<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments for TrustDefender Labs</title>
	<atom:link href="http://www.trustdefender.com/blog/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.trustdefender.com/blog</link>
	<description>Technical Updates from the TrustDefender Labs</description>
	<pubDate>Tue, 06 Jan 2009 01:44:16 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Firefox Malware - ChromeInject - the honeymoon is over by hypatia dot ca » 25C3 Day 2</title>
		<link>http://www.trustdefender.com/blog/2008/12/06/firefox-malware-chromeinject-the-honeymoon-is-over/comment-page-1/#comment-84</link>
		<dc:creator>hypatia dot ca » 25C3 Day 2</dc:creator>
		<pubDate>Sat, 03 Jan 2009 01:31:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.trustdefender.com/blog/?p=48#comment-84</guid>
		<description>[...] a drive-by-installer targeting users of the Greasemonkey plugin.  There&#8217;s more on it here; it wasn&#8217;t covered at all in the talk, and it no longer [...]</description>
		<content:encoded><![CDATA[<p>[...] a drive-by-installer targeting users of the Greasemonkey plugin.  There&#8217;s more on it here; it wasn&#8217;t covered at all in the talk, and it no longer [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Firefox Malware - ChromeInject - the honeymoon is over by Odette</title>
		<link>http://www.trustdefender.com/blog/2008/12/06/firefox-malware-chromeinject-the-honeymoon-is-over/comment-page-1/#comment-82</link>
		<dc:creator>Odette</dc:creator>
		<pubDate>Thu, 25 Dec 2008 03:46:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.trustdefender.com/blog/?p=48#comment-82</guid>
		<description>Just stopped by, nice blog!</description>
		<content:encoded><![CDATA[<p>Just stopped by, nice blog!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Firefox Malware - ChromeInject - the honeymoon is over by Thierry Zoller</title>
		<link>http://www.trustdefender.com/blog/2008/12/06/firefox-malware-chromeinject-the-honeymoon-is-over/comment-page-1/#comment-61</link>
		<dc:creator>Thierry Zoller</dc:creator>
		<pubDate>Wed, 10 Dec 2008 19:01:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.trustdefender.com/blog/?p=48#comment-61</guid>
		<description>It is known for years that you can silently install Firefox extensions:
POC from 2006
http://secdev.zoller.lu/firespy.htm


They also don't plan to do much abou it :
https://bugzilla.mozilla.org/show_bug.cgi?id=442153</description>
		<content:encoded><![CDATA[<p>It is known for years that you can silently install Firefox extensions:<br />
POC from 2006<br />
<a href="http://secdev.zoller.lu/firespy.htm" rel="nofollow">http://secdev.zoller.lu/firespy.htm</a></p>
<p>They also don&#8217;t plan to do much abou it :<br />
<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=442153" rel="nofollow">https://bugzilla.mozilla.org/show_bug.cgi?id=442153</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Firefox Malware - ChromeInject - the honeymoon is over by Ant &#187; Blog Archive &#187; Firefox malware: Trojan.PWS.ChromeInject.A/B</title>
		<link>http://www.trustdefender.com/blog/2008/12/06/firefox-malware-chromeinject-the-honeymoon-is-over/comment-page-1/#comment-59</link>
		<dc:creator>Ant &#187; Blog Archive &#187; Firefox malware: Trojan.PWS.ChromeInject.A/B</dc:creator>
		<pubDate>Wed, 10 Dec 2008 06:35:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.trustdefender.com/blog/?p=48#comment-59</guid>
		<description>[...] TrustDefender Labs 的實際樣本測試報告中，這個程式雖然是以 plugins [...]</description>
		<content:encoded><![CDATA[<p>[...] TrustDefender Labs 的實際樣本測試報告中，這個程式雖然是以 plugins [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Firefox Malware - ChromeInject - the honeymoon is over by meandering wildly &#187; Firefox Malware?</title>
		<link>http://www.trustdefender.com/blog/2008/12/06/firefox-malware-chromeinject-the-honeymoon-is-over/comment-page-1/#comment-57</link>
		<dc:creator>meandering wildly &#187; Firefox Malware?</dc:creator>
		<pubDate>Mon, 08 Dec 2008 17:28:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.trustdefender.com/blog/?p=48#comment-57</guid>
		<description>[...] credit to TrustDefender Labs&#8217; blog post on the [...]</description>
		<content:encoded><![CDATA[<p>[...] credit to TrustDefender Labs&#8217; blog post on the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Recent mutation of Rustock.B - or is it zlob? (rootkit) by Noelani</title>
		<link>http://www.trustdefender.com/blog/2008/09/25/recent-mutation-of-rustockb-or-is-it-zlob-rootkit/comment-page-1/#comment-27</link>
		<dc:creator>Noelani</dc:creator>
		<pubDate>Mon, 10 Nov 2008 07:06:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.trustdefender.com/blog/?p=21#comment-27</guid>
		<description>Good post.</description>
		<content:encoded><![CDATA[<p>Good post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on new mutation of yaludle/silentbanker rootkit in the wild by Daniel Craig</title>
		<link>http://www.trustdefender.com/blog/2008/10/02/new-mutation-of-yaludlesilentbanker-rootkit-in-the-wild/comment-page-1/#comment-26</link>
		<dc:creator>Daniel Craig</dc:creator>
		<pubDate>Fri, 31 Oct 2008 04:59:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.trustdefender.com/blog/?p=31#comment-26</guid>
		<description>Hello, I was looking around for a while searching for rootkit and I happened upon this site and your post regarding new mutation of yaludle/silentbanker rootkit in the wild, I will definitely this to my rootkit bookmarks!</description>
		<content:encoded><![CDATA[<p>Hello, I was looking around for a while searching for rootkit and I happened upon this site and your post regarding new mutation of yaludle/silentbanker rootkit in the wild, I will definitely this to my rootkit bookmarks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on new mutation of yaludle/silentbanker rootkit in the wild by admin</title>
		<link>http://www.trustdefender.com/blog/2008/10/02/new-mutation-of-yaludlesilentbanker-rootkit-in-the-wild/comment-page-1/#comment-4</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Thu, 02 Oct 2008 17:56:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.trustdefender.com/blog/?p=31#comment-4</guid>
		<description>@anonymous: well, the problem is that the trojan controls the session and the content you are seeing is NOT from the bank. So in this sense a mutual https authentication does not help much as the form where the confidential information is lost, is not the real deal.</description>
		<content:encoded><![CDATA[<p>@anonymous: well, the problem is that the trojan controls the session and the content you are seeing is NOT from the bank. So in this sense a mutual https authentication does not help much as the form where the confidential information is lost, is not the real deal.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on new mutation of yaludle/silentbanker rootkit in the wild by anonymous</title>
		<link>http://www.trustdefender.com/blog/2008/10/02/new-mutation-of-yaludlesilentbanker-rootkit-in-the-wild/comment-page-1/#comment-3</link>
		<dc:creator>anonymous</dc:creator>
		<pubDate>Thu, 02 Oct 2008 15:01:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.trustdefender.com/blog/?p=31#comment-3</guid>
		<description>so, would mutual https authentication thwart this attack?</description>
		<content:encoded><![CDATA[<p>so, would mutual https authentication thwart this attack?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
