<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Didier Stevens &#187; Update</title>
	<atom:link href="http://blog.didierstevens.com/category/update/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Sat, 04 Feb 2012 06:57:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.didierstevens.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Didier Stevens &#187; Update</title>
		<link>http://blog.didierstevens.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.didierstevens.com/osd.xml" title="Didier Stevens" />
	<atom:link rel='hub' href='http://blog.didierstevens.com/?pushpress=hub'/>
		<item>
		<title>Update: USBVirusScan 1.7.4</title>
		<link>http://blog.didierstevens.com/2011/10/08/update-usbvirusscan-1-7-3/</link>
		<comments>http://blog.didierstevens.com/2011/10/08/update-usbvirusscan-1-7-3/#comments</comments>
		<pubDate>Sat, 08 Oct 2011 00:00:08 +0000</pubDate>
		<dc:creator>Didier Stevens</dc:creator>
				<category><![CDATA[Update]]></category>
		<category><![CDATA[My Software]]></category>

		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2833</guid>
		<description><![CDATA[This new version 1.7.4 adds some extra debug info to the debug option (-d) and adds a new option (-w) to disable WOW64 filesystem redirection. When USBVirusScan launches the program that was specified as argument upon insertion of a removable drive, it will provide debug information regarding the launching of this program. In case of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=2833&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This <a href="http://blog.didierstevens.com/programs/usbvirusscan/">new version 1.7.4</a> adds some extra debug info to the debug option (-d) and adds a new option (-w) to disable WOW64 filesystem redirection.</p>
<p>When USBVirusScan launches the program that was specified as argument upon insertion of a removable drive, it will provide debug information regarding the launching of this program.</p>
<p>In case of failure to launch the program, the debug info will include the error message from the Windows API:</p>
<p><img class="alignnone size-full wp-image-2835" title="20111005-145624" src="http://didierstevens.files.wordpress.com/2011/10/20111005-145624.png" alt="" width="891" height="316" /></p>
<p>If successfully launched, the debug info will include the process ID of the launched program:</p>
<p><img class="alignnone size-full wp-image-2836" title="20111005-145859" src="http://didierstevens.files.wordpress.com/2011/10/20111005-145859.png" alt="" width="891" height="316" /></p>
<p>USBVirusScan is a 32-bit application, but it works fine on 64-bit Windows. It can launch 64-bit programs without problems, except Windows&#8217; own applications that come in 32-bit and 64-bit versions. For example, if you configure USBVirusScan to launch calc.exe on 64-bit Windows 7, it will launch the 32-bit version of calc.exe and not the 64-bit version. This is due to the WOW64 filesystem redirection mechanism. USBVirusScan has an option (-w) to disable this WOW64 filesystem redirection (only for USBVirusScan, not for your other programs). Disabling WOW64 filesystem redirection allows USBVirusScan to launch the 64-bit version of calc.exe.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/didierstevens.wordpress.com/2833/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/didierstevens.wordpress.com/2833/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/didierstevens.wordpress.com/2833/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/didierstevens.wordpress.com/2833/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/didierstevens.wordpress.com/2833/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/didierstevens.wordpress.com/2833/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/didierstevens.wordpress.com/2833/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/didierstevens.wordpress.com/2833/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/didierstevens.wordpress.com/2833/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/didierstevens.wordpress.com/2833/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/didierstevens.wordpress.com/2833/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/didierstevens.wordpress.com/2833/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/didierstevens.wordpress.com/2833/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/didierstevens.wordpress.com/2833/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=2833&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.didierstevens.com/2011/10/08/update-usbvirusscan-1-7-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">didierstevens</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2011/10/20111005-145624.png" medium="image">
			<media:title type="html">20111005-145624</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2011/10/20111005-145859.png" medium="image">
			<media:title type="html">20111005-145859</media:title>
		</media:content>
	</item>
		<item>
		<title>Update: TaskManager.xls Version 0.0.3</title>
		<link>http://blog.didierstevens.com/2011/03/01/update-taskmanager-xls-version-0-0-3/</link>
		<comments>http://blog.didierstevens.com/2011/03/01/update-taskmanager-xls-version-0-0-3/#comments</comments>
		<pubDate>Tue, 01 Mar 2011 11:47:27 +0000</pubDate>
		<dc:creator>Didier Stevens</dc:creator>
				<category><![CDATA[My Software]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2599</guid>
		<description><![CDATA[My TaskManager.xls spreadsheet is very popular, so here&#8217;s a new version. I&#8217;ve added a couple of columns with info I need (the Filename, the process Creation time and a 32/64 bit indicator). And this new version also enables the debug privilege to display info for processes of other users. Of course, you need the debug [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=2599&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>My <a href="http://blog.didierstevens.com/2011/02/03/taskmanager-xls/">TaskManager.xls spreadsheet</a> is very popular, so here&#8217;s a new version.</p>
<p>I&#8217;ve added a couple of columns with info I need (the Filename, the process Creation time and a 32/64 bit indicator).</p>
<p>And this new version also enables the debug privilege to display info for processes of other users. Of course, you need the debug privilege in first place for this to work. So you have to be a local admin, and if you use an OS with UAC, you have to elevate the Excel application (run as administrator).</p>
<p>TaskManager.xls works on 64-bit Windows, provided you use 32-bit Excel. It doesn&#8217;t work on 64-bit Excel yet, I&#8217;ll release a new version that does later.</p>
<p>Download:</p>
<p><a href="http://www.didierstevens.com/files/software/TaskManager_V0_0_3.zip">TaskManager_V0_0_3.zip</a> (<a href="https://www.didierstevens.com/files/software/TaskManager_V0_0_3.zip">https</a>)</p>
<p>MD5: BF40B4317C7E04E1F65B8CEE55ED3A7A</p>
<p>SHA256: 0D48C2E6986F1DD8FA3A0671A1A53F0FC489923701963031FDC4FA516603EEC1</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/didierstevens.wordpress.com/2599/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/didierstevens.wordpress.com/2599/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/didierstevens.wordpress.com/2599/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/didierstevens.wordpress.com/2599/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/didierstevens.wordpress.com/2599/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/didierstevens.wordpress.com/2599/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/didierstevens.wordpress.com/2599/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/didierstevens.wordpress.com/2599/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/didierstevens.wordpress.com/2599/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/didierstevens.wordpress.com/2599/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/didierstevens.wordpress.com/2599/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/didierstevens.wordpress.com/2599/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/didierstevens.wordpress.com/2599/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/didierstevens.wordpress.com/2599/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=2599&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.didierstevens.com/2011/03/01/update-taskmanager-xls-version-0-0-3/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">didierstevens</media:title>
		</media:content>
	</item>
		<item>
		<title>Update: WhoAmI? Version 0.1.5</title>
		<link>http://blog.didierstevens.com/2011/02/11/update-whoami-version-0-1-5/</link>
		<comments>http://blog.didierstevens.com/2011/02/11/update-whoami-version-0-1-5/#comments</comments>
		<pubDate>Fri, 11 Feb 2011 10:05:58 +0000</pubDate>
		<dc:creator>Didier Stevens</dc:creator>
				<category><![CDATA[My Software]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2588</guid>
		<description><![CDATA[I’ve updated my WhoAmI? Firefox add-on for Firefox version 4. You can get it from the Mozilla site.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=2588&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I’ve updated my WhoAmI? Firefox add-on for Firefox version 4.</p>
<p>You can get it from the <a href="https://addons.mozilla.org/en-US/firefox/addon/5797" target="_blank">Mozilla</a> site.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/didierstevens.wordpress.com/2588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/didierstevens.wordpress.com/2588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/didierstevens.wordpress.com/2588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/didierstevens.wordpress.com/2588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/didierstevens.wordpress.com/2588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/didierstevens.wordpress.com/2588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/didierstevens.wordpress.com/2588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/didierstevens.wordpress.com/2588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/didierstevens.wordpress.com/2588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/didierstevens.wordpress.com/2588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/didierstevens.wordpress.com/2588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/didierstevens.wordpress.com/2588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/didierstevens.wordpress.com/2588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/didierstevens.wordpress.com/2588/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=2588&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.didierstevens.com/2011/02/11/update-whoami-version-0-1-5/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">didierstevens</media:title>
		</media:content>
	</item>
		<item>
		<title>Update: LoadDLLViaAppInit</title>
		<link>http://blog.didierstevens.com/2010/10/26/update-loaddllviaappinit/</link>
		<comments>http://blog.didierstevens.com/2010/10/26/update-loaddllviaappinit/#comments</comments>
		<pubDate>Tue, 26 Oct 2010 09:04:50 +0000</pubDate>
		<dc:creator>Didier Stevens</dc:creator>
				<category><![CDATA[My Software]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2376</guid>
		<description><![CDATA[This new version of LoadDLLViaAppInit allows you to load more than one DLL inside a process. You separate the DLL names with a semi-colon (;). For example, to load DLLs hook-createprocess.dll and EnforcePermanentDEP.dll inside process acrord32.exe, you configure this: acrord32.exe    hook-createprocess.dll;EnforcePermanentDEP.dll Download: LoadDLLViaAppInit_V0_0_0_2.zip (https) MD5: F458DAEAB1A3E68870EE0608E2A1FFFC SHA256: 9C8BA52A68893F33E0019CC64264C24A7EEC09C5D0DAE6F43C110ACFD45E621F<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=2376&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This new version of <a href="http://blog.didierstevens.com/2009/12/23/loaddllviaappinit/">LoadDLLViaAppInit</a> allows you to load more than one DLL inside a process. You separate the DLL names with a semi-colon (;).</p>
<p>For example, to load DLLs hook-createprocess.dll and EnforcePermanentDEP.dll inside process acrord32.exe, you configure this:</p>
<pre>acrord32.exe    hook-createprocess.dll;EnforcePermanentDEP.dll</pre>
<p>Download:</p>
<p><a href="http://www.didierstevens.com/files/software/LoadDLLViaAppInit_V0_0_0_2.zip">LoadDLLViaAppInit_V0_0_0_2.zip</a> (<a href="https://www.didierstevens.com/files/software/LoadDLLViaAppInit_V0_0_0_2.zip">https</a>)</p>
<p>MD5: F458DAEAB1A3E68870EE0608E2A1FFFC</p>
<p>SHA256: 9C8BA52A68893F33E0019CC64264C24A7EEC09C5D0DAE6F43C110ACFD45E621F</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/didierstevens.wordpress.com/2376/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/didierstevens.wordpress.com/2376/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/didierstevens.wordpress.com/2376/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/didierstevens.wordpress.com/2376/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/didierstevens.wordpress.com/2376/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/didierstevens.wordpress.com/2376/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/didierstevens.wordpress.com/2376/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/didierstevens.wordpress.com/2376/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/didierstevens.wordpress.com/2376/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/didierstevens.wordpress.com/2376/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/didierstevens.wordpress.com/2376/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/didierstevens.wordpress.com/2376/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/didierstevens.wordpress.com/2376/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/didierstevens.wordpress.com/2376/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=2376&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.didierstevens.com/2010/10/26/update-loaddllviaappinit/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">didierstevens</media:title>
		</media:content>
	</item>
		<item>
		<title>Update: PDFiD Version 0.0.11 to Detect /Launch</title>
		<link>http://blog.didierstevens.com/2010/04/29/update-pdfid-version-0-0-11-to-detect-launch/</link>
		<comments>http://blog.didierstevens.com/2010/04/29/update-pdfid-version-0-0-11-to-detect-launch/#comments</comments>
		<pubDate>Thu, 29 Apr 2010 10:11:03 +0000</pubDate>
		<dc:creator>Didier Stevens</dc:creator>
				<category><![CDATA[My Software]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2144</guid>
		<description><![CDATA[Now that malicious PDFs using the /Launch action become more prevalent, I release a new PDFiD version to detect (and disarm) the /Launch action.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=2144&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Now that malicious PDFs using the /Launch action become more prevalent, I release a new <a href="http://blog.didierstevens.com/programs/pdf-tools/#pdfid">PDFiD</a> version to detect (and disarm) the /Launch action.</p>
<p><img class="alignnone size-full wp-image-2146" title="20100428-215941" src="http://didierstevens.files.wordpress.com/2010/04/20100428-215941.png" alt="" width="240" height="87" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/didierstevens.wordpress.com/2144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/didierstevens.wordpress.com/2144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/didierstevens.wordpress.com/2144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/didierstevens.wordpress.com/2144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/didierstevens.wordpress.com/2144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/didierstevens.wordpress.com/2144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/didierstevens.wordpress.com/2144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/didierstevens.wordpress.com/2144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/didierstevens.wordpress.com/2144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/didierstevens.wordpress.com/2144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/didierstevens.wordpress.com/2144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/didierstevens.wordpress.com/2144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/didierstevens.wordpress.com/2144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/didierstevens.wordpress.com/2144/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=2144&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.didierstevens.com/2010/04/29/update-pdfid-version-0-0-11-to-detect-launch/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">didierstevens</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2010/04/20100428-215941.png" medium="image">
			<media:title type="html">20100428-215941</media:title>
		</media:content>
	</item>
		<item>
		<title>Update: Escape From PDF</title>
		<link>http://blog.didierstevens.com/2010/04/06/update-escape-from-pdf/</link>
		<comments>http://blog.didierstevens.com/2010/04/06/update-escape-from-pdf/#comments</comments>
		<pubDate>Tue, 06 Apr 2010 00:01:57 +0000</pubDate>
		<dc:creator>Didier Stevens</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2119</guid>
		<description><![CDATA[Some new info after last week&#8217;s Adobe and Foxit escapes. Foxit Software has release a new version to issue a warning when using a /Launch action, like Adobe Reader does: The interesting thing about this fix is that it breaks my Foxit PoC, but that the Adobe PoC works for Foxit now! This means that [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=2119&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Some new info after last week&#8217;s <a href="http://blog.didierstevens.com/2010/03/29/escape-from-pdf/">Adobe</a> and <a href="http://blog.didierstevens.com/2010/03/31/escape-from-foxit-reader/">Foxit</a> escapes.</p>
<p>Foxit Software has release a new version to issue a warning when using a /Launch action, like Adobe Reader does:</p>
<p><img class="alignnone size-full wp-image-2120" title="20100403-231726" src="http://didierstevens.files.wordpress.com/2010/04/20100403-231726.png" alt="" width="434" height="247" /></p>
<p>The interesting thing about this fix is that it breaks my Foxit PoC, but that the Adobe PoC works for Foxit now!</p>
<p>This means that Foxit Software changed the way arguments are passed to the launched application (in the previous version, it didn&#8217;t work per the PDF standard, and that&#8217;s why I had to use a workaround). I draw some interesting conclusions from this:</p>
<ol>
<li>Nobody used the /Launch action in Foxit Reader with arguments. It didn&#8217;t work, and I assume Foxit would have received bug reports about this and fixed it by now.</li>
<li>Nobody used the /Launch action in Foxit Reader with arguments via the workaround. Because this fix breaks the workaround, and I assume Foxit would not have broken a feature used by some of its users.</li>
<li>From 1. and 2., I can say nobody used the /Launch action in Foxit Reader with arguments.</li>
</ol>
<p>Adobe Reader has a Trust Manager setting to disable opening non-PDF attachments with external applications.</p>
<p><img class="alignnone size-full wp-image-2121" title="20100403-123054" src="http://didierstevens.files.wordpress.com/2010/04/20100403-123054.png" alt="" width="764" height="596" /></p>
<p>This setting also disables the /Launch action:</p>
<p><img class="alignnone size-full wp-image-2122" title="20100403-124947" src="http://didierstevens.files.wordpress.com/2010/04/20100403-124947.png" alt="" width="478" height="223" /></p>
<p>For more details about the PoC, I refer to my <a href="http://www.eurotrashsecurity.eu/episodes/exclusocast1.mp3">interview</a> on the <a href="http://www.eurotrashsecurity.eu">Eurotrash Security podcast</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/didierstevens.wordpress.com/2119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/didierstevens.wordpress.com/2119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/didierstevens.wordpress.com/2119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/didierstevens.wordpress.com/2119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/didierstevens.wordpress.com/2119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/didierstevens.wordpress.com/2119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/didierstevens.wordpress.com/2119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/didierstevens.wordpress.com/2119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/didierstevens.wordpress.com/2119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/didierstevens.wordpress.com/2119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/didierstevens.wordpress.com/2119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/didierstevens.wordpress.com/2119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/didierstevens.wordpress.com/2119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/didierstevens.wordpress.com/2119/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=2119&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.didierstevens.com/2010/04/06/update-escape-from-pdf/feed/</wfw:commentRss>
		<slash:comments>17</slash:comments>
<enclosure url="http://www.eurotrashsecurity.eu/episodes/exclusocast1.mp3" length="27273854" type="audio/mpeg" />
<enclosure url="http://www.eurotrashsecurity.eu/episodes/exclusocast1.mp3" length="27273854" type="audio/mpeg" />
<enclosure url="http://www.eurotrashsecurity.eu/episodes/exclusocast1.mp3" length="27273854" type="audio/mpeg" />
<enclosure url="http://www.eurotrashsecurity.eu/episodes/exclusocast1.mp3" length="27273854" type="audio/mpeg" />
<enclosure url="http://www.eurotrashsecurity.eu/episodes/exclusocast1.mp3" length="27273854" type="audio/mpeg" />
<enclosure url="http://www.eurotrashsecurity.eu/episodes/exclusocast1.mp3" length="27273854" type="audio/mpeg" />
<enclosure url="http://www.eurotrashsecurity.eu/episodes/exclusocast1.mp3" length="27273854" type="audio/mpeg" />
	
		<media:content url="" medium="image">
			<media:title type="html">didierstevens</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2010/04/20100403-231726.png" medium="image">
			<media:title type="html">20100403-231726</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2010/04/20100403-123054.png" medium="image">
			<media:title type="html">20100403-123054</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2010/04/20100403-124947.png" medium="image">
			<media:title type="html">20100403-124947</media:title>
		</media:content>
	</item>
		<item>
		<title>Update: XORSearch Version 1.6.0</title>
		<link>http://blog.didierstevens.com/2010/01/18/update-xorsearch-version-1-6-0/</link>
		<comments>http://blog.didierstevens.com/2010/01/18/update-xorsearch-version-1-6-0/#comments</comments>
		<pubDate>Mon, 18 Jan 2010 01:26:11 +0000</pubDate>
		<dc:creator>Didier Stevens</dc:creator>
				<category><![CDATA[My Software]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1949</guid>
		<description><![CDATA[A couple of new features: searching for Unicode searching for Hex code printing of neighbouring bytes Unicode support is rather simple: I consider Unicode as ASCII with 2 bytes per character, last byte always equals 0. Usage case of hexcode search: search for embedded and encoded PE-file by searching for the PE-magic bytes MZ: XORSearch [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=1949&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A couple of new features:</p>
<ul>
<li>searching for Unicode</li>
<li>searching for Hex code</li>
<li>printing of neighbouring bytes</li>
</ul>
<p>Unicode support is rather simple: I consider Unicode as ASCII with 2 bytes per character, last byte always equals 0.</p>
<p>Usage case of hexcode search: search for embedded and encoded PE-file by searching for the PE-magic bytes MZ:</p>
<p>XORSearch -h malware.exe 50450000</p>
<p>Remember that XORSearch is not limited to win32, you can compile it on *nix too: cc -o XORSearch XORSearch.c</p>
<p>Download <a href="http://blog.didierstevens.com/programs/xorsearch/" target="_self">here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/didierstevens.wordpress.com/1949/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/didierstevens.wordpress.com/1949/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/didierstevens.wordpress.com/1949/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/didierstevens.wordpress.com/1949/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/didierstevens.wordpress.com/1949/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/didierstevens.wordpress.com/1949/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/didierstevens.wordpress.com/1949/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/didierstevens.wordpress.com/1949/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/didierstevens.wordpress.com/1949/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/didierstevens.wordpress.com/1949/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/didierstevens.wordpress.com/1949/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/didierstevens.wordpress.com/1949/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/didierstevens.wordpress.com/1949/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/didierstevens.wordpress.com/1949/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=1949&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.didierstevens.com/2010/01/18/update-xorsearch-version-1-6-0/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">didierstevens</media:title>
		</media:content>
	</item>
		<item>
		<title>Update: bpmtk with hook-createprocess.dll</title>
		<link>http://blog.didierstevens.com/2009/11/19/update-bpmtk-with-hook-createprocess-dll/</link>
		<comments>http://blog.didierstevens.com/2009/11/19/update-bpmtk-with-hook-createprocess-dll/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 19:32:34 +0000</pubDate>
		<dc:creator>Didier Stevens</dc:creator>
				<category><![CDATA[bpmtk]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[My Software]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1841</guid>
		<description><![CDATA[There are no real changes in this new version of bpmtk, only a new DLL (hook-createprocess.dll) was added. You can use this DLL to protect your Windows machine from getting infected by the current malicious documents found in-the-wild. You can download bpmtk version 0.1.6.0 here. Hook-createprocess.dll is a DLL that patches the process into which [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=1841&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>There are no real changes in this new version of bpmtk, only a new DLL (hook-createprocess.dll) was added. You can use this DLL to protect your Windows machine from getting infected by the current malicious documents found in-the-wild.</p>
<p>You can download bpmtk version 0.1.6.0 <a href="http://www.didierstevens.com/files/software/bpmtk_V0_1_6_0.zip" target="_self">here</a>.</p>
<p>Hook-createprocess.dll is a DLL that patches the process into which it is loaded to prevent it from creating new processes. It does this by patching the Import Address Table of kernel32.dll for ntdll.dll to hook API functions NtCreateProcessEx, NtCreateProcess and NtCreateUserProcess.<br />
Calls to these functions are intercepted and not passed on to the original functions. Instead, a code is returned indicating that the operation was blocked. The result is that functions in kernel32 used to create new processes fail (like WinExec) and hence that the patched process can’t create new processes.<br />
This is all it takes to block most shellcode found in malicious documents like PDF malware. Shellcode like this does the following:</p>
<p><img class="alignnone size-full wp-image-1842" title="20091119-01" src="http://didierstevens.files.wordpress.com/2009/11/20091119-01.png" alt="" width="656" height="260" /><br />
Of course, since this protective measure is taken by patching the process, shellcode could undo this patching and bypass our protection. Or it could use the ntdll API and not be hindered by our patch. But actual malware found in-the-wild doesn’t do this (not talking about targeted attacks) and is thus prevented from executing the trojan it just downloaded or extracted from the PDF document.</p>
<p>If you want better protection, you&#8217;ll have to use something that works at the level of the kernel, like sandboxing software.</p>
<p>However, this patch comes with some drawbacks, because it also blocks bening new processes. For example, the update function of Adobe Acrobat requires the creation of a new process. To reenable the creation of processes, you have to unload hook-createprocess.dll (unloading removes the hooks). bpmtk has a function to unload DLLs from a process (reject).</p>
<p>There are a couple of trick to load this DLL with the program you want to protect. I&#8217;ll describe a generic method in an upcoming post, but now I want to explain it for a specific program.<br />
Programs have a list of DLLs they need for their execution. We will use a PE-file editor to add our hook-createprocess.dll to this list. hook-createprocess.dll exports a dummy function (_Dummy) just so you can add to the imports table of an executable. We will use <a href="http://www.woodmann.net/collaborative/tools/index.php/LordPE" target="_blank">LordPE</a> to add hook-createprocess.dll with _Dummy to Adobe Reader:</p>
<p><img class="alignnone size-full wp-image-1843" title="20091119-195802" src="http://didierstevens.files.wordpress.com/2009/11/20091119-195802.png" alt="" width="653" height="301" /></p>
<p><img class="alignnone size-full wp-image-1844" title="20091119-195846" src="http://didierstevens.files.wordpress.com/2009/11/20091119-195846.png" alt="" width="626" height="496" /></p>
<p><img class="alignnone size-full wp-image-1855" title="20091119-203031" src="http://didierstevens.files.wordpress.com/2009/11/20091119-203031.png" alt="" width="560" height="268" /></p>
<p><img class="alignnone size-full wp-image-1846" title="20091119-200145" src="http://didierstevens.files.wordpress.com/2009/11/20091119-200145.png" alt="" width="446" height="421" /></p>
<p>Right-click the Import table:</p>
<p><img class="alignnone size-full wp-image-1847" title="20091119-200229" src="http://didierstevens.files.wordpress.com/2009/11/20091119-200229.png" alt="" width="644" height="308" /></p>
<p><img class="alignnone size-full wp-image-1848" title="20091119-200412" src="http://didierstevens.files.wordpress.com/2009/11/20091119-200412.png" alt="" width="358" height="203" /></p>
<p><img class="alignnone size-full wp-image-1849" title="20091119-200422" src="http://didierstevens.files.wordpress.com/2009/11/20091119-200422.png" alt="" width="358" height="203" /></p>
<p><img class="alignnone size-full wp-image-1850" title="20091119-200442" src="http://didierstevens.files.wordpress.com/2009/11/20091119-200442.png" alt="" width="644" height="308" /></p>
<p>And don&#8217;t forget to save&#8230;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/didierstevens.wordpress.com/1841/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/didierstevens.wordpress.com/1841/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/didierstevens.wordpress.com/1841/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/didierstevens.wordpress.com/1841/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/didierstevens.wordpress.com/1841/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/didierstevens.wordpress.com/1841/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/didierstevens.wordpress.com/1841/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/didierstevens.wordpress.com/1841/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/didierstevens.wordpress.com/1841/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/didierstevens.wordpress.com/1841/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/didierstevens.wordpress.com/1841/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/didierstevens.wordpress.com/1841/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/didierstevens.wordpress.com/1841/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/didierstevens.wordpress.com/1841/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=1841&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.didierstevens.com/2009/11/19/update-bpmtk-with-hook-createprocess-dll/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">didierstevens</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2009/11/20091119-01.png" medium="image">
			<media:title type="html">20091119-01</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2009/11/20091119-195802.png" medium="image">
			<media:title type="html">20091119-195802</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2009/11/20091119-195846.png" medium="image">
			<media:title type="html">20091119-195846</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2009/11/20091119-203031.png" medium="image">
			<media:title type="html">20091119-203031</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2009/11/20091119-200145.png" medium="image">
			<media:title type="html">20091119-200145</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2009/11/20091119-200229.png" medium="image">
			<media:title type="html">20091119-200229</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2009/11/20091119-200412.png" medium="image">
			<media:title type="html">20091119-200412</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2009/11/20091119-200422.png" medium="image">
			<media:title type="html">20091119-200422</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2009/11/20091119-200442.png" medium="image">
			<media:title type="html">20091119-200442</media:title>
		</media:content>
	</item>
		<item>
		<title>Update: WhoAmI? Version 0.1.3</title>
		<link>http://blog.didierstevens.com/2009/10/14/update-whoami-version-0-1-3/</link>
		<comments>http://blog.didierstevens.com/2009/10/14/update-whoami-version-0-1-3/#comments</comments>
		<pubDate>Wed, 14 Oct 2009 18:00:02 +0000</pubDate>
		<dc:creator>Didier Stevens</dc:creator>
				<category><![CDATA[My Software]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1811</guid>
		<description><![CDATA[I’ve updated my WhoAmI? Firefox add-on for Firefox version 3.5. You can download it here or get it from the Mozilla site. I’ve nominated it to leave the Sandbox. If you use it, please post a review on the Mozilla page to help it on its way out of the the Sandbox (or keep it [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=1811&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I’ve updated my <a href="http://blog.didierstevens.com/2007/10/09/whoami-firefox-extension/">WhoAmI?</a> Firefox add-on for Firefox version 3.5.</p>
<p>You can download it <a href="http://didierstevens.com/files/software/whoami_-0.1.3-fx.zip" target="_self">here</a> or get it from the <a href="https://addons.mozilla.org/en-US/firefox/addon/5797" target="_blank">Mozilla</a> site. I’ve nominated it to leave the Sandbox. If you use it, please post a review on the <a href="https://addons.mozilla.org/en-US/firefox/addon/5797" target="_blank">Mozilla</a> page to help it on its way out of the the Sandbox (or keep it there if it’s too buggy).</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/didierstevens.wordpress.com/1811/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/didierstevens.wordpress.com/1811/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/didierstevens.wordpress.com/1811/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/didierstevens.wordpress.com/1811/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/didierstevens.wordpress.com/1811/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/didierstevens.wordpress.com/1811/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/didierstevens.wordpress.com/1811/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/didierstevens.wordpress.com/1811/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/didierstevens.wordpress.com/1811/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/didierstevens.wordpress.com/1811/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/didierstevens.wordpress.com/1811/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/didierstevens.wordpress.com/1811/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/didierstevens.wordpress.com/1811/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/didierstevens.wordpress.com/1811/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=1811&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.didierstevens.com/2009/10/14/update-whoami-version-0-1-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">didierstevens</media:title>
		</media:content>
	</item>
		<item>
		<title>Update: Time Lapse Photography with a Nokia Mobile</title>
		<link>http://blog.didierstevens.com/2009/08/21/update-time-lapse-photography-with-a-nokia-mobile/</link>
		<comments>http://blog.didierstevens.com/2009/08/21/update-time-lapse-photography-with-a-nokia-mobile/#comments</comments>
		<pubDate>Fri, 21 Aug 2009 14:51:05 +0000</pubDate>
		<dc:creator>Didier Stevens</dc:creator>
				<category><![CDATA[My Software]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1666</guid>
		<description><![CDATA[I&#8217;ve debugged the issues some people had with my Nokia time lapse Python script, you can find a new version here.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=1666&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve debugged the issues some people had with my <a href="http://blog.didierstevens.com/2009/06/29/quickpost-time-lapse-photography-with-a-nokia-mobile/" target="_self">Nokia time lapse Python script</a>, you can find a <a href="http://blog.didierstevens.com/programs/nokia-time-lapse-photography/" target="_self">new version here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/didierstevens.wordpress.com/1666/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/didierstevens.wordpress.com/1666/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/didierstevens.wordpress.com/1666/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/didierstevens.wordpress.com/1666/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/didierstevens.wordpress.com/1666/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/didierstevens.wordpress.com/1666/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/didierstevens.wordpress.com/1666/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/didierstevens.wordpress.com/1666/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/didierstevens.wordpress.com/1666/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/didierstevens.wordpress.com/1666/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/didierstevens.wordpress.com/1666/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/didierstevens.wordpress.com/1666/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/didierstevens.wordpress.com/1666/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/didierstevens.wordpress.com/1666/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&amp;blog=264765&amp;post=1666&amp;subd=didierstevens&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.didierstevens.com/2009/08/21/update-time-lapse-photography-with-a-nokia-mobile/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">didierstevens</media:title>
		</media:content>
	</item>
	</channel>
</rss>
