<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: McAfee: Internet Explorer 0day Fueled Attacks on Google, Adobe</title> <atom:link href="http://krebsonsecurity.com/2010/01/mcafee-ie-0day-fueled-attacks-on-google-adobe/feed/" rel="self" type="application/rss+xml" /><link>http://krebsonsecurity.com/2010/01/mcafee-ie-0day-fueled-attacks-on-google-adobe/</link> <description>In-depth security news and investigation</description> <lastBuildDate>Fri, 30 Jul 2010 04:29:12 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.0</generator> <item><title>By: Google in China: Unanswered Questions &#171; Free Expression Network</title><link>http://krebsonsecurity.com/2010/01/mcafee-ie-0day-fueled-attacks-on-google-adobe/#comment-602</link> <dc:creator>Google in China: Unanswered Questions &#171; Free Expression Network</dc:creator> <pubDate>Tue, 19 Jan 2010 15:57:11 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=473#comment-602</guid> <description>[...] that Google was not the only company targeted by this attack: other names mentioned have included Yahoo, Symantec, Juniper, Northrop Grumman and Dow Chemical. We don&#039;t know whether those attacks obtained proprietary information or personal user data. But [...]</description> <content:encoded><![CDATA[<p>[...] that Google was not the only company targeted by this attack: other names mentioned have included Yahoo, Symantec, Juniper, Northrop Grumman and Dow Chemical. We don&#39;t know whether those attacks obtained proprietary information or personal user data. But [...]</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-602" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('602', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-602-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-602" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('602', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-602-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: jbmoore</title><link>http://krebsonsecurity.com/2010/01/mcafee-ie-0day-fueled-attacks-on-google-adobe/#comment-519</link> <dc:creator>jbmoore</dc:creator> <pubDate>Mon, 18 Jan 2010 03:17:44 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=473#comment-519</guid> <description>The attack code has been made public by a University of California Santa Barbara computer lab (http://wepawet.iseclab.org/view.php?hash=1aea206aa64ebeabb07237f1e2230d0f&amp;type=js ). Consequently, the developers of Metasploit have released an exploit after only one day of the publication of the code that will allow people to test their systems ( http://blog.metasploit.com/2010/01/reproducing-aurora-ie-exploit.html ) for this vulnerability. It is likely that Core Technology and Immunity Labs have similar updates to their exploit frameworks. Hope this helps.</description> <content:encoded><![CDATA[<p>The attack code has been made public by a University of California Santa Barbara computer lab (<a
href="http://wepawet.iseclab.org/view.php?hash=1aea206aa64ebeabb07237f1e2230d0f&amp;type=js" rel="nofollow">http://wepawet.iseclab.org/view.php?hash=1aea206aa64ebeabb07237f1e2230d0f&amp;type=js</a> ). Consequently, the developers of Metasploit have released an exploit after only one day of the publication of the code that will allow people to test their systems ( <a
href="http://blog.metasploit.com/2010/01/reproducing-aurora-ie-exploit.html" rel="nofollow">http://blog.metasploit.com/2010/01/reproducing-aurora-ie-exploit.html</a> ) for this vulnerability. It is likely that Core Technology and Immunity Labs have similar updates to their exploit frameworks. Hope this helps.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-519" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('519', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-519-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-519" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('519', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-519-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: Google in China: Unanswered Questions &#124; Left to chance</title><link>http://krebsonsecurity.com/2010/01/mcafee-ie-0day-fueled-attacks-on-google-adobe/#comment-447</link> <dc:creator>Google in China: Unanswered Questions &#124; Left to chance</dc:creator> <pubDate>Sat, 16 Jan 2010 04:06:06 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=473#comment-447</guid> <description>[...] that Google was not the only company targeted by this attack: other names mentioned have included Yahoo, Symantec, Juniper, Northrop Grumman and Dow Chemical. We don&#8217;t know whether those attacks obtained proprietary information or personal user data. [...]</description> <content:encoded><![CDATA[<p>[...] that Google was not the only company targeted by this attack: other names mentioned have included Yahoo, Symantec, Juniper, Northrop Grumman and Dow Chemical. We don&#8217;t know whether those attacks obtained proprietary information or personal user data. [...]</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-447" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('447', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-447-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-447" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('447', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-447-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: JohnJ</title><link>http://krebsonsecurity.com/2010/01/mcafee-ie-0day-fueled-attacks-on-google-adobe/#comment-416</link> <dc:creator>JohnJ</dc:creator> <pubDate>Fri, 15 Jan 2010 15:41:02 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=473#comment-416</guid> <description>Since I use Vista and IE8, I found this Microsoft tibit to be interesting:&quot;In addition, Protected Mode in IE 7 on Windows Vista and later significantly reduces the ability of an attacker to impact data on a user’s machine. Customers should also enable Data Execution Prevention (DEP) which helps mitigate online attacks. DEP is enabled by default in IE 8 but must be manually enabled in prior versions.&quot;http://blogs.technet.com/msrc/archive/2010/01/14/security-advisory-979352.aspx</description> <content:encoded><![CDATA[<p>Since I use Vista and IE8, I found this Microsoft tibit to be interesting:</p><p>&#8220;In addition, Protected Mode in IE 7 on Windows Vista and later significantly reduces the ability of an attacker to impact data on a user’s machine. Customers should also enable Data Execution Prevention (DEP) which helps mitigate online attacks. DEP is enabled by default in IE 8 but must be manually enabled in prior versions.&#8221;</p><p><a
href="http://blogs.technet.com/msrc/archive/2010/01/14/security-advisory-979352.aspx" rel="nofollow">http://blogs.technet.com/msrc/archive/2010/01/14/security-advisory-979352.aspx</a></p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-416" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('416', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-416-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-416" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('416', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-416-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: Google Cyberattack Exploits IE Vulernability &#171; Integracon Tech Blog</title><link>http://krebsonsecurity.com/2010/01/mcafee-ie-0day-fueled-attacks-on-google-adobe/#comment-414</link> <dc:creator>Google Cyberattack Exploits IE Vulernability &#171; Integracon Tech Blog</dc:creator> <pubDate>Fri, 15 Jan 2010 15:01:29 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=473#comment-414</guid> <description>[...] announced that the recent cyber attack against Google was related to a vulnerability in IE (via KrebsonSecurity). McAfee analyzed the malicious code and tracked what they are calling &#8220;Aurora&#8221; to a [...]</description> <content:encoded><![CDATA[<p>[...] announced that the recent cyber attack against Google was related to a vulnerability in IE (via KrebsonSecurity). McAfee analyzed the malicious code and tracked what they are calling &#8220;Aurora&#8221; to a [...]</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-414" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('414', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-414-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-414" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('414', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-414-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: Most Tweeted Articles by Defcon Experts: MrTweet</title><link>http://krebsonsecurity.com/2010/01/mcafee-ie-0day-fueled-attacks-on-google-adobe/#comment-411</link> <dc:creator>Most Tweeted Articles by Defcon Experts: MrTweet</dc:creator> <pubDate>Fri, 15 Jan 2010 10:01:48 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=473#comment-411</guid> <description>&lt;strong&gt;Your article was most tweeted by Defcon experts in the Twitterverse...&lt;/strong&gt;Come see other top popular articles surfaced by Defcon experts!...</description> <content:encoded><![CDATA[<p><strong>Your article was most tweeted by Defcon experts in the Twitterverse&#8230;</strong></p><p>Come see other top popular articles surfaced by Defcon experts!&#8230;</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-411" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('411', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-411-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-411" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('411', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-411-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: Tweets that mention McAfee: Internet Explorer 0day Fueled Attacks on Google, Adobe — Krebs on Security -- Topsy.com</title><link>http://krebsonsecurity.com/2010/01/mcafee-ie-0day-fueled-attacks-on-google-adobe/#comment-408</link> <dc:creator>Tweets that mention McAfee: Internet Explorer 0day Fueled Attacks on Google, Adobe — Krebs on Security -- Topsy.com</dc:creator> <pubDate>Fri, 15 Jan 2010 07:28:57 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=473#comment-408</guid> <description>[...] This post was mentioned on Twitter by briankrebs, Dave Lewis, wikidsystems, Ed Nadrotowicz, Jeff Beardsley and others. Jeff Beardsley said: So the Chinese attacks on Google were via an unpatched and unpublished flaw in IE - shocking. USE FIREFOX PEOPLE!! http://bit.ly/5CfJFk [...]</description> <content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by briankrebs, Dave Lewis, wikidsystems, Ed Nadrotowicz, Jeff Beardsley and others. Jeff Beardsley said: So the Chinese attacks on Google were via an unpatched and unpublished flaw in IE &#8211; shocking. USE FIREFOX PEOPLE!! <a
href="http://bit.ly/5CfJFk" rel="nofollow">http://bit.ly/5CfJFk</a> [...]</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-408" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('408', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-408-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-408" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('408', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-408-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: All Versions of IE Vulnerable to 0day? &#124; Marcos Christodonte II - Information Security Blog</title><link>http://krebsonsecurity.com/2010/01/mcafee-ie-0day-fueled-attacks-on-google-adobe/#comment-404</link> <dc:creator>All Versions of IE Vulnerable to 0day? &#124; Marcos Christodonte II - Information Security Blog</dc:creator> <pubDate>Fri, 15 Jan 2010 02:50:58 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=473#comment-404</guid> <description>[...] security reporter at the Washington Post, has been following this story quite closely. On his blog, he notes that the attackers appear to have targeted source code and trade secrets, and that MS has [...]</description> <content:encoded><![CDATA[<p>[...] security reporter at the Washington Post, has been following this story quite closely. On his blog, he notes that the attackers appear to have targeted source code and trade secrets, and that MS has [...]</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-404" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('404', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-404-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-404" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('404', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-404-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: Chinese activist attacks based on Internet Explorer 0day? @ AskWoody.com</title><link>http://krebsonsecurity.com/2010/01/mcafee-ie-0day-fueled-attacks-on-google-adobe/#comment-401</link> <dc:creator>Chinese activist attacks based on Internet Explorer 0day? @ AskWoody.com</dc:creator> <pubDate>Fri, 15 Jan 2010 00:32:19 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=473#comment-401</guid> <description>[...] Krebs reports that the attacks on Chinese human rights activists that I talked about a couple of days ago &#8211; [...]</description> <content:encoded><![CDATA[<p>[...] Krebs reports that the attacks on Chinese human rights activists that I talked about a couple of days ago &#8211; [...]</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-401" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('401', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-401-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-401" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('401', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-401-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using memcached
Page Caching using memcached (user agent is rejected)
Database Caching 2/9 queries in 0.002 seconds using memcached

Served from: krebsonsecurity.com @ 2010-07-30 05:26:41 -->