<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for Exodus Intelligence</title>
	<atom:link href="http://blog.exodusintel.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.exodusintel.com</link>
	<description></description>
	<lastBuildDate>Fri, 01 Feb 2013 15:40:17 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>Comment on Bypassing Microsoft&#8217;s Internet Explorer 0day &#8220;Fix It&#8221; Patch for CVE-2012-4792 by Get Latest News Around The World</title>
		<link>http://blog.exodusintel.com/2013/01/04/bypassing-microsofts-internet-explorer-0day-fix-it-patch-for-cve-2012-4792/comment-page-1/#comment-2831</link>
		<dc:creator><![CDATA[Get Latest News Around The World]]></dc:creator>
		<pubDate>Fri, 01 Feb 2013 15:40:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.exodusintel.com/?p=788#comment-2831</guid>
		<description><![CDATA[[...] Source: http://blog.exodusintel.com/2013/01/04/bypassing-microsofts-internet-explorer-0day-fix-it-patch-for-... [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Source: <a href="http://blog.exodusintel.com/2013/01/04/bypassing-microsofts-internet-explorer-0day-fix-it-patch-for-" rel="nofollow">http://blog.exodusintel.com/2013/01/04/bypassing-microsofts-internet-explorer-0day-fix-it-patch-for-</a>&#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About Exodus by Brian Ortiz</title>
		<link>http://blog.exodusintel.com/about/comment-page-1/#comment-1731</link>
		<dc:creator><![CDATA[Brian Ortiz]]></dc:creator>
		<pubDate>Wed, 16 Jan 2013 08:42:03 +0000</pubDate>
		<guid isPermaLink="false">http://exodusintel.wordpress.com/?page_id=2#comment-1731</guid>
		<description><![CDATA[Please send me a link or site i can accwess more on this topic]]></description>
		<content:encoded><![CDATA[<p>Please send me a link or site i can accwess more on this topic</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Happy New Year Analysis of CVE-2012-4792 by chris</title>
		<link>http://blog.exodusintel.com/2013/01/02/happy-new-year-analysis-of-cve-2012-4792/comment-page-1/#comment-1707</link>
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Tue, 15 Jan 2013 23:38:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.exodusintel.com/?p=718#comment-1707</guid>
		<description><![CDATA[Excellent article, keep on doing such quality work !
I really love the HTML+TIME trick :-)]]></description>
		<content:encoded><![CDATA[<p>Excellent article, keep on doing such quality work !<br />
I really love the HTML+TIME trick :-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Bypassing Microsoft&#8217;s Internet Explorer 0day &#8220;Fix It&#8221; Patch for CVE-2012-4792 by Microsoft repariert ältere IE-Versionen außerhalb des Patch-Day - ComputerBase</title>
		<link>http://blog.exodusintel.com/2013/01/04/bypassing-microsofts-internet-explorer-0day-fix-it-patch-for-cve-2012-4792/comment-page-1/#comment-1559</link>
		<dc:creator><![CDATA[Microsoft repariert ältere IE-Versionen außerhalb des Patch-Day - ComputerBase]]></dc:creator>
		<pubDate>Mon, 14 Jan 2013 20:33:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.exodusintel.com/?p=788#comment-1559</guid>
		<description><![CDATA[[...] für diese Lücke bereitgestellt. Nach bereits wenigen Tagen wurde jedoch bekannt, dass sich der Fix umgehen lässt. Jetzt hat Microsoft mit einem außerplanmäßigen Patch reagiert, der das Fix-it überflüssig [...]]]></description>
		<content:encoded><![CDATA[<p>[...] für diese Lücke bereitgestellt. Nach bereits wenigen Tagen wurde jedoch bekannt, dass sich der Fix umgehen lässt. Jetzt hat Microsoft mit einem außerplanmäßigen Patch reagiert, der das Fix-it überflüssig [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on DoS? Then Who Was Phone? by Weekendowa Lektura &#124; Zaufana Trzecia Strona</title>
		<link>http://blog.exodusintel.com/2013/01/07/who-was-phone/comment-page-1/#comment-1400</link>
		<dc:creator><![CDATA[Weekendowa Lektura &#124; Zaufana Trzecia Strona]]></dc:creator>
		<pubDate>Sun, 13 Jan 2013 06:43:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.exodusintel.com/?p=417#comment-1400</guid>
		<description><![CDATA[[...] Exodus Intelligence analizuje ciekawy błąd w Asterisku [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Exodus Intelligence analizuje ciekawy błąd w Asterisku [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Bypassing Microsoft&#8217;s Internet Explorer 0day &#8220;Fix It&#8221; Patch for CVE-2012-4792 by SafeTI Blog &#8211; Windows: Update da Microsoft conserta falha grave no sistema</title>
		<link>http://blog.exodusintel.com/2013/01/04/bypassing-microsofts-internet-explorer-0day-fix-it-patch-for-cve-2012-4792/comment-page-1/#comment-1269</link>
		<dc:creator><![CDATA[SafeTI Blog &#8211; Windows: Update da Microsoft conserta falha grave no sistema]]></dc:creator>
		<pubDate>Fri, 11 Jan 2013 14:55:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.exodusintel.com/?p=788#comment-1269</guid>
		<description><![CDATA[[...] contra os ataques conhecidos na rede, bem como o módulo de exploração Metasploit. No entanto, a Exodus Intelligence descobriu que há outras maneiras de explorar as vulnerabilidades que não são corrigidas pela [...]]]></description>
		<content:encoded><![CDATA[<p>[...] contra os ataques conhecidos na rede, bem como o módulo de exploração Metasploit. No entanto, a Exodus Intelligence descobriu que há outras maneiras de explorar as vulnerabilidades que não são corrigidas pela [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Bypassing Microsoft&#8217;s Internet Explorer 0day &#8220;Fix It&#8221; Patch for CVE-2012-4792 by Bug festif du premier janvier… et conséquences d’un abus de Fix-It - CNIS mag</title>
		<link>http://blog.exodusintel.com/2013/01/04/bypassing-microsofts-internet-explorer-0day-fix-it-patch-for-cve-2012-4792/comment-page-1/#comment-1212</link>
		<dc:creator><![CDATA[Bug festif du premier janvier… et conséquences d’un abus de Fix-It - CNIS mag]]></dc:creator>
		<pubDate>Fri, 11 Jan 2013 09:22:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.exodusintel.com/?p=788#comment-1212</guid>
		<description><![CDATA[[...] Tout commence par un très classique trou affectant Internet Explorer 6,7 et 8, immatriculé CVE-2012-4792. Un véritable ZDE exploitable à distance (et  effectivement exploité) et qui affecterait essentiellement les éditions Chinoises et Anglaises du navigateur. Microsoft publie coup sur coup  une alerte puis, le jour de la Saint Sylvestre, une  mesure de contournement sous forme d’une macro « Fix-It »… en attendant qu’une véritable rustine soit développée. Cette mesure provisoire n’est hélas, estiment les chercheurs de la société Exodus,  pas franchement efficace puisqu’il serait possible de la contourner. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Tout commence par un très classique trou affectant Internet Explorer 6,7 et 8, immatriculé CVE-2012-4792. Un véritable ZDE exploitable à distance (et  effectivement exploité) et qui affecterait essentiellement les éditions Chinoises et Anglaises du navigateur. Microsoft publie coup sur coup  une alerte puis, le jour de la Saint Sylvestre, une  mesure de contournement sous forme d’une macro « Fix-It »… en attendant qu’une véritable rustine soit développée. Cette mesure provisoire n’est hélas, estiment les chercheurs de la société Exodus,  pas franchement efficace puisqu’il serait possible de la contourner. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Happy New Year Analysis of CVE-2012-4792 by LolyRop</title>
		<link>http://blog.exodusintel.com/2013/01/02/happy-new-year-analysis-of-cve-2012-4792/comment-page-1/#comment-1082</link>
		<dc:creator><![CDATA[LolyRop]]></dc:creator>
		<pubDate>Thu, 10 Jan 2013 13:34:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.exodusintel.com/?p=718#comment-1082</guid>
		<description><![CDATA[From what i see i don&#039;t need to do this LFH trick (20 allocations) since after the CollectGarbage(); if i allocate the string it works.

is this done for more reliability ? or indeed this is useless and not needed ?]]></description>
		<content:encoded><![CDATA[<p>From what i see i don&#8217;t need to do this LFH trick (20 allocations) since after the CollectGarbage(); if i allocate the string it works.</p>
<p>is this done for more reliability ? or indeed this is useless and not needed ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Bypassing Microsoft&#8217;s Internet Explorer 0day &#8220;Fix It&#8221; Patch for CVE-2012-4792 by IT Secure Site &#187; Blog Archive &#187; January 2013 Patch Tuesday</title>
		<link>http://blog.exodusintel.com/2013/01/04/bypassing-microsofts-internet-explorer-0day-fix-it-patch-for-cve-2012-4792/comment-page-1/#comment-1024</link>
		<dc:creator><![CDATA[IT Secure Site &#187; Blog Archive &#187; January 2013 Patch Tuesday]]></dc:creator>
		<pubDate>Thu, 10 Jan 2013 07:00:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.exodusintel.com/?p=788#comment-1024</guid>
		<description><![CDATA[[...] a famous attacks in a wild, and also counters a Metasploit module. However, as Exodus Intelligence pointed out over a weekend, there are other ways of triggering a disadvantage that have not been lonesome by a [...]]]></description>
		<content:encoded><![CDATA[<p>[...] a famous attacks in a wild, and also counters a Metasploit module. However, as Exodus Intelligence pointed out over a weekend, there are other ways of triggering a disadvantage that have not been lonesome by a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on DoS? Then Who Was Phone? by Keegan McAllister</title>
		<link>http://blog.exodusintel.com/2013/01/07/who-was-phone/comment-page-1/#comment-1020</link>
		<dc:creator><![CDATA[Keegan McAllister]]></dc:creator>
		<pubDate>Thu, 10 Jan 2013 02:20:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.exodusintel.com/?p=417#comment-1020</guid>
		<description><![CDATA[Fantastic exploit and writeup!  Thanks for taking the time to explain everything so well.

The general approach reminds me a bit of Jon Oberheide&#039;s half-nelson.c, which involves colliding two Linux kernel stacks.

&gt; I found it interesting that the code looks as though it may have been written with memory management issues in mind, as the check to ensure content_length is not zero would catch an integer overflow caused by adding one to the value.

I think they&#039;re just checking that content_length got set within the for loop.  At any rate, content_length is a signed int, so overflow behavior is undefined -- of course, many developers don&#039;t know this.]]></description>
		<content:encoded><![CDATA[<p>Fantastic exploit and writeup!  Thanks for taking the time to explain everything so well.</p>
<p>The general approach reminds me a bit of Jon Oberheide&#8217;s half-nelson.c, which involves colliding two Linux kernel stacks.</p>
<p>&gt; I found it interesting that the code looks as though it may have been written with memory management issues in mind, as the check to ensure content_length is not zero would catch an integer overflow caused by adding one to the value.</p>
<p>I think they&#8217;re just checking that content_length got set within the for loop.  At any rate, content_length is a signed int, so overflow behavior is undefined &#8212; of course, many developers don&#8217;t know this.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
