<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>System7 &#187; anti-virus</title>
	<atom:link href="http://www.system7.org/tag/anti-virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.system7.org</link>
	<description>Spread the word, information is free.</description>
	<lastBuildDate>Mon, 16 Jan 2012 13:24:39 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>wtf</title>
		<link>http://www.system7.org/2011/08/13/wtf/</link>
		<comments>http://www.system7.org/2011/08/13/wtf/#comments</comments>
		<pubDate>Sat, 13 Aug 2011 13:19:16 +0000</pubDate>
		<dc:creator>.</dc:creator>
				<category><![CDATA[apple]]></category>
		<category><![CDATA[hardware & software]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[vmware]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=859</guid>
		<description><![CDATA[]]></description>
			<content:encoded><![CDATA[<div id="attachment_860" class="wp-caption alignnone" style="width: 310px"><a href="http://www.system7.org/wp-content/uploads/2011/08/Screen-shot-2011-06-27-at-9.30.41-PM.png"><img class="size-medium wp-image-860" title="VMWare Fusion Recommends Anti-Virus" src="http://www.system7.org/wp-content/uploads/2011/08/Screen-shot-2011-06-27-at-9.30.41-PM-300x271.png" alt="" width="300" height="271" /></a><p class="wp-caption-text">VMWare Fusion Recommends Anti-Virus</p></div>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2011/08/13/wtf/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SophosLabs Released Free Tool to Validate Microsoft Shortcut</title>
		<link>http://www.system7.org/2010/07/27/sophoslabs-released-free-tool-to-validate-microsoft-shortcut/</link>
		<comments>http://www.system7.org/2010/07/27/sophoslabs-released-free-tool-to-validate-microsoft-shortcut/#comments</comments>
		<pubDate>Tue, 27 Jul 2010 09:42:46 +0000</pubDate>
		<dc:creator>.</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=590</guid>
		<description><![CDATA[I read this on the Internet Storm Center yesterday.  Sophos has released a tool that will provide detection against the Windows shortcut exploit announced last week (originally being used to exploit Siemens SCADA machines).  Be careful, this is a nasty &#8230; <a href="http://www.system7.org/2010/07/27/sophoslabs-released-free-tool-to-validate-microsoft-shortcut/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I read this on the <a href="http://isc.sans.edu/diary.html?storyid=9268&amp;rss">Internet Storm Center yesterday</a>.  <a href="http://www.sophos.com/products/free-tools/sophos-windows-shortcut-exploit-protection-tool.html">Sophos has released a tool</a> that will provide detection against the Windows shortcut exploit announced last week (originally being used to <a title="Stuxnet worm" href="http://www.schneier.com/blog/archives/2010/07/internet_worm_t.html">exploit Siemens SCADA machines</a>).  Be careful, this is a nasty vulnerability with a large scope &#8212; the entire Windows family of OS going back to NT as far I&#8217;m aware.  If you want to play with the vulnerability yourself it has to be <a title="Microsoft Windows Shell LNK Code Execution" href="http://www.metasploit.com/modules/exploit/windows/browser/ms10_xxx_windows_shell_lnk_execute">added to Metasploit</a> &#8212; thanks <a href="http://digitaloffense.net/">hd</a>!</p>
<p>SophosLabs has made a video available on what is the exploit and how the tool works <a href="http://www.youtube.com/watch?v=Gucn5xWZ1m8">here</a> and the tool is available for downloaded <a href="http://www.sophos.com/products/free-tools/sophos-windows-shortcut-exploit-protection-tool.html">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2010/07/27/sophoslabs-released-free-tool-to-validate-microsoft-shortcut/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trend Officescan &#8211; Proof of concept</title>
		<link>http://www.system7.org/2009/06/06/trend-officescan-proof-of-concept/</link>
		<comments>http://www.system7.org/2009/06/06/trend-officescan-proof-of-concept/#comments</comments>
		<pubDate>Sat, 06 Jun 2009 19:19:29 +0000</pubDate>
		<dc:creator>.</dc:creator>
				<category><![CDATA[hardware & software]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[avg]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[trend]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=206</guid>
		<description><![CDATA[In April a Trend vulnerability was discovered.  The Trend real time scan service can be exploited by running a scan on a long directory name.  It&#8217;s surprising that this vulnerability was discovered and yet is still exploitable in the latest &#8230; <a href="http://www.system7.org/2009/06/06/trend-officescan-proof-of-concept/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>In April a <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1435">Trend vulnerability</a> was discovered.  The Trend real time scan service can be exploited by running a scan on a long directory name.  It&#8217;s surprising that this vulnerability was discovered and yet is still exploitable in the latest release of Trend &#8212; which I&#8217;ve confirmed today.  What&#8217;s neat is someone who only has user level privilege on a machine would be able to halt the Trend service and then potentially run some nasty code.</p>
<p>Here&#8217;s a VB project that will generate a long directory name and then attempt to run the scan: <a href="http://www.system7.org/wp-content/uploads/2009/06/office-scan.zip">Trend POC</a> (I&#8217;ve also compiled the source for those who don&#8217;t have VB &#8212; rename the .exe_ to .exe)</p>
<p>I&#8217;m running <a href="http://free.avg.com">AVG Free</a> on my Windows machine and happy with that.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2009/06/06/trend-officescan-proof-of-concept/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

