<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: winzip]]></title>
    <link>http://securityratty.com/tag/winzip</link>
    <description></description>
    <pubDate>Tue, 25 Mar 2008 10:21:04 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Gdiplus.dll Vulnerability In WinZip Fixed In Version 11.2 SR-1]]></title>
      <link>http://securityratty.com/article/477003b4659b0c74efab977459241ed4</link>
      <guid>http://securityratty.com/article/477003b4659b0c74efab977459241ed4</guid>
      <description><![CDATA[WinZip Computing released WinZip 11.2 SR-1 on September 25 with a critical update to all installations of WinZip 11. The release addresses a security vulnerability that exists in one of the modules...]]></description>
      <content:encoded><![CDATA[WinZip Computing released WinZip 11.2 SR-1 on September 25 with a critical update to all installations of WinZip 11. The release addresses a security vulnerability that exists in one of the modules shipped with WinZip 11. This component is not a WinZip module but rather a Microsoft module that WinZip Computing shipped for the convenience [...]]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 19:09:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/winzip">winzip</category>
      <category domain="http://securityratty.com/tag/winzip module">winzip module</category>
      <category domain="http://securityratty.com/tag/security vulnerability">security vulnerability</category>
      <category domain="http://securityratty.com/tag/release addresses">release addresses</category>
      <category domain="http://securityratty.com/tag/microsoft module">microsoft module</category>
      <category domain="http://securityratty.com/tag/sr-1">sr-1</category>
      <category domain="http://securityratty.com/tag/critical">critical</category>
      <category domain="http://securityratty.com/tag/modules">modules</category>
      <category domain="http://securityratty.com/tag/component">component</category>
      <source url="http://cyberinsecure.com/gdiplus-vulnerability-in-winzip-fixed-in-version-11-2-sr-1/">Gdiplus.dll Vulnerability In WinZip Fixed In Version 11.2 SR-1</source>
    </item>
    <item>
      <title><![CDATA[DIY Exploit Embedding Tool - A Proprietary Release]]></title>
      <link>http://securityratty.com/article/bd88a2d37e624ae52acda097cdc8986b</link>
      <guid>http://securityratty.com/article/bd88a2d37e624ae52acda097cdc8986b</guid>
      <description><![CDATA[Rember the reprospective on DIY exploit embedding tools , those cybercrime 1.0 point'n'click exploits serving generators? Despite that the cybercrime 2.0 has to do with malicious economies of scale,...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SBU_b9DpjII/AAAAAAAABpA/p1Q7xLOGrXE/s1600-h/DIY_exploit_generator.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SBU_b9DpjII/AAAAAAAABpA/p1Q7xLOGrXE/s200/DIY_exploit_generator.jpg" alt="" id="BLOGGER_PHOTO_ID_5194127494720621698" border="0" /></a>Rember the <a href="http://ddanchev.blogspot.com/2007/09/diy-exploits-embedding-tools.html">reprospective on DIY exploit embedding tools</a>, those cybercrime 1.0 point'n'click exploits serving generators? Despite that the cybercrime 2.0 has to do with malicious economies of scale, that is the use of web malware exploitation kits compared to their 1.0 alternative, the DIY tools, such tools continue to be developed, like this proprietary one including sixteen exploits for the buyer to take advantage of, if she's willing to invest £100 (GBP) of course. Exploits listed :<br /><br />- D-Link MPEG4 VAPGDecoder ActiveX<br />- Macrovision Installshield ActiveX<br />- MySpace Uploader ActiveX<br />- Symantec BackupExec ActiveX<br />- Yahoo! JukeBox ActiveX<br />- Microsoft Works ActiveX (0day)<br />- Microsoft Internet Explorer MS06-014 (MDAC)<br />- Microsoft Internet Explorer MS07-009<br />- Facebook Uploader ActiveX<br />- Microsoft DirectSpeechSynthesis ActiveX<br />- Realplayer ActiveX<br />- WinZip FileView ActiveX<br />- Yahoo Messenger Webcam ActiveX<br />- Microsoft Internet Explorer MS06-013<br />- Microsoft Internet Explorer MS07-004<br />- Microsoft Internet Explorer MS07-055<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SBVBKNDpjJI/AAAAAAAABpI/lr8FpJFWyyM/s1600-h/PSI_client_side.png"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/SBVBKNDpjJI/AAAAAAAABpI/lr8FpJFWyyM/s200/PSI_client_side.png" alt="" id="BLOGGER_PHOTO_ID_5194129388801199250" border="0" /></a>With the now commodity web malware exploitation kits and their modularity streamlining "innovation" in the field, such DIY tools are only a fad compared to malicious parties' interest in exploiting as many people as possible, without putting extra efforts in the process (malicious economies of scale). And with the <a href="http://ddanchev.blogspot.com/2007/09/popular-web-malware-exploitation.html">overall proliferation of client-side vulnerabilities</a>, and the surprisingly <a href="http://ddanchev.blogspot.com/2007/07/malware-embedded-sites-increasing.html">high success rate of exploiting outdated and already patched vulnerabilities</a> on a large scale (Stormy Wormy), <a href="http://psi.secunia.com">ensuring your client-side applications are vulnerable to zero days only</a> is highly recommended.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4s2JZG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4s2JZG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RV2FqG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RV2FqG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=eDdm2g"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=eDdm2g" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=h67v7g"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=h67v7g" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=W2FQmG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=W2FQmG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fIL48G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fIL48G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9rr7eg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9rr7eg" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/279279990" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 28 Apr 2008 00:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/activex">activex</category>
      <category domain="http://securityratty.com/tag/myspace uploader activex">myspace uploader activex</category>
      <category domain="http://securityratty.com/tag/jukebox activex">jukebox activex</category>
      <category domain="http://securityratty.com/tag/winzip fileview activex">winzip fileview activex</category>
      <category domain="http://securityratty.com/tag/symantec backupexec activex">symantec backupexec activex</category>
      <category domain="http://securityratty.com/tag/realplayer activex">realplayer activex</category>
      <category domain="http://securityratty.com/tag/facebook uploader activex">facebook uploader activex</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/tools continue">tools continue</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/279279990/diy-exploit-embedding-tool-proprietary.html">DIY Exploit Embedding Tool - A Proprietary Release</source>
    </item>
    <item>
      <title><![CDATA[Martin Hellman on the Invention of Public-Key Cryptography]]></title>
      <link>http://securityratty.com/article/033cac1111cbadbec89ce47cc7517e9f</link>
      <guid>http://securityratty.com/article/033cac1111cbadbec89ce47cc7517e9f</guid>
      <description><![CDATA[At the DISI conference last December, Martin Hellman gave a lecure on the invention of public-key cryptography. A video is online (it's hard to find, search for his name), along with PowerPoint...]]></description>
      <content:encoded><![CDATA[<p>At the DISI conference last December, Martin Hellman gave a lecure on the invention of public-key cryptography.  A <a href="http://www.criptored.upm.es/paginas/docencia.htm">video is online</a> (it's hard to find, search for his name), along with PowerPoint slides.</p>

<p>(Unfortunately, the video isn't set up for streaming; in order to view the it, you'll have to download the ten files, then use a fairly recent version of WinZip to concatenate the files.)</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=WoMfBSF"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=WoMfBSF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=JY6CT1F"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=JY6CT1F" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 25 Mar 2008 10:21:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/martin hellman">martin hellman</category>
      <category domain="http://securityratty.com/tag/public-key cryptography">public-key cryptography</category>
      <category domain="http://securityratty.com/tag/fairly recent version">fairly recent version</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/files">files</category>
      <category domain="http://securityratty.com/tag/powerpoint slides">powerpoint slides</category>
      <category domain="http://securityratty.com/tag/invention">invention</category>
      <category domain="http://securityratty.com/tag/disi conference">disi conference</category>
      <category domain="http://securityratty.com/tag/winzip">winzip</category>
      <source url="http://www.schneier.com/blog/archives/2008/03/martin_hellman.html">Martin Hellman on the Invention of Public-Key Cryptography</source>
    </item>
  </channel>
</rss>
