<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: 4th of July, Business as Usual</title>
	<atom:link href="http://blog.didierstevens.com/2008/07/04/4th-of-july-business-as-usual/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2008/07/04/4th-of-july-business-as-usual/</link>
	<description>(blog 'DidierStevens)</description>
	<pubDate>Tue, 06 Jan 2009 11:46:35 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Dave</title>
		<link>http://blog.didierstevens.com/2008/07/04/4th-of-july-business-as-usual/#comment-33057</link>
		<dc:creator>Dave</dc:creator>
		<pubDate>Sun, 06 Jul 2008 10:45:59 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=453#comment-33057</guid>
		<description>The line which didn't display correctly in my first comment was that which starts with iframe src=

I just noticed the fw.gif, so assume that's the image of the fireworks and false video controls.</description>
		<content:encoded><![CDATA[<p>The line which didn&#8217;t display correctly in my first comment was that which starts with iframe src=</p>
<p>I just noticed the fw.gif, so assume that&#8217;s the image of the fireworks and false video controls.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave</title>
		<link>http://blog.didierstevens.com/2008/07/04/4th-of-july-business-as-usual/#comment-33056</link>
		<dc:creator>Dave</dc:creator>
		<pubDate>Sun, 06 Jul 2008 10:42:00 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=453#comment-33056</guid>
		<description>OK, I fell for it (I'm a sucker!).  I visited the site (using fully patched XP Pro which I reformat and reinstall frequently).  I got the ActiveX warning (which I didn't run), then I looked at the source code, which was as you displayed.

I've a number of questions:

I'm somewhat reluctant to allow the ActiveX ... what's the next stage for me?  Should I allow the ActiveX and, if so, what will the outcome be?  Is it possible to download the ActiveX for future analysis but without allowing it to run?

I've looked at the source code, but what actually invokes the ActiveX?  How is the image generated?  I realise that it's not a real video.

I see that if I hover over the image, it wants to run fireworks.exe (I didn't allow that, nor did I save the file to my PC).

I'm suspicious about the line:

""

but, as my HTML coding skills can be written on the back of a postage stamp, that doesn't surprise me!

Sorry to ask so many questions.  I guess I could have e-mailed you directly (and I'm quite happy to continue this in that way), but I just wondered if you, or other contributors, might be able and willing to "fill me in"?</description>
		<content:encoded><![CDATA[<p>OK, I fell for it (I&#8217;m a sucker!).  I visited the site (using fully patched XP Pro which I reformat and reinstall frequently).  I got the ActiveX warning (which I didn&#8217;t run), then I looked at the source code, which was as you displayed.</p>
<p>I&#8217;ve a number of questions:</p>
<p>I&#8217;m somewhat reluctant to allow the ActiveX &#8230; what&#8217;s the next stage for me?  Should I allow the ActiveX and, if so, what will the outcome be?  Is it possible to download the ActiveX for future analysis but without allowing it to run?</p>
<p>I&#8217;ve looked at the source code, but what actually invokes the ActiveX?  How is the image generated?  I realise that it&#8217;s not a real video.</p>
<p>I see that if I hover over the image, it wants to run fireworks.exe (I didn&#8217;t allow that, nor did I save the file to my PC).</p>
<p>I&#8217;m suspicious about the line:</p>
<p>&#8220;&#8221;</p>
<p>but, as my HTML coding skills can be written on the back of a postage stamp, that doesn&#8217;t surprise me!</p>
<p>Sorry to ask so many questions.  I guess I could have e-mailed you directly (and I&#8217;m quite happy to continue this in that way), but I just wondered if you, or other contributors, might be able and willing to &#8220;fill me in&#8221;?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
