<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for PhishLabs Blog - News on Fraud, Phishing, Malware and Cybercrime</title>
	<atom:link href="http://www.phishlabs.com/blog/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://www.phishlabs.com/blog</link>
	<description></description>
	<lastBuildDate>Sat, 24 Oct 2009 22:30:54 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Open formmailers won&#8217;t die by Robert</title>
		<link>http://www.phishlabs.com/blog/archives/150/comment-page-1#comment-2580</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Sat, 24 Oct 2009 22:30:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.phishlabs.com/blog/?p=150#comment-2580</guid>
		<description>Hi,

I have just come across this article and I am somewhat confused.

Although you seem to be totally against formmailers, you supply a link to Matt Wright’s site and you use formmail yourself. This is a formmail I am filling in, isn’t it?

I have just put up some formmailers with Matt Wright’s script on my sites, but I neither want to facilitate phishing nor spamming.

Can you tell me if there are save scripts to use, and if so which ones?

Thank you

Robert</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>I have just come across this article and I am somewhat confused.</p>
<p>Although you seem to be totally against formmailers, you supply a link to Matt Wright’s site and you use formmail yourself. This is a formmail I am filling in, isn’t it?</p>
<p>I have just put up some formmailers with Matt Wright’s script on my sites, but I neither want to facilitate phishing nor spamming.</p>
<p>Can you tell me if there are save scripts to use, and if so which ones?</p>
<p>Thank you</p>
<p>Robert</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Acrobat 0-day used in targeted attacks by Mitigating Vulnerabilities in Adobe Reader and Acrobat</title>
		<link>http://www.phishlabs.com/blog/archives/122/comment-page-1#comment-141</link>
		<dc:creator>Mitigating Vulnerabilities in Adobe Reader and Acrobat</dc:creator>
		<pubDate>Tue, 17 Mar 2009 14:07:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.phishlabs.com/blog/?p=122#comment-141</guid>
		<description>[...] you need to implement this change across a large number of machines, PhishLabs have posted some information which will make your life [...]</description>
		<content:encoded><![CDATA[<p>[...] you need to implement this change across a large number of machines, PhishLabs have posted some information which will make your life [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Acrobat 0-day used in targeted attacks by Adobe Vulnerability on the Loose? &#124; Complete Source</title>
		<link>http://www.phishlabs.com/blog/archives/122/comment-page-1#comment-113</link>
		<dc:creator>Adobe Vulnerability on the Loose? &#124; Complete Source</dc:creator>
		<pubDate>Tue, 10 Mar 2009 12:58:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.phishlabs.com/blog/?p=122#comment-113</guid>
		<description>[...] Phishlabs has written a bat file that can automatically handle the registry edit. You can download the necessary files here: http://www.phishlabs.com/blog/archives/122 [...]</description>
		<content:encoded><![CDATA[<p>[...] Phishlabs has written a bat file that can automatically handle the registry edit. You can download the necessary files here: <a href="http://www.phishlabs.com/blog/archives/122" rel="nofollow">http://www.phishlabs.com/blog/archives/122</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Acrobat 0-day used in targeted attacks by Tecnologia e Informação &#187; Como se manter seguro usando Adobe Flash e Reader</title>
		<link>http://www.phishlabs.com/blog/archives/122/comment-page-1#comment-81</link>
		<dc:creator>Tecnologia e Informação &#187; Como se manter seguro usando Adobe Flash e Reader</dc:creator>
		<pubDate>Wed, 04 Mar 2009 10:21:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.phishlabs.com/blog/?p=122#comment-81</guid>
		<description>[...] explorações através de arquivos PDF maliciosos estão acontecendo). Por enquanto, sobreviva de workarounds. Outra opção é instalar um patch não oficial que um consultor da SourceFire [...]</description>
		<content:encoded><![CDATA[<p>[...] explorações através de arquivos PDF maliciosos estão acontecendo). Por enquanto, sobreviva de workarounds. Outra opção é instalar um patch não oficial que um consultor da SourceFire [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Acrobat 0-day used in targeted attacks by Vlad</title>
		<link>http://www.phishlabs.com/blog/archives/122/comment-page-1#comment-67</link>
		<dc:creator>Vlad</dc:creator>
		<pubDate>Sat, 28 Feb 2009 04:01:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.phishlabs.com/blog/?p=122#comment-67</guid>
		<description>Yeah - how do you disable the pop-up warning about enabling the java (fricking annoying)?</description>
		<content:encoded><![CDATA[<p>Yeah &#8211; how do you disable the pop-up warning about enabling the java (fricking annoying)?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How AV software can stop phishing sites by Light Blue Touchpaper &#187; Blog Archive &#187; Evil Searching</title>
		<link>http://www.phishlabs.com/blog/archives/35/comment-page-1#comment-60</link>
		<dc:creator>Light Blue Touchpaper &#187; Blog Archive &#187; Evil Searching</dc:creator>
		<pubDate>Wed, 25 Feb 2009 17:19:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.phishlabs.com/blog/?p=35#comment-60</guid>
		<description>[...] phishing websites (&#8221;if you can break in, then so can I&#8221;); or they were seeking the PHP &#8220;shells&#8221; that phishing attackers often install to help them upload files onto the website (&#8221;if you [...]</description>
		<content:encoded><![CDATA[<p>[...] phishing websites (&#8221;if you can break in, then so can I&#8221;); or they were seeking the PHP &#8220;shells&#8221; that phishing attackers often install to help them upload files onto the website (&#8221;if you [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Acrobat 0-day used in targeted attacks by max</title>
		<link>http://www.phishlabs.com/blog/archives/122/comment-page-1#comment-58</link>
		<dc:creator>max</dc:creator>
		<pubDate>Wed, 25 Feb 2009 12:53:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.phishlabs.com/blog/?p=122#comment-58</guid>
		<description>how do you disable the pop-up warning about enabling the java ??</description>
		<content:encoded><![CDATA[<p>how do you disable the pop-up warning about enabling the java ??</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Acrobat 0-day used in targeted attacks by 山寨PDF补丁比Adobe官方提前两周发布 &#124; 紧跟IT潮流</title>
		<link>http://www.phishlabs.com/blog/archives/122/comment-page-1#comment-57</link>
		<dc:creator>山寨PDF补丁比Adobe官方提前两周发布 &#124; 紧跟IT潮流</dc:creator>
		<pubDate>Wed, 25 Feb 2009 06:27:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.phishlabs.com/blog/?p=122#comment-57</guid>
		<description>[...] 此外安全公司PhishLabs也发布了补丁去重置一个Windows注册表项，禁用Adobe Reader 9.0的JavaScript，从而切断黑客入侵之路。 Grenier的补丁下载。 [...]</description>
		<content:encoded><![CDATA[<p>[...] 此外安全公司PhishLabs也发布了补丁去重置一个Windows注册表项，禁用Adobe Reader 9.0的JavaScript，从而切断黑客入侵之路。 Grenier的补丁下载。 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Acrobat 0-day used in targeted attacks by jcg</title>
		<link>http://www.phishlabs.com/blog/archives/122/comment-page-1#comment-55</link>
		<dc:creator>jcg</dc:creator>
		<pubDate>Tue, 24 Feb 2009 17:55:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.phishlabs.com/blog/?p=122#comment-55</guid>
		<description>acrobat 6 pro:
HKCU\Software\Adobe\Adobe Acrobat\6.0\JSPrefs\bEnableJS

reader 7:
HKCU\Software\Adobe\Acrobat Reader\7.0\JSPrefs\bEnableJS</description>
		<content:encoded><![CDATA[<p>acrobat 6 pro:<br />
HKCU\Software\Adobe\Adobe Acrobat\6.0\JSPrefs\bEnableJS</p>
<p>reader 7:<br />
HKCU\Software\Adobe\Acrobat Reader\7.0\JSPrefs\bEnableJS</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Acrobat 0-day used in targeted attacks by Dave Howe</title>
		<link>http://www.phishlabs.com/blog/archives/122/comment-page-1#comment-53</link>
		<dc:creator>Dave Howe</dc:creator>
		<pubDate>Tue, 24 Feb 2009 13:06:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.phishlabs.com/blog/?p=122#comment-53</guid>
		<description>Note that for acrobat reader v8, that key becomes

HKCU\Software\Adobe\Acrobat Reader\8.0\JSPrefs\bEnableJS

I would imagine that there may be other versions also, although localizations tend to use the same keys.</description>
		<content:encoded><![CDATA[<p>Note that for acrobat reader v8, that key becomes</p>
<p>HKCU\Software\Adobe\Acrobat Reader\8.0\JSPrefs\bEnableJS</p>
<p>I would imagine that there may be other versions also, although localizations tend to use the same keys.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Acrobat 0-day used in targeted attacks by .blog &#187; Blog Archive &#187; Adobe flaw work arounds</title>
		<link>http://www.phishlabs.com/blog/archives/122/comment-page-1#comment-51</link>
		<dc:creator>.blog &#187; Blog Archive &#187; Adobe flaw work arounds</dc:creator>
		<pubDate>Tue, 24 Feb 2009 03:24:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.phishlabs.com/blog/?p=122#comment-51</guid>
		<description>[...] the security for several computers you may wish to disable JavaScript via the registry. The guys at PhishLabs have pointed out how to do this. according to their blog you can disable JavaScript in Adobe Reader [...]</description>
		<content:encoded><![CDATA[<p>[...] the security for several computers you may wish to disable JavaScript via the registry. The guys at PhishLabs have pointed out how to do this. according to their blog you can disable JavaScript in Adobe Reader [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Acrobat 0-day used in targeted attacks by More Acrobatics &#124; ThreatBlog</title>
		<link>http://www.phishlabs.com/blog/archives/122/comment-page-1#comment-46</link>
		<dc:creator>More Acrobatics &#124; ThreatBlog</dc:creator>
		<pubDate>Sat, 21 Feb 2009 19:27:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.phishlabs.com/blog/?p=122#comment-46</guid>
		<description>[...] batch-file for turning off JavaScript in Adobe Reader&#160;by altering Registry settings at http://www.phishlabs.com/blog/archives/122&#160;(I haven&#8217;t tested it!). Assuming that it works as advertised, there&#8217;s no advantage [...]</description>
		<content:encoded><![CDATA[<p>[...] batch-file for turning off JavaScript in Adobe Reader&nbsp;by altering Registry settings at <a href="http://www.phishlabs.com/blog/archives/122&nbsp;(I" rel="nofollow">http://www.phishlabs.com/blog/archives/122&nbsp;(I</a> haven&#8217;t tested it!). Assuming that it works as advertised, there&#8217;s no advantage [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How AV software can stop phishing sites by jal</title>
		<link>http://www.phishlabs.com/blog/archives/35/comment-page-1#comment-5</link>
		<dc:creator>jal</dc:creator>
		<pubDate>Wed, 26 Nov 2008 23:31:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.phishlabs.com/blog/?p=35#comment-5</guid>
		<description>@Jarek

Trend Micro and 29 other vendors were tested.    The published results only include the top 10 performing vendors.   The point of the test was not to shame the underperforming vendors, but rather to call attention to the need to detect these files in general since all vendors performed relatively poor compared to, for example, the typical Win32 trojan.   Soon, the same samples will be tested again to see which vendors have responded and which have not.  Stay tuned.</description>
		<content:encoded><![CDATA[<p>@Jarek</p>
<p>Trend Micro and 29 other vendors were tested.    The published results only include the top 10 performing vendors.   The point of the test was not to shame the underperforming vendors, but rather to call attention to the need to detect these files in general since all vendors performed relatively poor compared to, for example, the typical Win32 trojan.   Soon, the same samples will be tested again to see which vendors have responded and which have not.  Stay tuned.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How AV software can stop phishing sites by Jarek Bechemot</title>
		<link>http://www.phishlabs.com/blog/archives/35/comment-page-1#comment-4</link>
		<dc:creator>Jarek Bechemot</dc:creator>
		<pubDate>Wed, 26 Nov 2008 17:13:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.phishlabs.com/blog/?p=35#comment-4</guid>
		<description>Dear All,
I wonder why there was no TrendMicro in this test  ? TM has av scan engine for Linux (unix) system - eg.: http://emea.trendmicro.com/emea/products/enterprise/serverprotect-for-linux/index.html and detects PHP shells, backdoors, etc.
This is because neither av-test.org nor VirusTotal has it in its scan engine pool ?
Any answer will be appreciated. Regards,</description>
		<content:encoded><![CDATA[<p>Dear All,<br />
I wonder why there was no TrendMicro in this test  ? TM has av scan engine for Linux (unix) system &#8211; eg.: <a href="http://emea.trendmicro.com/emea/products/enterprise/serverprotect-for-linux/index.html" rel="nofollow">http://emea.trendmicro.com/emea/products/enterprise/serverprotect-for-linux/index.html</a> and detects PHP shells, backdoors, etc.<br />
This is because neither av-test.org nor VirusTotal has it in its scan engine pool ?<br />
Any answer will be appreciated. Regards,</p>
]]></content:encoded>
	</item>
</channel>
</rss>
