<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: PDF Exploit &#8211; In the wild, and how to decode</title>
	<atom:link href="http://ddos.arbornetworks.com/2008/11/pdf-exploit-in-the-wild-and-how-to-decode/feed/" rel="self" type="application/rss+xml" />
	<link>http://ddos.arbornetworks.com/2008/11/pdf-exploit-in-the-wild-and-how-to-decode/</link>
	<description>A weblog dedicated to educating the community on security threats that matter</description>
	<lastBuildDate>Sun, 29 Jan 2012 02:23:23 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://ddos.arbornetworks.com/2008/11/pdf-exploit-in-the-wild-and-how-to-decode/comment-page-1/#comment-177200</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Mon, 10 Nov 2008 22:59:54 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=449#comment-177200</guid>
		<description>I analyzed 2 malicious PDF files (data.pdf and info.pdf). My info.pdf has the same MD5 hash as the file you analyzed. data.pdf is an older version, I uncovered this via incremental updates and metadata found in data.pdf. Details here:
http://blog.didierstevens.com/2008/11/10/shoulder-surfing-a-malicious-pdf-author/</description>
		<content:encoded><![CDATA[<p>I analyzed 2 malicious PDF files (data.pdf and info.pdf). My info.pdf has the same MD5 hash as the file you analyzed. data.pdf is an older version, I uncovered this via incremental updates and metadata found in data.pdf. Details here:<br />
<a href="http://blog.didierstevens.com/2008/11/10/shoulder-surfing-a-malicious-pdf-author/" rel="nofollow">http://blog.didierstevens.com/2008/11/10/shoulder-surfing-a-malicious-pdf-author/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew Hay &#187; Blog Archive &#187; links for 2008-11-10</title>
		<link>http://ddos.arbornetworks.com/2008/11/pdf-exploit-in-the-wild-and-how-to-decode/comment-page-1/#comment-177169</link>
		<dc:creator>Andrew Hay &#187; Blog Archive &#187; links for 2008-11-10</dc:creator>
		<pubDate>Mon, 10 Nov 2008 21:02:22 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=449#comment-177169</guid>
		<description>[...] PDF Exploit - In the wild, and how to decode &#124; Security to the Core &#124; Arbor Networks Security (tags: pdf exploit) [...]</description>
		<content:encoded><![CDATA[<p>[...] PDF Exploit &#8211; In the wild, and how to decode | Security to the Core | Arbor Networks Security (tags: pdf exploit) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Juha-Matti Laurio</title>
		<link>http://ddos.arbornetworks.com/2008/11/pdf-exploit-in-the-wild-and-how-to-decode/comment-page-1/#comment-177165</link>
		<dc:creator>Juha-Matti Laurio</dc:creator>
		<pubDate>Mon, 10 Nov 2008 20:43:35 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=449#comment-177165</guid>
		<description>Fine that the post had the update during the weekend time. Yes, SANS ISC published this id -2992 mentioned at their Diary entry.</description>
		<content:encoded><![CDATA[<p>Fine that the post had the update during the weekend time. Yes, SANS ISC published this id -2992 mentioned at their Diary entry.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: J. Warren</title>
		<link>http://ddos.arbornetworks.com/2008/11/pdf-exploit-in-the-wild-and-how-to-decode/comment-page-1/#comment-177111</link>
		<dc:creator>J. Warren</dc:creator>
		<pubDate>Mon, 10 Nov 2008 13:55:38 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=449#comment-177111</guid>
		<description>If one was thinking of replacing the Adobe Reader with Foxit, -now- would be the time...

Adobe Reader v9... 33.5MB
- http://www.adobe.com/go/getreader
-OR-
- http://www.foxitsoftware.com/downloads/
Latest version: Foxit Reader 2.3 (.exe) 2.3 Build 3309 - 2.57 MB - 10/14/08</description>
		<content:encoded><![CDATA[<p>If one was thinking of replacing the Adobe Reader with Foxit, -now- would be the time&#8230;</p>
<p>Adobe Reader v9&#8230; 33.5MB<br />
- <a href="http://www.adobe.com/go/getreader" rel="nofollow">http://www.adobe.com/go/getreader</a><br />
-OR-<br />
- <a href="http://www.foxitsoftware.com/downloads/" rel="nofollow">http://www.foxitsoftware.com/downloads/</a><br />
Latest version: Foxit Reader 2.3 (.exe) 2.3 Build 3309 &#8211; 2.57 MB &#8211; 10/14/08</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jose Nazario</title>
		<link>http://ddos.arbornetworks.com/2008/11/pdf-exploit-in-the-wild-and-how-to-decode/comment-page-1/#comment-176826</link>
		<dc:creator>Jose Nazario</dc:creator>
		<pubDate>Sat, 08 Nov 2008 18:56:43 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/?p=449#comment-176826</guid>
		<description>yeah, i misread the adobe bulletin and assumed the wrong CVE ID. someone else out there had a reference to it so i had to update the writeup. :) wanted to make sure i got it right for posterity&#039;s sake.</description>
		<content:encoded><![CDATA[<p>yeah, i misread the adobe bulletin and assumed the wrong CVE ID. someone else out there had a reference to it so i had to update the writeup. :) wanted to make sure i got it right for posterity&#8217;s sake.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

