<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1029833275466591797.post3680128912350570089..comments</id><updated>2011-09-02T10:08:15.649-04:00</updated><category term='2009'/><category term='Razorback'/><category term='SMB DoS'/><category term='MS09-022'/><category term='Boss-Hates-Me'/><category term='development'/><category term='MS09-006'/><category term='MS09-031'/><category term='cybershockwave'/><category term='Windows'/><category term='shared object rules'/><category term='CVE-2009-0520'/><category term='MS09-015'/><category term='pulled pork'/><category term='detection'/><category term='Blacklisting'/><category term='MS09-005'/><category term='exploitation'/><category term='FTP'/><category term='Functional Not Elegant'/><category term='MS09-023'/><category term='Vulnerability'/><category term='Trojan.Rincux'/><category term='MS09-014'/><category term='Apache'/><category term='SMBv2'/><category term='H2H'/><category term='DEP'/><category term='Event Mapping'/><category term='patch'/><category term='MS09-008'/><category term='MS09-041'/><category term='ClamAV'/><category term='Opera'/><category term='Metasploit'/><category term='MS09-013'/><category term='MS08-068'/><category term='Rules'/><category term='MS09-024'/><category term='Perl'/><category term='Exploiting'/><category term='wireshark'/><category term='trojan'/><category term='OSX'/><category term='IIS'/><category term='Word'/><category term='MS09-042'/><category term='iPhone'/><category term='Firefox'/><category term='iTunes'/><category term='Coverage'/><category term='CVE-2008-5911'/><category term='PE-Sig'/><category term='VMware'/><category term='Conficker'/><category term='Snort'/><category term='MS09-012'/><category term='worm'/><category term='MS09-030'/><category term='SO Rules'/><category term='Rawbytes'/><category term='Internet Explorer'/><category term='PoE'/><category term='MS08-067'/><category term='Gumblar'/><category term='Beta site'/><category term='conferences'/><category term='Excel'/><category term='Innovation'/><category term='Olney&apos;s Horrible DB'/><category term='cybersecurity'/><category term='Snort.org'/><category term='Evasions'/><category term='Microsoft'/><category term='MS09-011'/><category term='MS09-034'/><category term='Acrobat'/><category term='MS09-003'/><category term='Oracle'/><category term='MS08-078'/><category term='Sweden'/><category term='Whitepaper'/><category term='dumbpig'/><category term='planning'/><category term='OfficeCat'/><category term='ask the VRT'/><category term='IRC'/><category term='MS09-010'/><category term='tuning'/><category term='MS09-002'/><category term='DoJoSec'/><category term='SSL'/><category term='Brad Arkin'/><category term='preprocessor'/><category term='Powerpoint'/><category term='MS09-032'/><category term='Snort Rule Options'/><category term='Snort User Groups'/><category term='Snort Overview'/><category term='backdoor'/><category term='dhclient'/><category term='MS09-027'/><category term='0-day'/><category term='Jobs'/><category term='THC'/><category term='Fun'/><category term='phishing'/><category term='CVE-2009-0045'/><category term='pentesting'/><category term='CUPS'/><category term='O:DTLWWOT'/><category term='MS09-028'/><category term='preprocessor options'/><category term='Linux'/><category term='twitter'/><category term='Weblogic'/><category term='virus'/><category term='DoS'/><category term='Ubuntu'/><category term='md5'/><category term='MS09-004'/><category term='Neural Network'/><category term='DNS'/><category term='immunet'/><category term='predictions'/><category term='OMRON FINS'/><category term='methodology'/><category term='C rules'/><category term='omg'/><category term='Buffers'/><category term='Flash'/><category term='dcerpc'/><category term='dsniff'/><category term='MS09-039'/><category term='ActiveX'/><category term='SubSeven'/><category term='Mac'/><category term='Marketing'/><category term='awbo'/><category term='SCADA'/><category term='Defcon'/><category term='MS09-048'/><category term='CVE-2010-1885'/><category term='CVE-2008-5457'/><category term='Anomaly Detection'/><category term='Adobe'/><category term='Amish Hammers'/><category term='DoJoCon'/><category term='MS09-047'/><category term='SANS'/><category term='cloud'/><category term='We&apos;re all going to die'/><category term='http_inspect'/><category term='APT'/><category term='IDA Pro'/><category term='labs'/><category term='MS09-001'/><category term='MS09-046'/><category term='MS09-029'/><category term='Dial-up'/><category term='winamp'/><category term='Education'/><category term='OpenSSH'/><category term='MS09-019'/><category term='Soothsaying'/><category term='Vulnerability Report'/><category term='obfuscation'/><category term='MS09-045'/><category term='signatures'/><category term='javascript'/><category term='Updating software'/><category term='apple'/><category term='Reader'/><category term='rogye antivirus'/><category term='Green Curtain'/><category term='MS09-018'/><category term='Buffer Overflow'/><category term='Security'/><category term='MS09-037'/><category term='MS09-009'/><category term='MS09-020'/><category term='dnssnarf'/><category term='Vendor Response'/><category term='polymorphic'/><category term='MS03-039'/><category term='MS09-044'/><category term='script'/><category term='MS09-036'/><category term='Disclosure'/><category term='rocket pig'/><category term='MS09-017'/><category term='prediction'/><category term='Magic'/><category term='bots'/><category term='rsplug'/><category term='MS09-038'/><category term='cygwin'/><category term='so_rules'/><category term='MS09-043'/><category term='WebDAV'/><category term='four way handshake'/><category term='MS09-016'/><category term='VRT'/><category term='windbg'/><category term='Malware'/><category term='antivirus'/><category term='flowbits'/><category term='Mattland'/><category term='Byakugan'/><category term='Virut'/><category term='TLS'/><category term='freakshow'/><category term='MS09-021'/><title type='text'>Comments on VRT: MacDefender and its variants</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://vrt-blog.snort.org/feeds/3680128912350570089/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/3680128912350570089/comments/default'/><link rel='alternate' type='text/html' href='http://vrt-blog.snort.org/2011/05/macdefender-and-its-variants.html'/><author><name>Nigel Houghton</name><uri>http://www.blogger.com/profile/11599266012164775142</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://2.bp.blogspot.com/_Mw9WV6qG-BY/SSrnMflI5VI/AAAAAAAAABo/bVCkKIU8zWs/S220/nigelphoto.png'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1029833275466591797.post-4802730620775962496</id><published>2011-06-23T10:56:11.463-04:00</published><updated>2011-06-23T10:56:11.463-04:00</updated><title type='text'>Slog6969 -- There is only one ClamAV pipeline. If ...</title><content type='html'>Slog6969 -- There is only one ClamAV pipeline. If your Untangle system is grabbing it&amp;#39;s definitions using freshclam, from the Official ClamAV repository, yes, you should have had them -- before this post came out.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/3680128912350570089/comments/default/4802730620775962496'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/3680128912350570089/comments/default/4802730620775962496'/><link rel='alternate' type='text/html' href='http://vrt-blog.snort.org/2011/05/macdefender-and-its-variants.html?showComment=1308840971463#c4802730620775962496' title=''/><author><name>Joel Esler</name><uri>http://www.blogger.com/profile/13911640885160917108</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_cMCd9mdQ_m0/TQapQCLpj3I/AAAAAAAAAAM/3JuBi1c88Bc/S220/Headshot.png'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://vrt-blog.snort.org/2011/05/macdefender-and-its-variants.html' ref='tag:blogger.com,1999:blog-1029833275466591797.post-3680128912350570089' source='http://www.blogger.com/feeds/1029833275466591797/posts/default/3680128912350570089' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-716923824'/></entry><entry><id>tag:blogger.com,1999:blog-1029833275466591797.post-4365947208764518350</id><published>2011-06-10T02:04:52.509-04:00</published><updated>2011-06-10T02:04:52.509-04:00</updated><title type='text'>Great piece, Joel.

Thanks for the screenshots, in...</title><content type='html'>Great piece, Joel.&lt;br /&gt;&lt;br /&gt;Thanks for the screenshots, in particular. I&amp;#39;ve quoted your blog unabashedly (with attribution, of course!) in my own recent blog on &lt;a href="http://update.pcantivirusreviews.com/news/2011/06/macdefender-screenshots-so-heres-what-it-looks-like.html" rel="nofollow"&gt;MacDefender&lt;/a&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/3680128912350570089/comments/default/4365947208764518350'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/3680128912350570089/comments/default/4365947208764518350'/><link rel='alternate' type='text/html' href='http://vrt-blog.snort.org/2011/05/macdefender-and-its-variants.html?showComment=1307685892509#c4365947208764518350' title=''/><author><name>ksmith</name><uri>http://www.blogger.com/profile/05387473401444362557</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://vrt-blog.snort.org/2011/05/macdefender-and-its-variants.html' ref='tag:blogger.com,1999:blog-1029833275466591797.post-3680128912350570089' source='http://www.blogger.com/feeds/1029833275466591797/posts/default/3680128912350570089' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-470799196'/></entry><entry><id>tag:blogger.com,1999:blog-1029833275466591797.post-494843323995623133</id><published>2011-05-30T09:57:20.495-04:00</published><updated>2011-05-30T09:57:20.495-04:00</updated><title type='text'>Joel, I run an Untangle UTM and it has ClamAV at t...</title><content type='html'>Joel, I run an Untangle UTM and it has ClamAV at the gateway. Will these Mac sigs be in that feed and get updated? &lt;br /&gt;&lt;br /&gt;Are you putting Mac sigs in EVERY possible Clamav sig pipline?&lt;br /&gt;&lt;br /&gt;http://www.untangle.com/&lt;br /&gt;&lt;br /&gt;.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/3680128912350570089/comments/default/494843323995623133'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/3680128912350570089/comments/default/494843323995623133'/><link rel='alternate' type='text/html' href='http://vrt-blog.snort.org/2011/05/macdefender-and-its-variants.html?showComment=1306763840495#c494843323995623133' title=''/><author><name>Slog6969</name><uri>http://www.blogger.com/profile/08302314289090536676</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://vrt-blog.snort.org/2011/05/macdefender-and-its-variants.html' ref='tag:blogger.com,1999:blog-1029833275466591797.post-3680128912350570089' source='http://www.blogger.com/feeds/1029833275466591797/posts/default/3680128912350570089' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-240190982'/></entry><entry><id>tag:blogger.com,1999:blog-1029833275466591797.post-6401425375880545518</id><published>2011-05-23T11:01:58.392-04:00</published><updated>2011-05-23T11:01:58.392-04:00</updated><title type='text'>Kate,

Yes.  It would simply require an extra step...</title><content type='html'>Kate,&lt;br /&gt;&lt;br /&gt;Yes.  It would simply require an extra step to open the package file.  It&amp;#39;s not an exploit against a browser in anyway, any browser with javascript turned on should download the file in the background.  Safari just opens the package for you by default.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/3680128912350570089/comments/default/6401425375880545518'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/3680128912350570089/comments/default/6401425375880545518'/><link rel='alternate' type='text/html' href='http://vrt-blog.snort.org/2011/05/macdefender-and-its-variants.html?showComment=1306162918392#c6401425375880545518' title=''/><author><name>Joel Esler</name><uri>http://www.blogger.com/profile/13911640885160917108</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_cMCd9mdQ_m0/TQapQCLpj3I/AAAAAAAAAAM/3JuBi1c88Bc/S220/Headshot.png'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://vrt-blog.snort.org/2011/05/macdefender-and-its-variants.html' ref='tag:blogger.com,1999:blog-1029833275466591797.post-3680128912350570089' source='http://www.blogger.com/feeds/1029833275466591797/posts/default/3680128912350570089' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-716923824'/></entry><entry><id>tag:blogger.com,1999:blog-1029833275466591797.post-692604529302706770</id><published>2011-05-23T09:53:24.829-04:00</published><updated>2011-05-23T09:53:24.829-04:00</updated><title type='text'>From this article, it seems to be only exploiting ...</title><content type='html'>From this article, it seems to be only exploiting Safari for Mac. Would it also affect a Mac if you were running Firefox or Chrome?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/3680128912350570089/comments/default/692604529302706770'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1029833275466591797/3680128912350570089/comments/default/692604529302706770'/><link rel='alternate' type='text/html' href='http://vrt-blog.snort.org/2011/05/macdefender-and-its-variants.html?showComment=1306158804829#c692604529302706770' title=''/><author><name>Kate Hutchinson</name><uri>http://www.blogger.com/profile/17664981385715429246</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_j32PyN0W0DE/SygPFruAi8I/AAAAAAAAC00/wOfZA1D5Bx0/S220/s41343cb113120_8_0_2.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://vrt-blog.snort.org/2011/05/macdefender-and-its-variants.html' ref='tag:blogger.com,1999:blog-1029833275466591797.post-3680128912350570089' source='http://www.blogger.com/feeds/1029833275466591797/posts/default/3680128912350570089' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-728033162'/></entry></feed>
