<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Mitigating .LNK Exploitation With SRP</title>
	<atom:link href="http://blog.didierstevens.com/2010/07/20/mitigating-lnk-exploitation-with-srp/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2010/07/20/mitigating-lnk-exploitation-with-srp/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Sat, 11 Feb 2012 16:16:49 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Stuxnet / CPLink la situation ne s’arrange pas &#124; Linux-backtrack.com</title>
		<link>http://blog.didierstevens.com/2010/07/20/mitigating-lnk-exploitation-with-srp/#comment-41784</link>
		<dc:creator><![CDATA[Stuxnet / CPLink la situation ne s’arrange pas &#124; Linux-backtrack.com]]></dc:creator>
		<pubDate>Thu, 10 Feb 2011 21:32:38 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2242#comment-41784</guid>
		<description><![CDATA[[...] la mise en place de règles locales de sécurité qui empêchent l&#8217;exécution de fichiers extérieurs au disque système C:; [...]]]></description>
		<content:encoded><![CDATA[<p>[...] la mise en place de règles locales de sécurité qui empêchent l&#8217;exécution de fichiers extérieurs au disque système C:; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Quickpost: Ariad &#38; DLL Preloading &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2010/07/20/mitigating-lnk-exploitation-with-srp/#comment-39659</link>
		<dc:creator><![CDATA[Quickpost: Ariad &#38; DLL Preloading &#171; Didier Stevens]]></dc:creator>
		<pubDate>Thu, 26 Aug 2010 12:11:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2242#comment-39659</guid>
		<description><![CDATA[[...] writing this quickpost just in case you hadn&#8217;t figured this out for yourself: the techniques I described to protect machines from the .LNK vulnerability also help you mitigate the DLL preloading [...]]]></description>
		<content:encoded><![CDATA[<p>[...] writing this quickpost just in case you hadn&#8217;t figured this out for yourself: the techniques I described to protect machines from the .LNK vulnerability also help you mitigate the DLL preloading [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Free_Sophos_tool_blocks_Windows_shortcut_attacks</title>
		<link>http://blog.didierstevens.com/2010/07/20/mitigating-lnk-exploitation-with-srp/#comment-39350</link>
		<dc:creator><![CDATA[Free_Sophos_tool_blocks_Windows_shortcut_attacks]]></dc:creator>
		<pubDate>Wed, 28 Jul 2010 05:07:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2242#comment-39350</guid>
		<description><![CDATA[[...] is still a disgrace    Details. http://technet.microsoft.com/en-us/l.../bb457006.aspx  Mitigating .LNK Exploitation with SRP &#124; Didier Stevens  Sujay, that&#039;s one of the best OS defensive pillbox. But it wont appeal to [...]]]></description>
		<content:encoded><![CDATA[<p>[...] is still a disgrace    Details. <a href="http://technet.microsoft.com/en-us/l.../bb457006.aspx" rel="nofollow">http://technet.microsoft.com/en-us/l&#8230;/bb457006.aspx</a>  Mitigating .LNK Exploitation with SRP | Didier Stevens  Sujay, that&#039;s one of the best OS defensive pillbox. But it wont appeal to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: -</title>
		<link>http://blog.didierstevens.com/2010/07/20/mitigating-lnk-exploitation-with-srp/#comment-39344</link>
		<dc:creator><![CDATA[-]]></dc:creator>
		<pubDate>Tue, 27 Jul 2010 10:48:40 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2242#comment-39344</guid>
		<description><![CDATA[after looking over the ms kb, and googling, it looks like it&#039;s easiest for everyday win users to set webclient to &quot;stopped&quot; and &quot;disabled&quot; in services.msc
webclient is probably already off, i assume (uh oh ;-) ) that disabling it will prevent a .lnk file (in explorer.exe) from starting up webclient?]]></description>
		<content:encoded><![CDATA[<p>after looking over the ms kb, and googling, it looks like it&#8217;s easiest for everyday win users to set webclient to &#8220;stopped&#8221; and &#8220;disabled&#8221; in services.msc<br />
webclient is probably already off, i assume (uh oh <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  ) that disabling it will prevent a .lnk file (in explorer.exe) from starting up webclient?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2010/07/20/mitigating-lnk-exploitation-with-srp/#comment-39336</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Mon, 26 Jul 2010 16:26:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2242#comment-39336</guid>
		<description><![CDATA[@prk No, nothing special.]]></description>
		<content:encoded><![CDATA[<p>@prk No, nothing special.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: prk</title>
		<link>http://blog.didierstevens.com/2010/07/20/mitigating-lnk-exploitation-with-srp/#comment-39332</link>
		<dc:creator><![CDATA[prk]]></dc:creator>
		<pubDate>Mon, 26 Jul 2010 07:34:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2242#comment-39332</guid>
		<description><![CDATA[There are a few... I.e

http://jafat.sourceforge.net/files.html
http://www.javafaq.nu/java-example-code-468.html

Plus the good reference at http://msdn.microsoft.com/en-us/library/dd871305%28PROT.10%29.aspx (which lately has received some well needed updates)

I phrased it wrong though, I really meant any common LNK Parser (the public ones, EnCase&#039;s, etc). Do you get any useful information out of your template on these specific LNKs?]]></description>
		<content:encoded><![CDATA[<p>There are a few&#8230; I.e</p>
<p><a href="http://jafat.sourceforge.net/files.html" rel="nofollow">http://jafat.sourceforge.net/files.html</a><br />
<a href="http://www.javafaq.nu/java-example-code-468.html" rel="nofollow">http://www.javafaq.nu/java-example-code-468.html</a></p>
<p>Plus the good reference at <a href="http://msdn.microsoft.com/en-us/library/dd871305%28PROT.10%29.aspx" rel="nofollow">http://msdn.microsoft.com/en-us/library/dd871305%28PROT.10%29.aspx</a> (which lately has received some well needed updates)</p>
<p>I phrased it wrong though, I really meant any common LNK Parser (the public ones, EnCase&#8217;s, etc). Do you get any useful information out of your template on these specific LNKs?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2010/07/20/mitigating-lnk-exploitation-with-srp/#comment-39331</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Mon, 26 Jul 2010 07:15:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2242#comment-39331</guid>
		<description><![CDATA[@prk No, but I&#039;ve written my own 010 Editor template for the .LNK binary format. Do you have a link to a publicly available LNK parser?]]></description>
		<content:encoded><![CDATA[<p>@prk No, but I&#8217;ve written my own 010 Editor template for the .LNK binary format. Do you have a link to a publicly available LNK parser?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: prk</title>
		<link>http://blog.didierstevens.com/2010/07/20/mitigating-lnk-exploitation-with-srp/#comment-39330</link>
		<dc:creator><![CDATA[prk]]></dc:creator>
		<pubDate>Mon, 26 Jul 2010 07:06:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2242#comment-39330</guid>
		<description><![CDATA[@Didier
Hey Didier! Yes, it does. I wasn&#039;t too sure what the stroke meant as I hadn&#039;t seen the original post.
*hint* Have you tried parsing these LNKs with any current publicly available LNK parser? :)]]></description>
		<content:encoded><![CDATA[<p>@Didier<br />
Hey Didier! Yes, it does. I wasn&#8217;t too sure what the stroke meant as I hadn&#8217;t seen the original post.<br />
*hint* Have you tried parsing these LNKs with any current publicly available LNK parser? <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Week 29 in Review – 2010 &#124; Portable Digital Video Recorder</title>
		<link>http://blog.didierstevens.com/2010/07/20/mitigating-lnk-exploitation-with-srp/#comment-39329</link>
		<dc:creator><![CDATA[Week 29 in Review – 2010 &#124; Portable Digital Video Recorder]]></dc:creator>
		<pubDate>Mon, 26 Jul 2010 05:46:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2242#comment-39329</guid>
		<description><![CDATA[[...] Mitigating .LNK Exploitation With SRP &#8211; didierstevens.com [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Mitigating .LNK Exploitation With SRP &#8211; didierstevens.com [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Week 29 in Review &#8211; 2010 &#124; Infosec Events</title>
		<link>http://blog.didierstevens.com/2010/07/20/mitigating-lnk-exploitation-with-srp/#comment-39328</link>
		<dc:creator><![CDATA[Week 29 in Review &#8211; 2010 &#124; Infosec Events]]></dc:creator>
		<pubDate>Mon, 26 Jul 2010 04:34:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2242#comment-39328</guid>
		<description><![CDATA[[...] Mitigating .LNK Exploitation With SRP &#8211; didierstevens.com [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Mitigating .LNK Exploitation With SRP &#8211; didierstevens.com [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

