<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Excel with cmd.dll &amp; regedit.dll</title>
	<atom:link href="http://blog.didierstevens.com/2010/02/08/excel-with-cmd-dll-regedit-dll/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2010/02/08/excel-with-cmd-dll-regedit-dll/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Sat, 11 Feb 2012 16:16:49 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Exploit writing tutorial part 11 : Heap Spraying Demystified &#124; Corelan Team</title>
		<link>http://blog.didierstevens.com/2010/02/08/excel-with-cmd-dll-regedit-dll/#comment-49202</link>
		<dc:creator><![CDATA[Exploit writing tutorial part 11 : Heap Spraying Demystified &#124; Corelan Team]]></dc:creator>
		<pubDate>Sun, 01 Jan 2012 06:53:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1989#comment-49202</guid>
		<description><![CDATA[[...] Excel with cmd.dll &amp; regedit.dll [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Excel with cmd.dll &amp; regedit.dll [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2010/02/08/excel-with-cmd-dll-regedit-dll/#comment-48528</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Thu, 15 Dec 2011 22:34:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1989#comment-48528</guid>
		<description><![CDATA[@danielweis A Kiwi neighbor of yours has done that ;-) http://blog.didierstevens.com/2011/04/19/signed-spreadsheet-with-cmd-dll-regedit-dll/]]></description>
		<content:encoded><![CDATA[<p>@danielweis A Kiwi neighbor of yours has done that <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  <a href="http://blog.didierstevens.com/2011/04/19/signed-spreadsheet-with-cmd-dll-regedit-dll/" rel="nofollow">http://blog.didierstevens.com/2011/04/19/signed-spreadsheet-with-cmd-dll-regedit-dll/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: danielweis</title>
		<link>http://blog.didierstevens.com/2010/02/08/excel-with-cmd-dll-regedit-dll/#comment-48527</link>
		<dc:creator><![CDATA[danielweis]]></dc:creator>
		<pubDate>Thu, 15 Dec 2011 22:28:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1989#comment-48527</guid>
		<description><![CDATA[Hi There, will you be making your completed spreadsheet with all the macro configuration in it available for download?  Great work by the way :)]]></description>
		<content:encoded><![CDATA[<p>Hi There, will you be making your completed spreadsheet with all the macro configuration in it available for download?  Great work by the way <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2010/02/08/excel-with-cmd-dll-regedit-dll/#comment-42507</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Fri, 22 Apr 2011 08:10:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1989#comment-42507</guid>
		<description><![CDATA[@teo I&#039;ve used it in 2 situations:
1) you administer LUA users, you&#039;ve restricted them from using cmd.exe and/or regedit, and now you need to debug an issue in a LUA context.
2) cleaning up an infected PC where the malware prevents you from running tools like cmd.exe and regedit.]]></description>
		<content:encoded><![CDATA[<p>@teo I&#8217;ve used it in 2 situations:<br />
1) you administer LUA users, you&#8217;ve restricted them from using cmd.exe and/or regedit, and now you need to debug an issue in a LUA context.<br />
2) cleaning up an infected PC where the malware prevents you from running tools like cmd.exe and regedit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: teo</title>
		<link>http://blog.didierstevens.com/2010/02/08/excel-with-cmd-dll-regedit-dll/#comment-42497</link>
		<dc:creator><![CDATA[teo]]></dc:creator>
		<pubDate>Thu, 21 Apr 2011 18:30:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1989#comment-42497</guid>
		<description><![CDATA[Can u pls give me an example where I could use this thing? Apart from demonstrating all these techniques. In what situation would that this be useful? Keep &quot;wow-ing&quot; us Didier.]]></description>
		<content:encoded><![CDATA[<p>Can u pls give me an example where I could use this thing? Apart from demonstrating all these techniques. In what situation would that this be useful? Keep &#8220;wow-ing&#8221; us Didier.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Signed Spreadsheet with cmd.dll &#38; regedit.dll &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2010/02/08/excel-with-cmd-dll-regedit-dll/#comment-42469</link>
		<dc:creator><![CDATA[Signed Spreadsheet with cmd.dll &#38; regedit.dll &#171; Didier Stevens]]></dc:creator>
		<pubDate>Tue, 19 Apr 2011 14:05:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1989#comment-42469</guid>
		<description><![CDATA[[...] Remember my Excel with cmd.dll &amp; regedit.dll? [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Remember my Excel with cmd.dll &amp; regedit.dll? [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Circumventing SRP and AppLocker, By Design &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2010/02/08/excel-with-cmd-dll-regedit-dll/#comment-41578</link>
		<dc:creator><![CDATA[Circumventing SRP and AppLocker, By Design &#171; Didier Stevens]]></dc:creator>
		<pubDate>Mon, 24 Jan 2011 00:04:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1989#comment-41578</guid>
		<description><![CDATA[[...] to block this DLL with SRP or AppLocker. But now I found out it&#8217;s also easy to bypass this, much easier than what I&#8217;ve done before. I just have to replace a call to LoadLibrary with a call to LoadLibraryEx, and pass it argument [...]]]></description>
		<content:encoded><![CDATA[<p>[...] to block this DLL with SRP or AppLocker. But now I found out it&#8217;s also easy to bypass this, much easier than what I&#8217;ve done before. I just have to replace a call to LoadLibrary with a call to LoadLibraryEx, and pass it argument [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Prevent Files With These Extensions Running From These Locations...</title>
		<link>http://blog.didierstevens.com/2010/02/08/excel-with-cmd-dll-regedit-dll/#comment-39074</link>
		<dc:creator><![CDATA[Prevent Files With These Extensions Running From These Locations...]]></dc:creator>
		<pubDate>Sun, 11 Jul 2010 10:20:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1989#comment-39074</guid>
		<description><![CDATA[[...] and wscript.exe?  It&#039;s also worth mentioning that even after you have done the above, it is still very easy to bypass these restrictions via process injection. I reckon a student could easily do this if they [...]]]></description>
		<content:encoded><![CDATA[<p>[...] and wscript.exe?  It&#039;s also worth mentioning that even after you have done the above, it is still very easy to bypass these restrictions via process injection. I reckon a student could easily do this if they [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2010/02/08/excel-with-cmd-dll-regedit-dll/#comment-37855</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Fri, 19 Mar 2010 16:36:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1989#comment-37855</guid>
		<description><![CDATA[@sgt Pepper Regedit.dll and cmd.dll run inside the Excel process with new threads. Provided Excel runs under the (elevated) Admin account, regedit will too.]]></description>
		<content:encoded><![CDATA[<p>@sgt Pepper Regedit.dll and cmd.dll run inside the Excel process with new threads. Provided Excel runs under the (elevated) Admin account, regedit will too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sgt Pepper</title>
		<link>http://blog.didierstevens.com/2010/02/08/excel-with-cmd-dll-regedit-dll/#comment-37854</link>
		<dc:creator><![CDATA[sgt Pepper]]></dc:creator>
		<pubDate>Fri, 19 Mar 2010 16:17:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1989#comment-37854</guid>
		<description><![CDATA[cool stuff. Is the regedit in godmode (admin)?]]></description>
		<content:encoded><![CDATA[<p>cool stuff. Is the regedit in godmode (admin)?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

