<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"
	xml:lang="en-us">
	<title>Comments on Who is Exploiting the Adobe Flash 0-day?</title>
	<subtitle></subtitle>
	<link rel="self" type="application/atom+xml" title="Comments on Who is Exploiting the Adobe Flash 0-day?" href="http://blog.fireeye.com/research/2009/07/who-is-exploiting-the-flash-0day/comments/atom.xml" />
	<link rel="alternate" type="text/html" title="Who is Exploiting the Adobe Flash 0-day?" href="http://blog.fireeye.com/research/2009/07/who-is-exploiting-the-flash-0day.html"/>
	<generator uri="http://www.typepad.com/">TypePad</generator>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<updated>2009-07-22T20:35:44Z</updated>
	<author>
		<name>FireEye</name>
		<uri>http://blog.fireeye.com/research/</uri>
	</author>
	<id>tag:typepad.com,2003:http://blog.fireeye.com/research/2009/07/who-is-exploiting-the-flash-0day/comments/atom.xml/</id>
    
		<entry>
			<title>bot commented on &#39;Who is Exploiting the Adobe Flash 0-day?&#39;</title>
			<link rel="alternate" type="text/html" title="the same is true (i think) for a vista UAC &quot;normal&quot; user." href="http://blog.fireeye.com/research/2009/07/who-is-exploiting-the-flash-0day.html?cid=6a00d835018afd53ef0120a5ad76eb970c#comment-6a00d835018afd53ef0120a5ad76eb970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a5ad76eb970c</id>
			<published>2009-09-08T11:27:45Z</published>
			<updated>2009-09-08T11:27:45Z</updated>
			<author>
				<name>bot</name>
                <uri>http://themalwareremovalbot.com/</uri>
			</author>
			<summary>the same is true (i think) for a vista UAC &quot;normal&quot; user.</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/07/who-is-exploiting-the-flash-0day.html">&lt;p&gt;the same is true (i think) for a vista UAC &amp;quot;normal&amp;quot; user.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>James Larsof commented on &#39;Who is Exploiting the Adobe Flash 0-day?&#39;</title>
			<link rel="alternate" type="text/html" title="Will NoScript still protect against this sort of attack in a driveby download form, as it does against other driveby..." href="http://blog.fireeye.com/research/2009/07/who-is-exploiting-the-flash-0day.html?cid=6a00d835018afd53ef0120a4fa3148970b#comment-6a00d835018afd53ef0120a4fa3148970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0120a4fa3148970b</id>
			<published>2009-08-16T07:01:34Z</published>
			<updated>2009-08-16T07:01:34Z</updated>
			<author>
				<name>James Larsof</name>
                
			</author>
			<summary>Will NoScript still protect against this sort of attack in a driveby download form, as it does against other driveby...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/07/who-is-exploiting-the-flash-0day.html">&lt;p&gt;Will NoScript still protect against this sort of attack in a driveby download form, as it does against other driveby downloads? Or are we left high and dry here too? Thanks.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Fake Name commented on &#39;Who is Exploiting the Adobe Flash 0-day?&#39;</title>
			<link rel="alternate" type="text/html" title="The best solution to simply use a 3rd party pdf reader. SumatraPDF is Fast and open source: http://blog.kowalczyk.info/software/sumatrapdf/index.html Foxit reader..." href="http://blog.fireeye.com/research/2009/07/who-is-exploiting-the-flash-0day.html?cid=6a00d835018afd53ef011572366f23970b#comment-6a00d835018afd53ef011572366f23970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef011572366f23970b</id>
			<published>2009-07-26T09:54:54Z</published>
			<updated>2009-07-26T09:54:54Z</updated>
			<author>
				<name>Fake Name</name>
                
			</author>
			<summary>The best solution to simply use a 3rd party pdf reader. SumatraPDF is Fast and open source: http://blog.kowalczyk.info/software/sumatrapdf/index.html Foxit reader...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/07/who-is-exploiting-the-flash-0day.html">&lt;p&gt;The best solution to simply use a 3rd party pdf reader.&lt;/p&gt;

&lt;p&gt;SumatraPDF is Fast and open source:&lt;br /&gt;
&lt;a href=&quot;http://blog.kowalczyk.info/software/sumatrapdf/index.html&quot; rel=&quot;nofollow&quot;&gt;http://blog.kowalczyk.info/software/sumatrapdf/index.html&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Foxit reader is a bit more powerful, though it&amp;#39;s closed source:&lt;br /&gt;
&lt;a href=&quot;http://www.foxitsoftware.com/pdf/reader/&quot; rel=&quot;nofollow&quot;&gt;http://www.foxitsoftware.com/pdf/reader/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Both are far faster than acrobat, too.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>H. Karimi commented on &#39;Who is Exploiting the Adobe Flash 0-day?&#39;</title>
			<link rel="alternate" type="text/html" title="I have a question... How do you guys find samples to analysis... I have a security blog too and I..." href="http://blog.fireeye.com/research/2009/07/who-is-exploiting-the-flash-0day.html?cid=6a00d835018afd53ef01157231440a970b#comment-6a00d835018afd53ef01157231440a970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef01157231440a970b</id>
			<published>2009-07-24T19:45:02Z</published>
			<updated>2009-07-24T19:45:02Z</updated>
			<author>
				<name>H. Karimi</name>
                
			</author>
			<summary>I have a question... How do you guys find samples to analysis... I have a security blog too and I...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/07/who-is-exploiting-the-flash-0day.html">&lt;p&gt;I have a question...&lt;/p&gt;

&lt;p&gt;How do you guys find samples to analysis... I have a security blog too and I want to analyze and publish very detailed explanations about it, but I&amp;#39;m not able to find any sample for none of 0-day bugs... What should I do? How you find samples to analysis?&lt;/p&gt;

&lt;p&gt;Please explain it if possible... I really need to know...&lt;br /&gt;
Here is my e-mail: hkarimi83 [at] yahoo [dot] com&lt;/p&gt;

&lt;p&gt;If possible send me sample of this Flash file sample.&lt;/p&gt;

&lt;p&gt;Thanks&lt;br /&gt;
Regards&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>iTinker commented on &#39;Who is Exploiting the Adobe Flash 0-day?&#39;</title>
			<link rel="alternate" type="text/html" title="RE: mitigation Q: would DEP (hardware+software, opt-in or always on) prevent the heap spray from succeeding? Q: if the attacked..." href="http://blog.fireeye.com/research/2009/07/who-is-exploiting-the-flash-0day.html?cid=6a00d835018afd53ef0115722f186e970b#comment-6a00d835018afd53ef0115722f186e970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0115722f186e970b</id>
			<published>2009-07-24T15:00:21Z</published>
			<updated>2009-07-24T15:00:21Z</updated>
			<author>
				<name>iTinker</name>
                
			</author>
			<summary>RE: mitigation Q: would DEP (hardware+software, opt-in or always on) prevent the heap spray from succeeding? Q: if the attacked...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/07/who-is-exploiting-the-flash-0day.html">&lt;p&gt;RE: mitigation&lt;/p&gt;

&lt;p&gt;Q: would DEP (hardware+software, opt-in or always on) prevent the heap spray from succeeding?&lt;/p&gt;

&lt;p&gt;Q: if the attacked (XP) user was a normal (not admin) user and was running under a &amp;quot;line of business&amp;quot; software restriction policy (SRP) the execution of any exe from %TEMP% should be blocked.  the same is true (i think) for a vista UAC &amp;quot;normal&amp;quot; user.  does the exe attempt any permission escalation to avoid this?  is the attack successful against an XP normal user with SRP or a vista normal user with UAC?&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>heh commented on &#39;Who is Exploiting the Adobe Flash 0-day?&#39;</title>
			<link rel="alternate" type="text/html" title="Did you notice that the server shows directory listings and right up front a phpmyadmin directory? hxxp://59.175.238.82/" href="http://blog.fireeye.com/research/2009/07/who-is-exploiting-the-flash-0day.html?cid=6a00d835018afd53ef011571342d6f970c#comment-6a00d835018afd53ef011571342d6f970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef011571342d6f970c</id>
			<published>2009-07-23T17:01:35Z</published>
			<updated>2009-07-23T17:01:35Z</updated>
			<author>
				<name>heh</name>
                
			</author>
			<summary>Did you notice that the server shows directory listings and right up front a phpmyadmin directory? hxxp://59.175.238.82/</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/07/who-is-exploiting-the-flash-0day.html">&lt;p&gt;Did you notice that the server shows directory listings and right up front a phpmyadmin directory? hxxp://59.175.238.82/&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Eric &quot;Secrunner&quot; commented on &#39;Who is Exploiting the Adobe Flash 0-day?&#39;</title>
			<link rel="alternate" type="text/html" title="Very good analysis. I think this is further evidence that Adobe still needs to address their security announcements. The would..." href="http://blog.fireeye.com/research/2009/07/who-is-exploiting-the-flash-0day.html?cid=6a00d835018afd53ef01157133e622970c#comment-6a00d835018afd53ef01157133e622970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef01157133e622970c</id>
			<published>2009-07-23T15:44:51Z</published>
			<updated>2009-07-23T15:44:51Z</updated>
			<author>
				<name>Eric &quot;Secrunner&quot;</name>
                <uri>http://twitter.com%5Csecrunner</uri>
			</author>
			<summary>Very good analysis. I think this is further evidence that Adobe still needs to address their security announcements. The would...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/07/who-is-exploiting-the-flash-0day.html">&lt;p&gt;Very good analysis.  I think this is further evidence that Adobe still needs to address their security announcements.  The would do well to analyze beyond the entry-point.  Of course, I&amp;#39;m sure from a PR angle, it&amp;#39;s easier to say, &amp;quot;oh yeah, just disable this and your fixed...patch coming end of month&amp;quot;, than to actually have to say, &amp;quot;yeah, it&amp;#39;s nasty and there isn&amp;#39;t a good fix beyond good AV until we have a patch available&amp;quot;.  &lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>MarkN commented on &#39;Who is Exploiting the Adobe Flash 0-day?&#39;</title>
			<link rel="alternate" type="text/html" title="Can you advise on the best way to analyse sys files?" href="http://blog.fireeye.com/research/2009/07/who-is-exploiting-the-flash-0day.html?cid=6a00d835018afd53ef011572284b7f970b#comment-6a00d835018afd53ef011572284b7f970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef011572284b7f970b</id>
			<published>2009-07-23T15:19:40Z</published>
			<updated>2009-07-23T15:19:40Z</updated>
			<author>
				<name>MarkN</name>
                
			</author>
			<summary>Can you advise on the best way to analyse sys files?</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2009/07/who-is-exploiting-the-flash-0day.html">&lt;p&gt;Can you advise on the best way to analyse sys files?&lt;/p&gt;</content>
		</entry>
	
</feed>
<!-- ph=1 -->
<!-- nhm:from_kauri -->