<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: ISR-evilgrade &#8211; Inject Updates to Exploit Software</title>
	<atom:link href="http://www.darknet.org.uk/2008/08/isr-evilgrade-inject-updates-to-exploit-software/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2008/08/isr-evilgrade-inject-updates-to-exploit-software/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Sat, 21 Nov 2009 06:04:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Morgan Storey</title>
		<link>http://www.darknet.org.uk/2008/08/isr-evilgrade-inject-updates-to-exploit-software/#comment-124714</link>
		<dc:creator>Morgan Storey</dc:creator>
		<pubDate>Mon, 01 Sep 2008 10:33:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=988#comment-124714</guid>
		<description>@Navin: Well yes windows updates is insecure, but have a look at Redhat, its key was compromised, and a few packages signed with it. A lot of Linux package managers (except apt I am pretty sure) have been shown to install an older (vulnerable) version of a package over an existing newer package, so the same dns redirect would work there, as long as the repo&#039;s gpg key was trusted, but how many users would just click continue...</description>
		<content:encoded><![CDATA[<p>@Navin: Well yes windows updates is insecure, but have a look at Redhat, its key was compromised, and a few packages signed with it. A lot of Linux package managers (except apt I am pretty sure) have been shown to install an older (vulnerable) version of a package over an existing newer package, so the same dns redirect would work there, as long as the repo&#8217;s gpg key was trusted, but how many users would just click continue&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Navin</title>
		<link>http://www.darknet.org.uk/2008/08/isr-evilgrade-inject-updates-to-exploit-software/#comment-124712</link>
		<dc:creator>Navin</dc:creator>
		<pubDate>Mon, 01 Sep 2008 09:55:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=988#comment-124712</guid>
		<description>+1
c&#039;mon its like a holy grail for a dark-hatter...the ability to infect millions of people at a go!! Windows Update seriously, as Morgan pointed out, shows how insecure Windows is compared to other OSes</description>
		<content:encoded><![CDATA[<p>+1<br />
c&#8217;mon its like a holy grail for a dark-hatter&#8230;the ability to infect millions of people at a go!! Windows Update seriously, as Morgan pointed out, shows how insecure Windows is compared to other OSes</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: d347hm4n</title>
		<link>http://www.darknet.org.uk/2008/08/isr-evilgrade-inject-updates-to-exploit-software/#comment-124710</link>
		<dc:creator>d347hm4n</dc:creator>
		<pubDate>Mon, 01 Sep 2008 07:42:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=988#comment-124710</guid>
		<description>Was wondering when a tool was going to come out to use this P.O.C.</description>
		<content:encoded><![CDATA[<p>Was wondering when a tool was going to come out to use this P.O.C.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Morgan Storey</title>
		<link>http://www.darknet.org.uk/2008/08/isr-evilgrade-inject-updates-to-exploit-software/#comment-124705</link>
		<dc:creator>Morgan Storey</dc:creator>
		<pubDate>Sun, 31 Aug 2008 00:01:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=988#comment-124705</guid>
		<description>well I decdied to check a bit how windows updates works, cause I was sure it is http.
I google, no mention of any internal signing process.
Next step a quick netstat. It is plain http traffic, as I originally thought. Makes me feel all safe and warm... sarcasm doesn&#039;t present well on the internet, but yikes I am glad I have moved away from windows.</description>
		<content:encoded><![CDATA[<p>well I decdied to check a bit how windows updates works, cause I was sure it is http.<br />
I google, no mention of any internal signing process.<br />
Next step a quick netstat. It is plain http traffic, as I originally thought. Makes me feel all safe and warm&#8230; sarcasm doesn&#8217;t present well on the internet, but yikes I am glad I have moved away from windows.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lyz</title>
		<link>http://www.darknet.org.uk/2008/08/isr-evilgrade-inject-updates-to-exploit-software/#comment-124700</link>
		<dc:creator>lyz</dc:creator>
		<pubDate>Sat, 30 Aug 2008 12:09:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=988#comment-124700</guid>
		<description>Windows update crack prolly just in the making.. lol</description>
		<content:encoded><![CDATA[<p>Windows update crack prolly just in the making.. lol</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Morgan Storey</title>
		<link>http://www.darknet.org.uk/2008/08/isr-evilgrade-inject-updates-to-exploit-software/#comment-124686</link>
		<dc:creator>Morgan Storey</dc:creator>
		<pubDate>Fri, 29 Aug 2008 11:24:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=988#comment-124686</guid>
		<description>Thanks for the mention... Nah I am kidding. It is an awesome little proof of concept, I am wondering why they aren&#039;t including windows updates. I am pretty sure from what I have seen it is only http (not https), so it could be broken as well in the same manner, anyone have a link to prove me wrong?</description>
		<content:encoded><![CDATA[<p>Thanks for the mention&#8230; Nah I am kidding. It is an awesome little proof of concept, I am wondering why they aren&#8217;t including windows updates. I am pretty sure from what I have seen it is only http (not https), so it could be broken as well in the same manner, anyone have a link to prove me wrong?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
