<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for inREVERSE</title>
	<atom:link href="http://www.inreverse.net/?feed=comments-rss2" rel="self" type="application/rss+xml" />
	<link>http://www.inreverse.net</link>
	<description></description>
	<lastBuildDate>Sat, 21 Aug 2010 05:33:22 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>Comment on Malware Analysis via Reflection by CurtW</title>
		<link>http://www.inreverse.net/?p=1153&#038;cpage=1#comment-137</link>
		<dc:creator>CurtW</dc:creator>
		<pubDate>Sat, 21 Aug 2010 05:33:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.inreverse.net/?p=1153#comment-137</guid>
		<description>Hi, thanks for the post. Is the tool available? I have something I could use it for, a sample of the newest unruy. In the meanwhile, I&#039;m going to look at JavaSnoop. I&#039;ve learned that there are some Java options for calling the jar that will also do something of a run trace, but I need to fire up the goat first.
@curtw</description>
		<content:encoded><![CDATA[<p>Hi, thanks for the post. Is the tool available? I have something I could use it for, a sample of the newest unruy. In the meanwhile, I&#8217;m going to look at JavaSnoop. I&#8217;ve learned that there are some Java options for calling the jar that will also do something of a run trace, but I need to fire up the goat first.<br />
@curtw</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About TmpHider/Stuxnet #1 by rur</title>
		<link>http://www.inreverse.net/?p=1246&#038;cpage=1#comment-136</link>
		<dc:creator>rur</dc:creator>
		<pubDate>Tue, 17 Aug 2010 15:18:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.inreverse.net/?p=1246#comment-136</guid>
		<description>Thank you!</description>
		<content:encoded><![CDATA[<p>Thank you!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About TmpHider/Stuxnet #1 by cP</title>
		<link>http://www.inreverse.net/?p=1246&#038;cpage=1#comment-131</link>
		<dc:creator>cP</dc:creator>
		<pubDate>Sat, 07 Aug 2010 11:26:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.inreverse.net/?p=1246#comment-131</guid>
		<description>You can download it from here:
http://ivanlef0u.nibbles.fr/repo/windoz/[MS-SHLLINK].pdf

:)</description>
		<content:encoded><![CDATA[<p>You can download it from here:<br />
<a href="http://ivanlef0u.nibbles.fr/repo/windoz/MS-SHLLINK.pdf" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/ivanlef0u.nibbles.fr/repo/windoz/MS-SHLLINK.pdf?referer=');">http://ivanlef0u.nibbles.fr/repo/windoz/MS-SHLLINK.pdf</a></p>
<p>:)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About TmpHider/Stuxnet #1 by swirl</title>
		<link>http://www.inreverse.net/?p=1246&#038;cpage=1#comment-130</link>
		<dc:creator>swirl</dc:creator>
		<pubDate>Wed, 21 Jul 2010 13:27:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.inreverse.net/?p=1246#comment-130</guid>
		<description>we will upload it here shortly :)</description>
		<content:encoded><![CDATA[<p>we will upload it here shortly :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About TmpHider/Stuxnet #1 by rur</title>
		<link>http://www.inreverse.net/?p=1246&#038;cpage=1#comment-129</link>
		<dc:creator>rur</dc:creator>
		<pubDate>Wed, 21 Jul 2010 13:23:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.inreverse.net/?p=1246#comment-129</guid>
		<description>Hi! 
Thank you for interesting research! The bad thing is microsoft removed pdf with documentation ([MS-SHLLINK].PDF) from their site :(
May be someone saved it and can upload it to sendspace or rapidshare?
Thanks</description>
		<content:encoded><![CDATA[<p>Hi!<br />
Thank you for interesting research! The bad thing is microsoft removed pdf with documentation ([MS-SHLLINK].PDF) from their site :(<br />
May be someone saved it and can upload it to sendspace or rapidshare?<br />
Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About TmpHider/Stuxnet #1 by swirl</title>
		<link>http://www.inreverse.net/?p=1246&#038;cpage=1#comment-127</link>
		<dc:creator>swirl</dc:creator>
		<pubDate>Sun, 18 Jul 2010 22:55:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.inreverse.net/?p=1246#comment-127</guid>
		<description>Hey gb,

if I blur all the image there would be no point in publishing it right ? ;) 
and anyway now there are already POCs out there so no harm done</description>
		<content:encoded><![CDATA[<p>Hey gb,</p>
<p>if I blur all the image there would be no point in publishing it right ? ;)<br />
and anyway now there are already POCs out there so no harm done</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About TmpHider/Stuxnet #1 by swirl</title>
		<link>http://www.inreverse.net/?p=1246&#038;cpage=1#comment-126</link>
		<dc:creator>swirl</dc:creator>
		<pubDate>Sun, 18 Jul 2010 22:47:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.inreverse.net/?p=1246#comment-126</guid>
		<description>Hi Fotis, 

I got it from a private feed but you can ask a copy from &lt;a href=&quot;http://contagiodump.blogspot.com/2010/07/cve-2010-2568-lnk-vunerability-stuxnet.html&quot; rel=&quot;nofollow&quot;&gt;contagiodump&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Hi Fotis, </p>
<p>I got it from a private feed but you can ask a copy from <a href="http://contagiodump.blogspot.com/2010/07/cve-2010-2568-lnk-vunerability-stuxnet.html" rel="nofollow" onclick="pageTracker._trackPageview('/outgoing/contagiodump.blogspot.com/2010/07/cve-2010-2568-lnk-vunerability-stuxnet.html?referer=');">contagiodump</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About TmpHider/Stuxnet #1 by gb</title>
		<link>http://www.inreverse.net/?p=1246&#038;cpage=1#comment-125</link>
		<dc:creator>gb</dc:creator>
		<pubDate>Sat, 17 Jul 2010 20:02:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.inreverse.net/?p=1246#comment-125</guid>
		<description>Hey, it&#039;s good that you&#039;re analyzing and posting info on it, I recommend you blur out the whole image and not just the ascii part.</description>
		<content:encoded><![CDATA[<p>Hey, it&#8217;s good that you&#8217;re analyzing and posting info on it, I recommend you blur out the whole image and not just the ascii part.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About TmpHider/Stuxnet #1 by Fotis</title>
		<link>http://www.inreverse.net/?p=1246&#038;cpage=1#comment-124</link>
		<dc:creator>Fotis</dc:creator>
		<pubDate>Fri, 16 Jul 2010 18:50:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.inreverse.net/?p=1246#comment-124</guid>
		<description>Hey nice info posted there. I would be glad if you could give me some links for a sample of this worm. I am especially interested in analyzing those lnk files that trigger the exploit.

Thanks</description>
		<content:encoded><![CDATA[<p>Hey nice info posted there. I would be glad if you could give me some links for a sample of this worm. I am especially interested in analyzing those lnk files that trigger the exploit.</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Malware Analysis via Reflection by Sarkie</title>
		<link>http://www.inreverse.net/?p=1153&#038;cpage=1#comment-122</link>
		<dc:creator>Sarkie</dc:creator>
		<pubDate>Fri, 09 Jul 2010 10:01:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.inreverse.net/?p=1153#comment-122</guid>
		<description>I used to use DJ Java for decompiling any Java malware, used to be pretty good before it went payware.

Surprised this was .net reflection! I suppose most people have out dated Java inside their browser.

Anyway, nice article.

@sarkie_dave</description>
		<content:encoded><![CDATA[<p>I used to use DJ Java for decompiling any Java malware, used to be pretty good before it went payware.</p>
<p>Surprised this was .net reflection! I suppose most people have out dated Java inside their browser.</p>
<p>Anyway, nice article.</p>
<p>@sarkie_dave</p>
]]></content:encoded>
	</item>
</channel>
</rss>
