<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Updates: bpmtk and Hakin9; PDF and Metasploit</title>
	<atom:link href="http://blog.didierstevens.com/2008/12/09/updates-bpmtk-and-hakin9-pdf-and-metasploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2008/12/09/updates-bpmtk-and-hakin9-pdf-and-metasploit/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Sat, 11 Feb 2012 16:16:49 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: PDF Info Stealer PoC &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2008/12/09/updates-bpmtk-and-hakin9-pdf-and-metasploit/#comment-37792</link>
		<dc:creator><![CDATA[PDF Info Stealer PoC &#171; Didier Stevens]]></dc:creator>
		<pubDate>Mon, 08 Mar 2010 00:01:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=994#comment-37792</guid>
		<description><![CDATA[[...] To protect confidential data, don&#8217;t let it be accessed by systems with Internet access. That&#8217;s not very practical, but it&#8217;s reliable. Or use strong encryption with strong passwords (not the default RC4 Excel encryption). The info stealer will have the extra difficulty to steal the password too. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] To protect confidential data, don&#8217;t let it be accessed by systems with Internet access. That&#8217;s not very practical, but it&#8217;s reliable. Or use strong encryption with strong passwords (not the default RC4 Excel encryption). The info stealer will have the extra difficulty to steal the password too. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan J</title>
		<link>http://blog.didierstevens.com/2008/12/09/updates-bpmtk-and-hakin9-pdf-and-metasploit/#comment-34729</link>
		<dc:creator><![CDATA[Ryan J]]></dc:creator>
		<pubDate>Wed, 29 Apr 2009 10:41:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=994#comment-34729</guid>
		<description><![CDATA[Thanks for the swift reply!
I&#039;ll have to look into it, thanks for pointing me in the right direction
Ryan J]]></description>
		<content:encoded><![CDATA[<p>Thanks for the swift reply!<br />
I&#8217;ll have to look into it, thanks for pointing me in the right direction<br />
Ryan J</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2008/12/09/updates-bpmtk-and-hakin9-pdf-and-metasploit/#comment-34724</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Wed, 29 Apr 2009 09:21:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=994#comment-34724</guid>
		<description><![CDATA[The Sysinternals tools, like Procmon. I noticed cmd.exe accessed registry key DisableCMD just before the warning was displayed the cmd.exe is disabled by the administrator.]]></description>
		<content:encoded><![CDATA[<p>The Sysinternals tools, like Procmon. I noticed cmd.exe accessed registry key DisableCMD just before the warning was displayed the cmd.exe is disabled by the administrator.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan J</title>
		<link>http://blog.didierstevens.com/2008/12/09/updates-bpmtk-and-hakin9-pdf-and-metasploit/#comment-34723</link>
		<dc:creator><![CDATA[Ryan J]]></dc:creator>
		<pubDate>Wed, 29 Apr 2009 09:17:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=994#comment-34723</guid>
		<description><![CDATA[I&#039;m sorry but how did you observe the process?
Did you use the Toolkit? Or some other tool?
I had a look at your Reverse Engineering Mentoring and found a reference to DisableCMD in the cmd.exe but couldn&#039;t understand what it meant.
Thanks for your Blog and Programs.
Ryan J]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m sorry but how did you observe the process?<br />
Did you use the Toolkit? Or some other tool?<br />
I had a look at your Reverse Engineering Mentoring and found a reference to DisableCMD in the cmd.exe but couldn&#8217;t understand what it meant.<br />
Thanks for your Blog and Programs.<br />
Ryan J</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2008/12/09/updates-bpmtk-and-hakin9-pdf-and-metasploit/#comment-34692</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Fri, 24 Apr 2009 12:22:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=994#comment-34692</guid>
		<description><![CDATA[Well, for DisableCMD I did it with dynamic analysis, i.e. observing the process started with and without the setting and see what&#039;s different.]]></description>
		<content:encoded><![CDATA[<p>Well, for DisableCMD I did it with dynamic analysis, i.e. observing the process started with and without the setting and see what&#8217;s different.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan J</title>
		<link>http://blog.didierstevens.com/2008/12/09/updates-bpmtk-and-hakin9-pdf-and-metasploit/#comment-34690</link>
		<dc:creator><![CDATA[Ryan J]]></dc:creator>
		<pubDate>Fri, 24 Apr 2009 09:33:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=994#comment-34690</guid>
		<description><![CDATA[Hey there,

I&#039;ve bought the Hackin9 magazine and read your article.
To me its a little confusing but that&#039;s because im new to this kind of thing.
It may sound a little n00bish but how do you find out that there is a reference to DisableCMD and the like?
I would appreciate any help you can give me as this toolkit really interests me.
Thanks
Ryan J
p.s I love your work!]]></description>
		<content:encoded><![CDATA[<p>Hey there,</p>
<p>I&#8217;ve bought the Hackin9 magazine and read your article.<br />
To me its a little confusing but that&#8217;s because im new to this kind of thing.<br />
It may sound a little n00bish but how do you find out that there is a reference to DisableCMD and the like?<br />
I would appreciate any help you can give me as this toolkit really interests me.<br />
Thanks<br />
Ryan J<br />
p.s I love your work!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: freagan</title>
		<link>http://blog.didierstevens.com/2008/12/09/updates-bpmtk-and-hakin9-pdf-and-metasploit/#comment-33843</link>
		<dc:creator><![CDATA[freagan]]></dc:creator>
		<pubDate>Thu, 11 Dec 2008 20:59:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=994#comment-33843</guid>
		<description><![CDATA[Thank you for your reply, since I live in Italy I think that I have to wait for the pdf version ;-)]]></description>
		<content:encoded><![CDATA[<p>Thank you for your reply, since I live in Italy I think that I have to wait for the pdf version <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2008/12/09/updates-bpmtk-and-hakin9-pdf-and-metasploit/#comment-33841</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Thu, 11 Dec 2008 12:02:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=994#comment-33841</guid>
		<description><![CDATA[It&#039;s in the last issue, published this week.]]></description>
		<content:encoded><![CDATA[<p>It&#8217;s in the last issue, published this week.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: freagan</title>
		<link>http://blog.didierstevens.com/2008/12/09/updates-bpmtk-and-hakin9-pdf-and-metasploit/#comment-33840</link>
		<dc:creator><![CDATA[freagan]]></dc:creator>
		<pubDate>Thu, 11 Dec 2008 07:52:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=994#comment-33840</guid>
		<description><![CDATA[I&#039;m curious to read that hakin9 article, is it already out? In wich issue can I find it?
thank you and keep up the good work ;-)]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m curious to read that hakin9 article, is it already out? In wich issue can I find it?<br />
thank you and keep up the good work <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>

