<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Latest PDF Zero Day Leads to Exploit Egg Hunt</title>
	<atom:link href="http://www.avertlabs.com/research/blog/index.php/2009/10/13/latest-pdf-zero-day-leads-to-exploit-egg-hunt/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.avertlabs.com/research/blog/index.php/2009/10/13/latest-pdf-zero-day-leads-to-exploit-egg-hunt/</link>
	<description>Cutting edge security research as it happens.......</description>
	<lastBuildDate>Tue, 02 Mar 2010 09:26:54 -0600</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: PDF file loader to extract and analyse shellcode &#171; c0llateral Blog</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2009/10/13/latest-pdf-zero-day-leads-to-exploit-egg-hunt/comment-page-1/#comment-923734</link>
		<dc:creator>PDF file loader to extract and analyse shellcode &#171; c0llateral Blog</dc:creator>
		<pubDate>Wed, 06 Jan 2010 23:19:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=2706#comment-923734</guid>
		<description>[...] you need more information please check Didier Steven&#8217;s site and this blog entry, also check Jon Paterson and Dennis Elser blog entry showing how they extracted the shellcode manually and loaded it into IDA for [...]</description>
		<content:encoded><![CDATA[<p>[...] you need more information please check Didier Steven&#8217;s site and this blog entry, also check Jon Paterson and Dennis Elser blog entry showing how they extracted the shellcode manually and loaded it into IDA for [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: [パッチ] Adobe Reader/Acrobat 9.2 &#171; UnderForge of Lack</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2009/10/13/latest-pdf-zero-day-leads-to-exploit-egg-hunt/comment-page-1/#comment-881851</link>
		<dc:creator>[パッチ] Adobe Reader/Acrobat 9.2 &#171; UnderForge of Lack</dc:creator>
		<pubDate>Wed, 21 Oct 2009 22:58:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=2706#comment-881851</guid>
		<description>[...] Latest PDF Zero Day Leads to Exploit Egg Hunt 技術検証 : Egg Hunter found signature &#8216;eof&#8217; [...]</description>
		<content:encoded><![CDATA[<p>[...] Latest PDF Zero Day Leads to Exploit Egg Hunt 技術検証 : Egg Hunter found signature &#8216;eof&#8217; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2009/10/13/latest-pdf-zero-day-leads-to-exploit-egg-hunt/comment-page-1/#comment-879377</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Fri, 16 Oct 2009 12:39:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=2706#comment-879377</guid>
		<description>FYI, I&#039;ve updated my PDFiD tool to detect this 0day: http://blog.didierstevens.com/2009/10/13/update-pdfid-version-0-0-9-to-detect-another-adobe-0day/</description>
		<content:encoded><![CDATA[<p>FYI, I&#8217;ve updated my PDFiD tool to detect this 0day: <a href="http://blog.didierstevens.com/2009/10/13/update-pdfid-version-0-0-9-to-detect-another-adobe-0day/" rel="nofollow">http://blog.didierstevens.com/2009/10/13/update-pdfid-version-0-0-9-to-detect-another-adobe-0day/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: user</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2009/10/13/latest-pdf-zero-day-leads-to-exploit-egg-hunt/comment-page-1/#comment-879073</link>
		<dc:creator>user</dc:creator>
		<pubDate>Thu, 15 Oct 2009 19:05:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=2706#comment-879073</guid>
		<description>Can you guys point out how you guys are actually going about decoding this to make it viewable using your tool fileinsight?

Thanks and love the blog very informational!! :)</description>
		<content:encoded><![CDATA[<p>Can you guys point out how you guys are actually going about decoding this to make it viewable using your tool fileinsight?</p>
<p>Thanks and love the blog very informational!! <img src='http://www.avertlabs.com/research/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: iTinker</title>
		<link>http://www.avertlabs.com/research/blog/index.php/2009/10/13/latest-pdf-zero-day-leads-to-exploit-egg-hunt/comment-page-1/#comment-878433</link>
		<dc:creator>iTinker</dc:creator>
		<pubDate>Wed, 14 Oct 2009 18:33:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.avertlabs.com/research/blog/?p=2706#comment-878433</guid>
		<description>Q: what would be the effect of DEP set to &#039;optOut&#039; or &#039;alwaysOn&#039; on the heap spray attempt? (winXP+)

&quot;The hidden executable ...is written to disk and executed ...&quot;
Q: written where, executed by whom?  
If the attacked user is a &quot;normal&quot; user as opposed to an admin is the attack successful?  
What happens if a &quot;normal&quot; user is protected by a &quot;line of business&quot; Software Restriction Policy?  Write+Execute should result in a security fault, preventing the attack.  Is there a privilege escalation step?

DEP, &quot;normal&quot; user and SRP are readily available mitigations/defenses against &quot;drive by&quot; attacks.  Testing consistently against them and reporting the results would help to aquaint the non-specialist public with their use.  Hopefully some will be encouraged to investigate and apply these measures, making themselves and the rest of the internet just that little bit safer.</description>
		<content:encoded><![CDATA[<p>Q: what would be the effect of DEP set to &#8216;optOut&#8217; or &#8216;alwaysOn&#8217; on the heap spray attempt? (winXP+)</p>
<p>&#8220;The hidden executable &#8230;is written to disk and executed &#8230;&#8221;<br />
Q: written where, executed by whom?<br />
If the attacked user is a &#8220;normal&#8221; user as opposed to an admin is the attack successful?<br />
What happens if a &#8220;normal&#8221; user is protected by a &#8220;line of business&#8221; Software Restriction Policy?  Write+Execute should result in a security fault, preventing the attack.  Is there a privilege escalation step?</p>
<p>DEP, &#8220;normal&#8221; user and SRP are readily available mitigations/defenses against &#8220;drive by&#8221; attacks.  Testing consistently against them and reporting the results would help to aquaint the non-specialist public with their use.  Hopefully some will be encouraged to investigate and apply these measures, making themselves and the rest of the internet just that little bit safer.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
