<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>blog.anta.net &#187; malware</title>
	<atom:link href="http://blog.anta.net/tag/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.anta.net</link>
	<description>Internetworking, security, safety and more</description>
	<lastBuildDate>Mon, 06 Feb 2012 11:24:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Mandiant report on APT online espionage available</title>
		<link>http://blog.anta.net/2010/02/07/mandiant-report-on-apt-online-espionage-available/</link>
		<comments>http://blog.anta.net/2010/02/07/mandiant-report-on-apt-online-espionage-available/#comments</comments>
		<pubDate>Sun, 07 Feb 2010 16:58:47 +0000</pubDate>
		<dc:creator>Thor Kottelin</dc:creator>
				<category><![CDATA[Internetworking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Advanced Persistent Threat]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[intrusion]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Mandiant]]></category>
		<category><![CDATA[media releases]]></category>
		<category><![CDATA[reports]]></category>
		<category><![CDATA[United States]]></category>

		<guid isPermaLink="false">http://blog.anta.net/?p=1075</guid>
		<description><![CDATA[Information security company Mandiant has published a report on the Advanced Persistent Threat (APT), a sophisticated and organized means to steal information from compromised computers in another country. Although the APT is a generic concept that may refer to activity from any country, it is primarily linked to several years of systematic Chinese attacks on [...]<script type="text/javascript">SHARETHIS.addEntry({ title: "Mandiant report on APT online espionage available", url: "http://blog.anta.net/2010/02/07/mandiant-report-on-apt-online-espionage-available/" });</script>]]></description>
		<wfw:commentRss>http://blog.anta.net/2010/02/07/mandiant-report-on-apt-online-espionage-available/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Why just say no to IM at work</title>
		<link>http://blog.anta.net/2009/10/28/why-just-say-no-to-im-at-work/</link>
		<comments>http://blog.anta.net/2009/10/28/why-just-say-no-to-im-at-work/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 22:41:45 +0000</pubDate>
		<dc:creator>Thor Kottelin</dc:creator>
				<category><![CDATA[Internetworking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[firewalls]]></category>
		<category><![CDATA[instant messaging]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[UDP]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[wire tapping]]></category>

		<guid isPermaLink="false">http://blog.anta.net/?p=825</guid>
		<description><![CDATA[People sometimes ask me for my business IM address. Well, I do not have one, because I do not use IM for business transactions. However, if you do, please make sure that you are aware of the risks involved. Here are a couple of the topmost reasons why IM, IMO, does not mix well with [...]<script type="text/javascript">SHARETHIS.addEntry({ title: "Why just say no to IM at work", url: "http://blog.anta.net/2009/10/28/why-just-say-no-to-im-at-work/" });</script>]]></description>
		<wfw:commentRss>http://blog.anta.net/2009/10/28/why-just-say-no-to-im-at-work/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>“Autorun” on Windows&#174; may be active even if disabled</title>
		<link>http://blog.anta.net/2009/01/21/%e2%80%9cautorun%e2%80%9d-on-windows-may-be-active-even-if-disabled/</link>
		<comments>http://blog.anta.net/2009/01/21/%e2%80%9cautorun%e2%80%9d-on-windows-may-be-active-even-if-disabled/#comments</comments>
		<pubDate>Wed, 21 Jan 2009 10:03:29 +0000</pubDate>
		<dc:creator>Thor Kottelin</dc:creator>
				<category><![CDATA[Internetworking/Windows]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Autorun]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[US-CERT]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://blog.anta.net/?p=498</guid>
		<description><![CDATA[US-CERT has issued an alert about a flaw in Microsoft&#8217;s (NASDAQ:&#160;MSFT) guidelines on disabling the auto-run functionality, the feature from hell that causes certain optional code on removable media&#8202;&#8212;&#8202;or on network drives&#8202;&#8212;&#8202;to be automatically executed as soon as that drive is mounted as well as under certain other circumstances. Of course, such behaviour is a [...]<script type="text/javascript">SHARETHIS.addEntry({ title: "“Autorun” on Windows&#174; may be active even if disabled", url: "http://blog.anta.net/2009/01/21/%e2%80%9cautorun%e2%80%9d-on-windows-may-be-active-even-if-disabled/" });</script>]]></description>
		<wfw:commentRss>http://blog.anta.net/2009/01/21/%e2%80%9cautorun%e2%80%9d-on-windows-may-be-active-even-if-disabled/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Widget inflicts malware&#8212;Facebook ignores advisory?</title>
		<link>http://blog.anta.net/2008/01/05/widget-inflicts-malware-facebook-ignores-advisory/</link>
		<comments>http://blog.anta.net/2008/01/05/widget-inflicts-malware-facebook-ignores-advisory/#comments</comments>
		<pubDate>Sat, 05 Jan 2008 08:00:20 +0000</pubDate>
		<dc:creator>Thor Kottelin</dc:creator>
				<category><![CDATA[Internetworking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[widgets]]></category>

		<guid isPermaLink="false">http://blog.anta.net/2008/01/05/widget-inflicts-malware-facebook-ignores-advisory/</guid>
		<description><![CDATA[Many years ago, I described how the social engineering tactic of alleging an &#8220;InstaKiss&#8221; from a secret admirer was used in order to steal AOL passwords. If online services were all the rage at that time, now is the era of social networking sites. Relative newcomer Facebook, which according to its own factsheet implements &#8220;a [...]<script type="text/javascript">SHARETHIS.addEntry({ title: "Widget inflicts malware&#8212;Facebook ignores advisory?", url: "http://blog.anta.net/2008/01/05/widget-inflicts-malware-facebook-ignores-advisory/" });</script>]]></description>
		<wfw:commentRss>http://blog.anta.net/2008/01/05/widget-inflicts-malware-facebook-ignores-advisory/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tainted Squirrelmail versions 1.4.11 and 1.4.12</title>
		<link>http://blog.anta.net/2007/12/15/tainted-squirrelmail-versions-1411-and-1412/</link>
		<comments>http://blog.anta.net/2007/12/15/tainted-squirrelmail-versions-1411-and-1412/#comments</comments>
		<pubDate>Sat, 15 Dec 2007 21:37:22 +0000</pubDate>
		<dc:creator>Thor Kottelin</dc:creator>
				<category><![CDATA[Internetworking/Mail and news]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Squirrelmail]]></category>
		<category><![CDATA[webmail]]></category>

		<guid isPermaLink="false">http://blog.anta.net/2007/12/15/tainted-squirrelmail-versions-1411-and-1412/</guid>
		<description><![CDATA[A maintainer account has been compromised, and malicious code inserted into versions 1.4.11 and 1.4.12 of the Squirrelmail webmail software. Contrary to Squirrelmail’s initial statement that the changes should have little to no impact, current information indicates that a remote user could execute code on a victim server. Webmail operators running a vulnerable Squirrelmail version [...]<script type="text/javascript">SHARETHIS.addEntry({ title: "Tainted Squirrelmail versions 1.4.11 and 1.4.12", url: "http://blog.anta.net/2007/12/15/tainted-squirrelmail-versions-1411-and-1412/" });</script>]]></description>
		<wfw:commentRss>http://blog.anta.net/2007/12/15/tainted-squirrelmail-versions-1411-and-1412/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

