<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: XORSearch V1.3.0</title>
	<atom:link href="http://blog.didierstevens.com/2008/01/16/xorsearch-v130/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2008/01/16/xorsearch-v130/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Wed, 08 Feb 2012 19:23:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Jordan</title>
		<link>http://blog.didierstevens.com/2008/01/16/xorsearch-v130/#comment-26598</link>
		<dc:creator><![CDATA[Jordan]]></dc:creator>
		<pubDate>Thu, 17 Jan 2008 01:55:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2008/01/16/xorsearch-v130/#comment-26598</guid>
		<description><![CDATA[It&#039;s all about lucky timing of when the post publishes, the RSS reader updates, and when you read it.  

I found it the same way too -- just looking through strings.  I figured I ought to at least try xorsearch against itself and noticed there were too many &quot;didier stevens&quot; strings in the binary compared to the source.  

Incidentally, it compiled smoothly on ubuntu gutsy, and works on osx leopard too, though leopard required a change from &quot;malloc.h&quot; to &quot;sys/malloc.h&quot;.]]></description>
		<content:encoded><![CDATA[<p>It&#8217;s all about lucky timing of when the post publishes, the RSS reader updates, and when you read it.  </p>
<p>I found it the same way too &#8212; just looking through strings.  I figured I ought to at least try xorsearch against itself and noticed there were too many &#8220;didier stevens&#8221; strings in the binary compared to the source.  </p>
<p>Incidentally, it compiled smoothly on ubuntu gutsy, and works on osx leopard too, though leopard required a change from &#8220;malloc.h&#8221; to &#8220;sys/malloc.h&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Klau</title>
		<link>http://blog.didierstevens.com/2008/01/16/xorsearch-v130/#comment-26573</link>
		<dc:creator><![CDATA[Klau]]></dc:creator>
		<pubDate>Wed, 16 Jan 2008 19:31:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2008/01/16/xorsearch-v130/#comment-26573</guid>
		<description><![CDATA[The funny part it that i didn&#039;t even get to check my e-mail to see the clue, because i was so caught up with Process Explorer, but what the heck, you&#039;re right, i&#039;ve did it on my own. Looking forward for a new challenge (very soon i hope)]]></description>
		<content:encoded><![CDATA[<p>The funny part it that i didn&#8217;t even get to check my e-mail to see the clue, because i was so caught up with Process Explorer, but what the heck, you&#8217;re right, i&#8217;ve did it on my own. Looking forward for a new challenge (very soon i hope)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2008/01/16/xorsearch-v130/#comment-26571</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Wed, 16 Jan 2008 19:27:59 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2008/01/16/xorsearch-v130/#comment-26571</guid>
		<description><![CDATA[Don&#039;t feel miserable, you still discovered it on your own. Apart from you two, no-one can claim this because the &quot;secret&quot; is out now.]]></description>
		<content:encoded><![CDATA[<p>Don&#8217;t feel miserable, you still discovered it on your own. Apart from you two, no-one can claim this because the &#8220;secret&#8221; is out now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Klau</title>
		<link>http://blog.didierstevens.com/2008/01/16/xorsearch-v130/#comment-26570</link>
		<dc:creator><![CDATA[Klau]]></dc:creator>
		<pubDate>Wed, 16 Jan 2008 19:23:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2008/01/16/xorsearch-v130/#comment-26570</guid>
		<description><![CDATA[Yep, only now i&#039;ve seen your comment after the refresh in my browser...
Place No.2 it feel&#039;s so miserable!]]></description>
		<content:encoded><![CDATA[<p>Yep, only now i&#8217;ve seen your comment after the refresh in my browser&#8230;<br />
Place No.2 it feel&#8217;s so miserable!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Klau</title>
		<link>http://blog.didierstevens.com/2008/01/16/xorsearch-v130/#comment-26569</link>
		<dc:creator><![CDATA[Klau]]></dc:creator>
		<pubDate>Wed, 16 Jan 2008 19:20:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2008/01/16/xorsearch-v130/#comment-26569</guid>
		<description><![CDATA[Indeed, it shows that you have your own signing certificate (7Didier Stevens Code Signing) along VeriSign Time Stamping Services CA, and here are some other interesting strings that i&#039;ve found:
Brussels1
Brussels1&quot;0
didier stevens Google mail
but since i don&#039;t know to what i should compare it or what to search for, i&#039;m waiting for another clue to enlighten me...]]></description>
		<content:encoded><![CDATA[<p>Indeed, it shows that you have your own signing certificate (7Didier Stevens Code Signing) along VeriSign Time Stamping Services CA, and here are some other interesting strings that i&#8217;ve found:<br />
Brussels1<br />
Brussels1&#8243;0<br />
didier stevens Google mail<br />
but since i don&#8217;t know to what i should compare it or what to search for, i&#8217;m waiting for another clue to enlighten me&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2008/01/16/xorsearch-v130/#comment-26568</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Wed, 16 Jan 2008 19:19:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2008/01/16/xorsearch-v130/#comment-26568</guid>
		<description><![CDATA[Congratz Jordan, you spotted it first, this new version of XORSearch.exe is digitally signed. I rolled my own set of certificates and used it to digitally sign the executable. When you inspect the certificate, you&#039;ll see a warning that the root CA is not trusted. That&#039;s normal, because I created my own root CA and it&#039;s not part of the root CAs that are trusted by default by Windows.]]></description>
		<content:encoded><![CDATA[<p>Congratz Jordan, you spotted it first, this new version of XORSearch.exe is digitally signed. I rolled my own set of certificates and used it to digitally sign the executable. When you inspect the certificate, you&#8217;ll see a warning that the root CA is not trusted. That&#8217;s normal, because I created my own root CA and it&#8217;s not part of the root CAs that are trusted by default by Windows.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jordan</title>
		<link>http://blog.didierstevens.com/2008/01/16/xorsearch-v130/#comment-26566</link>
		<dc:creator><![CDATA[Jordan]]></dc:creator>
		<pubDate>Wed, 16 Jan 2008 19:10:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2008/01/16/xorsearch-v130/#comment-26566</guid>
		<description><![CDATA[Was the previous version a signed binary?]]></description>
		<content:encoded><![CDATA[<p>Was the previous version a signed binary?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Klau</title>
		<link>http://blog.didierstevens.com/2008/01/16/xorsearch-v130/#comment-26565</link>
		<dc:creator><![CDATA[Klau]]></dc:creator>
		<pubDate>Wed, 16 Jan 2008 19:00:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2008/01/16/xorsearch-v130/#comment-26565</guid>
		<description><![CDATA[Ok, there&#039;s something tricky about &#039;And there is something new about the XORSearch.exe in the ZIP file. First one to post a comment with the correct answer gets an honorable mention ;)&#039;
What exactly should we search for? I&#039;ve tought that it&#039;s something regarding the md5 and sha256 checksums, but it&#039;s all good here. There&#039;s nothing extraordinary regarding the zip compression rate (50%). Is it that because it uses snprintf your .exe isn&#039;t vulnerable to buffer overflow&#039;s, or that it detect&#039;s a stack overflow at 0040D9A4, or what? I&#039;ve tried to look after the version 1.0 of your application, but didn&#039;t found it (and i don&#039;t think that there&#039;s where the catch is), so please enlighten us, what exactly should we search for in it?]]></description>
		<content:encoded><![CDATA[<p>Ok, there&#8217;s something tricky about &#8216;And there is something new about the XORSearch.exe in the ZIP file. First one to post a comment with the correct answer gets an honorable mention <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> &#8217;<br />
What exactly should we search for? I&#8217;ve tought that it&#8217;s something regarding the md5 and sha256 checksums, but it&#8217;s all good here. There&#8217;s nothing extraordinary regarding the zip compression rate (50%). Is it that because it uses snprintf your .exe isn&#8217;t vulnerable to buffer overflow&#8217;s, or that it detect&#8217;s a stack overflow at 0040D9A4, or what? I&#8217;ve tried to look after the version 1.0 of your application, but didn&#8217;t found it (and i don&#8217;t think that there&#8217;s where the catch is), so please enlighten us, what exactly should we search for in it?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

