<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Mitigating .LNK Exploitation With Ariad</title>
	<atom:link href="http://blog.didierstevens.com/2010/07/18/mitigating-lnk-exploitation-with-ariad/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2010/07/18/mitigating-lnk-exploitation-with-ariad/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Sat, 11 Feb 2012 16:16:49 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: How do I protect myself against the .LNK vulnerability?</title>
		<link>http://blog.didierstevens.com/2010/07/18/mitigating-lnk-exploitation-with-ariad/#comment-42019</link>
		<dc:creator><![CDATA[How do I protect myself against the .LNK vulnerability?]]></dc:creator>
		<pubDate>Mon, 07 Mar 2011 07:43:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2210#comment-42019</guid>
		<description><![CDATA[[...] approach to mitigate the possible LNK attack involves the use of Didier Stevens&#8217; tool Ariad. Note that the tool is beta-software operating in the OS kernel, so it&#8217;s probably not a good [...]]]></description>
		<content:encoded><![CDATA[<p>[...] approach to mitigate the possible LNK attack involves the use of Didier Stevens&#8217; tool Ariad. Note that the tool is beta-software operating in the OS kernel, so it&#8217;s probably not a good [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stuxnet / CPLink la situation ne s’arrange pas &#124; Linux-backtrack.com</title>
		<link>http://blog.didierstevens.com/2010/07/18/mitigating-lnk-exploitation-with-ariad/#comment-41785</link>
		<dc:creator><![CDATA[Stuxnet / CPLink la situation ne s’arrange pas &#124; Linux-backtrack.com]]></dc:creator>
		<pubDate>Thu, 10 Feb 2011 21:32:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2210#comment-41785</guid>
		<description><![CDATA[[...] l&#8217;utilisation de son logiciel Ariad qui permet de contrôler finement l&#8217;ouverture automatique de fichiers depuis les supports amovibles ou externes. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] l&#8217;utilisation de son logiciel Ariad qui permet de contrôler finement l&#8217;ouverture automatique de fichiers depuis les supports amovibles ou externes. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jan Willem</title>
		<link>http://blog.didierstevens.com/2010/07/18/mitigating-lnk-exploitation-with-ariad/#comment-40405</link>
		<dc:creator><![CDATA[Jan Willem]]></dc:creator>
		<pubDate>Fri, 29 Oct 2010 23:24:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2210#comment-40405</guid>
		<description><![CDATA[Thanks a lot Sr. Didier Stevens,
I think Ariad will contribute a lot in the fight with an outbreak of LNK FLAW exploiting rootkit-virusses here in Juigalpa, Nicaragua.

gracias, Jan Willem]]></description>
		<content:encoded><![CDATA[<p>Thanks a lot Sr. Didier Stevens,<br />
I think Ariad will contribute a lot in the fight with an outbreak of LNK FLAW exploiting rootkit-virusses here in Juigalpa, Nicaragua.</p>
<p>gracias, Jan Willem</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Quickpost: Ariad &#38; DLL Preloading &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2010/07/18/mitigating-lnk-exploitation-with-ariad/#comment-39658</link>
		<dc:creator><![CDATA[Quickpost: Ariad &#38; DLL Preloading &#171; Didier Stevens]]></dc:creator>
		<pubDate>Thu, 26 Aug 2010 12:11:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2210#comment-39658</guid>
		<description><![CDATA[[...]   I&#8217;m writing this quickpost just in case you hadn&#8217;t figured this out for yourself: the techniques I described to protect machines from the .LNK vulnerability also help you mitigate the DLL [...]]]></description>
		<content:encoded><![CDATA[<p>[...]   I&#8217;m writing this quickpost just in case you hadn&#8217;t figured this out for yourself: the techniques I described to protect machines from the .LNK vulnerability also help you mitigate the DLL [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: How do I protect myself against the .LNK vulnerability? &#124; Blogs News</title>
		<link>http://blog.didierstevens.com/2010/07/18/mitigating-lnk-exploitation-with-ariad/#comment-39420</link>
		<dc:creator><![CDATA[How do I protect myself against the .LNK vulnerability? &#124; Blogs News]]></dc:creator>
		<pubDate>Thu, 05 Aug 2010 13:24:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2210#comment-39420</guid>
		<description><![CDATA[[...] approach to mitigate the possible LNK attack involves the use of Didier Stevens&#8217; tool Ariad. Note that the tool is beta-software operating in the OS kernel, so it&#8217;s probably not a good [...]]]></description>
		<content:encoded><![CDATA[<p>[...] approach to mitigate the possible LNK attack involves the use of Didier Stevens&#8217; tool Ariad. Note that the tool is beta-software operating in the OS kernel, so it&#8217;s probably not a good [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CloneRanger</title>
		<link>http://blog.didierstevens.com/2010/07/18/mitigating-lnk-exploitation-with-ariad/#comment-39363</link>
		<dc:creator><![CDATA[CloneRanger]]></dc:creator>
		<pubDate>Fri, 30 Jul 2010 23:34:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2210#comment-39363</guid>
		<description><![CDATA[@ssj100

Ditto, You write:

&quot;I don’t see why that would be relevant in the case of a USB device. When you plug in an infected USB device (eg. which ALREADY has the DLL file on it), you wouldn’t need to copy anything first.&quot;

I have already posted at least TWICE,

&quot;ONLY if dll.dll has already been placed in C:\ first manually. Please see Post 178 here - http://www.wilderssecurity.com/showthread.php?p=1717108#post1717108&quot;

From my wilders post,

&quot;I deleted dll.dll from C:\ and tried the POC again from both my USB stick and a folder on my desktop. This time just cruising and double clicking showed NO entry in DbgView ! = Fail&quot;

Do remember i am talking about the POC !

Still no PM with a Real Stuxnet nasty for me to run and test and respond to ?

Have a nice weekend everybody

*]]></description>
		<content:encoded><![CDATA[<p>@ssj100</p>
<p>Ditto, You write:</p>
<p>&#8220;I don’t see why that would be relevant in the case of a USB device. When you plug in an infected USB device (eg. which ALREADY has the DLL file on it), you wouldn’t need to copy anything first.&#8221;</p>
<p>I have already posted at least TWICE,</p>
<p>&#8220;ONLY if dll.dll has already been placed in C:\ first manually. Please see Post 178 here &#8211; <a href="http://www.wilderssecurity.com/showthread.php?p=1717108#post1717108" rel="nofollow">http://www.wilderssecurity.com/showthread.php?p=1717108#post1717108</a>&#8221;</p>
<p>From my wilders post,</p>
<p>&#8220;I deleted dll.dll from C:\ and tried the POC again from both my USB stick and a folder on my desktop. This time just cruising and double clicking showed NO entry in DbgView ! = Fail&#8221;</p>
<p>Do remember i am talking about the POC !</p>
<p>Still no PM with a Real Stuxnet nasty for me to run and test and respond to ?</p>
<p>Have a nice weekend everybody</p>
<p>*</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ssj100</title>
		<link>http://blog.didierstevens.com/2010/07/18/mitigating-lnk-exploitation-with-ariad/#comment-39360</link>
		<dc:creator><![CDATA[ssj100]]></dc:creator>
		<pubDate>Thu, 29 Jul 2010 23:43:03 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2210#comment-39360</guid>
		<description><![CDATA[@CloneRanger My friend, thanks for the reply.  I&#039;ll give it one last shot.  You write:

***
&quot;I’m more concerned that UNLESS dll.dll is FIRST copied to C:\ NEITHER A or B test exploit works.&quot;
***

I don&#039;t see why that would be relevant in the case of a USB device.  When you plug in an infected USB device (eg. which ALREADY has the DLL file on it), you wouldn&#039;t need to copy anything first.]]></description>
		<content:encoded><![CDATA[<p>@CloneRanger My friend, thanks for the reply.  I&#8217;ll give it one last shot.  You write:</p>
<p>***<br />
&#8220;I’m more concerned that UNLESS dll.dll is FIRST copied to C:\ NEITHER A or B test exploit works.&#8221;<br />
***</p>
<p>I don&#8217;t see why that would be relevant in the case of a USB device.  When you plug in an infected USB device (eg. which ALREADY has the DLL file on it), you wouldn&#8217;t need to copy anything first.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CloneRanger</title>
		<link>http://blog.didierstevens.com/2010/07/18/mitigating-lnk-exploitation-with-ariad/#comment-39357</link>
		<dc:creator><![CDATA[CloneRanger]]></dc:creator>
		<pubDate>Thu, 29 Jul 2010 03:37:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2210#comment-39357</guid>
		<description><![CDATA[@ssj100

I see why you&#039;re hung up over the rundll32.exe thingy !

I&#039;m more concerned that UNLESS dll.dll is FIRST copied to C:\ NEITHER A or B test exploit works.

As i mentioned before, if you want to send me a version of the &quot;REAL&quot; Stuxnet i’ll test it LIVE from my USB stick. Someone will have to PM me at Wilders with a rapidshare etc link

C ya]]></description>
		<content:encoded><![CDATA[<p>@ssj100</p>
<p>I see why you&#8217;re hung up over the rundll32.exe thingy !</p>
<p>I&#8217;m more concerned that UNLESS dll.dll is FIRST copied to C:\ NEITHER A or B test exploit works.</p>
<p>As i mentioned before, if you want to send me a version of the &#8220;REAL&#8221; Stuxnet i’ll test it LIVE from my USB stick. Someone will have to PM me at Wilders with a rapidshare etc link</p>
<p>C ya</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ssj100</title>
		<link>http://blog.didierstevens.com/2010/07/18/mitigating-lnk-exploitation-with-ariad/#comment-39351</link>
		<dc:creator><![CDATA[ssj100]]></dc:creator>
		<pubDate>Wed, 28 Jul 2010 08:15:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2210#comment-39351</guid>
		<description><![CDATA[@CloneRanger Sorry, but you&#039;re still not understanding what I&#039;m trying to tell you.  &quot;rundll32.exe&quot; is only called when you double click the LNK file.  However, it is not called when you just browse the files (which is the original exploit).

Please repeat your tests against the POC as described here (test A):
http://ssj100.fullsubject.com/security-f7/vulnerability-in-windows-shell-could-allow-remote-code-execution-t187.htm#1308

Hopefully now you will understand why blocking &quot;rundll32.exe&quot; does absolutely nothing against the original exploit.  If you still disagree, then there&#039;s nothing more I can do.  You can ask someone professionally knowledgeable like EraserHW from Prevx for confirmation - he will agree with me, just like Zero_One from BluePoint Security did.  In fact, I&#039;m surprised Didier Stevens himself hasn&#039;t commented on this - it&#039;s his blog after all, and I would have thought his readers deserved clarification of any mis-information.]]></description>
		<content:encoded><![CDATA[<p>@CloneRanger Sorry, but you&#8217;re still not understanding what I&#8217;m trying to tell you.  &#8220;rundll32.exe&#8221; is only called when you double click the LNK file.  However, it is not called when you just browse the files (which is the original exploit).</p>
<p>Please repeat your tests against the POC as described here (test A):<br />
<a href="http://ssj100.fullsubject.com/security-f7/vulnerability-in-windows-shell-could-allow-remote-code-execution-t187.htm#1308" rel="nofollow">http://ssj100.fullsubject.com/security-f7/vulnerability-in-windows-shell-could-allow-remote-code-execution-t187.htm#1308</a></p>
<p>Hopefully now you will understand why blocking &#8220;rundll32.exe&#8221; does absolutely nothing against the original exploit.  If you still disagree, then there&#8217;s nothing more I can do.  You can ask someone professionally knowledgeable like EraserHW from Prevx for confirmation &#8211; he will agree with me, just like Zero_One from BluePoint Security did.  In fact, I&#8217;m surprised Didier Stevens himself hasn&#8217;t commented on this &#8211; it&#8217;s his blog after all, and I would have thought his readers deserved clarification of any mis-information.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CloneRanger</title>
		<link>http://blog.didierstevens.com/2010/07/18/mitigating-lnk-exploitation-with-ariad/#comment-39349</link>
		<dc:creator><![CDATA[CloneRanger]]></dc:creator>
		<pubDate>Wed, 28 Jul 2010 02:50:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2210#comment-39349</guid>
		<description><![CDATA[@ssj100

The following post is from July 21st, 2010, 04:03 PM You must have missed it ?

Tested the POC again today Post 158 - http://www.wilderssecurity.com/showthread.php?s=e552f5bdfcc2d68751a41d9f0a393206&amp;t=276994&amp;page=7

It shows what happened when i included, and removed run32.dll detection in ProcessGuard.]]></description>
		<content:encoded><![CDATA[<p>@ssj100</p>
<p>The following post is from July 21st, 2010, 04:03 PM You must have missed it ?</p>
<p>Tested the POC again today Post 158 &#8211; <a href="http://www.wilderssecurity.com/showthread.php?s=e552f5bdfcc2d68751a41d9f0a393206&#038;t=276994&#038;page=7" rel="nofollow">http://www.wilderssecurity.com/showthread.php?s=e552f5bdfcc2d68751a41d9f0a393206&#038;t=276994&#038;page=7</a></p>
<p>It shows what happened when i included, and removed run32.dll detection in ProcessGuard.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

