<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Didier Stevens</title>
	<atom:link href="http://blog.didierstevens.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com</link>
	<description>(blog \'DidierStevens)</description>
	<lastBuildDate>Mon, 14 May 2012 00:19:32 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.didierstevens.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Didier Stevens</title>
		<link>http://blog.didierstevens.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.didierstevens.com/osd.xml" title="Didier Stevens" />
	<atom:link rel='hub' href='http://blog.didierstevens.com/?pushpress=hub'/>
		<item>
		<title>ExitProcess Shellcode</title>
		<link>http://blog.didierstevens.com/2012/05/14/exitprocess-shellcode/</link>
		<comments>http://blog.didierstevens.com/2012/05/14/exitprocess-shellcode/#comments</comments>
		<pubDate>Mon, 14 May 2012 00:19:26 +0000</pubDate>
		<dc:creator>Didier Stevens</dc:creator>
				<category><![CDATA[My Software]]></category>
		<category><![CDATA[Shellcode]]></category>

		<guid isPermaLink="false">http://blog.didierstevens.com/?p=3110</guid>
		<description><![CDATA[I wrote shellcode that calls ExitProcess for my TaskManager.xls spreadsheet. Now I&#8217;ve added the asm files (sc-ep.asm for 32-bit and sc-64-ep.asm for 64-bit) for this shellcode to my library. Remark that the 32-bit version assembler code, that was generated with my simple shellcode generator, has a ret instruction after the call to ExitProcess. This instruction [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&#038;blog=264765&#038;post=3110&#038;subd=didierstevens&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I wrote shellcode that calls ExitProcess for my <a href="http://blog.didierstevens.com/2012/05/01/update-taskmanager-xls-v0-1-3-killer-shellcode/">TaskManager.xls spreadsheet</a>.</p>
<p>Now I&#8217;ve added the asm files (sc-ep.asm for 32-bit and sc-64-ep.asm for 64-bit) for this shellcode to my library.</p>
<p>Remark that the 32-bit version assembler code, that was generated with my <a href="http://blog.didierstevens.com/2011/09/23/simple-shellcode-generator-py/">simple shellcode generator</a>, has a ret instruction after the call to ExitProcess. This instruction will never be executed, as a call to ExitProcess does not return.</p>
<p>You can find this shellcode on my <a href="http://blog.didierstevens.com/programs/shellcode/">shellcode page</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/didierstevens.wordpress.com/3110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/didierstevens.wordpress.com/3110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/didierstevens.wordpress.com/3110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/didierstevens.wordpress.com/3110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/didierstevens.wordpress.com/3110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/didierstevens.wordpress.com/3110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/didierstevens.wordpress.com/3110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/didierstevens.wordpress.com/3110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/didierstevens.wordpress.com/3110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/didierstevens.wordpress.com/3110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/didierstevens.wordpress.com/3110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/didierstevens.wordpress.com/3110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/didierstevens.wordpress.com/3110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/didierstevens.wordpress.com/3110/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&#038;blog=264765&#038;post=3110&#038;subd=didierstevens&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.didierstevens.com/2012/05/14/exitprocess-shellcode/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">didierstevens</media:title>
		</media:content>
	</item>
		<item>
		<title>Why Isn&#8217;t my PoC Launching calc.exe?</title>
		<link>http://blog.didierstevens.com/2012/05/08/why-isnt-my-poc-launching-calc-exe/</link>
		<comments>http://blog.didierstevens.com/2012/05/08/why-isnt-my-poc-launching-calc-exe/#comments</comments>
		<pubDate>Tue, 08 May 2012 11:17:53 +0000</pubDate>
		<dc:creator>Didier Stevens</dc:creator>
				<category><![CDATA[Entertainment]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[My Software]]></category>
		<category><![CDATA[Nonsense]]></category>

		<guid isPermaLink="false">http://blog.didierstevens.com/?p=3102</guid>
		<description><![CDATA[I quickly developed a dll that kills calc.exe when started from anything else than explorer.exe. This way, you can mess with all those PoCs that launch calc.exe nocalcpoc_V0_0_0_1.zip (https) MD5: 05798543571B45E19536181DC7346330 SHA256: ED0FEDC6096420F6F09F4980A1CE36F7C4BC0A8C9191F4DFC27FA4C77D547976<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&#038;blog=264765&#038;post=3102&#038;subd=didierstevens&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I quickly developed a dll that kills calc.exe when started from anything else than explorer.exe.</p>
<p>This way, you can mess with all those PoCs that launch calc.exe <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p><img class="alignnone size-full wp-image-3103" title="20120506-140345" src="http://didierstevens.files.wordpress.com/2012/05/20120506-140345.png" alt="" width="716" height="316" /></p>
<p><a href="http://didierstevens.com/files/software/nocalcpoc_V0_0_0_1.zip" target="_self">nocalcpoc_V0_0_0_1.zip</a> (<a href="https://didierstevens.com/files/software/nocalcpoc_V0_0_0_1.zip" target="_self">https</a>)<br />
MD5: 05798543571B45E19536181DC7346330<br />
SHA256: ED0FEDC6096420F6F09F4980A1CE36F7C4BC0A8C9191F4DFC27FA4C77D547976</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/didierstevens.wordpress.com/3102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/didierstevens.wordpress.com/3102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/didierstevens.wordpress.com/3102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/didierstevens.wordpress.com/3102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/didierstevens.wordpress.com/3102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/didierstevens.wordpress.com/3102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/didierstevens.wordpress.com/3102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/didierstevens.wordpress.com/3102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/didierstevens.wordpress.com/3102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/didierstevens.wordpress.com/3102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/didierstevens.wordpress.com/3102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/didierstevens.wordpress.com/3102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/didierstevens.wordpress.com/3102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/didierstevens.wordpress.com/3102/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&#038;blog=264765&#038;post=3102&#038;subd=didierstevens&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.didierstevens.com/2012/05/08/why-isnt-my-poc-launching-calc-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">didierstevens</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2012/05/20120506-140345.png" medium="image">
			<media:title type="html">20120506-140345</media:title>
		</media:content>
	</item>
		<item>
		<title>Update: TaskManager.xls V0.1.3 Killer Shellcode</title>
		<link>http://blog.didierstevens.com/2012/05/01/update-taskmanager-xls-v0-1-3-killer-shellcode/</link>
		<comments>http://blog.didierstevens.com/2012/05/01/update-taskmanager-xls-v0-1-3-killer-shellcode/#comments</comments>
		<pubDate>Tue, 01 May 2012 10:49:25 +0000</pubDate>
		<dc:creator>Didier Stevens</dc:creator>
				<category><![CDATA[My Software]]></category>
		<category><![CDATA[Shellcode]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://blog.didierstevens.com/?p=3091</guid>
		<description><![CDATA[My TaskManager spreadsheet provides you with a couple of commands to terminate (malicious) programs. But sometimes these commands can&#8217;t terminate a process (for various reasons). Today I&#8217;m adding a new command to our toolkit: injecting and executing shellcode in the target process. I&#8217;m providing 32-bit and 64-bit shellcode that calls ExitProcess. When this shellcode is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&#038;blog=264765&#038;post=3091&#038;subd=didierstevens&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>My <a href="http://blog.didierstevens.com/2011/02/03/taskmanager-xls/">TaskManager spreadsheet</a> provides you with a couple of commands to terminate (malicious) programs. But sometimes these commands can&#8217;t terminate a process (for various reasons).</p>
<p>Today I&#8217;m adding a new command to our toolkit: injecting and executing shellcode in the target process. I&#8217;m providing 32-bit and 64-bit shellcode that calls ExitProcess. When this shellcode is injected and executed inside a process, the process will terminate itself.</p>
<p>Here I&#8217;m using the command &#8220;e ep64&#8243;: this command injects and executes the shellcode found in sheet ep64 (as hex strings) in process notepad:</p>
<p><img class="alignnone size-full wp-image-3093" title="20120501-123559" src="http://didierstevens.files.wordpress.com/2012/05/20120501-123559.png" alt="" width="713" height="237" /></p>
<p>The result is that notepad will terminate itself.</p>
<p>When using TaskManager on a 64-bit system, you&#8217;ll have to pay attention to the following: to terminate a 32-bit process, you inject 32-bit shellcode (ep32) and for a 64-bit process, you use 64-bit shellcode (ep64). And a 32-bit process can&#8217;t access a 64-bit process&#8217; memory through the Windows API, so if you are using 32-bit Excel on a 64-bit machine, you won&#8217;t be able to inject shellcode into 64-bit processes.</p>
<p>FYI: If you want to know more about 32-bit and 64-bit processes on x64 Windows, I&#8217;ll bedoing a workshop at Brucon this year: &#8220;Windows x64: The Essentials&#8221;.</p>
<p><a href="http://didierstevens.com/files/software/TaskManager_V0_1_3.zip" target="_self">TaskManager_V0_1_3.zip</a> (<a href="https://didierstevens.com/files/software/TaskManager_V0_1_3.zip" target="_self">https</a>)<br />
MD5: 38DED14A7A468923C3552A6135CC570C<br />
SHA256: CABD1F73C8D069A85EA439D7AFF736723B5759A6ED929FB3F21A4ADD3D0605BC</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/didierstevens.wordpress.com/3091/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/didierstevens.wordpress.com/3091/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/didierstevens.wordpress.com/3091/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/didierstevens.wordpress.com/3091/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/didierstevens.wordpress.com/3091/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/didierstevens.wordpress.com/3091/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/didierstevens.wordpress.com/3091/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/didierstevens.wordpress.com/3091/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/didierstevens.wordpress.com/3091/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/didierstevens.wordpress.com/3091/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/didierstevens.wordpress.com/3091/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/didierstevens.wordpress.com/3091/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/didierstevens.wordpress.com/3091/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/didierstevens.wordpress.com/3091/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&#038;blog=264765&#038;post=3091&#038;subd=didierstevens&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.didierstevens.com/2012/05/01/update-taskmanager-xls-v0-1-3-killer-shellcode/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">didierstevens</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2012/05/20120501-123559.png" medium="image">
			<media:title type="html">20120501-123559</media:title>
		</media:content>
	</item>
		<item>
		<title>InteractiveSieve</title>
		<link>http://blog.didierstevens.com/2012/04/17/interactivesieve/</link>
		<comments>http://blog.didierstevens.com/2012/04/17/interactivesieve/#comments</comments>
		<pubDate>Tue, 17 Apr 2012 11:33:34 +0000</pubDate>
		<dc:creator>Didier Stevens</dc:creator>
				<category><![CDATA[.NET]]></category>
		<category><![CDATA[My Software]]></category>

		<guid isPermaLink="false">http://blog.didierstevens.com/?p=3079</guid>
		<description><![CDATA[Interactive Sieve is a program I developed to help you analyze log files and other data in tabular form. It&#8217;s designed to help you when you don&#8217;t know exactly what you&#8217;re looking for. You sift through the data by hiding or coloring events (or data) that are not relevant. I started writing this program in [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&#038;blog=264765&#038;post=3079&#038;subd=didierstevens&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Interactive Sieve is a program I developed to help you analyze log files and other data in tabular form. It&#8217;s designed to help you when you don&#8217;t know exactly what you&#8217;re looking for. You sift through the data by hiding or coloring events (or data) that are not relevant.</p>
<p><img class="alignnone size-full wp-image-3080" title="20120415-155346" src="http://didierstevens.files.wordpress.com/2012/04/20120415-155346.png" alt="" width="841" height="579" /></p>
<p>I started writing this program in 2007 and use it often. <del datetime="2012-04-17T13:55:15+00:00">But there is a problem I&#8217;ve not been able to fix: when you hide a lot of rows, it takes a long time, probably because of the redraw operation that takes place for each hidden row. Maybe someone will find a solution.<br />
</del>Update: big thanks to <a href="https://twitter.com/#!/woanware">@woanware</a> for fixing the redraw performance problem!</p>
<p>For more details on how to use the program, select Help / About.</p>
<p><a href="http://didierstevens.com/files/software/InteractiveSieve_V_0_7_3_0.zip" target="_self">InteractiveSieve_V_0_7_3_0.zip</a> (<a href="https://didierstevens.com/files/software/InteractiveSieve_V_0_7_3_0.zip" target="_self">https</a>)<br />
MD5: F36B245584DE143A15F484AA6220D67F<br />
SHA256: AE0804EA739AEDC5FA32B7F6FD99AB99A35F7742B98953A653E0C24725E0FE6F</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/didierstevens.wordpress.com/3079/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/didierstevens.wordpress.com/3079/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/didierstevens.wordpress.com/3079/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/didierstevens.wordpress.com/3079/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/didierstevens.wordpress.com/3079/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/didierstevens.wordpress.com/3079/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/didierstevens.wordpress.com/3079/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/didierstevens.wordpress.com/3079/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/didierstevens.wordpress.com/3079/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/didierstevens.wordpress.com/3079/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/didierstevens.wordpress.com/3079/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/didierstevens.wordpress.com/3079/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/didierstevens.wordpress.com/3079/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/didierstevens.wordpress.com/3079/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&#038;blog=264765&#038;post=3079&#038;subd=didierstevens&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.didierstevens.com/2012/04/17/interactivesieve/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">didierstevens</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2012/04/20120415-155346.png" medium="image">
			<media:title type="html">20120415-155346</media:title>
		</media:content>
	</item>
		<item>
		<title>Update: SE_ASLR Version 0.0.0.2</title>
		<link>http://blog.didierstevens.com/2012/03/29/update-se_aslr-version-0-0-0-2/</link>
		<comments>http://blog.didierstevens.com/2012/03/29/update-se_aslr-version-0-0-0-2/#comments</comments>
		<pubDate>Thu, 29 Mar 2012 09:14:11 +0000</pubDate>
		<dc:creator>Didier Stevens</dc:creator>
				<category><![CDATA[My Software]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://blog.didierstevens.com/?p=3076</guid>
		<description><![CDATA[I added Bottom Up Randomization to my SE_ASLR tool. In this source code, I use a Windows Cryptographic Service Provider to generate random numbers. SE_ASLR_V0_0_0_2.zip (https) MD5: C835D1DDB64A68A1CD48CCF87AE03D18 SHA256: 1560BEE96CFC956A5E8954FEFD92ED227293418B19FE6B06D4ED703B6C50F4AC<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&#038;blog=264765&#038;post=3076&#038;subd=didierstevens&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I added <a href="http://blog.didierstevens.com/2011/09/29/add-bottom-up-randomization-to-your-own-source-code/">Bottom Up Randomization</a> to my <a href="http://blog.didierstevens.com/2011/08/10/force-aslr-on-shell-extensions/">SE_ASLR tool</a>.</p>
<p>In this source code, I use a <a href="https://en.wikipedia.org/wiki/Cryptographic_Service_Provider">Windows Cryptographic Service Provider</a> to generate random numbers.</p>
<p><a href="http://didierstevens.com/files/software/SE_ASLR_V0_0_0_2.zip" target="_self">SE_ASLR_V0_0_0_2.zip</a> (<a href="https://didierstevens.com/files/software/SE_ASLR_V0_0_0_2.zip" target="_self">https</a>)<br />
MD5: C835D1DDB64A68A1CD48CCF87AE03D18<br />
SHA256: 1560BEE96CFC956A5E8954FEFD92ED227293418B19FE6B06D4ED703B6C50F4AC</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/didierstevens.wordpress.com/3076/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/didierstevens.wordpress.com/3076/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/didierstevens.wordpress.com/3076/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/didierstevens.wordpress.com/3076/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/didierstevens.wordpress.com/3076/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/didierstevens.wordpress.com/3076/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/didierstevens.wordpress.com/3076/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/didierstevens.wordpress.com/3076/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/didierstevens.wordpress.com/3076/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/didierstevens.wordpress.com/3076/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/didierstevens.wordpress.com/3076/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/didierstevens.wordpress.com/3076/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/didierstevens.wordpress.com/3076/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/didierstevens.wordpress.com/3076/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&#038;blog=264765&#038;post=3076&#038;subd=didierstevens&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.didierstevens.com/2012/03/29/update-se_aslr-version-0-0-0-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">didierstevens</media:title>
		</media:content>
	</item>
		<item>
		<title>Update: PDFid And pdf-parser</title>
		<link>http://blog.didierstevens.com/2012/03/14/update-pdfid-and-pdf-parser/</link>
		<comments>http://blog.didierstevens.com/2012/03/14/update-pdfid-and-pdf-parser/#comments</comments>
		<pubDate>Wed, 14 Mar 2012 09:15:02 +0000</pubDate>
		<dc:creator>Didier Stevens</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.didierstevens.com/?p=3074</guid>
		<description><![CDATA[To mark the occasion of my Malicious PDF Analysis workshop at Black Hat Europe 2012, I&#8217;m releasing version 0.0.12 of PDFiD and version 0.3.9 of pdf-parser. The major change is that these 2 tools support Python 3 too now. And then there are a couple of bugfixes and new features given to me by readers. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&#038;blog=264765&#038;post=3074&#038;subd=didierstevens&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>To mark the occasion of my <a href="http://blog.didierstevens.com/screencasts-videos/">Malicious PDF Analysis workshop</a> at <a href="https://www.blackhat.com/html/bh-eu-12/bh-eu-12-home.html">Black Hat Europe 2012</a>, I&#8217;m releasing version 0.0.12 of PDFiD and version 0.3.9 of pdf-parser.</p>
<p>The major change is that these 2 tools support Python 3 too now. And then there are a couple of bugfixes and new features given to me by readers.</p>
<p>You can find these tools on the <a href="http://blog.didierstevens.com/programs/pdf-tools/">PDF Tools page</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/didierstevens.wordpress.com/3074/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/didierstevens.wordpress.com/3074/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/didierstevens.wordpress.com/3074/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/didierstevens.wordpress.com/3074/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/didierstevens.wordpress.com/3074/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/didierstevens.wordpress.com/3074/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/didierstevens.wordpress.com/3074/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/didierstevens.wordpress.com/3074/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/didierstevens.wordpress.com/3074/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/didierstevens.wordpress.com/3074/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/didierstevens.wordpress.com/3074/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/didierstevens.wordpress.com/3074/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/didierstevens.wordpress.com/3074/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/didierstevens.wordpress.com/3074/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&#038;blog=264765&#038;post=3074&#038;subd=didierstevens&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.didierstevens.com/2012/03/14/update-pdfid-and-pdf-parser/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">didierstevens</media:title>
		</media:content>
	</item>
		<item>
		<title>NAFT Release</title>
		<link>http://blog.didierstevens.com/2012/03/12/naft-release/</link>
		<comments>http://blog.didierstevens.com/2012/03/12/naft-release/#comments</comments>
		<pubDate>Mon, 12 Mar 2012 19:41:45 +0000</pubDate>
		<dc:creator>Didier Stevens</dc:creator>
				<category><![CDATA[My Software]]></category>
		<category><![CDATA[Networking]]></category>

		<guid isPermaLink="false">http://blog.didierstevens.com/?p=3062</guid>
		<description><![CDATA[You can find a first release of my Network Appliance Forensic Toolkit here. This first release contains a tool for generic network appliances, but also works on memory dumps of PC operating systems like Windows.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&#038;blog=264765&#038;post=3062&#038;subd=didierstevens&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>You can find a first release of my <a href="http://blog.didierstevens.com/2012/02/20/peeking-at-naft/">Network Appliance Forensic Toolkit</a> <a href="http://blog.didierstevens.com/programs/network-appliance-forensic-toolkit/">here</a>. This first release contains a tool for generic network appliances, but also works on memory dumps of PC operating systems like Windows.</p>
<p><img class="alignnone size-full wp-image-3035" title="20120220-200624" src="http://didierstevens.files.wordpress.com/2012/02/20120220-200624.png" alt="" width="851" height="720" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/didierstevens.wordpress.com/3062/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/didierstevens.wordpress.com/3062/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/didierstevens.wordpress.com/3062/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/didierstevens.wordpress.com/3062/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/didierstevens.wordpress.com/3062/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/didierstevens.wordpress.com/3062/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/didierstevens.wordpress.com/3062/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/didierstevens.wordpress.com/3062/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/didierstevens.wordpress.com/3062/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/didierstevens.wordpress.com/3062/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/didierstevens.wordpress.com/3062/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/didierstevens.wordpress.com/3062/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/didierstevens.wordpress.com/3062/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/didierstevens.wordpress.com/3062/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&#038;blog=264765&#038;post=3062&#038;subd=didierstevens&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.didierstevens.com/2012/03/12/naft-release/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">didierstevens</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2012/02/20120220-200624.png" medium="image">
			<media:title type="html">20120220-200624</media:title>
		</media:content>
	</item>
		<item>
		<title>Update: TaskManager.xls V0.1.2</title>
		<link>http://blog.didierstevens.com/2012/03/05/update-taskmanager-xls-v0-1-2/</link>
		<comments>http://blog.didierstevens.com/2012/03/05/update-taskmanager-xls-v0-1-2/#comments</comments>
		<pubDate>Mon, 05 Mar 2012 12:03:20 +0000</pubDate>
		<dc:creator>Didier Stevens</dc:creator>
				<category><![CDATA[My Software]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://blog.didierstevens.com/?p=3057</guid>
		<description><![CDATA[This is a new version of TaskManager.xls with memory usage statistics, with code given to me by sciomathman. I updated the code for 64-bit and edge cases. TaskManager_V0_1_2.zip (https) MD5: DEDB20DA6EE1A622DD3C234D07F5FE08 SHA256: 23EC10C7206BA43B56EF185E7C18EF528FD551FC0B34FFF9E4E183C37A114FF8<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&#038;blog=264765&#038;post=3057&#038;subd=didierstevens&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This is a new version of <a href="http://blog.didierstevens.com/2011/02/03/taskmanager-xls/">TaskManager.xls</a> with memory usage statistics, with code given to me by sciomathman.</p>
<p>I updated the code for 64-bit and edge cases.</p>
<p><a href="http://didierstevens.com/files/software/TaskManager_V0_1_2.zip" target="_self">TaskManager_V0_1_2.zip</a> (<a href="https://didierstevens.com/files/software/TaskManager_V0_1_2.zip" target="_self">https</a>)<br />
MD5: DEDB20DA6EE1A622DD3C234D07F5FE08<br />
SHA256: 23EC10C7206BA43B56EF185E7C18EF528FD551FC0B34FFF9E4E183C37A114FF8</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/didierstevens.wordpress.com/3057/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/didierstevens.wordpress.com/3057/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/didierstevens.wordpress.com/3057/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/didierstevens.wordpress.com/3057/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/didierstevens.wordpress.com/3057/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/didierstevens.wordpress.com/3057/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/didierstevens.wordpress.com/3057/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/didierstevens.wordpress.com/3057/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/didierstevens.wordpress.com/3057/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/didierstevens.wordpress.com/3057/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/didierstevens.wordpress.com/3057/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/didierstevens.wordpress.com/3057/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/didierstevens.wordpress.com/3057/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/didierstevens.wordpress.com/3057/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&#038;blog=264765&#038;post=3057&#038;subd=didierstevens&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.didierstevens.com/2012/03/05/update-taskmanager-xls-v0-1-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">didierstevens</media:title>
		</media:content>
	</item>
		<item>
		<title>Teensy PDF Dropper Part 2</title>
		<link>http://blog.didierstevens.com/2012/02/27/teensy-pdf-dropper-part-2/</link>
		<comments>http://blog.didierstevens.com/2012/02/27/teensy-pdf-dropper-part-2/#comments</comments>
		<pubDate>Mon, 27 Feb 2012 00:00:07 +0000</pubDate>
		<dc:creator>Didier Stevens</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[My Software]]></category>
		<category><![CDATA[PDF]]></category>

		<guid isPermaLink="false">http://blog.didierstevens.com/?p=3044</guid>
		<description><![CDATA[Last year I showed how to use a Teensy micro-controller to drop a PDF file with embedded executable. But I was limited to a file of a few kilobytes, because of the Arduino programming language I used for the Teensy. In this post, I&#8217;m using WinAVR and I&#8217;m only limited by the amount of flash [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&#038;blog=264765&#038;post=3044&#038;subd=didierstevens&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Last year I showed how to use a <a href="http://blog.didierstevens.com/2011/07/13/teensy-pdf-dropper-part-1/">Teensy micro-controller to drop a PDF file with embedded executable</a>. But I was limited to a file of a few kilobytes, because of the Arduino programming language I used for the Teensy.</p>
<p><img class="alignnone size-full wp-image-2715" title="20110713-232829" src="http://didierstevens.files.wordpress.com/2011/07/20110713-232829.png" alt="" width="640" height="373" /></p>
<p>In this post, I&#8217;m using WinAVR and I&#8217;m only limited by the amount of flash memory on my Teensy++.</p>
<p>First we use a <a href="http://blog.didierstevens.com/programs/pdf-tools/#make-pdf">new version of my PDF tools to create a PDF file with embedded file</a>:</p>
<p><img class="alignnone size-full wp-image-3047" title="20120225-214529" src="http://didierstevens.files.wordpress.com/2012/02/20120225-214529.png" alt="" width="685" height="354" /></p>
<p>Filter i is exactly like filter h (ASCIIHexDecode), except that the lines of hex code are wrapped at 512 hex digits, making them digestible to our C compiler.</p>
<p>Another new feature of my make PDF tools is Python 3 support.</p>
<p>Here is a sample of our C code showing how to embed each line of the pure-ASCII PDF document as strings:</p>
<p><img class="alignnone size-full wp-image-3049" title="20120225-214806" src="http://didierstevens.files.wordpress.com/2012/02/20120225-214806.png" alt="" width="978" height="522" /></p>
<p>Macro PSTR makes that the string is stored in flash memory. The embedded executable is 57KB large, but still only takes half of the flash memory of my Teensy++.</p>
<p>After programming my Teensy++, I can fire up Notepad and let my Teensy++ type out the PDF document:</p>
<p><img class="alignnone size-full wp-image-3050" title="20120225-214923" src="http://didierstevens.files.wordpress.com/2012/02/20120225-214923.png" alt="" width="550" height="423" /></p>
<p>You can download my example for the WinAVR compiler here:</p>
<p><a href="http://didierstevens.com/files/software/avr-teensy-pdf-dropper_V0_0_0_1.zip" target="_self">avr-teensy-pdf-dropper_V0_0_0_1.zip</a> (<a href="https://didierstevens.com/files/software/avr-teensy-pdf-dropper_V0_0_0_1.zip" target="_self">https</a>)<br />
MD5: EA14100A1BEDA4614D1AE9DE0F71B747<br />
SHA256: 2C9A5DF1831B564D82548C72F1050737BCF17E5A25DCDC41D7FA4EA446A8FDED</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/didierstevens.wordpress.com/3044/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/didierstevens.wordpress.com/3044/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/didierstevens.wordpress.com/3044/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/didierstevens.wordpress.com/3044/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/didierstevens.wordpress.com/3044/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/didierstevens.wordpress.com/3044/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/didierstevens.wordpress.com/3044/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/didierstevens.wordpress.com/3044/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/didierstevens.wordpress.com/3044/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/didierstevens.wordpress.com/3044/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/didierstevens.wordpress.com/3044/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/didierstevens.wordpress.com/3044/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/didierstevens.wordpress.com/3044/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/didierstevens.wordpress.com/3044/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&#038;blog=264765&#038;post=3044&#038;subd=didierstevens&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.didierstevens.com/2012/02/27/teensy-pdf-dropper-part-2/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">didierstevens</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2011/07/20110713-232829.png" medium="image">
			<media:title type="html">20110713-232829</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2012/02/20120225-214529.png" medium="image">
			<media:title type="html">20120225-214529</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2012/02/20120225-214806.png" medium="image">
			<media:title type="html">20120225-214806</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2012/02/20120225-214923.png" medium="image">
			<media:title type="html">20120225-214923</media:title>
		</media:content>
	</item>
		<item>
		<title>Peeking at NAFT</title>
		<link>http://blog.didierstevens.com/2012/02/20/peeking-at-naft/</link>
		<comments>http://blog.didierstevens.com/2012/02/20/peeking-at-naft/#comments</comments>
		<pubDate>Mon, 20 Feb 2012 20:02:17 +0000</pubDate>
		<dc:creator>Didier Stevens</dc:creator>
				<category><![CDATA[My Software]]></category>
		<category><![CDATA[Networking]]></category>

		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=3033</guid>
		<description><![CDATA[Here are DNS queries issued by a Windows XP machine: And here is a command history of a Cisco router: What do these results have in common? Both were produced by analyzing RAM dumps with a new forensic toolkit I&#8217;m developing, the Network Appliance Forensic Toolkit, or NAFT. More to be published soon. But if [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&#038;blog=264765&#038;post=3033&#038;subd=didierstevens&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Here are DNS queries issued by a Windows XP machine:</p>
<p><img class="alignnone size-full wp-image-3035" title="20120220-200624" src="http://didierstevens.files.wordpress.com/2012/02/20120220-200624.png" alt="" width="851" height="720" /></p>
<p>And here is a command history of a Cisco router:</p>
<p><img class="alignnone size-full wp-image-3036" title="20120220-204723" src="http://didierstevens.files.wordpress.com/2012/02/20120220-204723.png" alt="" width="693" height="358" /></p>
<p>What do these results have in common?</p>
<p>Both were produced by analyzing RAM dumps with a new forensic toolkit I&#8217;m developing, the Network Appliance Forensic Toolkit, or NAFT.</p>
<p>More to be published soon.</p>
<p>But if you want a beta version now, provide me a Cisco core dump in exchange <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/didierstevens.wordpress.com/3033/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/didierstevens.wordpress.com/3033/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/didierstevens.wordpress.com/3033/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/didierstevens.wordpress.com/3033/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/didierstevens.wordpress.com/3033/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/didierstevens.wordpress.com/3033/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/didierstevens.wordpress.com/3033/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/didierstevens.wordpress.com/3033/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/didierstevens.wordpress.com/3033/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/didierstevens.wordpress.com/3033/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/didierstevens.wordpress.com/3033/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/didierstevens.wordpress.com/3033/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/didierstevens.wordpress.com/3033/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/didierstevens.wordpress.com/3033/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.didierstevens.com&#038;blog=264765&#038;post=3033&#038;subd=didierstevens&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.didierstevens.com/2012/02/20/peeking-at-naft/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">didierstevens</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2012/02/20120220-200624.png" medium="image">
			<media:title type="html">20120220-200624</media:title>
		</media:content>

		<media:content url="http://didierstevens.files.wordpress.com/2012/02/20120220-204723.png" medium="image">
			<media:title type="html">20120220-204723</media:title>
		</media:content>
	</item>
	</channel>
</rss>
