<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Google and the Drive-by Download</title>
	<atom:link href="http://blog.didierstevens.com/2006/10/06/google-and-the-drive-by-download/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2006/10/06/google-and-the-drive-by-download/</link>
	<description>(blog 'DidierStevens)</description>
	<pubDate>Fri, 21 Nov 2008 02:27:48 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/10/06/google-and-the-drive-by-download/#comment-21108</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Wed, 28 Nov 2007 21:23:36 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2006/10/06/google-and-the-drive-by-download/#comment-21108</guid>
		<description>Made what?</description>
		<content:encoded><![CDATA[<p>Made what?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: naisioxerloro</title>
		<link>http://blog.didierstevens.com/2006/10/06/google-and-the-drive-by-download/#comment-21071</link>
		<dc:creator>naisioxerloro</dc:creator>
		<pubDate>Wed, 28 Nov 2007 15:42:20 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2006/10/06/google-and-the-drive-by-download/#comment-21071</guid>
		<description>Hi. 
Good design, who make it?</description>
		<content:encoded><![CDATA[<p>Hi.<br />
Good design, who make it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fellitmon</title>
		<link>http://blog.didierstevens.com/2006/10/06/google-and-the-drive-by-download/#comment-15920</link>
		<dc:creator>Fellitmon</dc:creator>
		<pubDate>Wed, 24 Oct 2007 01:22:26 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2006/10/06/google-and-the-drive-by-download/#comment-15920</guid>
		<description>view</description>
		<content:encoded><![CDATA[<p>view</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: videomarketingcoach.com &#187; A thousand pictures creates a story of a billion words</title>
		<link>http://blog.didierstevens.com/2006/10/06/google-and-the-drive-by-download/#comment-11388</link>
		<dc:creator>videomarketingcoach.com &#187; A thousand pictures creates a story of a billion words</dc:creator>
		<pubDate>Wed, 18 Jul 2007 14:00:42 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2006/10/06/google-and-the-drive-by-download/#comment-11388</guid>
		<description>[...] Stevens in his post Google and the Drive-by Download takes you step by step through the process of getting infected by a Drive-by [...]</description>
		<content:encoded><![CDATA[<p>[...] Stevens in his post Google and the Drive-by Download takes you step by step through the process of getting infected by a Drive-by [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex B</title>
		<link>http://blog.didierstevens.com/2006/10/06/google-and-the-drive-by-download/#comment-10076</link>
		<dc:creator>Alex B</dc:creator>
		<pubDate>Mon, 25 Jun 2007 08:28:43 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2006/10/06/google-and-the-drive-by-download/#comment-10076</guid>
		<description>Just a heads-up, the upload of service32.exe to Virustotal seems to have failed -- the filesize is 0 and indeed d41d8cd98f00b204e9800998ecf8427e is the MD5 hash of the empy string :)</description>
		<content:encoded><![CDATA[<p>Just a heads-up, the upload of service32.exe to Virustotal seems to have failed &#8212; the filesize is 0 and indeed d41d8cd98f00b204e9800998ecf8427e is the MD5 hash of the empy string <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Keys Corner &#187; Blog Archive &#187; One in 10 websites malicious</title>
		<link>http://blog.didierstevens.com/2006/10/06/google-and-the-drive-by-download/#comment-4970</link>
		<dc:creator>Keys Corner &#187; Blog Archive &#187; One in 10 websites malicious</dc:creator>
		<pubDate>Fri, 11 May 2007 21:01:28 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2006/10/06/google-and-the-drive-by-download/#comment-4970</guid>
		<description>[...] there is a good short introduction for &#8220;non-techies&#8221; here. And here&#8217;s a report showing how easy it is to get infected if you don&#8217;t pay attention properly, just by googling for a plumber and clicking on one of the results [...]</description>
		<content:encoded><![CDATA[<p>[...] there is a good short introduction for &#8220;non-techies&#8221; here. And here&#8217;s a report showing how easy it is to get infected if you don&#8217;t pay attention properly, just by googling for a plumber and clicking on one of the results [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/10/06/google-and-the-drive-by-download/#comment-289</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Tue, 05 Dec 2006 10:12:29 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2006/10/06/google-and-the-drive-by-download/#comment-289</guid>
		<description>I wrote "I’ve encountered ...", this doesn't imply I got bitten by this ;-)</description>
		<content:encoded><![CDATA[<p>I wrote &#8220;I’ve encountered &#8230;&#8221;, this doesn&#8217;t imply I got bitten by this <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anonymous</title>
		<link>http://blog.didierstevens.com/2006/10/06/google-and-the-drive-by-download/#comment-288</link>
		<dc:creator>anonymous</dc:creator>
		<pubDate>Tue, 05 Dec 2006 05:41:10 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2006/10/06/google-and-the-drive-by-download/#comment-288</guid>
		<description>Dear Mr Stevens,

How come someone so smart about reverse-engineering is not so wise about firewalling and ad blocking? That totally blows me away.  

Funny thing is I found this thread from http://www.astalavista.com/index.php?section=directory&#38;cmd=detail&#38;id=6972 this thread. 

And didn't expect to see something like this. Out of respect for what you do, I highly suggest some basic tcpip understanding, and an external firewall like ipcop along with ad block plus, kerio, or any other proxy / ad blocking methods that fit your fancy. 

My only real CRITIQUE here is I hate to see someone say, "1. Start Internet Explorer."  WRONG. 

DON'T RUN iexplorer.exe  in fact RENAME IT to iexplorer.e (If you have to run it for a BANK of WHATEVER rename it again)

Now my Value add to the discussion.
I ain't no expert on security but it you want your windows box to run longer than 4 years.

Personally, I do ipcop externally dedicated. With URL Filter, Banish (with some serious fsckin blacklists), and a couple little personally hacked up codes for it.

Windows Boxes: kerio (The FULL ONE not the FREE ONE), then filter out with the ad block. ztree is "the shit" for tracking down bad files/virus's and code (I use it instead of a virus scanner) Okay, sometimes I run ewido...
Sometimes I whip out some strange shit like proximotron. Sometimes others, sometimes wget only.  Spampal+TheBat html=OFF (Files are backed up all the time) 
note: To all the *NIX freaks, There is a reason to run windows boxes! VIDEO PRODUCTION! cinelerra sux

Linux Boxes: iptables + adblock + nice backup of the OS (I could care less about files, I burn disks all the time)  midnight commander "mc" is the equal of ztree on linux. (fact there's a mc for windows out there too, nice for drive to drive grafting.)

Got an linux extra box? Add a syslog, and etherape window.  Boom your now kicking your home network's ass!

Okay, hope you didn't take this wrong.  The more I read the thread here, the more I realized I don't SEE Google Drive-By's, they're blocked or something. (I actually had to load that jpg3 or whatever to see what you were talking about) I analyze the network and my files probably too much, but I also keep my shit running for years not days then reformat.

One thing I been looking for is a full windows XP registry backup.  No utility I have seen yet does that. The closest I come to that is Doing an Acronis True Image of the whole drive to drive. It's far more important to be able to track down things than worry about blocking the latest unknown problem, in my opinion. Problems are going to happen, how you can deal with it is what matters.

Sorry if I was wordy, and too chickenshit to post a real name / real handle, I probably typed this crap up in vain.</description>
		<content:encoded><![CDATA[<p>Dear Mr Stevens,</p>
<p>How come someone so smart about reverse-engineering is not so wise about firewalling and ad blocking? That totally blows me away.  </p>
<p>Funny thing is I found this thread from <a href="http://www.astalavista.com/index.php?section=directory&amp;cmd=detail&amp;id=6972" rel="nofollow">http://www.astalavista.com/index.php?section=directory&amp;cmd=detail&amp;id=6972</a> this thread. </p>
<p>And didn&#8217;t expect to see something like this. Out of respect for what you do, I highly suggest some basic tcpip understanding, and an external firewall like ipcop along with ad block plus, kerio, or any other proxy / ad blocking methods that fit your fancy. </p>
<p>My only real CRITIQUE here is I hate to see someone say, &#8220;1. Start Internet Explorer.&#8221;  WRONG. </p>
<p>DON&#8217;T RUN iexplorer.exe  in fact RENAME IT to iexplorer.e (If you have to run it for a BANK of WHATEVER rename it again)</p>
<p>Now my Value add to the discussion.<br />
I ain&#8217;t no expert on security but it you want your windows box to run longer than 4 years.</p>
<p>Personally, I do ipcop externally dedicated. With URL Filter, Banish (with some serious fsckin blacklists), and a couple little personally hacked up codes for it.</p>
<p>Windows Boxes: kerio (The FULL ONE not the FREE ONE), then filter out with the ad block. ztree is &#8220;the shit&#8221; for tracking down bad files/virus&#8217;s and code (I use it instead of a virus scanner) Okay, sometimes I run ewido&#8230;<br />
Sometimes I whip out some strange shit like proximotron. Sometimes others, sometimes wget only.  Spampal+TheBat html=OFF (Files are backed up all the time)<br />
note: To all the *NIX freaks, There is a reason to run windows boxes! VIDEO PRODUCTION! cinelerra sux</p>
<p>Linux Boxes: iptables + adblock + nice backup of the OS (I could care less about files, I burn disks all the time)  midnight commander &#8220;mc&#8221; is the equal of ztree on linux. (fact there&#8217;s a mc for windows out there too, nice for drive to drive grafting.)</p>
<p>Got an linux extra box? Add a syslog, and etherape window.  Boom your now kicking your home network&#8217;s ass!</p>
<p>Okay, hope you didn&#8217;t take this wrong.  The more I read the thread here, the more I realized I don&#8217;t SEE Google Drive-By&#8217;s, they&#8217;re blocked or something. (I actually had to load that jpg3 or whatever to see what you were talking about) I analyze the network and my files probably too much, but I also keep my shit running for years not days then reformat.</p>
<p>One thing I been looking for is a full windows XP registry backup.  No utility I have seen yet does that. The closest I come to that is Doing an Acronis True Image of the whole drive to drive. It&#8217;s far more important to be able to track down things than worry about blocking the latest unknown problem, in my opinion. Problems are going to happen, how you can deal with it is what matters.</p>
<p>Sorry if I was wordy, and too chickenshit to post a real name / real handle, I probably typed this crap up in vain.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Update 3: Google and the Drive-by Download &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/10/06/google-and-the-drive-by-download/#comment-263</link>
		<dc:creator>Update 3: Google and the Drive-by Download &#171; Didier Stevens</dc:creator>
		<pubDate>Sun, 19 Nov 2006 09:18:21 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2006/10/06/google-and-the-drive-by-download/#comment-263</guid>
		<description>[...] A few days ago I Googled again for Vanderelst Chauffagiste (Google and the Drive-by Download), I noticed the Spamdexing &#8220;R&#8221; Us site has disappeared from the SERPs. But it still exists. [...]</description>
		<content:encoded><![CDATA[<p>[...] A few days ago I Googled again for Vanderelst Chauffagiste (Google and the Drive-by Download), I noticed the Spamdexing &#8220;R&#8221; Us site has disappeared from the SERPs. But it still exists. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spamdexing &#8220;R&#8221; Us &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/10/06/google-and-the-drive-by-download/#comment-180</link>
		<dc:creator>Spamdexing &#8220;R&#8221; Us &#171; Didier Stevens</dc:creator>
		<pubDate>Mon, 23 Oct 2006 10:17:14 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2006/10/06/google-and-the-drive-by-download/#comment-180</guid>
		<description>[...] Still wondering how likely is it to land on a drive-by download page when doing a (Google) search, I analyzed the infamous AOL search data to try to answer this question. [...]</description>
		<content:encoded><![CDATA[<p>[...] Still wondering how likely is it to land on a drive-by download page when doing a (Google) search, I analyzed the infamous AOL search data to try to answer this question. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
