<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Preventing Malicious Documents from Compromising Windows Machines</title>
	<atom:link href="http://blog.didierstevens.com/2009/09/27/preventing-malicious-documents-from-compromising-windows-machines/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2009/09/27/preventing-malicious-documents-from-compromising-windows-machines/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Tue, 16 Mar 2010 07:37:33 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Michael Lim</title>
		<link>http://blog.didierstevens.com/2009/09/27/preventing-malicious-documents-from-compromising-windows-machines/#comment-36039</link>
		<dc:creator>Michael Lim</dc:creator>
		<pubDate>Wed, 28 Oct 2009 10:33:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1762#comment-36039</guid>
		<description>I used to use http://sudown.sourceforge.net on my shared machine at home, but I had hard time when installing most of the programs. In the end I lost track of which users installed this program and that programs.</description>
		<content:encoded><![CDATA[<p>I used to use <a href="http://sudown.sourceforge.net" rel="nofollow">http://sudown.sourceforge.net</a> on my shared machine at home, but I had hard time when installing most of the programs. In the end I lost track of which users installed this program and that programs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Preventing Applications From Starting (Malicious) Applications &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2009/09/27/preventing-malicious-documents-from-compromising-windows-machines/#comment-35862</link>
		<dc:creator>Preventing Applications From Starting (Malicious) Applications &#171; Didier Stevens</dc:creator>
		<pubDate>Mon, 05 Oct 2009 00:02:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1762#comment-35862</guid>
		<description>[...] Software, PDF, Vulnerabilities, bpmtk &#8212; Didier Stevens @ 0:00   Another very effective way to prevent malicious documents from infecting PCs, is to prevent vulnerable applications from starting other applications. As almost all shellcode [...]</description>
		<content:encoded><![CDATA[<p>[...] Software, PDF, Vulnerabilities, bpmtk &#8212; Didier Stevens @ 0:00   Another very effective way to prevent malicious documents from infecting PCs, is to prevent vulnerable applications from starting other applications. As almost all shellcode [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2009/09/27/preventing-malicious-documents-from-compromising-windows-machines/#comment-35860</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Sun, 04 Oct 2009 10:27:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1762#comment-35860</guid>
		<description>@krazykatfelix

Thanks! To restrict the rights of explorer.exe and all the programs it starts, it&#039;s even better to create an Image File Execution Options for explorer.exe This way, explorer.exe will never start with full rights.</description>
		<content:encoded><![CDATA[<p>@krazykatfelix</p>
<p>Thanks! To restrict the rights of explorer.exe and all the programs it starts, it&#8217;s even better to create an Image File Execution Options for explorer.exe This way, explorer.exe will never start with full rights.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: krazykatfelix</title>
		<link>http://blog.didierstevens.com/2009/09/27/preventing-malicious-documents-from-compromising-windows-machines/#comment-35859</link>
		<dc:creator>krazykatfelix</dc:creator>
		<pubDate>Sun, 04 Oct 2009 09:09:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1762#comment-35859</guid>
		<description>Hello,

No comment

start taskkill /IM explorer.exe /F
c:\DropMyRights\DropMyRights.exe &quot;c:\windows\explorer.exe &quot;

not so bad !</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>No comment</p>
<p>start taskkill /IM explorer.exe /F<br />
c:\DropMyRights\DropMyRights.exe &#8220;c:\windows\explorer.exe &#8221;</p>
<p>not so bad !</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Machine Manufacturing</title>
		<link>http://blog.didierstevens.com/2009/09/27/preventing-malicious-documents-from-compromising-windows-machines/#comment-35843</link>
		<dc:creator>Machine Manufacturing</dc:creator>
		<pubDate>Tue, 29 Sep 2009 10:50:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1762#comment-35843</guid>
		<description>Thanks for sharing this important information. This article is very useful and can help anyone who wants to protect his/her PC from malicious documents and viruses.</description>
		<content:encoded><![CDATA[<p>Thanks for sharing this important information. This article is very useful and can help anyone who wants to protect his/her PC from malicious documents and viruses.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2009/09/27/preventing-malicious-documents-from-compromising-windows-machines/#comment-35838</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Mon, 28 Sep 2009 18:03:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1762#comment-35838</guid>
		<description>@kurt wismer
Neither do I had real issues running as a non-admin on XP. Except when developing COM and ActiveX components with VS6.</description>
		<content:encoded><![CDATA[<p>@kurt wismer<br />
Neither do I had real issues running as a non-admin on XP. Except when developing COM and ActiveX components with VS6.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Quickpost: SAFER and Malicious Documents &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2009/09/27/preventing-malicious-documents-from-compromising-windows-machines/#comment-35837</link>
		<dc:creator>Quickpost: SAFER and Malicious Documents &#171; Didier Stevens</dc:creator>
		<pubDate>Mon, 28 Sep 2009 17:52:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1762#comment-35837</guid>
		<description>[...] under: My Software, Quickpost &#8212; Didier Stevens @ 17:50   I wasn’t going to mention SAFER to restrict the rights of an application, because Software Restriction Policies can be bypassed. But a Tweet by Edi Strosar made me review [...]</description>
		<content:encoded><![CDATA[<p>[...] under: My Software, Quickpost &#8212; Didier Stevens @ 17:50   I wasn’t going to mention SAFER to restrict the rights of an application, because Software Restriction Policies can be bypassed. But a Tweet by Edi Strosar made me review [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kurt wismer</title>
		<link>http://blog.didierstevens.com/2009/09/27/preventing-malicious-documents-from-compromising-windows-machines/#comment-35835</link>
		<dc:creator>kurt wismer</dc:creator>
		<pubDate>Mon, 28 Sep 2009 17:37:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1762#comment-35835</guid>
		<description>y&#039;know, i&#039;ve never really had much difficulty running as a non-admin on my XP box. i only ever run as an admin when i&#039;m applying updates (no more than once a week if that) or need to install something new (which i try my best to keep to a minimum - to the point of opting for portable apps instead).

that said, i also use sandboxie, not just for browsing and email but for reading documents from the outside world as well. 

and i use application whitelisting which, if i&#039;m not mistaken, would likely stop the 3rd step of the system compromise you describe (unless further exotic execution is used).</description>
		<content:encoded><![CDATA[<p>y&#8217;know, i&#8217;ve never really had much difficulty running as a non-admin on my XP box. i only ever run as an admin when i&#8217;m applying updates (no more than once a week if that) or need to install something new (which i try my best to keep to a minimum &#8211; to the point of opting for portable apps instead).</p>
<p>that said, i also use sandboxie, not just for browsing and email but for reading documents from the outside world as well. </p>
<p>and i use application whitelisting which, if i&#8217;m not mistaken, would likely stop the 3rd step of the system compromise you describe (unless further exotic execution is used).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2009/09/27/preventing-malicious-documents-from-compromising-windows-machines/#comment-35833</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Sun, 27 Sep 2009 17:06:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1762#comment-35833</guid>
		<description>Hi Xavier.

Yes, sandboxes are great tools too, I remember your blogpost. I use Sandboxie myself.

The advantage of DropMyRights and StripMyRights is that they are easy to deploy. You could use an AD GPO to deploy them in case of an emergency, for example a new vulnerability is being massively exploited and you can&#039;t update the vulnerable program immediately.</description>
		<content:encoded><![CDATA[<p>Hi Xavier.</p>
<p>Yes, sandboxes are great tools too, I remember your blogpost. I use Sandboxie myself.</p>
<p>The advantage of DropMyRights and StripMyRights is that they are easy to deploy. You could use an AD GPO to deploy them in case of an emergency, for example a new vulnerability is being massively exploited and you can&#8217;t update the vulnerable program immediately.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TwittLink - Your headlines on Twitter</title>
		<link>http://blog.didierstevens.com/2009/09/27/preventing-malicious-documents-from-compromising-windows-machines/#comment-35829</link>
		<dc:creator>TwittLink - Your headlines on Twitter</dc:creator>
		<pubDate>Sun, 27 Sep 2009 15:02:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1762#comment-35829</guid>
		<description>[...] Preventing Malicious Documents from Compromising Windows Machines « Didier Stevens [...]</description>
		<content:encoded><![CDATA[<p>[...] Preventing Malicious Documents from Compromising Windows Machines « Didier Stevens [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
