabs.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/unixlabs.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/unixlabs.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/unixlabs.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/unixlabs.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/unixlabs.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/unixlabs.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/unixlabs.wordpress.com/8/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=unixlabs.wordpress.com&amp;blog=5659244&amp;post=8&amp;subd=unixlabs&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://unixlabs.wordpress.com/2008/12/12/restoring-machines-after-malware-infection-have-removed-the-safeboot-option/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/11a21b5bc3bc634d438d41214831052b?s=96&#38;d=identicon" medium="image">
			<media:title type="html">shellprompt</media:title>
		</media:content>
	</item>
		<item>
		<title>Symantec report on the underground economy</title>
		<link>http://unixlabs.wordpress.com/2008/12/12/symantec-report-on-the-underground-economy/</link>
		<comments>http://unixlabs.wordpress.com/2008/12/12/symantec-report-on-the-underground-economy/#comments</comments>
		<pubDate>Fri, 12 Dec 2008 09:10:25 +0000</pubDate>
		<dc:creator>unixlabs</dc:creator>
				<category><![CDATA[Security Reports]]></category>

		<guid isPermaLink="false">http://unixlabs.wordpress.com/2008/12/12/symantec-report-on-the-underground-economy/</guid>
		<description><![CDATA[Internet Security Threat Report &#8211; Symantec Corp. Symantec have posted their latest threat report.&#160; Have your cheque books ready to purchase your new security products.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=unixlabs.wordpress.com&amp;blog=5659244&amp;post=7&amp;subd=unixlabs&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.symantec.com/business/theme.jsp?themeid=threatreport">Internet Security Threat Report &#8211; Symantec Corp.</a></p>
<p>Symantec have posted their latest threat report.&nbsp; Have your cheque books ready to purchase your new security products.<br />
<blockquote></blockquote>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/unixlabs.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/unixlabs.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/unixlabs.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/unixlabs.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/unixlabs.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/unixlabs.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/unixlabs.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/unixlabs.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/unixlabs.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/unixlabs.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/unixlabs.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/unixlabs.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/unixlabs.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/unixlabs.wordpress.com/7/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=unixlabs.wordpress.com&amp;blog=5659244&amp;post=7&amp;subd=unixlabs&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://unixlabs.wordpress.com/2008/12/12/symantec-report-on-the-underground-economy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/11a21b5bc3bc634d438d41214831052b?s=96&#38;d=identicon" medium="image">
			<media:title type="html">shellprompt</media:title>
		</media:content>
	</item>
	</channel>
</rss>
