<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Analyzing a Suspect WMF File</title>
	<atom:link href="http://blog.didierstevens.com/2007/08/28/analyzing-a-suspect-wmf-file/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2007/08/28/analyzing-a-suspect-wmf-file/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Sat, 11 Feb 2012 16:16:49 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: spinwobble.com &#187; Dissecting a Suspect WMF File</title>
		<link>http://blog.didierstevens.com/2007/08/28/analyzing-a-suspect-wmf-file/#comment-13415</link>
		<dc:creator><![CDATA[spinwobble.com &#187; Dissecting a Suspect WMF File]]></dc:creator>
		<pubDate>Thu, 30 Aug 2007 11:59:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2007/08/28/analyzing-a-suspect-wmf-file/#comment-13415</guid>
		<description><![CDATA[[...] is an amazing blog post. This guy, Randy Armknecht spotted a suspect WMF file and decided to analyze it further. The [...]]]></description>
		<content:encoded><![CDATA[<p>[...] is an amazing blog post. This guy, Randy Armknecht spotted a suspect WMF file and decided to analyze it further. The [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: www.andrewhay.ca &#187; Suggested Blog Reading - Wednesday August 29th, 2007</title>
		<link>http://blog.didierstevens.com/2007/08/28/analyzing-a-suspect-wmf-file/#comment-13383</link>
		<dc:creator><![CDATA[www.andrewhay.ca &#187; Suggested Blog Reading - Wednesday August 29th, 2007]]></dc:creator>
		<pubDate>Wed, 29 Aug 2007 21:56:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2007/08/28/analyzing-a-suspect-wmf-file/#comment-13383</guid>
		<description><![CDATA[[...] Analyzing a Suspect WMF File - Great article Didier! My analysis will show that this WMF file doesn’t contain shellcode. I use a tool I discovered recently, the 010 Editor, a professional hex editor with binary templates. Binary templates allow you to define the structure of a binary file with a C-like scripting language. A binary file parsed with a template is much easier to understand, as you will see. Unfortunately, I found no free alternative for this tool. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Analyzing a Suspect WMF File &#8211; Great article Didier! My analysis will show that this WMF file doesn’t contain shellcode. I use a tool I discovered recently, the 010 Editor, a professional hex editor with binary templates. Binary templates allow you to define the structure of a binary file with a C-like scripting language. A binary file parsed with a template is much easier to understand, as you will see. Unfortunately, I found no free alternative for this tool. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2007/08/28/analyzing-a-suspect-wmf-file/#comment-13370</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Wed, 29 Aug 2007 16:40:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2007/08/28/analyzing-a-suspect-wmf-file/#comment-13370</guid>
		<description><![CDATA[Thanks for looking for free alternatives. I tried to find some free alternatives before posting this (see http://en.wikipedia.org/wiki/Comparison_of_hex_editors). I didn&#039;t install them, I just looked at screenshots.

But I&#039;ll find some time to play with Tiny Hex.

Please feel free to add your suggestions.]]></description>
		<content:encoded><![CDATA[<p>Thanks for looking for free alternatives. I tried to find some free alternatives before posting this (see <a href="http://en.wikipedia.org/wiki/Comparison_of_hex_editors" rel="nofollow">http://en.wikipedia.org/wiki/Comparison_of_hex_editors</a>). I didn&#8217;t install them, I just looked at screenshots.</p>
<p>But I&#8217;ll find some time to play with Tiny Hex.</p>
<p>Please feel free to add your suggestions.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Bruce</title>
		<link>http://blog.didierstevens.com/2007/08/28/analyzing-a-suspect-wmf-file/#comment-13368</link>
		<dc:creator><![CDATA[Daniel Bruce]]></dc:creator>
		<pubDate>Wed, 29 Aug 2007 16:00:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2007/08/28/analyzing-a-suspect-wmf-file/#comment-13368</guid>
		<description><![CDATA[I&#039;d just like to mention a free hex editor called &quot;tiny hexer&quot; as a free alternative to that editor. It touts a &quot;structure viewer&quot; feature which seems to aim to serve the same purpose as those templates. The scripting language used to run these scans seems less straight-forward, though. (You have to explicitly write out any info you want shown, f.ex.)
Even so, it might still be worth a look for the monetarily disabled. ;)
It&#039;s available from http://www.mirkes.de/en/freeware/tinyhex.php]]></description>
		<content:encoded><![CDATA[<p>I&#8217;d just like to mention a free hex editor called &#8220;tiny hexer&#8221; as a free alternative to that editor. It touts a &#8220;structure viewer&#8221; feature which seems to aim to serve the same purpose as those templates. The scripting language used to run these scans seems less straight-forward, though. (You have to explicitly write out any info you want shown, f.ex.)<br />
Even so, it might still be worth a look for the monetarily disabled. <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /><br />
It&#8217;s available from <a href="http://www.mirkes.de/en/freeware/tinyhex.php" rel="nofollow">http://www.mirkes.de/en/freeware/tinyhex.php</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

