<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Tool Blunts Threat from Windows Shortcut Flaw</title>
	<atom:link href="http://krebsonsecurity.com/2010/07/tool-blunts-threat-from-windows-shortcut-flaw/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2010/07/tool-blunts-threat-from-windows-shortcut-flaw/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Wed, 23 May 2012 21:31:36 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Patrick</title>
		<link>http://krebsonsecurity.com/2010/07/tool-blunts-threat-from-windows-shortcut-flaw/comment-page-1/#comment-17038</link>
		<dc:creator>Patrick</dc:creator>
		<pubDate>Thu, 27 Jan 2011 01:03:27 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=4137#comment-17038</guid>
		<description>Cool shortcuts, very useful. Thanks a bunch!!! I found a few more shortcuts here: http://www.usingcomputers.co.uk/tutorials/useful-windows-shortcuts.php its worth taking a look at combined with this article. Thanks, keep up the good posts!

Big Thanks :D :D</description>
		<content:encoded><![CDATA[<p>Cool shortcuts, very useful. Thanks a bunch!!! I found a few more shortcuts here: <a href="http://www.usingcomputers.co.uk/tutorials/useful-windows-shortcuts.php" rel="nofollow">http://www.usingcomputers.co.uk/tutorials/useful-windows-shortcuts.php</a> its worth taking a look at combined with this article. Thanks, keep up the good posts!</p>
<p>Big Thanks <img src='http://krebsonsecurity.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  <img src='http://krebsonsecurity.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-17038" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('17038', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-17038-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-17038" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('17038', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-17038-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Axel</title>
		<link>http://krebsonsecurity.com/2010/07/tool-blunts-threat-from-windows-shortcut-flaw/comment-page-1/#comment-7755</link>
		<dc:creator>Axel</dc:creator>
		<pubDate>Tue, 27 Jul 2010 22:36:07 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=4137#comment-7755</guid>
		<description>FYI. Another tool - G Data&#039;s LNK-Checker was mentioned by heise online:
http://www.h-online.com/security/news/item/Anti-virus-vendors-offer-free-LNK-protection-Update-1046183.html</description>
		<content:encoded><![CDATA[<p>FYI. Another tool &#8211; G Data&#8217;s LNK-Checker was mentioned by heise online:<br />
<a href="http://www.h-online.com/security/news/item/Anti-virus-vendors-offer-free-LNK-protection-Update-1046183.html" rel="nofollow">http://www.h-online.com/security/news/item/Anti-virus-vendors-offer-free-LNK-protection-Update-1046183.html</a></p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7755" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7755', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7755-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7755" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7755', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7755-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: xAdmin</title>
		<link>http://krebsonsecurity.com/2010/07/tool-blunts-threat-from-windows-shortcut-flaw/comment-page-1/#comment-7744</link>
		<dc:creator>xAdmin</dc:creator>
		<pubDate>Tue, 27 Jul 2010 17:47:26 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=4137#comment-7744</guid>
		<description>I agree Microsoft&#039;s workaround/fixit is sub-par to say the least. I&#039;m not saying anyone shouldn&#039;t use it or Sophos&#039; tool. For the record, I&#039;m NOT using either. I feel quite comfortable with the multiple layers of defense that are already in place on my systems, so I&#039;ll leave it at that and take my risks as they may be while I wait for Microsoft to release a patch. Everyone has to make up their own mind on how best to proceed based on their environment and perceived risk level.

I just wanted to make the point that third party fixes can complicate the issue and that they will most likely have to be backed out before installing Microsoft&#039;s official patch (when it&#039;s released). Besides, it goes against my strict rule of limiting what software is installed and keeping the system in as clean a state as possible. Not to mention I question the real efficacy of the Sophos tool and their intentions. But, that&#039;s my own cynicism. :)

Also, while I frequent Sans ISC numerous times a day and did see the Sophos diary post, I don&#039;t believe it&#039;s an endorsement of the Sophos tool or that it makes the tool any more important. They&#039;re just passing along the info. :)</description>
		<content:encoded><![CDATA[<p>I agree Microsoft&#8217;s workaround/fixit is sub-par to say the least. I&#8217;m not saying anyone shouldn&#8217;t use it or Sophos&#8217; tool. For the record, I&#8217;m NOT using either. I feel quite comfortable with the multiple layers of defense that are already in place on my systems, so I&#8217;ll leave it at that and take my risks as they may be while I wait for Microsoft to release a patch. Everyone has to make up their own mind on how best to proceed based on their environment and perceived risk level.</p>
<p>I just wanted to make the point that third party fixes can complicate the issue and that they will most likely have to be backed out before installing Microsoft&#8217;s official patch (when it&#8217;s released). Besides, it goes against my strict rule of limiting what software is installed and keeping the system in as clean a state as possible. Not to mention I question the real efficacy of the Sophos tool and their intentions. But, that&#8217;s my own cynicism. <img src='http://krebsonsecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Also, while I frequent Sans ISC numerous times a day and did see the Sophos diary post, I don&#8217;t believe it&#8217;s an endorsement of the Sophos tool or that it makes the tool any more important. They&#8217;re just passing along the info. <img src='http://krebsonsecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7744" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7744', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7744-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7744" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7744', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7744-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: PC.Tech</title>
		<link>http://krebsonsecurity.com/2010/07/tool-blunts-threat-from-windows-shortcut-flaw/comment-page-1/#comment-7742</link>
		<dc:creator>PC.Tech</dc:creator>
		<pubDate>Tue, 27 Jul 2010 16:02:12 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=4137#comment-7742</guid>
		<description>@ xAdmin

&quot;... Would rather it come from the vendor directly&quot;
We&#039;d ALL like to have that, and if M$ had given us a better workaround than that crap &quot;FixIt&quot; for this issue, we wouldn&#039;t be looking for something better. BTW, the ISC offered it up: 
- http://isc.sans.edu/diary.html?storyid=9268

.</description>
		<content:encoded><![CDATA[<p>@ xAdmin</p>
<p>&#8220;&#8230; Would rather it come from the vendor directly&#8221;<br />
We&#8217;d ALL like to have that, and if M$ had given us a better workaround than that crap &#8220;FixIt&#8221; for this issue, we wouldn&#8217;t be looking for something better. BTW, the ISC offered it up:<br />
- <a href="http://isc.sans.edu/diary.html?storyid=9268" rel="nofollow">http://isc.sans.edu/diary.html?storyid=9268</a></p>
<p>.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7742" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7742', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7742-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7742" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7742', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7742-down" style="font-size:14px; color:#990033;">2</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Phoenix</title>
		<link>http://krebsonsecurity.com/2010/07/tool-blunts-threat-from-windows-shortcut-flaw/comment-page-1/#comment-7741</link>
		<dc:creator>Phoenix</dc:creator>
		<pubDate>Tue, 27 Jul 2010 14:44:16 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=4137#comment-7741</guid>
		<description>I got an unexpected result when I ran Microsoft&#039;s Fixit: All it did was open Microsoft Security Essentials (which I as using as my anti-virus).  I tried again this time as administrator and got the same result. I ran a scan and came up with nothing. Running Windows 7 64 bit.</description>
		<content:encoded><![CDATA[<p>I got an unexpected result when I ran Microsoft&#8217;s Fixit: All it did was open Microsoft Security Essentials (which I as using as my anti-virus).  I tried again this time as administrator and got the same result. I ran a scan and came up with nothing. Running Windows 7 64 bit.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7741" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7741', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7741-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7741" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7741', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7741-down" style="font-size:14px; color:#990033;">2</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: xAdmin</title>
		<link>http://krebsonsecurity.com/2010/07/tool-blunts-threat-from-windows-shortcut-flaw/comment-page-1/#comment-7740</link>
		<dc:creator>xAdmin</dc:creator>
		<pubDate>Tue, 27 Jul 2010 14:43:14 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=4137#comment-7740</guid>
		<description>Something that hasn&#039;t been said enough is the value of using a limited user account! As with most malware, it needs full administrator access to fully infect a system. Those areas of the hard drive and registry (listed below) are READ ONLY when you&#039;re logged in with a limited user, so the malware is unable to write there and is unable to do its bidding! Of course all of this is assuming malware gets past your primary defenses first. Thus, the value of a multi-layered defense!

From Sophos (http://www.sophos.com/security/analyses/viruses-and-spyware/w32stuxnetb.html):

&quot;When W32/Stuxnet-B is run, it installs rootkit component by creating files:

\drivers\mrxcls.sys
\drivers\mrxnet.sys

The file mrxcls.sys and mrxnet.sys are registered as new services named &quot;MRxCls&quot; and &quot;MRxNet, with display names of &quot;MRXCLS&quot; and &quot;MRXNET&quot; respectively. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\MRxCls
HKLM\SYSTEM\CurrentControlSet\Services\MRxNet 

The rootkit component has funcionalities to hide the presence of W32/Stuxnet-B.&quot;

Symantec has more (http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-071400-3123-99&amp;tabid=2) including mentioning:

&quot;Ensure that programs and users of the computer use the lowest level of privileges necessary to complete a task. When prompted for a root or UAC password, ensure that the program asking for administration-level access is a legitimate application.&quot;</description>
		<content:encoded><![CDATA[<p>Something that hasn&#8217;t been said enough is the value of using a limited user account! As with most malware, it needs full administrator access to fully infect a system. Those areas of the hard drive and registry (listed below) are READ ONLY when you&#8217;re logged in with a limited user, so the malware is unable to write there and is unable to do its bidding! Of course all of this is assuming malware gets past your primary defenses first. Thus, the value of a multi-layered defense!</p>
<p>From Sophos (<a href="http://www.sophos.com/security/analyses/viruses-and-spyware/w32stuxnetb.html" rel="nofollow">http://www.sophos.com/security/analyses/viruses-and-spyware/w32stuxnetb.html</a>):</p>
<p>&#8220;When W32/Stuxnet-B is run, it installs rootkit component by creating files:</p>
<p>\drivers\mrxcls.sys<br />
\drivers\mrxnet.sys</p>
<p>The file mrxcls.sys and mrxnet.sys are registered as new services named &#8220;MRxCls&#8221; and &#8220;MRxNet, with display names of &#8220;MRXCLS&#8221; and &#8220;MRXNET&#8221; respectively. Registry entries are created under:</p>
<p>HKLM\SYSTEM\CurrentControlSet\Services\MRxCls<br />
HKLM\SYSTEM\CurrentControlSet\Services\MRxNet </p>
<p>The rootkit component has funcionalities to hide the presence of W32/Stuxnet-B.&#8221;</p>
<p>Symantec has more (<a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-071400-3123-99&#038;tabid=2" rel="nofollow">http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-071400-3123-99&#038;tabid=2</a>) including mentioning:</p>
<p>&#8220;Ensure that programs and users of the computer use the lowest level of privileges necessary to complete a task. When prompted for a root or UAC password, ensure that the program asking for administration-level access is a legitimate application.&#8221;</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7740" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7740', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7740-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7740" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7740', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7740-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: xAdmin</title>
		<link>http://krebsonsecurity.com/2010/07/tool-blunts-threat-from-windows-shortcut-flaw/comment-page-1/#comment-7739</link>
		<dc:creator>xAdmin</dc:creator>
		<pubDate>Tue, 27 Jul 2010 14:06:56 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=4137#comment-7739</guid>
		<description>Haven&#039;t tried it. I&#039;ve always been very uncomfortable implementing third party fixes. Would rather it come from the vendor directly! Regardless of whether it&#039;s effective or not, IMO, such third party fixes complicate the situation as you&#039;ll have to uninstall it before installing Microsoft&#039;s official patch (when it gets released, hopefully soon). Then you have to hope that the Sophos tool doesn&#039;t leave something behind that may interfere with Microsoft&#039;s patch or prevent its installation.

From what I&#039;ve read on Sophos&#039; fix, it seems more a marketing strategy of, &quot;Look, we came up with a fix, try our product!&quot;

From their site (first link of MowGreen&#039;s post):
&quot;Sophos customers are safe from this exploit. Not a Sophos customer? Try Sophos Endpoint Security and Data Protection for free.&quot;</description>
		<content:encoded><![CDATA[<p>Haven&#8217;t tried it. I&#8217;ve always been very uncomfortable implementing third party fixes. Would rather it come from the vendor directly! Regardless of whether it&#8217;s effective or not, IMO, such third party fixes complicate the situation as you&#8217;ll have to uninstall it before installing Microsoft&#8217;s official patch (when it gets released, hopefully soon). Then you have to hope that the Sophos tool doesn&#8217;t leave something behind that may interfere with Microsoft&#8217;s patch or prevent its installation.</p>
<p>From what I&#8217;ve read on Sophos&#8217; fix, it seems more a marketing strategy of, &#8220;Look, we came up with a fix, try our product!&#8221;</p>
<p>From their site (first link of MowGreen&#8217;s post):<br />
&#8220;Sophos customers are safe from this exploit. Not a Sophos customer? Try Sophos Endpoint Security and Data Protection for free.&#8221;</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7739" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7739', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7739-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7739" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7739', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7739-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://krebsonsecurity.com/2010/07/tool-blunts-threat-from-windows-shortcut-flaw/comment-page-1/#comment-7738</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Tue, 27 Jul 2010 13:54:30 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=4137#comment-7738</guid>
		<description>SANS says the Sophos tool works for .LNKs but not for .PIFs.</description>
		<content:encoded><![CDATA[<p>SANS says the Sophos tool works for .LNKs but not for .PIFs.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7738" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7738', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7738-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7738" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7738', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7738-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Peter</title>
		<link>http://krebsonsecurity.com/2010/07/tool-blunts-threat-from-windows-shortcut-flaw/comment-page-1/#comment-7736</link>
		<dc:creator>Peter</dc:creator>
		<pubDate>Tue, 27 Jul 2010 12:02:16 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=4137#comment-7736</guid>
		<description>Has anyone installed and used/tested this tool?  What have the results been?</description>
		<content:encoded><![CDATA[<p>Has anyone installed and used/tested this tool?  What have the results been?</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7736" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7736', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7736-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7736" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7736', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7736-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: MowGreen</title>
		<link>http://krebsonsecurity.com/2010/07/tool-blunts-threat-from-windows-shortcut-flaw/comment-page-1/#comment-7719</link>
		<dc:creator>MowGreen</dc:creator>
		<pubDate>Mon, 26 Jul 2010 17:38:47 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=4137#comment-7719</guid>
		<description>Sophos has a issued a tool to provide protection from this vulnerability: 
Windows Shortcut Exploit
Protection Tool
http://www.sophos.com/products/free-tools/sophos-windows-shortcut-exploit-protection-tool.html

Sophos KB article explaining how it works: 
http://www.sophos.com/support/knowledgebase/article/111570.html</description>
		<content:encoded><![CDATA[<p>Sophos has a issued a tool to provide protection from this vulnerability:<br />
Windows Shortcut Exploit<br />
Protection Tool<br />
<a href="http://www.sophos.com/products/free-tools/sophos-windows-shortcut-exploit-protection-tool.html" rel="nofollow">http://www.sophos.com/products/free-tools/sophos-windows-shortcut-exploit-protection-tool.html</a></p>
<p>Sophos KB article explaining how it works:<br />
<a href="http://www.sophos.com/support/knowledgebase/article/111570.html" rel="nofollow">http://www.sophos.com/support/knowledgebase/article/111570.html</a></p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7719" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7719', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7719-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7719" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7719', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7719-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 5/18 queries in 0.004 seconds using memcached
Object Caching 969/975 objects using memcached

Served from: krebsonsecurity.com @ 2012-05-23 19:30:06 -->
