<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Tracking Coreflood from Shellcode</title>
	<atom:link href="http://blog.threatfire.com/2008/06/tracking-coreflood-from-shellcode.html/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.threatfire.com/2008/06/tracking-coreflood-from-shellcode.html</link>
	<description>ThreatFire™ AntiVirus protects when others can&#039;t</description>
	<lastBuildDate>Sun, 14 Mar 2010 19:21:30 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: ThreatFire Blogger</title>
		<link>http://blog.threatfire.com/2008/06/tracking-coreflood-from-shellcode.html/comment-page-1#comment-38</link>
		<dc:creator>ThreatFire Blogger</dc:creator>
		<pubDate>Tue, 01 Jul 2008 16:34:00 +0000</pubDate>
		<guid isPermaLink="false">http://newblog.threatfire.com/2008/06/tracking-coreflood-from-shellcode/#comment-38</guid>
		<description>Heya Willy:&lt;br/&gt;&lt;br/&gt;Robert Vamosi commented on Joe Stewart&#039;s post here:&lt;br/&gt;http://news.cnet.com/8301-10789_3-9981248-57.html&lt;br/&gt;&lt;br/&gt;And Joe Stewart posted some info on Coreflood&#039;s use of Sysinternals&#039; PsExec tool, to spread within a company on systems using domain admin accounts. Also, your question about infostealing is answered here as well:&lt;br/&gt;http://www.secureworks.com/research/threats/coreflood/?threat=coreflood&lt;br/&gt;&lt;br/&gt;And Willy, Charlie got the golden ticket, but family will make you happy. Sometimes at least.</description>
		<content:encoded><![CDATA[<p>Heya Willy:</p>
<p>Robert Vamosi commented on Joe Stewart&#8217;s post here:<br /><a href="http://news.cnet.com/8301-10789_3-9981248-57.html" rel="nofollow">http://news.cnet.com/8301-10789_3-9981248-57.html</a></p>
<p>And Joe Stewart posted some info on Coreflood&#8217;s use of Sysinternals&#8217; PsExec tool, to spread within a company on systems using domain admin accounts. Also, your question about infostealing is answered here as well:<br /><a href="http://www.secureworks.com/research/threats/coreflood/?threat=coreflood" rel="nofollow">http://www.secureworks.com/research/threats/coreflood/?threat=coreflood</a></p>
<p>And Willy, Charlie got the golden ticket, but family will make you happy. Sometimes at least.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Willy Wonka</title>
		<link>http://blog.threatfire.com/2008/06/tracking-coreflood-from-shellcode.html/comment-page-1#comment-35</link>
		<dc:creator>Willy Wonka</dc:creator>
		<pubDate>Sun, 29 Jun 2008 14:32:00 +0000</pubDate>
		<guid isPermaLink="false">http://newblog.threatfire.com/2008/06/tracking-coreflood-from-shellcode/#comment-35</guid>
		<description>Can you please post more detail about the information it gathers from the host and then posts?&lt;br/&gt;&lt;br/&gt;Thanks</description>
		<content:encoded><![CDATA[<p>Can you please post more detail about the information it gathers from the host and then posts?</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Willy Wonka</title>
		<link>http://blog.threatfire.com/2008/06/tracking-coreflood-from-shellcode.html/comment-page-1#comment-33</link>
		<dc:creator>Willy Wonka</dc:creator>
		<pubDate>Fri, 27 Jun 2008 04:03:00 +0000</pubDate>
		<guid isPermaLink="false">http://newblog.threatfire.com/2008/06/tracking-coreflood-from-shellcode/#comment-33</guid>
		<description>Any chance that you guys have been able to figure out how it would spread inside a company? Would it use net view or query against network neighboorhood or something like that to figure out where to propagate? &lt;br/&gt;&lt;br/&gt;Thanks</description>
		<content:encoded><![CDATA[<p>Any chance that you guys have been able to figure out how it would spread inside a company? Would it use net view or query against network neighboorhood or something like that to figure out where to propagate? </p>
<p>Thanks</p>
]]></content:encoded>
	</item>
</channel>
</rss>
