<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: P0wned by a QT movie</title>
	<atom:link href="http://blog.didierstevens.com/2007/03/12/p0wned-by-a-qt-movie/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2007/03/12/p0wned-by-a-qt-movie/</link>
	<description>(blog 'DidierStevens)</description>
	<pubDate>Fri, 21 Nov 2008 04:15:41 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: kevstelo</title>
		<link>http://blog.didierstevens.com/2007/03/12/p0wned-by-a-qt-movie/#comment-8904</link>
		<dc:creator>kevstelo</dc:creator>
		<pubDate>Mon, 11 Jun 2007 07:30:09 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/03/12/p0wned-by-a-qt-movie/#comment-8904</guid>
		<description>I think I've read something simillar a few days ago. I don't remember where, might have been on digg.com or slashdot.</description>
		<content:encoded><![CDATA[<p>I think I&#8217;ve read something simillar a few days ago. I don&#8217;t remember where, might have been on digg.com or slashdot.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HelloWorld</title>
		<link>http://blog.didierstevens.com/2007/03/12/p0wned-by-a-qt-movie/#comment-3614</link>
		<dc:creator>HelloWorld</dc:creator>
		<pubDate>Sat, 28 Apr 2007 11:48:10 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/03/12/p0wned-by-a-qt-movie/#comment-3614</guid>
		<description>Peace people 
 
We love you</description>
		<content:encoded><![CDATA[<p>Peace people </p>
<p>We love you</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: me 4you</title>
		<link>http://blog.didierstevens.com/2007/03/12/p0wned-by-a-qt-movie/#comment-3206</link>
		<dc:creator>me 4you</dc:creator>
		<pubDate>Wed, 25 Apr 2007 21:23:45 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/03/12/p0wned-by-a-qt-movie/#comment-3206</guid>
		<description>&lt;strong&gt;their own personal space at last&lt;/strong&gt;

Yeah!. Congratulations for the blog
Your post is very interesting .In your blog are a lot of good  post..
I'll bookmark you.
A462fc6cb9bbeb</description>
		<content:encoded><![CDATA[<p><strong>their own personal space at last</strong></p>
<p>Yeah!. Congratulations for the blog<br />
Your post is very interesting .In your blog are a lot of good  post..<br />
I&#8217;ll bookmark you.<br />
A462fc6cb9bbeb</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2007/03/12/p0wned-by-a-qt-movie/#comment-1682</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Sun, 01 Apr 2007 18:49:34 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/03/12/p0wned-by-a-qt-movie/#comment-1682</guid>
		<description>Yes, a lot of malware programs can disable security software, like AV. However, most of them can only do this when you run as local admin.</description>
		<content:encoded><![CDATA[<p>Yes, a lot of malware programs can disable security software, like AV. However, most of them can only do this when you run as local admin.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elizabeth m Maloney</title>
		<link>http://blog.didierstevens.com/2007/03/12/p0wned-by-a-qt-movie/#comment-1312</link>
		<dc:creator>Elizabeth m Maloney</dc:creator>
		<pubDate>Wed, 28 Mar 2007 01:57:34 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/03/12/p0wned-by-a-qt-movie/#comment-1312</guid>
		<description>I am protected by McAfe...but have this trojan I suspect...is it possible that somehow this malware or whatever can disable my virus protection? There have been a few occasions when I have found my protection disabled, yet I hadn't disabled it.

                                                          Elizabeth</description>
		<content:encoded><![CDATA[<p>I am protected by McAfe&#8230;but have this trojan I suspect&#8230;is it possible that somehow this malware or whatever can disable my virus protection? There have been a few occasions when I have found my protection disabled, yet I hadn&#8217;t disabled it.</p>
<p>                                                          Elizabeth</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: :: Binary Paradox :: &#187; Blog Archive &#187; A Eulogy for Flatfiles</title>
		<link>http://blog.didierstevens.com/2007/03/12/p0wned-by-a-qt-movie/#comment-908</link>
		<dc:creator>:: Binary Paradox :: &#187; Blog Archive &#187; A Eulogy for Flatfiles</dc:creator>
		<pubDate>Mon, 19 Mar 2007 18:02:16 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/03/12/p0wned-by-a-qt-movie/#comment-908</guid>
		<description>[...] to execute scriptable content in the context of the current website. Didier Stevens has a nice write up of the particular exploit.  Though it appears patched with the latest version of Quicktime it [...]</description>
		<content:encoded><![CDATA[<p>[...] to execute scriptable content in the context of the current website. Didier Stevens has a nice write up of the particular exploit.  Though it appears patched with the latest version of Quicktime it [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Russ McRee</title>
		<link>http://blog.didierstevens.com/2007/03/12/p0wned-by-a-qt-movie/#comment-907</link>
		<dc:creator>Russ McRee</dc:creator>
		<pubDate>Mon, 19 Mar 2007 17:57:51 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/03/12/p0wned-by-a-qt-movie/#comment-907</guid>
		<description>Posted a Snort sig to BleedingThreats.net.

alert tcp $HOME_NET any -&#62; $EXTERNAL_NET $HTTP_PORTS (msg:”BLEEDING-EDGE CURRENT EVENTS SpaceTalk-QT-js”; flow:to_server,established; uricontent:”/logs4/sqltrack.js”; nocase; classtype:trojan-activity; reference:url,didierstevens.wordpress.com/2007/03/12/p0wned-by-a-qt-movie/; sid:2003507; rev:1;)</description>
		<content:encoded><![CDATA[<p>Posted a Snort sig to BleedingThreats.net.</p>
<p>alert tcp $HOME_NET any -&gt; $EXTERNAL_NET $HTTP_PORTS (msg:”BLEEDING-EDGE CURRENT EVENTS SpaceTalk-QT-js”; flow:to_server,established; uricontent:”/logs4/sqltrack.js”; nocase; classtype:trojan-activity; reference:url,didierstevens.wordpress.com/2007/03/12/p0wned-by-a-qt-movie/; sid:2003507; rev:1;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Mosby at myITforum.com : McAfee Avert Labs Blog - MySpace Woes: Trojan Targets French Rock Band Fans - Friday March 16, 2007</title>
		<link>http://blog.didierstevens.com/2007/03/12/p0wned-by-a-qt-movie/#comment-905</link>
		<dc:creator>Chris Mosby at myITforum.com : McAfee Avert Labs Blog - MySpace Woes: Trojan Targets French Rock Band Fans - Friday March 16, 2007</dc:creator>
		<pubDate>Mon, 19 Mar 2007 16:14:13 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/03/12/p0wned-by-a-qt-movie/#comment-905</guid>
		<description>[...] detailed analysis of this interesting infection vector can be viewed at Didier Stevens’s blog. A silver lining in the whole murky episode is that McAfee customers are proactively protected from [...]</description>
		<content:encoded><![CDATA[<p>[...] detailed analysis of this interesting infection vector can be viewed at Didier Stevens’s blog. A silver lining in the whole murky episode is that McAfee customers are proactively protected from [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2007/03/12/p0wned-by-a-qt-movie/#comment-903</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Mon, 19 Mar 2007 11:36:30 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/03/12/p0wned-by-a-qt-movie/#comment-903</guid>
		<description>@Anonymous

ADODB.Stream for example, http://www.f-secure.com/v-descs/adodb_stream.shtml</description>
		<content:encoded><![CDATA[<p>@Anonymous</p>
<p>ADODB.Stream for example, <a href="http://www.f-secure.com/v-descs/adodb_stream.shtml" rel="nofollow">http://www.f-secure.com/v-descs/adodb_stream.shtml</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Update: P0wned by a QT movie &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2007/03/12/p0wned-by-a-qt-movie/#comment-901</link>
		<dc:creator>Update: P0wned by a QT movie &#171; Didier Stevens</dc:creator>
		<pubDate>Sun, 18 Mar 2007 19:14:45 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/03/12/p0wned-by-a-qt-movie/#comment-901</guid>
		<description>[...] version (7.1.5) without support for JavaScript. This happened about a week before I posted &#8220;P0wned by a QT movie&#8221;. I had analyzed the infection and written (but not published) my post before Apple published the [...]</description>
		<content:encoded><![CDATA[<p>[...] version (7.1.5) without support for JavaScript. This happened about a week before I posted &#8220;P0wned by a QT movie&#8221;. I had analyzed the infection and written (but not published) my post before Apple published the [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
