<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: ANI File Exploit Has Connection With Hacked Super Bowl Site</title>
	<atom:link href="http://www.avertlabs.com/research/blog/index.php/2007/03/29/ani-file-exploit-has-connection-with-hacked-super-bowl-site/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.avertlabs.com/research/blog/index.php/2007/03/29/ani-file-exploit-has-connection-with-hacked-super-bowl-site/</link>
	<description>Cutting edge security research as it happens.......</description>
	<lastBuildDate>Mon, 15 Mar 2010 10:26:50 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: ANI Exploit + SQL injection &#171; Among the Impostors - Cyber Fraud</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/03/29/ani-file-exploit-has-connection-with-hacked-super-bowl-site/comment-page-1/#comment-217097</link>
		<dc:creator>ANI Exploit + SQL injection &#171; Among the Impostors - Cyber Fraud</dc:creator>
		<pubDate>Thu, 29 Nov 2007 10:42:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=237#comment-217097</guid>
		<description>[...] It’s an interesting thought to think that one attack compromised 25,000 websites, which in turn could have compromised potentially hundreds of thousands or even millions of remote machines via the ANI payload through XSS. And ultimately, the attackers are still at large. Pretty scary concept when you think about the low level of diversity in open source web applications, making them much more susceptible to attack. Maybe that tiny webapp hole isn’t so tiny after all. [...]</description>
		<content:encoded><![CDATA[<p>[...] It’s an interesting thought to think that one attack compromised 25,000 websites, which in turn could have compromised potentially hundreds of thousands or even millions of remote machines via the ANI payload through XSS. And ultimately, the attackers are still at large. Pretty scary concept when you think about the low level of diversity in open source web applications, making them much more susceptible to attack. Maybe that tiny webapp hole isn’t so tiny after all. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ha.ckers.org web application security lab - Archive &#187; ANI Exploit + SQL injection</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/03/29/ani-file-exploit-has-connection-with-hacked-super-bowl-site/comment-page-1/#comment-214294</link>
		<dc:creator>ha.ckers.org web application security lab - Archive &#187; ANI Exploit + SQL injection</dc:creator>
		<pubDate>Mon, 26 Nov 2007 23:09:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=237#comment-214294</guid>
		<description>[...] I know we&#8217;ve all thought about it, but for some reason this one is hitting a little more than others. Partially because I think we all like to think we are unique and every hack needs to be forensically important. Think about if you were running the Miami Dolphins and you were to see this happen to your site. You&#8217;d want answers, and you&#8217;d want them now. And then after spending countless hours and tons of resources you&#8217;d find that the answer is you were just one hack of 25,000. An interesting website but insignificant in the grand scheme of the attack. [...]</description>
		<content:encoded><![CDATA[<p>[...] I know we&#8217;ve all thought about it, but for some reason this one is hitting a little more than others. Partially because I think we all like to think we are unique and every hack needs to be forensically important. Think about if you were running the Miami Dolphins and you were to see this happen to your site. You&#8217;d want answers, and you&#8217;d want them now. And then after spending countless hours and tons of resources you&#8217;d find that the answer is you were just one hack of 25,000. An interesting website but insignificant in the grand scheme of the attack. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Computer Security Research - McAfee Avert Labs Blog</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/03/29/ani-file-exploit-has-connection-with-hacked-super-bowl-site/comment-page-1/#comment-61265</link>
		<dc:creator>Computer Security Research - McAfee Avert Labs Blog</dc:creator>
		<pubDate>Wed, 02 May 2007 21:34:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=237#comment-61265</guid>
		<description>[...] As for websites, this can be a bit trickier. There are some more clear-cut cases where the website itself is dodgy - warez sites, software-cracks sites, etc. If you&#8217;re getting stolen or hacked software, you run the risk of getting more than you bargained for, plain and simple. A website can also be basically innocent, yet still be problematic: Websites need to be protected and patched just like any other machine. Even big websites can be hacked to serve up nasty code to be dumped on you when you come to visit, like in the case of the recent ANI zero-day exploit. [...]</description>
		<content:encoded><![CDATA[<p>[...] As for websites, this can be a bit trickier. There are some more clear-cut cases where the website itself is dodgy &#8211; warez sites, software-cracks sites, etc. If you&#8217;re getting stolen or hacked software, you run the risk of getting more than you bargained for, plain and simple. A website can also be basically innocent, yet still be problematic: Websites need to be protected and patched just like any other machine. Even big websites can be hacked to serve up nasty code to be dumped on you when you come to visit, like in the case of the recent ANI zero-day exploit. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Computer Security Research - McAfee Avert Labs Blog</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/03/29/ani-file-exploit-has-connection-with-hacked-super-bowl-site/comment-page-1/#comment-45438</link>
		<dc:creator>Computer Security Research - McAfee Avert Labs Blog</dc:creator>
		<pubDate>Mon, 02 Apr 2007 22:04:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=237#comment-45438</guid>
		<description>[...] There are a huge number of innocent Web sites&#8211;hacked by the same group that hacked the Superbowl site&#8211;that are hosting a file which exploits an unpatched hole in many recent Windows versions. The file was created in such a way that it can cause a system to download and run malware. [...]</description>
		<content:encoded><![CDATA[<p>[...] There are a huge number of innocent Web sites&#8211;hacked by the same group that hacked the Superbowl site&#8211;that are hosting a file which exploits an unpatched hole in many recent Windows versions. The file was created in such a way that it can cause a system to download and run malware. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: luc</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/03/29/ani-file-exploit-has-connection-with-hacked-super-bowl-site/comment-page-1/#comment-44327</link>
		<dc:creator>luc</dc:creator>
		<pubDate>Sun, 01 Apr 2007 18:15:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=237#comment-44327</guid>
		<description>AVG also detect it</description>
		<content:encoded><![CDATA[<p>AVG also detect it</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Mosby at myITforum.com : McAfee Avert Labs Blog - ANI File Exploit Has Connection With Hacked Super Bowl Site</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/03/29/ani-file-exploit-has-connection-with-hacked-super-bowl-site/comment-page-1/#comment-43212</link>
		<dc:creator>Chris Mosby at myITforum.com : McAfee Avert Labs Blog - ANI File Exploit Has Connection With Hacked Super Bowl Site</dc:creator>
		<pubDate>Fri, 30 Mar 2007 16:34:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=237#comment-43212</guid>
		<description>[...] Trackback [...]</description>
		<content:encoded><![CDATA[<p>[...] Trackback [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2007/03/29/ani-file-exploit-has-connection-with-hacked-super-bowl-site/comment-page-1/#comment-43100</link>
		<dc:creator>Jeff</dc:creator>
		<pubDate>Fri, 30 Mar 2007 13:58:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=237#comment-43100</guid>
		<description>http://isc.sans.org/diary.html?storyid=2537

IE7.0 SP2</description>
		<content:encoded><![CDATA[<p><a href="http://isc.sans.org/diary.html?storyid=2537" rel="nofollow">http://isc.sans.org/diary.html?storyid=2537</a></p>
<p>IE7.0 SP2</p>
]]></content:encoded>
	</item>
</channel>
</rss>
