<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Revisiting the Eleonore Exploit Kit</title>
	<atom:link href="http://krebsonsecurity.com/2010/05/revisiting-the-eleonore-exploit-kit/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2010/05/revisiting-the-eleonore-exploit-kit/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Wed, 23 May 2012 21:31:36 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2010/05/revisiting-the-eleonore-exploit-kit/comment-page-1/#comment-6140</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Tue, 25 May 2010 22:16:12 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3176#comment-6140</guid>
		<description>I agree TJ;

Most of the FF users I know make it a habit to &quot;approve all on page&quot; using the NoScript control wide open.

With that set that way there is less advantage on page protection, unless they are at least using ABP.</description>
		<content:encoded><![CDATA[<p>I agree TJ;</p>
<p>Most of the FF users I know make it a habit to &#8220;approve all on page&#8221; using the NoScript control wide open.</p>
<p>With that set that way there is less advantage on page protection, unless they are at least using ABP.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6140" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6140', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6140-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6140" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6140', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6140-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2010/05/revisiting-the-eleonore-exploit-kit/comment-page-1/#comment-6139</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Tue, 25 May 2010 22:00:11 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3176#comment-6139</guid>
		<description>Yes of course, any version including and after version 3.2.1.0401 is secure, even if it is not the latest version.

That is probably why it is not flagging it. I guess I just assumed folks could read between the lines; I digress.</description>
		<content:encoded><![CDATA[<p>Yes of course, any version including and after version 3.2.1.0401 is secure, even if it is not the latest version.</p>
<p>That is probably why it is not flagging it. I guess I just assumed folks could read between the lines; I digress.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6139" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6139', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6139-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6139" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6139', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6139-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Bart</title>
		<link>http://krebsonsecurity.com/2010/05/revisiting-the-eleonore-exploit-kit/comment-page-1/#comment-6136</link>
		<dc:creator>Bart</dc:creator>
		<pubDate>Tue, 25 May 2010 20:41:27 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3176#comment-6136</guid>
		<description>I was just saying that Secunia did not flag my 3.2.1 version on their weekly scans.</description>
		<content:encoded><![CDATA[<p>I was just saying that Secunia did not flag my 3.2.1 version on their weekly scans.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6136" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6136', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6136-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6136" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6136', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6136-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2010/05/revisiting-the-eleonore-exploit-kit/comment-page-1/#comment-6108</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Tue, 25 May 2010 14:54:58 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3176#comment-6108</guid>
		<description>Yes, Wladimir, of course. Thank you!</description>
		<content:encoded><![CDATA[<p>Yes, Wladimir, of course. Thank you!</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6108" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6108', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6108-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6108" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6108', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6108-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: BrianKrebs</title>
		<link>http://krebsonsecurity.com/2010/05/revisiting-the-eleonore-exploit-kit/comment-page-1/#comment-6099</link>
		<dc:creator>BrianKrebs</dc:creator>
		<pubDate>Tue, 25 May 2010 14:02:17 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3176#comment-6099</guid>
		<description>Haha. Yes, and 197 people surfing porn with their iPhones!</description>
		<content:encoded><![CDATA[<div style="background-color:#FFFFCC !important"><p>Haha. Yes, and 197 people surfing porn with their iPhones!</p>
</div><div class="CommentRating">Well-loved. Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6099" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6099', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6099-up" style="font-size:14px; color:#009933;">7</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6099" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6099', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6099-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: gregory</title>
		<link>http://krebsonsecurity.com/2010/05/revisiting-the-eleonore-exploit-kit/comment-page-1/#comment-6081</link>
		<dc:creator>gregory</dc:creator>
		<pubDate>Tue, 25 May 2010 10:26:29 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3176#comment-6081</guid>
		<description>I&#039;m also using Safari on Windows, though I generally use a different browser when accessing adult sites (therefore I&#039;m probably not one of the six in the statistics) :)</description>
		<content:encoded><![CDATA[<p>I&#8217;m also using Safari on Windows, though I generally use a different browser when accessing adult sites (therefore I&#8217;m probably not one of the six in the statistics) <img src='http://krebsonsecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6081" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6081', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6081-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6081" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6081', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6081-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: CyberNorris</title>
		<link>http://krebsonsecurity.com/2010/05/revisiting-the-eleonore-exploit-kit/comment-page-1/#comment-6079</link>
		<dc:creator>CyberNorris</dc:creator>
		<pubDate>Tue, 25 May 2010 09:07:53 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3176#comment-6079</guid>
		<description>Hey look... there are six people running Safari on Windows!</description>
		<content:encoded><![CDATA[<p>Hey look&#8230; there are six people running Safari on Windows!</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6079" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6079', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6079-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6079" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6079', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6079-down" style="font-size:14px; color:#990033;">2</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: TJ</title>
		<link>http://krebsonsecurity.com/2010/05/revisiting-the-eleonore-exploit-kit/comment-page-1/#comment-6077</link>
		<dc:creator>TJ</dc:creator>
		<pubDate>Tue, 25 May 2010 08:28:00 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3176#comment-6077</guid>
		<description>According Net Applications, MSIE&#039;s world market share is 59%. In this sample, MSIE accounted for just 47% of the total traffic.  That means IE&#039;s traffic was actually under-represented compared to its world market share, yet (if you believe the Firefox numbers) it still accounted for a stunning 94.6 of the successful loads . 

That said, I agree with Brian&#039;s statement...&quot;it seems highly unlikely that all of the nearly 5,600 Firefox users who visited the exploit sites detailed here escaped unscathed.&quot;</description>
		<content:encoded><![CDATA[<p>According Net Applications, MSIE&#8217;s world market share is 59%. In this sample, MSIE accounted for just 47% of the total traffic.  That means IE&#8217;s traffic was actually under-represented compared to its world market share, yet (if you believe the Firefox numbers) it still accounted for a stunning 94.6 of the successful loads . </p>
<p>That said, I agree with Brian&#8217;s statement&#8230;&#8221;it seems highly unlikely that all of the nearly 5,600 Firefox users who visited the exploit sites detailed here escaped unscathed.&#8221;</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6077" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6077', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6077-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6077" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6077', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6077-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Wladimir Palant</title>
		<link>http://krebsonsecurity.com/2010/05/revisiting-the-eleonore-exploit-kit/comment-page-1/#comment-6074</link>
		<dc:creator>Wladimir Palant</dc:creator>
		<pubDate>Tue, 25 May 2010 06:51:59 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3176#comment-6074</guid>
		<description>Yes, the Firefox stats remain puzzling. Your guess that &quot;these kits are detecting Firefox visitors as users of some other browser&quot; isn&#039;t really likely - Firefox visit numbers make total sense. Maybe the exploit kit can correctly recognize Firefox visits but not infections through Firefox. But given that for the latter the browser is probably not used at all I cannot see how this can be.

Btw, thank you for this Foxit hint - for some reason Foxit didn&#039;t notify me about an update yet.</description>
		<content:encoded><![CDATA[<p>Yes, the Firefox stats remain puzzling. Your guess that &#8220;these kits are detecting Firefox visitors as users of some other browser&#8221; isn&#8217;t really likely &#8211; Firefox visit numbers make total sense. Maybe the exploit kit can correctly recognize Firefox visits but not infections through Firefox. But given that for the latter the browser is probably not used at all I cannot see how this can be.</p>
<p>Btw, thank you for this Foxit hint &#8211; for some reason Foxit didn&#8217;t notify me about an update yet.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6074" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6074', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6074-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6074" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6074', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6074-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Wladimir Palant</title>
		<link>http://krebsonsecurity.com/2010/05/revisiting-the-eleonore-exploit-kit/comment-page-1/#comment-6073</link>
		<dc:creator>Wladimir Palant</dc:creator>
		<pubDate>Tue, 25 May 2010 06:42:32 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3176#comment-6073</guid>
		<description>Secunia PSI will only show you updates that are known to fix a vulnerability - if you installed version isn&#039;t &quot;dangerous&quot; it won&#039;t complain.</description>
		<content:encoded><![CDATA[<p>Secunia PSI will only show you updates that are known to fix a vulnerability &#8211; if you installed version isn&#8217;t &#8220;dangerous&#8221; it won&#8217;t complain.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6073" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6073', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6073-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6073" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6073', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6073-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 7/24 queries in 0.005 seconds using memcached
Object Caching 958/976 objects using memcached

Served from: krebsonsecurity.com @ 2012-05-23 18:32:52 -->
