<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for Didier Stevens</title>
	<atom:link href="http://blog.didierstevens.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Mon, 15 Mar 2010 17:38:44 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Authenticode Challenge by Nibbles microblog &#187; Write-up Codegate 2010 &#8211; Déchiffrer un https utilisant RSA-768bits</title>
		<link>http://blog.didierstevens.com/2008/07/22/authenticode-challenge/#comment-37838</link>
		<dc:creator>Nibbles microblog &#187; Write-up Codegate 2010 &#8211; Déchiffrer un https utilisant RSA-768bits</dc:creator>
		<pubDate>Mon, 15 Mar 2010 17:38:44 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=493#comment-37838</guid>
		<description>[...] à l&#8217;excellente solution de messieurs P &amp; Q au challenge Authenticode de Didier Stevens, ça a été très [...]</description>
		<content:encoded><![CDATA[<p>[...] à l&#8217;excellente solution de messieurs P &amp; Q au challenge Authenticode de Didier Stevens, ça a été très [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Mister P and Q&#8217;s Excellent Solution by Nibbles microblog &#187; Write-up Codegate 2010 &#8211; Déchiffrer un https utilisant RSA-768bits</title>
		<link>http://blog.didierstevens.com/2008/09/07/mister-p-and-qs-excellent-solution/#comment-37837</link>
		<dc:creator>Nibbles microblog &#187; Write-up Codegate 2010 &#8211; Déchiffrer un https utilisant RSA-768bits</dc:creator>
		<pubDate>Mon, 15 Mar 2010 17:37:36 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=647#comment-37837</guid>
		<description>[...] à l&#8217;excellente solution de messieurs P &amp; Q au challenge Authenticode de Didier Stevens, ça a été très [...]</description>
		<content:encoded><![CDATA[<p>[...] à l&#8217;excellente solution de messieurs P &amp; Q au challenge Authenticode de Didier Stevens, ça a été très [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Frisky Solitaire &#8211; Another Info Stealer by Week 10 in Review &#8211; 2010 &#124; Infosec Events</title>
		<link>http://blog.didierstevens.com/2010/03/09/frisky-solitaire-another-info-stealer/#comment-37836</link>
		<dc:creator>Week 10 in Review &#8211; 2010 &#124; Infosec Events</dc:creator>
		<pubDate>Mon, 15 Mar 2010 08:31:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2072#comment-37836</guid>
		<description>[...] Frisky Solitaire – Another Info Stealer &#8211; didierstevens.com No need to exploit a software vulnerability to steal info. [...]</description>
		<content:encoded><![CDATA[<p>[...] Frisky Solitaire – Another Info Stealer &#8211; didierstevens.com No need to exploit a software vulnerability to steal info. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PDF Info Stealer PoC by Didier Stevens</title>
		<link>http://blog.didierstevens.com/2010/03/08/pdf-info-stealer-poc/#comment-37833</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Sun, 14 Mar 2010 21:22:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2046#comment-37833</guid>
		<description>No, even if I call this a PoC, the payload is still an info stealer, I&#039;m not publishing this. And the DLL can be adapted to collect several files.</description>
		<content:encoded><![CDATA[<p>No, even if I call this a PoC, the payload is still an info stealer, I&#8217;m not publishing this. And the DLL can be adapted to collect several files.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Restoring Safe Mode with a .REG file by Didier Stevens</title>
		<link>http://blog.didierstevens.com/2007/02/19/restoring-safe-mode-with-a-reg-file/#comment-37832</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Sun, 14 Mar 2010 21:21:00 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/02/19/restoring-safe-mode-with-a-reg-file/#comment-37832</guid>
		<description>@Duo Your machine must be infected with malware that disables all types of programs to run. I recommend you go to a malware cleaning forum and get help there. I&#039;ve a blogpost that explains how to use the F-Secure Rescue CD to clean your machine, but I believe you&#039;re better consult malware cleaning experts on a forum.</description>
		<content:encoded><![CDATA[<p>@Duo Your machine must be infected with malware that disables all types of programs to run. I recommend you go to a malware cleaning forum and get help there. I&#8217;ve a blogpost that explains how to use the F-Secure Rescue CD to clean your machine, but I believe you&#8217;re better consult malware cleaning experts on a forum.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PDF Info Stealer PoC by Nazz</title>
		<link>http://blog.didierstevens.com/2010/03/08/pdf-info-stealer-poc/#comment-37829</link>
		<dc:creator>Nazz</dc:creator>
		<pubDate>Sat, 13 Mar 2010 20:14:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2046#comment-37829</guid>
		<description>Any way of releasing the payload itself, So it loads a certain dll into the memory to search for important files in which you gave it to search e.g. passwords.xls, secret.txt, ftp.txt could it search for more than one file or do you have to edit shellcode each time?</description>
		<content:encoded><![CDATA[<p>Any way of releasing the payload itself, So it loads a certain dll into the memory to search for important files in which you gave it to search e.g. passwords.xls, secret.txt, <a href="http://ftp.txt" rel="nofollow">http://ftp.txt</a> could it search for more than one file or do you have to edit shellcode each time?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Restoring Safe Mode with a .REG file by Duo</title>
		<link>http://blog.didierstevens.com/2007/02/19/restoring-safe-mode-with-a-reg-file/#comment-37826</link>
		<dc:creator>Duo</dc:creator>
		<pubDate>Sat, 13 Mar 2010 04:39:27 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/02/19/restoring-safe-mode-with-a-reg-file/#comment-37826</guid>
		<description>Hi. I downloaded the undeletable safeboot key. Copied it to the crippled PC. Hola ! The application can not be run. The system looks for the program to run the application. Too bad. What should I do next ? 
Thanks.</description>
		<content:encoded><![CDATA[<p>Hi. I downloaded the undeletable safeboot key. Copied it to the crippled PC. Hola ! The application can not be run. The system looks for the program to run the application. Too bad. What should I do next ?<br />
Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Restoring Safe Mode with a .REG file by Didier Stevens</title>
		<link>http://blog.didierstevens.com/2007/02/19/restoring-safe-mode-with-a-reg-file/#comment-37823</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Fri, 12 Mar 2010 08:07:51 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/02/19/restoring-safe-mode-with-a-reg-file/#comment-37823</guid>
		<description>@Duo It could be that the malware is actively monitoring the registry and deleting the Safeboot key as soon as you create it. I&#039;ve another program to help with this, look for The Undeletable Safeboot key on my blog.</description>
		<content:encoded><![CDATA[<p>@Duo It could be that the malware is actively monitoring the registry and deleting the Safeboot key as soon as you create it. I&#8217;ve another program to help with this, look for The Undeletable Safeboot key on my blog.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on &#8220;Is your PC virus-free? Get it infected here!&#8221; by So easy with online &#124; Another weblog</title>
		<link>http://blog.didierstevens.com/2007/05/07/is-your-pc-virus-free-get-it-infected-here/#comment-37821</link>
		<dc:creator>So easy with online &#124; Another weblog</dc:creator>
		<pubDate>Fri, 12 Mar 2010 02:54:51 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/05/07/is-your-pc-virus-free-get-it-infected-here/#comment-37821</guid>
		<description>[...] And that Google ad I showed above—the person who wrote that advertisement did it only to see how stupid PC users are. And 409 people clicked on it. [...]</description>
		<content:encoded><![CDATA[<p>[...] And that Google ad I showed above—the person who wrote that advertisement did it only to see how stupid PC users are. And 409 people clicked on it. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Restoring Safe Mode with a .REG file by Duo</title>
		<link>http://blog.didierstevens.com/2007/02/19/restoring-safe-mode-with-a-reg-file/#comment-37817</link>
		<dc:creator>Duo</dc:creator>
		<pubDate>Thu, 11 Mar 2010 09:41:06 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/2007/02/19/restoring-safe-mode-with-a-reg-file/#comment-37817</guid>
		<description>While I was desperately looking for a way for repairing my windows xp, I stumbled here into your website. I am not really a computer expert, so I tried doing the above instruction hoping that it will fix my problem. I have the same problem as the others: windows can boot, can not run IE, any .exe file like antivirus because it is looking for a program to run the file. When I try to run in safe mode so as to run the antivirus, the safe mode option can not be seen on the option. So I tried your instruction, but it didn&#039;t work. Kindly check if I did something wrong along the way.

Here&#039;s what I have done :
1. Downloaded the safeboot.zip
2. Copied it into the crippled laptop.
3. Then double clicked on the safeboot - windows xp sp2
  Then the system says that it has completed.

4. Restarted the crippled laptop, hit F8, i have been to the window where you have to choose normal or safe mode. but to my dismay i can not find the safe mode option.

Where i have gone wrong ?


Thank you for your reply. As long as I can, I don&#039;t want reinstall my system. Thank you in advance for the help.</description>
		<content:encoded><![CDATA[<p>While I was desperately looking for a way for repairing my windows xp, I stumbled here into your website. I am not really a computer expert, so I tried doing the above instruction hoping that it will fix my problem. I have the same problem as the others: windows can boot, can not run IE, any .exe file like antivirus because it is looking for a program to run the file. When I try to run in safe mode so as to run the antivirus, the safe mode option can not be seen on the option. So I tried your instruction, but it didn&#8217;t work. Kindly check if I did something wrong along the way.</p>
<p>Here&#8217;s what I have done :<br />
1. Downloaded the safeboot.zip<br />
2. Copied it into the crippled laptop.<br />
3. Then double clicked on the safeboot &#8211; windows xp sp2<br />
  Then the system says that it has completed.</p>
<p>4. Restarted the crippled laptop, hit F8, i have been to the window where you have to choose normal or safe mode. but to my dismay i can not find the safe mode option.</p>
<p>Where i have gone wrong ?</p>
<p>Thank you for your reply. As long as I can, I don&#8217;t want reinstall my system. Thank you in advance for the help.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
