<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; 0-day</title>
	<atom:link href="http://www.darknet.org.uk/tag/0-day/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Adobe Promises Patch For Flash 0-day Being Used In Targeted Attacks</title>
		<link>http://www.darknet.org.uk/2011/03/adobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks/</link>
		<comments>http://www.darknet.org.uk/2011/03/adobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks/#comments</comments>
		<pubDate>Tue, 15 Mar 2011 10:30:57 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[General News]]></category>
		<category><![CDATA[0-day]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[adobe flash]]></category>
		<category><![CDATA[adobe flash security]]></category>
		<category><![CDATA[adobe security]]></category>
		<category><![CDATA[flash 0-day]]></category>
		<category><![CDATA[flash exploit]]></category>
		<category><![CDATA[flash security]]></category>
		<category><![CDATA[flash vulnerability]]></category>
		<category><![CDATA[flash zero day]]></category>
		<category><![CDATA[hacking-flash]]></category>
		<category><![CDATA[out of band patch]]></category>
		<category><![CDATA[zero-day]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3066</guid>
		<description><![CDATA[With all the new vulnerabilities with working exploits pouring out of Pwn2Own, I can&#8217;t say I expected to see another 0-day in Adobe Flash outside of the contest. It wasn&#8217;t that long ago (back in October 2010) when there was another Critical 0-day Vulnerability In Adobe Flash Player, Reader &#038; Acrobat and Adobe were scrambling [...]]]></description>
			<content:encoded><![CDATA[<p>With all the new vulnerabilities with working exploits pouring out of <a href="http://www.darknet.org.uk/tag/pwn2own/">Pwn2Own</a>, I can&#8217;t say I expected to see another 0-day in <a href="http://www.darknet.org.uk/tag/adobe-flash/">Adobe Flash</a> outside of the contest.</p>
<p>It wasn&#8217;t that long ago (back in October 2010) when there was another <a href="http://www.darknet.org.uk/2010/10/critical-0-day-vulnerability-in-adobe-flash-player-reader-acrobat/">Critical 0-day Vulnerability In Adobe Flash Player, Reader &#038; Acrobat</a> and <a href="http://www.darknet.org.uk/tag/adobe/">Adobe</a> were scrambling to fix it.</p>
<p>They are promising an out of band patch for this vulnerability as it&#8217;s marked as critical and has apparently been seen in the wild, but only in a few targeted attacks according to this blog post by Adobe:</p>
<p><a href="http://blogs.adobe.com/asset/2011/03/background-on-apsa11-01-patch-schedule.html">Background on APSA11-01 Patch Schedule</a></p>
<blockquote><p>Adobe Systems plans to release emergency patches for its Flash and Reader applications after learning a critical vulnerability is being exploited to install malware on vulnerable machines.</p>
<p>The out-of-cycle patches for Adobe Flash Player 10 and Acrobat and Reader versions 9, 10, and X will arrive during the week March 21, the company said on Monday. The updates will cover all versions of those programs except for Reader X for Windows, which ships with a security sandbox that blocks the exploits Adobe has observed so far.</p>
<p>The announcement comes after members of Adobe&#8217;s security team received reports of targeted attacks aimed “at a very small number of organizations and limited in scope” that “install persistent malware on the victim&#8217;s machine,” the company said in an advisory. The exploits wield a booby-trapped Flash file hidden inside a Microsoft Excel file attached to an email.</p>
<p>The attacks exploit an unspecified flaw in Flash Player for the Windows, Mac, Linux, Solaris and Android operating systems. Adobe security members are unaware of other types of attacks, such as those that plant the malicious Flash file in documents using the the PDF, or portable document format, specification.</p></blockquote>
<p>It&#8217;s a pretty tricky attack with multiple layers, it seems like the Flash exploit itself is embedded in an Excel file attached to e-mails. It looks like corporate users of Reader X will be out of luck as there is no patch for that version. But then <a href="http://www.darknet.org.uk/tag/adobe/">Adobe</a> states as Reader X comes with a sandbox the exploit won&#8217;t actually function anyway.</p>
<p>The patch is slated to come out next week sometime, there are no specifics as of yet &#8211; I guess it depends how long it takes them to fix the problem reliably. They are looking to rush the patch out though rather than waiting for the next cycle.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>“However, attackers have leveraged these type [sic] of Flash Player vulnerabilities in the past via .pdf files to attack the embedded authplay.dll component shipping with Adobe Reader and Acrobat v9,” Brad Arkin, Adobe&#8217;s senior director of product security and privacy, wrote. “Out of a preponderance of caution we took the decision to ship out-of-cycle updates for Adobe Reader and Acrobat v9, and Acrobat X to mitigate the risk of attackers shifting the attack from an .xls container to a .pdf container.”</p>
<p>The unscheduled patch won&#8217;t cover Reader X for Windows, because that recently released version of the program contains a Sandbox that isolates remotely supplied payloads from the OS&#8217;s core functions. As a result, the exploits Adobe has seen to date aren&#8217;t able to successfully execute on machines that run it. Many Reader users, particularly those in corporate settings, still run versions 10 or 9 of Reader, meaning they will remain vulnerable until the emergency patch is installed.</p>
<p>Excluding Reader X for Windows from the out-of-cycle release will allow Adobe engineers to publish it more quickly than it otherwise could. The fix for that version will be released on June 14, during Adobe&#8217;s next scheduled quarterly update.</p></blockquote>
<p>The Security Bulletin from Adobe is here:</p>
<p><a href="http://www.adobe.com/support/security/advisories/apsa11-01.html">Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat</a></p>
<p>It has been assigned the CVE Number: CVE-2011-0609</p>
<p>Source: <a href="http://www.theregister.co.uk/2011/03/14/adobe_flash_reader_emergency_patch/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Adobe+Promises+Patch+For+Flash+0-day+Being+Used+In+Targeted+Attacks+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3066+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/03/adobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks/&amp;t=Adobe+Promises+Patch+For+Flash+0-day+Being+Used+In+Targeted+Attacks" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/03/adobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/03/adobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks/&amp;title=Adobe+Promises+Patch+For+Flash+0-day+Being+Used+In+Targeted+Attacks" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/03/adobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks/&amp;title=Adobe+Promises+Patch+For+Flash+0-day+Being+Used+In+Targeted+Attacks" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/03/adobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks/&amp;title=Adobe+Promises+Patch+For+Flash+0-day+Being+Used+In+Targeted+Attacks" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/03/adobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks/&amp;title=Adobe+Promises+Patch+For+Flash+0-day+Being+Used+In+Targeted+Attacks" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F03%2Fadobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/03/adobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Critical 0-day Vulnerability In Adobe Flash Player, Reader &amp; Acrobat</title>
		<link>http://www.darknet.org.uk/2010/10/critical-0-day-vulnerability-in-adobe-flash-player-reader-acrobat/</link>
		<comments>http://www.darknet.org.uk/2010/10/critical-0-day-vulnerability-in-adobe-flash-player-reader-acrobat/#comments</comments>
		<pubDate>Fri, 29 Oct 2010 10:35:27 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[0-day]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[adobe flash 0day]]></category>
		<category><![CDATA[adobe flash exploit]]></category>
		<category><![CDATA[adobe flash security]]></category>
		<category><![CDATA[adobe reader]]></category>
		<category><![CDATA[adobe reader 0day]]></category>
		<category><![CDATA[adobe reader exploit]]></category>
		<category><![CDATA[adobe reader vulnerability]]></category>
		<category><![CDATA[adobe security]]></category>
		<category><![CDATA[authplay]]></category>
		<category><![CDATA[authplay exploit]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[zeroday]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2984</guid>
		<description><![CDATA[Well this seems to be a frequently recurring theme, yes there is yet another critical 0day vulnerability in Adobe products &#8211; pretty much across the board this time. It was that long ago that a critical flaw in Flash put Android phones at risk. The core vulnerability exists in Flash but it&#8217;s being actively exploited [...]]]></description>
			<content:encoded><![CDATA[<p>Well this seems to be a frequently recurring theme, yes there is yet another critical 0day vulnerability in <a href="http://www.darknet.org.uk/tag/adobe/">Adobe</a> products &#8211; pretty much across the board this time.</p>
<p>It was that long ago that a <a href="http://www.darknet.org.uk/2010/09/critical-zero-day-abobe-flash-flaw-puts-android-phones-at-risk/">critical flaw in Flash put Android phones at risk</a>. The core vulnerability exists in Flash but it&#8217;s being actively exploited in Adobe Reader via the usual pdf route.</p>
<p>The vulnerability exists across all OS versions (including <a href="http://www.darknet.org.uk/tag/android/">Android</a>), but as usual the active exploitation seems to be taking place on the Windows platform.</p>
<blockquote><p>Adobe has confirmed reports that yet another unpatched vulnerability in the latest versions of its ubiquitous software is being actively exploited to infect end users with data-stealing malware.</p>
<p>The vulnerability exists in Adobe&#8217;s Reader document viewer and Flash Media Player for Windows, OS X and Unix operating systems, Adobe warned on Thursday. According to independent researchers, it is being exploited in the wild against Reader for Windows to install a nasty trojan known as Wisp, which according to Microsoft, steals sensitive user data and installs a backdoor on compromised systems.</p>
<p>The vulnerability itself resides in Adobe&#8217;s Flash Player, which is available as stand alone software and is also embedded into Reader. According to researcher Mila Parkour of the Contagio Malware Dump blog, poisoned PDF documents are circulating that drop two malicious binaries onto Windows machines that open the document files.</p>
<p>A screenshot identified the two files as nsunday.exe and nsunday.dll. A Virus Total scan showed just 15 of 42 antivirus programs were detecting the malicious EXE. She didn&#8217;t say whether the attacks succeed against more recent versions of the OS, which Microsoft has designed to withstand many of the most common types of exploits.</p></blockquote>
<p>This vector comes to pass as <a href="http://www.darknet.org.uk/tag/flash/">Flash</a> player is also embedded into Adobe Reader, so by using a malicious PDF file with the AuthPlay exploit &#8211; they can trigger the Flash player flaw and drop malware into the OS.</p>
<p>There is information on how to disable the AuthPlay functionality at the bottom of the Adobe advisory:</p>
<p><a href="http://www.adobe.com/support/security/advisories/apsa10-05.html">Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat</a></p>
<p>Basically you need to go to the <a href="http://www.darknet.org.uk/tag/adobe-reader/">Adobe Reader</a> directory and delete the <em>AuthPlayLib.bundle</em> (Windows/Mac OSX) or libauthplay.so.0.0.0. (linux) file.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Adobe said it planned to patch the vulnerability in Flash during the week of November 9 and in Reader during the week of November 15. The schedule is puzzling, since Reader has been confirmed to be under attack and Flash has not been confirmed.</p>
<p>In the meantime, users can protect themselves by using an alternate document viewer, such as Foxit. For those who must use Reader, Adobe said they can mitigate attacks by removing functionality known as AuthPlay, by following the instructions near the bottom of this advisory. Adobe provided no temporary measures Flash users can follow.</p>
<p>It&#8217;s been a bad couple of years for Adobe&#8217;s security team, which has gotten repeatedly hammered by critical vulnerabilities that are exploited by criminals to install malware on users&#8217; machines. Three weeks ago, the company issued a fix for a security flaw in Reader that was also under attack by a highly sophisticated exploit. Last month, Adobe fixed a critical vulnerability in Flash that was also being used to compromise end user computers.</p>
<p>Adobe is also in the process of developing a patch for a code-execution bug in its Shockwave Player. By many researchers&#8217; reckoning, Reader is among the world&#8217;s most exploited applications, in close competition with Oracle&#8217;s Java framework and, of course, various Microsoft programs.</p></blockquote>
<p>From recent attacks it seems Adobe Reader and Flash are amongst the most exploited applications, especially when it comes to serious vulnerabilities that allow code-execution.</p>
<p>The new generation <a href="http://www.darknet.org.uk/2010/10/adobe-pdf-reader-rewrite-to-include-sandbox-feature/">Adobe Reader with Sandbox Feature</a> can&#8217;t come soon enough.</p>
<p>There&#8217;s also more here:</p>
<p><a href="http://www.networkworld.com/news/2010/102810-hackers-exploit-newest-flash-zero-day.html?source=nww_rss">Hackers exploit newest Flash zero-day bug</a> </p>
<p>Source: <a href="http://www.theregister.co.uk/2010/10/28/adobe_reader_critical_vuln/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Critical+0-day+Vulnerability+In+Adobe+Flash+Player%2C+Reader+%26+Acrobat+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2984+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/10/critical-0-day-vulnerability-in-adobe-flash-player-reader-acrobat/&amp;t=Critical+0-day+Vulnerability+In+Adobe+Flash+Player%2C+Reader+%26+Acrobat" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/10/critical-0-day-vulnerability-in-adobe-flash-player-reader-acrobat/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/10/critical-0-day-vulnerability-in-adobe-flash-player-reader-acrobat/&amp;title=Critical+0-day+Vulnerability+In+Adobe+Flash+Player%2C+Reader+%26+Acrobat" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/10/critical-0-day-vulnerability-in-adobe-flash-player-reader-acrobat/&amp;title=Critical+0-day+Vulnerability+In+Adobe+Flash+Player%2C+Reader+%26+Acrobat" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/10/critical-0-day-vulnerability-in-adobe-flash-player-reader-acrobat/&amp;title=Critical+0-day+Vulnerability+In+Adobe+Flash+Player%2C+Reader+%26+Acrobat" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/10/critical-0-day-vulnerability-in-adobe-flash-player-reader-acrobat/&amp;title=Critical+0-day+Vulnerability+In+Adobe+Flash+Player%2C+Reader+%26+Acrobat" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F10%2Fcritical-0-day-vulnerability-in-adobe-flash-player-reader-acrobat%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/10/critical-0-day-vulnerability-in-adobe-flash-player-reader-acrobat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hackers Exploit Unpatched Firefox 0day Using Nobel Peace Prize Website</title>
		<link>http://www.darknet.org.uk/2010/10/hackers-exploit-unpatched-firefox-0day-using-nobel-peace-prize-website/</link>
		<comments>http://www.darknet.org.uk/2010/10/hackers-exploit-unpatched-firefox-0day-using-nobel-peace-prize-website/#comments</comments>
		<pubDate>Wed, 27 Oct 2010 08:12:46 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[0-day]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[belmoo]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[firefox 0day]]></category>
		<category><![CDATA[firefox exploit]]></category>
		<category><![CDATA[firefox-security]]></category>
		<category><![CDATA[firefox-vulnerability]]></category>
		<category><![CDATA[liu xiaobo]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[nobel peace prize]]></category>
		<category><![CDATA[race condition]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2982</guid>
		<description><![CDATA[It&#8217;s been a while since Firefox has been in the news, but this is a fairly high profile case involving the Nobel Peace Prize website. It seems there is a race condition vulnerability in the latest versions of Firefox (including 3.6.11) that allows remote exploitation. In this case it was used via an iFrame on [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a while since <a href="http://www.darknet.org.uk/tag/firefox/">Firefox</a> has been in the news, but this is a fairly high profile case involving the Nobel Peace Prize website. It seems there is a race condition vulnerability in the latest versions of Firefox (including 3.6.11) that allows remote exploitation.</p>
<p>In this case it was used via an iFrame on nobelpeaceprize.org which then downloaded <a href="http://www.darknet.org.uk/tag/malware/">malware</a> to the visitors machine using a multi-exploit back-end which amongst others also leveraged this 0day Firefox exploit.</p>
<blockquote><p>Malicious hackers have exploited an unpatched vulnerability in the latest version of Firefox to attack people visiting the Nobel Peace Prize website, a Norway-based security firm said on Tuesday.</p>
<p>Mozilla representatives confirmed a &#8220;critical vulnerability&#8221; in versions 3.5 and 3.6 of the open-source browser. It came several hours after the organization members were said to have made the same admission on this password-protected Bugzilla page. According to Einar Oftedal, a detection executive at Norman ASA in Oslo, the official website for the Nobel Peace prize, nobelpeaceprize.org, was compromised so that it contained an iframe link to a malicious server.</p>
<p>“This iframe has a multi exploit backend and serves exploits for Firefox, including a working remote exploit for Firefox 3.6.11,” he said in an instant message to The Register. “We didn&#8217;t see any 0day for IE,” he added, referring to Microsoft&#8217;s browser.</p></blockquote>
<p>Mozilla claims they will address this issue soon and past history dictates that a patch will come out within a few days, so look forwards to Firefox 3.6.12 by the end of the week. It seems to be a fairly advanced and targeted attack.</p>
<p>Of course the conspiracy theorists will say that the attack was carried out by the <a href="http://www.darknet.org.uk/tag/china/">Chinese Government</a> as their way of complaining that the most recent Nobel Peace Prize was given to a Chinese dissident named <a href="http://en.wikipedia.org/wiki/Liu_Xiaobo">Liu Xiaobo</a>.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>He said the attack exploited a race condition vulnerability in Firefox to force end users to install malware his firm has dubbed Belmoo. The Windows executable was created on Sunday and attempts to connect to several internet addresses, according to his analysis.</p>
<p>If the addresses resolve, “the malware attaches a command shell to the opened socket, giving an attacker access on the local computer with the same rights as the logged on user.” If not, the malware will exit.</p>
<p>If Norman&#8217;s report proves accurate, it&#8217;s the first time in recent memory attackers have exploited an unpatched vulnerability in Firefox. Most so-called zero-day attacks are perpetrated against Adobe Reader or Flash Player, Microsoft software and to a lesser extent Oracle&#8217;s Java. The report is also unusual because the attack didn&#8217;t appear to target other applications, as is typical with exploit packages.</p>
<p>Hours after the reports surfaced, Mozilla said it would issue a fix as soon as possible. In the meantime, users can protect themselves by disabling JavaScript altogether or installing the NoScript extension that allows users to control which websites are permitted to run JavaScript.</p></blockquote>
<p>As per usual you can protect yourself against this flaw by using NoScript or disabling <a href="http://www.darknet.org.uk/tag/javascript/">JavaScript</a> functionality in your browser.</p>
<p>It&#8217;s been a while since there&#8217;s been a serious bug in Firefox, most of the recent ones have <a href="http://www.darknet.org.uk/2009/07/mozilla-denies-firefox-3-5-bug-is-exploitable/">not been exploitable</a> or have involved passive activities like data leakage and <a href="http://www.darknet.org.uk/tag/clickjacking/">clickjacking</a>.</p>
<p>Source: <a href="http://www.theregister.co.uk/2010/10/26/firefox_0day_report/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Hackers+Exploit+Unpatched+Firefox+0day+Using+Nobel+Peace+Prize+Website+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2982+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/10/hackers-exploit-unpatched-firefox-0day-using-nobel-peace-prize-website/&amp;t=Hackers+Exploit+Unpatched+Firefox+0day+Using+Nobel+Peace+Prize+Website" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/10/hackers-exploit-unpatched-firefox-0day-using-nobel-peace-prize-website/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/10/hackers-exploit-unpatched-firefox-0day-using-nobel-peace-prize-website/&amp;title=Hackers+Exploit+Unpatched+Firefox+0day+Using+Nobel+Peace+Prize+Website" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/10/hackers-exploit-unpatched-firefox-0day-using-nobel-peace-prize-website/&amp;title=Hackers+Exploit+Unpatched+Firefox+0day+Using+Nobel+Peace+Prize+Website" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/10/hackers-exploit-unpatched-firefox-0day-using-nobel-peace-prize-website/&amp;title=Hackers+Exploit+Unpatched+Firefox+0day+Using+Nobel+Peace+Prize+Website" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/10/hackers-exploit-unpatched-firefox-0day-using-nobel-peace-prize-website/&amp;title=Hackers+Exploit+Unpatched+Firefox+0day+Using+Nobel+Peace+Prize+Website" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F10%2Fhackers-exploit-unpatched-firefox-0day-using-nobel-peace-prize-website%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/10/hackers-exploit-unpatched-firefox-0day-using-nobel-peace-prize-website/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Confirms Windows Zero Day Bug In Shortcut Files</title>
		<link>http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/</link>
		<comments>http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/#comments</comments>
		<pubDate>Fri, 23 Jul 2010 09:51:55 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[0-day]]></category>
		<category><![CDATA[0-day windows exploit]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[oob patch]]></category>
		<category><![CDATA[out of band]]></category>
		<category><![CDATA[out of band patch]]></category>
		<category><![CDATA[root kit]]></category>
		<category><![CDATA[stuxnet]]></category>
		<category><![CDATA[windows shortcut exploit]]></category>
		<category><![CDATA[windows vulnerability]]></category>
		<category><![CDATA[windows xp sp2]]></category>
		<category><![CDATA[windows-exploit]]></category>
		<category><![CDATA[windows-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2804</guid>
		<description><![CDATA[This is a pretty nasty attack and for once Microsoft have actually acknowledged and confirmed this is a critical unpatched vulnerability. Incidentally Microsoft also recently retired Windows XP SP2 from the support cycle, and this vulnerability effects that system and they have stated they will not be patching it. It&#8217;s a pretty serious bug and [...]]]></description>
			<content:encoded><![CDATA[<p>This is a pretty nasty attack and for once <a href="http://www.darknet.org.uk/tag/microsoft/">Microsoft</a> have actually acknowledged and confirmed this is a critical unpatched vulnerability. Incidentally Microsoft also recently retired Windows XP SP2 from the support cycle, and this vulnerability effects that system and they have stated they will not be patching it.</p>
<p>It&#8217;s a pretty serious bug and it seems hackers have been maliciously exploiting it in the wild for over a month. The Stuxnet malware has been using this vulnerability to gain access to machines then download further attack files including a <a href="http://www.darknet.org.uk/tag/root-kit/">root kit</a>.</p>
<blockquote><p>Microsoft on Friday warned that attackers are exploiting a critical unpatched Windows vulnerability using infected USB flash drives.</p>
<p>The bug admission is the first that affects Windows XP Service Pack 2 (SP2) since Microsoft retired the edition from support , researchers said. When Microsoft does fix the flaw, it will not be providing a patch for machines still running XP SP2. In a security advisory , Microsoft confirmed what other researchers had been saying for almost a month: Hackers have been exploiting a bug in Windows &#8220;shortcut&#8221; files, the placeholders typically dropped on the desktop or into the Start menu to represent links to actual files or programs.</p>
<p>&#8220;In the wild, this vulnerability has been found operating in conjunction with the Stuxnet malware,&#8221; Dave Forstrom, a director in Microsoft&#8217;s Trustworthy Computing group, said in a post Friday to a company blog . Stuxnet is a clan of malware that includes a Trojan horse that downloads further attack code, including a rootkit that hides evidence of the attack.</p>
<p>Forstrom characterized the threat as &#8220;limited, targeted attacks,&#8221; but the Microsoft group responsible for crafting antivirus signatures said it had tracked 6,000 attempts to infect Windows PCs as of July 15. </p></blockquote>
<p>Limited but targeted attacks are the worst kind as they can really burrow through corporate defenses. A lot of companies are taking this seriously, including all the main players in the anti-virus arena.</p>
<p>You have to wonder if Microsoft will break their <a href="http://www.darknet.org.uk/tag/patch-tuesday/">patch tuesday</a> policy and issue an emergency <a href="http://www.darknet.org.uk/tag/out-of-band-patch/">out-of-band patch</a> for this.</p>
<p>Especially since <a href="http://www.networkworld.com/news/2010/072310-virus-writers-are-picking-up.html?source=nww_rss">more virus writers are picking up on this flaw</a> meaning it&#8217;s becoming more widespread.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-BodyRec */
google_ad_slot = "8649785837";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div></p>
<blockquote><p>On Friday, Siemens alerted customers of its Simatic WinCC management software that attacks using the Windows vulnerability were targeting computers used to manage large-scale industrial control systems used by major manufacturing and utility companies. The vulnerability was first mentioned on June 17 in an alert issued by VirusBlokAda , a little-known security firm based in Belarus. Other security organizations, including U.K.-based Sophos and SANS Institute&#8217;s Internet Storm Center , picked up on the threat Friday. Security blogger Brian Krebs , formerly with the Washington Post, reported on it Thursday.</p>
<p>According to Microsoft, Windows fails to correctly parse shortcut files, identified by the &#8220;.lnk&#8221; extension. The flaw has been exploited most frequently using USB flash drives. By crafting a malicious .lnk file, hackers can hijack a Windows PC with little user interaction: All that&#8217;s necessary is that the user views the contents of the USB drive with a file manager like Windows Explorer.</p>
<p>Chester Wisniewski, a senior security advisory with Sophos, called the threat &#8220;nasty,&#8221; and said his tests showed that the exploit works even when AutoRun and AutoPlay &#8212; two functions that have previously been used by attackers to commandeer PCs using infected flash drives &#8212; are disabled. The rootkit also bypasses all security mechanisms in Windows, including the User Account Control (UAC) prompts in Vista and Windows 7 , said Wisniewski in a blog entry Friday. </p></blockquote>
<p>I&#8217;m sure they&#8217;ll come up with some reason for not patching this sooner rather than later. The scary part is the attack can still be carried out even if AutoRun and AutoPlay are disabled.</p>
<p>The rootkit also bypasses the security mechanisms in Windows 7 and Vista making this a very dangerous attack.</p>
<p>You can find a temporary workaround in the Microsoft Security Advisory here:</p>
<p><a href="http://support.microsoft.com/kb/2286198">Microsoft Security Advisory: Vulnerability in Windows Shell could allow remote code execution</a></p>
<p>And Microsoft has stated they are working on a patch.</p>
<p>Source: <a href="http://www.networkworld.com/news/2010/071710-microsoft-confirms-nasty-windows-zero-day.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+Confirms+Windows+Zero+Day+Bug+In+Shortcut+Files+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2804+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/&amp;t=Microsoft+Confirms+Windows+Zero+Day+Bug+In+Shortcut+Files" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/&amp;title=Microsoft+Confirms+Windows+Zero+Day+Bug+In+Shortcut+Files" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/&amp;title=Microsoft+Confirms+Windows+Zero+Day+Bug+In+Shortcut+Files" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/&amp;title=Microsoft+Confirms+Windows+Zero+Day+Bug+In+Shortcut+Files" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/&amp;title=Microsoft+Confirms+Windows+Zero+Day+Bug+In+Shortcut+Files" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F07%2Fmicrosoft-confirms-windows-zero-day-bug-in-shortcut-files%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/07/microsoft-confirms-windows-zero-day-bug-in-shortcut-files/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>eEye Launches 0-Day Exploit Tracker</title>
		<link>http://www.darknet.org.uk/2007/01/eeye-launches-0-day-exploit-tracker/</link>
		<comments>http://www.darknet.org.uk/2007/01/eeye-launches-0-day-exploit-tracker/#comments</comments>
		<pubDate>Mon, 01 Jan 2007 08:48:44 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[General News]]></category>
		<category><![CDATA[0-day]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[eeye]]></category>
		<category><![CDATA[exploit-database]]></category>
		<category><![CDATA[exploit-tracker]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[vulnerability-tracker]]></category>
		<category><![CDATA[zero-day]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/01/eeye-launches-0-day-exploit-tracker/</guid>
		<description><![CDATA[Ah finally a decent 0-day exploit tracker, one that isn&#8217;t underground and could be fairly useful to everyone. 0-day as basically stated in the article is an exploit not known publicly or available publicly well before any patches are available, some private groups often have exploits for a year or more before someone else discovers [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Ah finally a decent 0-day exploit tracker, one that isn&#8217;t underground and could be fairly useful to everyone.</p>
<p>0-day as basically stated in the article is an exploit not known publicly or available publicly well before any patches are available, some private groups often have exploits for a year or more before someone else discovers them, makes them public and they inevitably get fixed.</p>
<p>Like the famous remote exploit in Windows RPC, private groups had that for almost 2 years before it became public.</p>
<p>Scary eh?</p>
<blockquote><p>Security firm eEye has created what&#8217;s described as the industry&#8217;s first site designed solely to track zero-day vulnerabilities, flaws where exploits are available prior to the release of security patches.</p>
<p>eEye&#8217;s zero-day tracking <a href="http://research.eeye.com/html/alerts/zeroday/index.html">site</a> provides detailed information on flaws and remediation strategies to users. The site will be maintained by security researchers at eEye Research, who have a track record of unearthing new security bugs, and is essentially an eEye gig rather than a cross-industry effort.</p></blockquote>
<p>It&#8217;s a good idea even if it&#8217;s not an industry effort it&#8217;s solely an eEye effort, I&#8217;m glad someone has done it and eEye has a strong capable team, so it should be fairly relevant if it&#8217;s kept up to date.</p>
<blockquote><p>However, eEye invites other interested parties to contribute suggestions on flaws that merit inclusion on its list. eEye said it created the site, which includes information on how long flaws have remained unfixed, in response to the growing number of zero-day exploits.</p>
<p>In other security tracking news, security notification firm Secunia has released a tool designed to determine insecure versions of popular software packages (such as browsers, IM clients, and media players) on consumer&#8217;s PC. </p>
<p>Secunia&#8217;s <a href="http://secunia.com/software_inspector">Software Inspector</a> provides users with advice on what to do if they are running insecure software packages.</p>
<p>Both eEye zero-day tracking site and Secunia&#8217;s Software Inspector are available free of charge.</p></blockquote>
<p>You can find the site here:</p>
<p><a href="http://research.eeye.com/html/alerts/zeroday/index.html">eEye Zero Day Tracker</a></p>
<p></p>
<p>Source: <a href="http://www.theregister.co.uk/2006/12/07/0day_tracker/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=eEye+Launches+0-Day+Exploit+Tracker+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D409+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/01/eeye-launches-0-day-exploit-tracker/&amp;t=eEye+Launches+0-Day+Exploit+Tracker" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/01/eeye-launches-0-day-exploit-tracker/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/01/eeye-launches-0-day-exploit-tracker/&amp;title=eEye+Launches+0-Day+Exploit+Tracker" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/01/eeye-launches-0-day-exploit-tracker/&amp;title=eEye+Launches+0-Day+Exploit+Tracker" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/01/eeye-launches-0-day-exploit-tracker/&amp;title=eEye+Launches+0-Day+Exploit+Tracker" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/01/eeye-launches-0-day-exploit-tracker/&amp;title=eEye+Launches+0-Day+Exploit+Tracker" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F01%2Feeye-launches-0-day-exploit-tracker%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/01/eeye-launches-0-day-exploit-tracker/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

