<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Hero &#187; Virus</title>
	<atom:link href="http://sechero.com/tag/virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://sechero.com</link>
	<description>If it's about security, you heard it here first</description>
	<lastBuildDate>Mon, 12 Jul 2010 23:27:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Adobe Reader / Acrobat and Flash Remote Code Execution</title>
		<link>http://sechero.com/adobe-reader-acrobat-and-flash-remote-code-execution/</link>
		<comments>http://sechero.com/adobe-reader-acrobat-and-flash-remote-code-execution/#comments</comments>
		<pubDate>Fri, 24 Jul 2009 02:48:07 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Bugtraq]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Mail]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://sechero.com/?p=20895</guid>
		<description><![CDATA[Adobe Reader / Acrobat and Flash Remote Code Execution Summary: Fortinet&#8217;s FortiGuard Global Security Research Team investigates a vulnerability in multiple Adobe products through SWF. Impact: Remote Code Execution. Affected Software: Adobe Reader and Acrobat 9.1.2 and earlier 9.x versions Adobe Flash Player 9.0.159.0 and 10.0.22.87 and earlier 9.x and 10.x versions Solutions: The FortiGuard [...]]]></description>
			<content:encoded><![CDATA[<h1><a href="http://www.fortiguardcenter.com/advisory/FGA-2009-29.html">Adobe Reader / Acrobat and Flash Remote Code Execution</a></h1>
<p><b>Summary:</b></p>
<p>Fortinet&#8217;s FortiGuard Global Security Research Team investigates a vulnerability in multiple Adobe products through SWF.</p>
<p><b>Impact:</b></p>
<p>Remote Code Execution.</p>
<p><b>Affected Software:</b>
<ul>
<li>Adobe Reader and Acrobat 9.1.2 and earlier 9.x versions</li>
<li>Adobe Flash Player 9.0.159.0 and 10.0.22.87 and earlier 9.x and 10.x versions</li>
</ul>
<p><b>Solutions:</b>
<ul>
<li>The FortiGuard Global Security Research Team released a signature &#8220;Adobe.Products.SWF.Remote.Code.Execution&#8221;, which covers this specific vulnerability.</li>
<li>Apply the suggested workaround <a href="http://www.adobe.com/support/security/advisories/apsa09-03.html">from Adobe</a></li>
</ul>
<p>The FortiGuard Global Security Research Team continues to monitor attacks against this vulnerability.</p>
<p>Fortinet customers who subscribe to Fortinet¡¦s intrusion prevention (IPS) service should be protected against this remote code execution vulnerability. Fortinet¡¦s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat&#8217;s lifecycle. </p>
<p><b>References:</b>
<ul>
<li>Adobe Security Advisory: <a href="http://www.adobe.com/support/security/advisories/apsa09-03.html">APSA09-03</a></li>
<li>Adobe PSIRT: <a href="http://blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.html">http://blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.html</a></li>
<li>CVE ID: <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1862">CVE-2009-1862</a></li>
<li>Bugtraq ID: <a href="http://www.securityfocus.com/bid/35759">35759</a></li>
</ul>
<p>
<p>URL: <a href="http://www.fortiguardcenter.com/advisory/FGA-2009-29.html">http://www.fortiguardcenter.com/advisory/FGA-2009-29.html</a></p>
<p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/adobe-reader-acrobat-and-flash-remote-code-execution/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Its summer&#8230;Do you know what your kids are doing?, (Fri, May 29th)</title>
		<link>http://sechero.com/its-summerdo-you-know-what-your-kids-are-doing-fri-may-29th/</link>
		<comments>http://sechero.com/its-summerdo-you-know-what-your-kids-are-doing-fri-may-29th/#comments</comments>
		<pubDate>Fri, 29 May 2009 18:42:56 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Chat]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Its summer&#8230;Do you know what your kids are doing?, (Fri, May 29th) School is over or about to be over for many kids. With that comes many families whose parents work and kids will be left at home to relax and enjoy their summer vacation. This means alot of free time and an internet out [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://isc.sans.org/diary.php?storyid=6490&amp;rss">Its summer&#8230;Do you know what your kids are doing?, (Fri, May 29th)</a></h1>
</p>
<p>School is over or about to be over for many kids. With that comes many families whose parents work and kids will be left at home to relax and enjoy their summer vacation. This means alot of free time and an internet out there just waiting to be explored. Everyone is aware of the need to keep your kids safe while on the internet. But in some cases, there is a need to keep the internet and others safe from your kids. Let me explain that last comment. Kids with too much time on their hands get into trouble. You hear about it all the time on the news with kids getting into trouble with things such as vandalism, stealing,etc. What about kids getting into trouble on the internet?<br /> Do a google search on the phrase teenage hacker and see what comes up. Kids are curious and learn fast. The internet can become a playground for them to explore and test out cool new programs and tools they find on the internet or write themselves. Chat rooms are available where kids can learn many things from others and want to try them for themselves. They can also get pulled into the wrong crowd on the internet and get in way over their heads fast. They may not even see anything wrong with it, its just computers after all.<br /> Most of the filtering technology today focuses on web traffic. What are your kids looking at on the web. That is a good thing, but there are many other ports and protocols available and nothing watching them. Would you know if your child was running a botnet? Stealing credit card numbers? Hacking into websites? Its not a game and there are real consequences to it, even sometimes when the intent may have been to do good.Here are some recent examples:<br /> Nineteen-year-old  Dmitriy Guzner from New Jersey was part of an underground hacking group named  &#8216;Anonymous&#8217; that targeted the church with several attacks. He could face ten  years in prison on computer hacking charges and is due to be sentenced on August  24. <a href="http://www.securecomputing.net.au/News/144850,teenage-hacker-pleads-guilty-to-church-of-scientology-cyber-attacks.aspx<br" title="http://www.securecomputing.net.au/News/144850,teenage-hacker-pleads-guilty-to-church-of-scientology-cyber-attacks.aspx<br" target="_blank">www.securecomputing.net.au/News/144850,teenage-hacker-pleads-guilty-to-church-of-scientology-cyber-attacks.aspx<br</a> /></p>
<p></p>
<p> Twitter has announced a review into four worm attacks on the site as a teenage hacker admits he could be jailed for his role in the stunt. <a href="http://news.sky.com/skynews/Home/Technology/Twitter-Worm-Attack-Biz-Stone-Announces-Review-As-Teenage-Hacker-Michael-Mooney-Speaks-Out/Article/200904215261579<br" title="http://news.sky.com/skynews/Home/Technology/Twitter-Worm-Attack-Biz-Stone-Announces-Review-As-Teenage-Hacker-Michael-Mooney-Speaks-Out/Article/200904215261579<br" target="_blank">news.sky.com/skynews/Home/Technology/Twitter-Worm-Attack-Biz-Stone-Announces-Review-As-Teenage-Hacker-Michael-Mooney-Speaks-Out/Article/200904215261579<br</a> /> A teenage hacker whose campaign to expose holes in Internet security sparked an FBI investigation was being sentenced in court today. <a href="http://www.independent.co.uk/news/business/news/teenage-hacker-to-be-sentenced-for-internet-crusade-676871.html<br" title="http://www.independent.co.uk/news/business/news/teenage-hacker-to-be-sentenced-for-internet-crusade-676871.html<br" target="_blank">www.independent.co.uk/news/business/news/teenage-hacker-to-be-sentenced-for-internet-crusade-676871.html<br</a> /> <br /> As parents, we need to also talk to our kids about the other dangers that are on the internet. Dangers such as hacking, virus making, botnet creation, stealing, etc. You may think your child is doing nothing but sitting on a computer playing. But keep in mind that computer on the internet is a portal to a whole nother world.
<p>URL: <a href="http://isc.sans.org/diary.php?storyid=6490&amp;rss">http://isc.sans.org/diary.php?storyid=6490&amp;rss</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/its-summerdo-you-know-what-your-kids-are-doing-fri-may-29th/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>4116</title>
		<link>http://sechero.com/4116/</link>
		<comments>http://sechero.com/4116/#comments</comments>
		<pubDate>Fri, 29 May 2009 08:23:12 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AdWare]]></category>
		<category><![CDATA[Downloader]]></category>
		<category><![CDATA[Fake]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[4116 BAT/Qhost.NBP (2), INF/Autorun (3), PDF/Exploit.Pidief.ONM, PDF/Exploit.Pidief.ONN (2), PDF/Exploit.Pidief.ONO, PDF/Exploit.Pidief.ONP (2), Win32/Adware.BHO.NCX, Win32/Adware.Coolezweb (4), Win32/Adware.InternetAntivirus, Win32/Adware.PersonalAntivirus, Win32/Adware.SpywareRemover, Win32/Adware.SystemSecurity (18), Win32/Agent.PMR (2), Win32/Agent.WPI, Win32/AntiAV.AZQ, Win32/AntiAV.NAO (2), Win32/AutoRun.ABH, Win32/AutoRun.ADR (2), Win32/AutoRun.FakeAlert.BR, Win32/AutoRun.FakeAlert.M, Win32/AutoRun.VB.CN (2), Win32/Bagle.RG, Win32/Delf.NSQ (3), Win32/Dialer.NHQ (3), Win32/Dialer.NHR (3), Win32/FlyStudio.NMJ, Win32/FlyStudio.NMK, Win32/Hupigon.NPD, Win32/Injector.PK, Win32/IRCBot.ADZ, Win32/Koobface.NBG (2), Win32/Koutodoor.AB, Win32/Koutodoor.AD, Win32/Koutodoor.AE (4), Win32/Koutodoor.G, Win32/Kryptik.QY, Win32/Olmarik.GW (2), Win32/Olmarik.HG [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6085&amp;Itemid=26">4116</a></h1>
</p>
<p>BAT/Qhost.NBP (2), INF/Autorun (3), PDF/Exploit.Pidief.ONM, PDF/Exploit.Pidief.ONN (2), PDF/Exploit.Pidief.ONO, PDF/Exploit.Pidief.ONP (2), Win32/Adware.BHO.NCX, Win32/Adware.Coolezweb (4), Win32/Adware.InternetAntivirus, Win32/Adware.PersonalAntivirus, Win32/Adware.SpywareRemover, Win32/Adware.SystemSecurity (18), Win32/Agent.PMR (2), Win32/Agent.WPI, Win32/AntiAV.AZQ, Win32/AntiAV.NAO (2), Win32/AutoRun.ABH, Win32/AutoRun.ADR (2), Win32/AutoRun.FakeAlert.BR, Win32/AutoRun.FakeAlert.M, Win32/AutoRun.VB.CN (2), Win32/Bagle.RG, Win32/Delf.NSQ (3), Win32/Dialer.NHQ (3), Win32/Dialer.NHR (3), Win32/FlyStudio.NMJ, Win32/FlyStudio.NMK, Win32/Hupigon.NPD, Win32/Injector.PK, Win32/IRCBot.ADZ, Win32/Koobface.NBG (2), Win32/Koutodoor.AB, Win32/Koutodoor.AD, Win32/Koutodoor.AE (4), Win32/Koutodoor.G, Win32/Kryptik.QY, Win32/Olmarik.GW (2), Win32/Olmarik.HG (4), Win32/Olmarik.IB, Win32/Peerfrag.BA, Win32/Peerfrag.BG, Win32/Peerfrag.BH, Win32/Popwin.NBJ (2), Win32/PSW.OnLineGames.NMP, Win32/PSW.OnLineGames.NMY, Win32/PSW.OnLineGames.OKC, Win32/PSW.Small.NBE (4), Win32/Qhost, Win32/Qhost.NIJ (2), Win32/Rootkit.Agent.KZU, Win32/Rootkit.Ressdt.NBS, Win32/Spy.Banker.QRW (2), Win32/Spy.Banker.QYO (3), Win32/Spy.Banker.QZB (2), Win32/Spy.Banker.QZC (2), Win32/Spy.Goldun.NFA, Win32/Spy.Zbot.JF (3), Win32/Spy.Zbot.PG (2), Win32/Spy.Zbot.RD, Win32/Spy.Zbot.RN, Win32/Tifaut.C (4), Win32/TrojanDownloader.Agent.PCZ, Win32/TrojanDownloader.Agent.PDA, Win32/TrojanDownloader.Agent.PDB, Win32/TrojanDownloader.Agent.PDC, Win32/TrojanDownloader.Agent.PDD, Win32/TrojanDownloader.Bagle.NBJ, Win32/TrojanDownloader.Bredolab.AB, Win32/TrojanDownloader.FakeAlert.AAX, Win32/TrojanDownloader.FakeAlert.ABV, Win32/TrojanDownloader.Small.OPS (2), Win32/TrojanDownloader.Zlob.CZK, Win32/VB.NHD, Win32/VB.OEY (2), Win32/Wigon.KX
<p>URL: <a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6085&amp;Itemid=26">http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6085&amp;Itemid=26</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/4116/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft DirectShow Remote Code Execution Vulnerability</title>
		<link>http://sechero.com/microsoft-directshow-remote-code-execution-vulnerability/</link>
		<comments>http://sechero.com/microsoft-directshow-remote-code-execution-vulnerability/#comments</comments>
		<pubDate>Fri, 29 May 2009 08:00:00 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Mail]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Microsoft DirectShow Remote Code Execution Vulnerability Summary: Fortinet&#8217;s FortiGuard Global Security Research Team investigates a vulnerability in Microsoft DirectX (DirectShow) through a specially crafted QuickTime media file. Impact: Remote Code Execution. Affected Software: DirectX 7.0 on Microsoft Windows 2000 Service Pack 4 DirectX 8.1 on Microsoft Windows 2000 Service Pack 4 DirectX 9.0 on Microsoft [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.fortiguardcenter.com/advisory/FGA-2009-20.html">Microsoft DirectShow Remote Code Execution Vulnerability</a></h1>
</p>
<p><b>Summary:</b></p>
<p>Fortinet&#8217;s FortiGuard Global Security Research Team investigates a vulnerability in Microsoft DirectX (DirectShow) through a specially crafted QuickTime media file.</p>
<p><b>Impact:</b></p>
<p>Remote Code Execution.</p>
<p><b>Affected Software:</b>
<ul>
<li>DirectX 7.0 on Microsoft Windows 2000 Service Pack 4</li>
<li>DirectX 8.1 on Microsoft Windows 2000 Service Pack 4</li>
<li>DirectX 9.0 on Microsoft Windows 2000 Service Pack 4</li>
<li>DirectX 9.0 on Windows XP Service Pack 2 and Windows XP Service Pack 3</li>
<li>DirectX 9.0 on Windows XP Professional x64 Edition Service Pack 2</li>
<li>DirectX 9.0 on Windows Server 2003 Service Pack 2</li>
<li>DirectX 9.0 on Windows Server 2003 x64 Edition Service Pack 2</li>
<li>DirectX 9.0 on Windows Server 2003 with SP2 for Itanium-based Systems</li>
</ul>
<p><b>Solutions:</b>
<ul>
<li>The FortiGuard Global Security Research Team released a signature &#8220;MS.DirectShow.NULL.Byte.Overwrite&#8221;, which covers this specific vulnerability.</li>
</ul>
<p>The FortiGuard Global Security Research Team continues to monitor attacks against this vulnerability.</p>
<p>Fortinet customers who subscribe to Fortinet¡¦s intrusion prevention (IPS) service should be protected against this remote code execution vulnerability. Fortinet¡¦s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat&#8217;s lifecycle. </p>
<p><b>References:</b>
<ul>
<li>Microsoft Security Advisory: <a href="http://www.microsoft.com/technet/security/advisory/971778.mspx">http://www.microsoft.com/technet/security/advisory/971778.mspx</a></li>
<li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1537">CVE-2009-1537</a></li>
</ul>
<p>URL: <a href="http://www.fortiguardcenter.com/advisory/FGA-2009-20.html">http://www.fortiguardcenter.com/advisory/FGA-2009-20.html</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/microsoft-directshow-remote-code-execution-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Advanced Two-Way Firewall for Mac OS X unveiled</title>
		<link>http://sechero.com/advanced-two-way-firewall-for-mac-os-x-unveiled/</link>
		<comments>http://sechero.com/advanced-two-way-firewall-for-mac-os-x-unveiled/#comments</comments>
		<pubDate>Fri, 29 May 2009 00:46:32 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Advanced Two-Way Firewall for Mac OS X unveiled ProteMac has announced ProteMac NetMine 1.2, their network firewall for Mac OS X. ProteMac NetMine intercepts all network activity traveling from and to your Mac and from every an application of your Mac. NetMine firewall can prevent all unwanted outside and inside traffic from reaching protected machines. [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31491">Advanced Two-Way Firewall for Mac OS X unveiled</a></h1>
</p>
<p>ProteMac has announced ProteMac NetMine 1.2, their network firewall for Mac OS X. ProteMac NetMine intercepts all network activity traveling from and to your Mac and from every an application of your Mac. NetMine firewall can prevent all unwanted outside and inside traffic from reaching protected machines. </p>
<p>Firewall can restrict or prevent outright the spread of networked computer worms, trojans, viruses and malware. NetMine firewall is a new breed of information security technology designed to protect Mac OS X computers from attack from outside network and from software on your computer. </p>
<p>The two-way firewall stops inappropriate or malicious access to your computer from both internal and external network sources. As a frontline defense, it prevents malware from spreading, providing protection against hackers, loss of personal data, unknown malware, and unauthorized program activity.
<p>URL: <a href="http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31491">http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31491</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/advanced-two-way-firewall-for-mac-os-x-unveiled/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>4114</title>
		<link>http://sechero.com/4114/</link>
		<comments>http://sechero.com/4114/#comments</comments>
		<pubDate>Thu, 28 May 2009 20:36:55 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AdWare]]></category>
		<category><![CDATA[Downloader]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[4114 IRC/SdBot, Win32/Adware.Coolezweb (5), Win32/Adware.InternetAntivirus, Win32/Agent.WPI, Win32/AutoRun.Autoit.P, Win32/AutoRun.Delf.CB (2), Win32/AutoRun.IRCBot.AM (2), Win32/BHO.NLG, Win32/Kryptik.QW, Win32/Olmarik.HG (4), Win32/PSW.YahooPass.AF, Win32/Spy.Webmoner.NBN, Win32/Spy.Zbot.CK, Win32/TrojanClicker.Delf.NBA, Win32/TrojanClicker.Delf.NDS, Win32/TrojanClicker.Delf.NFC, Win32/TrojanDownloader.Adload.FIB (2) URL: http://www.eset.com/joomla/index.php?option=com_content&#38;task=view&#38;id=6083&#38;Itemid=26]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6083&amp;Itemid=26">4114</a></h1>
</p>
<p>IRC/SdBot, Win32/Adware.Coolezweb (5), Win32/Adware.InternetAntivirus, Win32/Agent.WPI, Win32/AutoRun.Autoit.P, Win32/AutoRun.Delf.CB (2), Win32/AutoRun.IRCBot.AM (2), Win32/BHO.NLG, Win32/Kryptik.QW, Win32/Olmarik.HG (4), Win32/PSW.YahooPass.AF, Win32/Spy.Webmoner.NBN, Win32/Spy.Zbot.CK, Win32/TrojanClicker.Delf.NBA, Win32/TrojanClicker.Delf.NDS, Win32/TrojanClicker.Delf.NFC, Win32/TrojanDownloader.Adload.FIB (2)
<p>URL: <a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6083&amp;Itemid=26">http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6083&amp;Itemid=26</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/4114/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>4113</title>
		<link>http://sechero.com/4113/</link>
		<comments>http://sechero.com/4113/#comments</comments>
		<pubDate>Thu, 28 May 2009 10:40:12 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AdWare]]></category>
		<category><![CDATA[Downloader]]></category>
		<category><![CDATA[Fake]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[Mail]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Proxy]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[4113 BAT/Agent.NBW, PDF/Exploit.Pidief.ONK, Win32/Adware.Antivirus2008 (2), Win32/Adware.Coolezweb (2), Win32/Adware.InternetAntivirus (5), Win32/Adware.SystemSecurity (4), Win32/Agent.NXT, Win32/Agent.PHC, Win32/Agent.PKT (2), Win32/Agent.WPI (4), Win32/AutoRun.Agent.OG, Win32/AutoRun.Agent.OH, Win32/AutoRun.Agent.OI, Win32/AutoRun.FakeAlert.AF (3), Win32/AutoRun.KS, Win32/AutoRun.VB.DQ, Win32/Boberog.AC, Win32/Dialer.NHP (2), Win32/Hupigon.NPB, Win32/Hupigon.NPC, Win32/Injector.PH, Win32/Injector.PI, Win32/IRCBot.ADZ (2), Win32/KeyLogger.BitLogic, Win32/NetPass (2), Win32/Obfuscated.NCY, Win32/Olmarik.HG (4), Win32/Poebot, Win32/Prosti.NCL (2), Win32/PSW.LdPinch.NJG, Win32/PSW.WOW.NKO (2), Win32/PSW.YahooPass.NAD (2), Win32/PSWTool.IEPassView.NAD, Win32/PSWTool.MailPassView.150, Win32/PSWTool.PassFox.111 (2), Win32/Rustock.NIH, Win32/Rustock.NIK, Win32/Sohanad.BM, Win32/Sohanad.NEJ, [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6082&amp;Itemid=26">4113</a></h1>
</p>
<p>BAT/Agent.NBW, PDF/Exploit.Pidief.ONK, Win32/Adware.Antivirus2008 (2), Win32/Adware.Coolezweb (2), Win32/Adware.InternetAntivirus (5), Win32/Adware.SystemSecurity (4), Win32/Agent.NXT, Win32/Agent.PHC, Win32/Agent.PKT (2), Win32/Agent.WPI (4), Win32/AutoRun.Agent.OG, Win32/AutoRun.Agent.OH, Win32/AutoRun.Agent.OI, Win32/AutoRun.FakeAlert.AF (3), Win32/AutoRun.KS, Win32/AutoRun.VB.DQ, Win32/Boberog.AC, Win32/Dialer.NHP (2), Win32/Hupigon.NPB, Win32/Hupigon.NPC, Win32/Injector.PH, Win32/Injector.PI, Win32/IRCBot.ADZ (2), Win32/KeyLogger.BitLogic, Win32/NetPass (2), Win32/Obfuscated.NCY, Win32/Olmarik.HG (4), Win32/Poebot, Win32/Prosti.NCL (2), Win32/PSW.LdPinch.NJG, Win32/PSW.WOW.NKO (2), Win32/PSW.YahooPass.NAD (2), Win32/PSWTool.IEPassView.NAD, Win32/PSWTool.MailPassView.150, Win32/PSWTool.PassFox.111 (2), Win32/Rustock.NIH, Win32/Rustock.NIK, Win32/Sohanad.BM, Win32/Sohanad.NEJ, Win32/Spy.Banker.QZA, Win32/Spy.KeyLogger.NEC (2), Win32/Spy.Zbot.CK, Win32/Spy.Zbot.JF, Win32/Spy.Zbot.RL, Win32/Spy.Zbot.RM, Win32/StartPage.BR, Win32/StartPage.NKJ (3), Win32/TrojanClicker.Agent.NGT (2), Win32/TrojanClicker.VB.NHG (2), Win32/TrojanClicker.VB.NHH, Win32/TrojanDownloader.Agent.PAQ (2), Win32/TrojanDownloader.Agent.PCY, Win32/TrojanDownloader.Bredolab.AB (2), Win32/TrojanDownloader.FakeAlert.UX, Win32/TrojanDownloader.Small.NTQ (3), Win32/TrojanDownloader.Small.OCS (2), Win32/TrojanDownloader.Small.OOT, Win32/TrojanDownloader.Small.OPP, Win32/TrojanDownloader.Small.OPR, Win32/TrojanDownloader.Zlob.CZK, Win32/TrojanDropper.VB.NHW, Win32/TrojanProxy.Wintu.B
<p>URL: <a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6082&amp;Itemid=26">http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6082&amp;Itemid=26</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/4113/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>4110</title>
		<link>http://sechero.com/4110/</link>
		<comments>http://sechero.com/4110/#comments</comments>
		<pubDate>Wed, 27 May 2009 20:59:40 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[AdWare]]></category>
		<category><![CDATA[Downloader]]></category>
		<category><![CDATA[Fake]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Proxy]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[4110 BAT/TrojanDownloader.Ftp.NDM, BAT/TrojanDownloader.Ftp.NDN, IRC/SdBot (2), PDF/Exploit.Pidief.ONF, Win32/Adware.AntiVirus1, Win32/Adware.Antivirus2008, Win32/Adware.AntivirusPlus (2), Win32/Adware.BHO.NCX, Win32/Adware.MySideSearch, Win32/Adware.NaviPromo (2), Win32/Adware.PersonalAntivirus (2), Win32/Adware.PrivacyComponents, Win32/Adware.UltraAntivirus2009 (3), Win32/Adware.Virtumonde (2), Win32/Adware.WinPCDefender, Win32/Agent.DKR (2), Win32/Agent.PGA, Win32/Agent.PKT, Win32/Agent.PMI (3), Win32/AntiAVNAK (2), Win32/Autoit.FV (2), Win32/AutoRun.FlyStudio.KC, Win32/AutoRun.IRCBot.AK, Win32/AutoRun.KS, Win32/AutoRun.VB.CX (2), Win32/AutoRun.VB.DP (2), Win32/Bagle.RD, Win32/BHO.NOR, Win32/Delf.ODU, Win32/Delf.OJB, Win32/Dialer.NAD, Win32/Hupigon.NOU, Win32/KillAV.NDT (4), Win32/KillProc.NAF, Win32/Kryptik.QR, Win32/Kryptik.QS, Win32/Mebroot.BL, Win32/Mebroot.BM (2), Win32/Mebroot.BN (2), [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6079&amp;Itemid=26">4110</a></h1>
</p>
<p>BAT/TrojanDownloader.Ftp.NDM, BAT/TrojanDownloader.Ftp.NDN, IRC/SdBot (2), PDF/Exploit.Pidief.ONF, Win32/Adware.AntiVirus1, Win32/Adware.Antivirus2008, Win32/Adware.AntivirusPlus (2), Win32/Adware.BHO.NCX, Win32/Adware.MySideSearch, Win32/Adware.NaviPromo (2), Win32/Adware.PersonalAntivirus (2), Win32/Adware.PrivacyComponents, Win32/Adware.UltraAntivirus2009 (3), Win32/Adware.Virtumonde (2), Win32/Adware.WinPCDefender, Win32/Agent.DKR (2), Win32/Agent.PGA, Win32/Agent.PKT, Win32/Agent.PMI (3), Win32/AntiAVNAK (2), Win32/Autoit.FV (2), Win32/AutoRun.FlyStudio.KC, Win32/AutoRun.IRCBot.AK, Win32/AutoRun.KS, Win32/AutoRun.VB.CX (2), Win32/AutoRun.VB.DP (2), Win32/Bagle.RD, Win32/BHO.NOR, Win32/Delf.ODU, Win32/Delf.OJB, Win32/Dialer.NAD, Win32/Hupigon.NOU, Win32/KillAV.NDT (4), Win32/KillProc.NAF, Win32/Kryptik.QR, Win32/Kryptik.QS, Win32/Mebroot.BL, Win32/Mebroot.BM (2), Win32/Mebroot.BN (2), Win32/Olmarik.GW, Win32/Olmarik.HG (2), Win32/Olmarik.HX (2), Win32/Olmarik.HY (2), Win32/Olmarik.HZ (2), Win32/OlmarikIA (2), Win32/Patched.AW, Win32/PcClient.NDW, Win32/Peerfrag.BD, Win32/Peerfrag.BE, Win32/PSW.Agent.NJL, Win32/PSW.OnLineGames.NMP (7), Win32/PSW.OnLineGames.NMY (11), Win32/PSW.OnLineGames.NNU (4), Win32/PSW.OnLineGames.ODJ (2), Win32/PSW.OnLineGames.OKC, Win32/PSW.OnLineGames.OKD, Win32/PSW.OnLineGames.XTT, Win32/Rootkit.Agent.NLY (2), Win32/Rustock.NIL (2), Win32/SpamTool.Agent.NCL, Win32/Spy.Banker.QYV (2), Win32/Spy.Banker.QYW (2), Win32/Spy.Banker.QYX (2), Win32/Spy.Zbot.JF (2), Win32/Spy.Zbot.RK, Win32/TrojanClicker.Delf.NHF, Win32/TrojanDownloader.Agent.OXA, Win32/TrojanDownloader.Agent.PCX, Win32/TrojanDownloader.Delf.ORH, Win32/TrojanDownloader.FakeAlert.AAX, Win32/TrojanDownloader.FakeAlert.ACE, Win32/TrojanDownloader.FakeAlert.ACT, Win32/TrojanDownloader.Small.OCS, Win32/TrojanDownloader.VB.NXX (2), Win32/TrojanDownloader.Zlob.CUG, Win32/TrojanDownloader.Zlob.CZW (2), Win32/TrojanDropper.Mudrop.NAM, Win32/TrojanDropper.VB.NHX (3), Win32/TrojanProxy.Small.NCA, Win32/Wigon.KU (2)
<p>URL: <a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6079&amp;Itemid=26">http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6079&amp;Itemid=26</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/4110/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Host file black lists , (Wed, May 27th)</title>
		<link>http://sechero.com/host-file-black-lists-wed-may-27th/</link>
		<comments>http://sechero.com/host-file-black-lists-wed-may-27th/#comments</comments>
		<pubDate>Wed, 27 May 2009 17:21:08 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[ASCII]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Proxy]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Host file black lists , (Wed, May 27th) Henry Hertz Hobbit who maintains a black list of bad hosts wrote in today with some host file links and comments on them. I have included most of his comments with very little editing (I removed a few names and comments about other list maintainers and corrected [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://isc.sans.org/diary.php?storyid=6469&amp;rss">Host file black lists , (Wed, May 27th)</a></h1>
</p>
<p>Henry Hertz Hobbit who maintains a black list of bad hosts wrote in today with some host file links </p>
<p> and comments on them. I have included most of his comments with very little editing</p>
<p> (I removed a few names and comments about other list maintainers and corrected a bit of the grammer). </p>
<p> I have NOT verified all of the lists than Henry discusses below. Our users should be warned that </p>
<p> I have seen poorly maintained lists block legitimate sites in the past. </p>
<p> We have had some less attentive or overly aggressive list maintainers use our hosts </p>
<p> list as a block list even though it clearly states DO NOT USE AS A BLOCK LIST </p>
<p> and then blame <a href="http://isc.sans.org" title="http://isc.sans.org" target="_blank">isc.sans.org</a> for the listing, <a href="http://isc.sans.org/ipsascii.html" title="http://isc.sans.org/ipsascii.html" target="_blank">isc.sans.org/ipsascii.html</a>. </p>
<p> Other handlers have written some excellent diaries about blacklists addressing issues </p>
<p> such as Spam blocking by RBLs, Blacklists and politics, </p>
<p> and making the right choice in black list selection:</p>
<p> <a href="http://isc.sans.org/diary.html?storyid=3194<br" title="http://isc.sans.org/diary.html?storyid=3194<br" target="_blank">isc.sans.org/diary.html?storyid=3194<br</a> /></p>
<p> <a href="http://isc.sans.org/diary.html?storyid=3042<br" title="http://isc.sans.org/diary.html?storyid=3042<br" target="_blank">isc.sans.org/diary.html?storyid=3042<br</a> /></p>
<p> <a href="http://isc.sans.org/diary.html?storyid=1309<br" title="http://isc.sans.org/diary.html?storyid=1309<br" target="_blank">isc.sans.org/diary.html?storyid=1309<br</a> /></p>
</p>
<p> For more information on host based blocking this site has a good descriptions, </p>
<p> some lists that are on Henrys lists and some additional lists didnt include in his set.</p>
<p> <a href="http://www.malwarehelp.org/how-to-effectively-prevent-malware-hosts-file.html<br" title="http://www.malwarehelp.org/how-to-effectively-prevent-malware-hosts-file.html<br" target="_blank">www.malwarehelp.org/how-to-effectively-prevent-malware-hosts-file.html<br</a> /></p>
</p>
<p> &gt;From Henry Hertz Hobbit:</p>
<p> Two old venerable lists are MVPHosts and hpHosts.</p>
<p> <a href="http://www.mvps.org/winhelp2002/hosts.htm<br" title="http://www.mvps.org/winhelp2002/hosts.htm<br" target="_blank">www.mvps.org/winhelp2002/hosts.htm<br</a> /></p>
<p> <a href="http://hosts-file.net/<br" title="http://hosts-file.net/<br" target="_blank">hosts-file.net/<br</a> /></p>
</p>
<p> MalwareDomainList is here with their lists and they block ONLY sites with malicious </p>
<p> content (no ads or trackers / spies):</p>
<p> <a href="http://www.malwaredomainlist.com/hostslist/hosts.txt<br" title="http://www.malwaredomainlist.com/hostslist/hosts.txt<br" target="_blank">www.malwaredomainlist.com/hostslist/hosts.txt<br</a> /></p>
<p> <a href="http://www.malwaredomainlist.com/<br" title="http://www.malwaredomainlist.com/<br" target="_blank">www.malwaredomainlist.com/<br</a> /></p>
<p> <a href="http://www.malwaredomainlist.com/mdl.php<br" title="http://www.malwaredomainlist.com/mdl.php<br" target="_blank">www.malwaredomainlist.com/mdl.php<br</a> /></p>
</p>
<p> The French connection consists of what I would call the MVPHosts file with a Franais twist </p>
<p> (there are some trackers that are quite prevalent if France that don&#8217;t exist any place else):</p>
<p> <a href="http://sysctl.org/cameleon/hosts<br" title="http://sysctl.org/cameleon/hosts<br" target="_blank">sysctl.org/cameleon/hosts<br</a> /></p>
<p> <a href="http://sysctl.org/cameleon/<br" title="http://sysctl.org/cameleon/<br" target="_blank">sysctl.org/cameleon/<br</a> /></p>
</p>
<p> Another list that has the most comprehensive lists that may need some pruning:</p>
<p> <a href="http://rlwpx.free.fr/WPFF/hosts.htm<br" title="http://rlwpx.free.fr/WPFF/hosts.htm<br" target="_blank">rlwpx.free.fr/WPFF/hosts.htm<br</a> /></p>
</p>
<p> This list primarily don&#8217;t belong on the desktop but into something like this:</p>
<p> <a href="http://www.peereboom.us/adsuck/<br" title="http://www.peereboom.us/adsuck/<br" target="_blank">www.peereboom.us/adsuck/<br</a> /></p>
</p>
<p> And then there is my list which includes many of the hosts that MalwareDomainList lists.</p>
<p> <a href="http://www.SecureMecca.com/hosts.html<br" title="http://www.SecureMecca.com/hosts.html<br" target="_blank">www.SecureMecca.com/hosts.html<br</a> /></p>
<p> <a href="http://www.HostsFile.org/hosts.html<br" title="http://www.HostsFile.org/hosts.html<br" target="_blank">www.HostsFile.org/hosts.html<br</a> /></p>
</p>
<p> But I provide something far more powerful called a PAC (Proxy Auto Configuration) filter </p>
<p> that blocks unknown threats:</p>
<p> <a href="http://www.SecureMecca.com/pac.html<br" title="http://www.SecureMecca.com/pac.html<br" target="_blank">www.SecureMecca.com/pac.html<br</a> /></p>
<p> <a href="http://www.HostsFile.org/pac.html<br" title="http://www.HostsFile.org/pac.html<br" target="_blank">www.HostsFile.org/pac.html<br</a> /></p>
<p> <a href="http://www.SecureMecca.com/Downloads/<br" title="http://www.SecureMecca.com/Downloads/<br" target="_blank">www.SecureMecca.com/Downloads/<br</a> /></p>
</p>
<p> Now I have heard you need an IQ of 130 plus or higher to use the PAC filter. </p>
<p> If that is a problem so be it. But consider the following points.</p>
</p>
<p> 1. hpHosts (<a href="http://hosts-file.net" title="http://hosts-file.net" target="_blank">hosts-file.net</a>) blocks approximately 3700 typo hosts. </p>
<p> I block them with just two hosts in the hosts file (<a href="http://ownbox.com" title="http://ownbox.com" target="_blank">ownbox.com</a> and <a href="http://www.ownbox.com" title="http://www.ownbox.com" target="_blank">www.ownbox.com</a>) </p>
<p> and these two rules in the PAC filter:</p>
</p>
<p> // OWNBOX FE TYPO</p>
<p> BadNetworks[i++] = 216.65.41.185, 255.255.255.255</p>
<p> BadNetworks[i++] = 216.65.41.188, 255.255.255.255</p>
</p>
<p> Now that cuts it down to size, doesn&#8217;t it? There is a lot of other power reducers and </p>
<p> falling through the cracks rules in there! Otherwise my file would be almost as large </p>
<p> as the list at rlwpx.free.fr/WPFF/hosts.htm.</p>
</p>
<p> 2. If you enable the PAC filter on Windows in IE you will have your eyes opened. </p>
<p> I had full debug on that way once and found the PAC filter was even working at the level </p>
<p> of tellimg me I sent a print-out to the network printer! But debug really should only </p>
<p> be used in Firefox with debug mode set to debugNormal. Do not turn debug on in Opera or </p>
<p> Safari (they kill it), or IE (you will have pop-up nightmares).</p>
</p>
<p> 3. The REGEXPs are precompiled for speed. It is faster in debug mode than John LoVerso&#8217;s </p>
<p> original was without any debug. But then I noticed some of his ad patterns are pretty convoluted. </p>
<p> But if you have to interpret them every time &#8230;</p>
</p>
<p> 4. I notice patterns that occur frequently enough that I block yet to be discovered </p>
<p> hosts with patterns like these:</p>
<p> BadHostParts[i++] = antispy // VOTRE CHOIX</p>
<p> BadHostParts[i++] = antivir // VOTRE CHOIX</p>
</p>
<p> There are of course some white-list rules to counteract the bad rules </p>
<p> (and now you are back to blocking in the hosts file):</p>
<p> GoodDomains[i++] = <a href="http://antispamfilterblocker.com" title="http://antispamfilterblocker.com" target="_blank">antispamfilterblocker.com</a></p>
<p> GoodDomains[i++] = <a href="http://antivirusyellowpages.com" title="http://antivirusyellowpages.com" target="_blank">antivirusyellowpages.com</a></p>
<p> GoodDomains[i++] = <a href="http://pcantivirusreviews.com" title="http://pcantivirusreviews.com" target="_blank">pcantivirusreviews.com</a></p>
</p>
<p> 5. Even if hosts make it past the rules for the hosts and there is no host block, </p>
<p> for some of the malware there are patterns and I block them as I discover and </p>
<p> mentally count them and consider the count high enough to go into panic mode </p>
<p> (and I think a lot of people are already there now):</p>
</p>
<p> BadURL_Parts[i++] = av2008</p>
<p> BadURL_Parts[i++] = av2009</p>
<p> BadURL_Parts[i++] = sms.exe</p>
<p> BadURL_Parts[i++] = smsreader</p>
</p>
<p> Oh yes, HostsMan is available here:</p>
<p> <a href="http://www.abelhadigital.com/" title="http://www.abelhadigital.com/" target="_blank">www.abelhadigital.com/</a> </p>
<p>
<p>URL: <a href="http://isc.sans.org/diary.php?storyid=6469&amp;rss">http://isc.sans.org/diary.php?storyid=6469&amp;rss</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/host-file-black-lists-wed-may-27th/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>4109</title>
		<link>http://sechero.com/4109/</link>
		<comments>http://sechero.com/4109/#comments</comments>
		<pubDate>Wed, 27 May 2009 07:37:54 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AdWare]]></category>
		<category><![CDATA[Downloader]]></category>
		<category><![CDATA[Fake]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[4109 IRC/SdBot, Win32/Adware.AdvancedCleaner (3), Win32/Adware.BHO.NCG, Win32/Adware.BHO.NCX, Win32/Adware.Coolezweb (2), Win32/Adware.PersonalAntivirus.AA, Win32/Adware.PersonalAntivirus.AB, Win32/Adware.SystemSecurity.AA (2), Win32/Adware.Virtumonde, Win32/Adware.WinPCDefender (2), Win32/Adware.WSearch, Win32/Agent.PME, Win32/Agent.PMF, Win32/Agent.PMG (6), Win32/Agent.PMH (2), Win32/AntiAV.NAK, Win32/AutoRun.Autoit.P, Win32/BHO.NOS, Win32/BHO.NPJ, Win32/BHO.TBL (2), Win32/Bifrose.ADR, Win32/Delf.OJA (2), Win32/Flyagent.NAV (2), Win32/Flyagent.NAW (2), Win32/FlyStudio.NMH, Win32/Injector.PB, Win32/Injector.PC, Win32/Koutodoor.AB (3), Win32/Koutodoor.G, Win32/Kryptik.QO, Win32/Kryptik.QP, Win32/Mebroot.BL, Win32/Merond.P (2), Win32/Olmarik.GW, Win32/Olmarik.HG (2), Win32/Popwin.NBI, Win32/PSW.OnLineGames.NMY, Win32/PSW.OnLineGames.OKB (3), Win32/PSW.QQPass.NEH (4), [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6078&amp;Itemid=26">4109</a></h1>
</p>
<p>IRC/SdBot, Win32/Adware.AdvancedCleaner (3), Win32/Adware.BHO.NCG, Win32/Adware.BHO.NCX, Win32/Adware.Coolezweb (2), Win32/Adware.PersonalAntivirus.AA, Win32/Adware.PersonalAntivirus.AB, Win32/Adware.SystemSecurity.AA (2), Win32/Adware.Virtumonde, Win32/Adware.WinPCDefender (2), Win32/Adware.WSearch, Win32/Agent.PME, Win32/Agent.PMF, Win32/Agent.PMG (6), Win32/Agent.PMH (2), Win32/AntiAV.NAK, Win32/AutoRun.Autoit.P, Win32/BHO.NOS, Win32/BHO.NPJ, Win32/BHO.TBL (2), Win32/Bifrose.ADR, Win32/Delf.OJA (2), Win32/Flyagent.NAV (2), Win32/Flyagent.NAW (2), Win32/FlyStudio.NMH, Win32/Injector.PB, Win32/Injector.PC, Win32/Koutodoor.AB (3), Win32/Koutodoor.G, Win32/Kryptik.QO, Win32/Kryptik.QP, Win32/Mebroot.BL, Win32/Merond.P (2), Win32/Olmarik.GW, Win32/Olmarik.HG (2), Win32/Popwin.NBI, Win32/PSW.OnLineGames.NMY, Win32/PSW.OnLineGames.OKB (3), Win32/PSW.QQPass.NEH (4), Win32/Rootkit.Agent.NLZ (2), Win32/Rootkit.Podnuha.NCB, Win32/Rustock.NIH, Win32/Rustock.NIK, Win32/Spy.Agent.NNQ, Win32/Spy.Banbra.NPR (2), Win32/Spy.Banker.QQJ, Win32/Spy.Banker.QYP (2), Win32/Spy.Banker.QYQ (2), Win32/Spy.Banker.QYR (2), Win32/Spy.Banker.QYS (2), Win32/Spy.Banker.QYT (2), Win32/Spy.Banker.QYU (2), Win32/Spy.Delf.NUL (2), Win32/SpyBot (2), Win32/StartPage.BR, Win32/TrojanDownloader.Adload.NFC, Win32/TrojanDownloader.Agent.PCW (2), Win32/TrojanDownloader.Autoit.NAM, Win32/TrojanDownloader.Bredolab.AA (2), Win32/TrojanDownloader.FakeAlert.AAX, Win32/TrojanDownloader.FakeAlert.ACS (2), Win32/TrojanDownloader.Flux, Win32/TrojanDownloader.Small.OPO, Win32/TrojanDownloader.Swizzor.NCA (2), Win32/TrojanDownloader.Zlob.CZK, Win32/TrojanDownloader.Zlob.CZV (3), Win32/TrojanDropper.Agent.OBD, Win32/TrojanDropper.Delf.NNK, Win32/VB.NRL, Win32/VB.OET (3)
<p>URL: <a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6078&amp;Itemid=26">http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6078&amp;Itemid=26</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/4109/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>4108</title>
		<link>http://sechero.com/4108/</link>
		<comments>http://sechero.com/4108/#comments</comments>
		<pubDate>Wed, 27 May 2009 02:43:16 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AdWare]]></category>
		<category><![CDATA[Downloader]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Proxy]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[4108 IRC/SdBot (2), SWF/Exploit.Agent.AB (2), Win32/Adware.Antivirus2008, Win32/Adware.BHO.NCX, Win32/Adware.SpywareProtect2009 (2), Win32/Adware.XPGuard, Win32/Agent.PIS, Win32/Agent.PIX, Win32/AutoRun.Agent.IE (3), Win32/AutoRun.FlyStudio.KB, Win32/AutoRun.VB.CD, Win32/Delf.NHH, Win32/Injector.MB, Win32/Injector.MC, Win32/Injector.MD, Win32/Injector.NV, Win32/IRCBot.ADZ, Win32/Koutodoor.AB (4), Win32/Koutodoor.G, Win32/Kryptik.QN, Win32/Lanc.A, Win32/Pacex.Gen (2), Win32/PSW.OnLineGames.OIX, Win32/PSW.YahooPass.NAD, Win32/StartPage.BR, Win32/TrojanClicker.Agent.NGS (2), Win32/TrojanDownloader.Agent.OXU, Win32/TrojanDownloader.Agent.OYU, Win32/TrojanDownloader.Banload.OOC, Win32/TrojanDownloader.Banload.OOP, Win32/TrojanDownloader.Bredolab.AA (2), Win32/TrojanDownloader.Delf.ORH, Win32/TrojanDownloader.Small.OKW (2), Win32/TrojanDownloader.VB.NWO, Win32/TrojanDownloader.Zlob.CZK, Win32/TrojanDropper.Agent.NSS, Win32/TrojanProxy.Small.NCA, Win32/Wigon.KU URL: http://www.eset.com/joomla/index.php?option=com_content&#38;task=view&#38;id=6077&#38;Itemid=26]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6077&amp;Itemid=26">4108</a></h1>
</p>
<p>IRC/SdBot (2), SWF/Exploit.Agent.AB (2), Win32/Adware.Antivirus2008, Win32/Adware.BHO.NCX, Win32/Adware.SpywareProtect2009 (2), Win32/Adware.XPGuard, Win32/Agent.PIS, Win32/Agent.PIX, Win32/AutoRun.Agent.IE (3), Win32/AutoRun.FlyStudio.KB, Win32/AutoRun.VB.CD, Win32/Delf.NHH, Win32/Injector.MB, Win32/Injector.MC, Win32/Injector.MD, Win32/Injector.NV, Win32/IRCBot.ADZ, Win32/Koutodoor.AB (4), Win32/Koutodoor.G, Win32/Kryptik.QN, Win32/Lanc.A, Win32/Pacex.Gen (2), Win32/PSW.OnLineGames.OIX, Win32/PSW.YahooPass.NAD, Win32/StartPage.BR, Win32/TrojanClicker.Agent.NGS (2), Win32/TrojanDownloader.Agent.OXU, Win32/TrojanDownloader.Agent.OYU, Win32/TrojanDownloader.Banload.OOC, Win32/TrojanDownloader.Banload.OOP, Win32/TrojanDownloader.Bredolab.AA (2), Win32/TrojanDownloader.Delf.ORH, Win32/TrojanDownloader.Small.OKW (2), Win32/TrojanDownloader.VB.NWO, Win32/TrojanDownloader.Zlob.CZK, Win32/TrojanDropper.Agent.NSS, Win32/TrojanProxy.Small.NCA, Win32/Wigon.KU
<p>URL: <a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6077&amp;Itemid=26">http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6077&amp;Itemid=26</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/4108/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Facebook sued by user over virus</title>
		<link>http://sechero.com/facebook-sued-by-user-over-virus/</link>
		<comments>http://sechero.com/facebook-sued-by-user-over-virus/#comments</comments>
		<pubDate>Tue, 26 May 2009 20:45:03 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Facebook sued by user over virus A Florida librarian and activist has filed a civil lawsuit against Facebook alleging that the social network failed to adequately protect users from a virus. Theodore Karantsalis, of Miami Springs, Fla., is seeking &#36;70.50 from Facebook in the lawsuit, which was filed a week ago in Miami-Dade county court. [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.pogowasright.org/article.php?story=20090526164503789">Facebook sued by user over virus</a></h1>
</p>
<p>
<p>A Florida librarian and activist has filed a civil lawsuit against Facebook alleging that the social network failed to adequately protect users from a virus.
<p>Theodore Karantsalis, of Miami Springs, Fla., is seeking &#36;70.50 from Facebook in the lawsuit, which was filed a week ago in Miami-Dade county court.</p>
<p>Source &#8211; <a href="http://news.cnet.com/8301-1009_3-10249301-83.html" target="_blank">Cnet  </a></p>
<p><a href="http://reddit.com/submit?url=http://www.pogowasright.org/article.php?story=20090526164503789" target="_new">Reddit It</a>Â |Â <a href="http://digg.com/submit?phase=2&amp;url=http://www.pogowasright.org/article.php?story=20090526164503789" target="_new">Digg This</a>Â |Â <a href="http://del.icio.us/post?url=http://www.pogowasright.org/article.php?story=20090526164503789" target="_new">Add to <a href="http://del.icio.us" title="http://del.icio.us" target="_blank">del.icio.us</a></a></p>
<p>URL: <a href="http://www.pogowasright.org/article.php?story=20090526164503789">http://www.pogowasright.org/article.php?story=20090526164503789</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/facebook-sued-by-user-over-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>4107</title>
		<link>http://sechero.com/4107/</link>
		<comments>http://sechero.com/4107/#comments</comments>
		<pubDate>Tue, 26 May 2009 17:34:49 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AdWare]]></category>
		<category><![CDATA[Downloader]]></category>
		<category><![CDATA[Fake]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[4107 BAT/Qhost.NBP (2), Win32/Adware.PersonalAntivirus (3), Win32/Adware.SystemSecurity (3), Win32/Adware.SystemSecurity.AA, Win32/Adware.WinPCDefender (6), Win32/Agent.CCWW, Win32/Agent.NYJ (2), Win32/Agent.PMD, Win32/AutoRun.ABH (4), Win32/AutoRun.FakeAlert.AF, Win32/AutoRun.FlyStudio.KA, Win32/Delf.NSE, Win32/Injector.PA, Win32/Koobface.NBG (2), Win32/Kryptik.QM, Win32/Qhost, Win32/Spy.Banker.QQJ (3), Win32/Spy.Webmoner.NBR (3), Win32/Spy.Zbot.JF, Win32/TrojanDownloader.Agent.OZA, Win32/TrojanDownloader.DelfOTP, Win32/TrojanDownloader.Small.NZM, Win32/TrojanDropper.Agent.OBC URL: http://www.eset.com/joomla/index.php?option=com_content&#38;task=view&#38;id=6076&#38;Itemid=26]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6076&amp;Itemid=26">4107</a></h1>
</p>
<p>BAT/Qhost.NBP (2), Win32/Adware.PersonalAntivirus (3), Win32/Adware.SystemSecurity (3), Win32/Adware.SystemSecurity.AA, Win32/Adware.WinPCDefender (6), Win32/Agent.CCWW, Win32/Agent.NYJ (2), Win32/Agent.PMD, Win32/AutoRun.ABH (4), Win32/AutoRun.FakeAlert.AF, Win32/AutoRun.FlyStudio.KA, Win32/Delf.NSE, Win32/Injector.PA, Win32/Koobface.NBG (2), Win32/Kryptik.QM, Win32/Qhost, Win32/Spy.Banker.QQJ (3), Win32/Spy.Webmoner.NBR (3), Win32/Spy.Zbot.JF, Win32/TrojanDownloader.Agent.OZA, Win32/TrojanDownloader.DelfOTP, Win32/TrojanDownloader.Small.NZM, Win32/TrojanDropper.Agent.OBC
<p>URL: <a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6076&amp;Itemid=26">http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6076&amp;Itemid=26</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/4107/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>4106</title>
		<link>http://sechero.com/4106/</link>
		<comments>http://sechero.com/4106/#comments</comments>
		<pubDate>Tue, 26 May 2009 11:14:09 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AdWare]]></category>
		<category><![CDATA[Downloader]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[4106 BAT/Agent.NBV (2), INF/Autorun, Win32/Adware.PersonalAntivirus, Win32/Adware.SystemSecurity, Win32/Adware.SystemSecurity.AA, Win32/Adware.WinPCDefender (2), Win32/Agent.CIHM, Win32/Agent.NYI (6), Win32/Agent.PLZ (2), Win32/Agent.PMA, Win32/Agent.PMB (3), Win32/Agent.PMC, Win32/Autoit.AG, Win32/BHO.NOR, Win32/Buzus.AZGJ, Win32/Daonol.B, Win32/Daonol.C, Win32/Delf.NFV (2), Win32/Delf.ODU, Win32/Delf.OIY, Win32/Delf.OIZ (2), Win32/FlyStudio.NMG (2), Win32/Hupigon.NOY (2), Win32/Koutodoor.AA (3), Win32/Koutodoor.G, Win32/Kryptik.QK, Win32/Kryptik.QL, Win32/Olmarik.GW (2), Win32/Olmarik.HG (4), Win32/Rootkit.Ressdt.NBO, Win32/SpamTool.Agent.NCL, Win32/Spy.Agent.NNS, Win32/Spy.Banbra.NPQ, Win32/Spy.Banker.QNJ, Win32/Spy.KeyLogger.ME (4), Win32/Spy.VB.NDV, Win32/Spy.Zbot.JF (3), Win32/Spy.Zbot.NJ, Win32/Spy.Zbot.RI, Win32/Spy.Zbot.RJ, [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6073&amp;Itemid=26">4106</a></h1>
</p>
<p>BAT/Agent.NBV (2), INF/Autorun, Win32/Adware.PersonalAntivirus, Win32/Adware.SystemSecurity, Win32/Adware.SystemSecurity.AA, Win32/Adware.WinPCDefender (2), Win32/Agent.CIHM, Win32/Agent.NYI (6), Win32/Agent.PLZ (2), Win32/Agent.PMA, Win32/Agent.PMB (3), Win32/Agent.PMC, Win32/Autoit.AG, Win32/BHO.NOR, Win32/Buzus.AZGJ, Win32/Daonol.B, Win32/Daonol.C, Win32/Delf.NFV (2), Win32/Delf.ODU, Win32/Delf.OIY, Win32/Delf.OIZ (2), Win32/FlyStudio.NMG (2), Win32/Hupigon.NOY (2), Win32/Koutodoor.AA (3), Win32/Koutodoor.G, Win32/Kryptik.QK, Win32/Kryptik.QL, Win32/Olmarik.GW (2), Win32/Olmarik.HG (4), Win32/Rootkit.Ressdt.NBO, Win32/SpamTool.Agent.NCL, Win32/Spy.Agent.NNS, Win32/Spy.Banbra.NPQ, Win32/Spy.Banker.QNJ, Win32/Spy.KeyLogger.ME (4), Win32/Spy.VB.NDV, Win32/Spy.Zbot.JF (3), Win32/Spy.Zbot.NJ, Win32/Spy.Zbot.RI, Win32/Spy.Zbot.RJ, Win32/StartPage.NJS, Win32/TrojanClicker.Delf.NDJ, Win32/TrojanClicker.Delf.NDK, Win32/TrojanClicker.Delf.NDR (3), Win32/TrojanClicker.Delf.NGK, Win32/TrojanClicker.Delf.NGM, Win32/TrojanClicker.Delf.NHF, Win32/TrojanClicker.VB.NHF, Win32/TrojanDownloader.Agent.OYF, Win32/TrojanDownloader.Delf.OIF, Win32/TrojanDropper.Agent.OBB, Win32/TrojanDropper.Mudrop.ABZ, Win32/VB.OES (3)
<p>URL: <a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6073&amp;Itemid=26">http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6073&amp;Itemid=26</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/4106/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New cscope packages fix arbitrary code execution</title>
		<link>http://sechero.com/new-cscope-packages-fix-arbitrary-code-execution-2/</link>
		<comments>http://sechero.com/new-cscope-packages-fix-arbitrary-code-execution-2/#comments</comments>
		<pubDate>Mon, 25 May 2009 16:50:01 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[ASCII]]></category>
		<category><![CDATA[Bugtraq]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Mail]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[[SECURITY] [DSA 1806-1] New cscope packages fix arbitrary code execution &#60;!&#8211; Envelope-to: email@address Delivery-date: Mon, 25 May 2009 17:47:31 +0100 Received: from outgoing.securityfocus.com ([205.206.231.26] helo=outgoing2.securityfocus.com) by lt.network5.net with esmtp (Exim 4.43) id 1M8dKl-0000wJ-NC for email@address; Mon, 25 May 2009 17:47:31 +0100 Received: from lists2.securityfocus.com (lists2.securityfocus.com [205.206.231.20]) by outgoing2.securityfocus.com (Postfix) with QMQP id C8835144259; Mon, 25 [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://lists.rootsecure.net/?p=view&amp;l=bugtraq&amp;m=86256">[SECURITY] [DSA 1806-1] New cscope packages fix arbitrary code execution</a></h1>
</p>
<p>&lt;!&#8211; Envelope-to: email@address Delivery-date: Mon, 25 May 2009 17:47:31 +0100 Received: from <a href="http://outgoing.securityfocus.com" title="http://outgoing.securityfocus.com" target="_blank">outgoing.securityfocus.com</a> ([205.206.231.26] helo=outgoing2.securityfocus.com) 	by <a href="http://lt.network5.net" title="http://lt.network5.net" target="_blank">lt.network5.net</a> with esmtp (Exim 4.43) 	id 1M8dKl-0000wJ-NC 	for email@address; Mon, 25 May 2009 17:47:31 +0100 Received: from <a href="http://lists2.securityfocus.com" title="http://lists2.securityfocus.com" target="_blank">lists2.securityfocus.com</a> (<a href="http://lists2.securityfocus.com" title="http://lists2.securityfocus.com" target="_blank">lists2.securityfocus.com</a> [205.206.231.20]) 	by <a href="http://outgoing2.securityfocus.com" title="http://outgoing2.securityfocus.com" target="_blank">outgoing2.securityfocus.com</a> (Postfix) with QMQP 	id C8835144259; Mon, 25 May 2009 08:14:14 -0600 (MDT) Mailing-List: contact <a href="mailto:bugtraq-help@securityfocus.com;" title="mailto:bugtraq-help@securityfocus.com;">bugtraq-help@securityfocus.com;</a> run by ezmlm Precedence: bulk List-Id: &lt;bugtraq.list-id.securityfocus.com&gt; List-Post: &lt;mailto:bugtraq@securityfocus.com&gt; List-Help: &lt;mailto:bugtraq-help@securityfocus.com&gt; List-Unsubscribe: &lt;mailto:bugtraq-unsubscribe@securityfocus.com&gt; List-Subscribe: &lt;mailto:bugtraq-subscribe@securityfocus.com&gt; Delivered-To: mailing list <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a> Delivered-To: moderator for <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a> Received: (qmail 14511 invoked from network); 24 May 2009 08:28:08 -0000 Resent-Cc: recipient list not shown: ; Old-Return-Path: &lt;jmm@inutil.org&gt; X-Original-To: <a href="mailto:lists-debian-security-announce@liszt.debian.org" title="mailto:lists-debian-security-announce@liszt.debian.org">lists-debian-security-announce@liszt.debian.org</a> Delivered-To: <a href="mailto:lists-debian-security-announce@liszt.debian.org" title="mailto:lists-debian-security-announce@liszt.debian.org">lists-debian-security-announce@liszt.debian.org</a> X-Virus-Scanned: at <a href="http://lists.debian.org" title="http://lists.debian.org" target="_blank">lists.debian.org</a> with policy bank moderated X-Spam-Flag: NO X-Spam-Score: -9.08 X-Spam-Level:  X-Spam-Status: No, score=-9.08 tagged_above=-10000 required=5.3 	tests=[BAYES_00=-2, FOURLA=0.1, FVGT_m_MULTI_ODD=0.02, 	IMPRONONCABLE_2=1, LDO_WHITELIST=-5, MURPHY_WRONG_WORD1=0.1, 	MURPHY_WRONG_WORD2=0.2, PGPSIGNATURE=-5, PHONENUMBER=1.5] 	autolearn=ham X-policyd-weight: using cached result; rate: -6.1 Message-ID: &lt;20090524082751.GA24821@galadriel.inutil.org&gt; MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.5.18 (2008-05-17) X-SA-Exim-Connect-IP: 82.83.229.75 X-SA-Exim-Mail-From: <a href="mailto:jmm@inutil.org" title="mailto:jmm@inutil.org">jmm@inutil.org</a> X-SA-Exim-Scanned: No (on <a href="http://inutil.org" title="http://inutil.org" target="_blank">inutil.org</a>); SAEximRunCond expanded to false X-Debian: PGP check passed for security officers Priority: urgent Resent-Message-ID: &lt;h-kgsMJsh7H.A.NWB.VUQGKB@liszt&gt; Reply-To: <a href="mailto:listadmin@securityfocus.com" title="mailto:listadmin@securityfocus.com">listadmin@securityfocus.com</a> Mail-Followup-To: <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a> Resent-Date: Sun, 24 May 2009 08:28:05 +0000 (UTC) Resent-From: <a href="mailto:list@liszt.debian.org" title="mailto:list@liszt.debian.org">list@liszt.debian.org</a> (Mailing List Manager) X-IMAPbase: 1176125385 9179 Status: O X-UID: 9179 Content-Length: 5245 X-Keywords:                                                                                                    </p>
<p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/new-cscope-packages-fix-arbitrary-code-execution-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

