<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; microsoft-word</title>
	<atom:link href="http://www.darknet.org.uk/tag/microsoft-word/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Collar Bomber Gets Owned By Word Metadata &amp; USB Drive</title>
		<link>http://www.darknet.org.uk/2011/08/collar-bomber-gets-owned-by-word-metadata-usb-drive/</link>
		<comments>http://www.darknet.org.uk/2011/08/collar-bomber-gets-owned-by-word-metadata-usb-drive/#comments</comments>
		<pubDate>Thu, 18 Aug 2011 17:34:07 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Legal Issues]]></category>
		<category><![CDATA[collar bomb]]></category>
		<category><![CDATA[collar bomber]]></category>
		<category><![CDATA[computer-forensics]]></category>
		<category><![CDATA[crime]]></category>
		<category><![CDATA[extortion]]></category>
		<category><![CDATA[microsoft-word]]></category>
		<category><![CDATA[Paul "Doug" Peters]]></category>
		<category><![CDATA[paul peters]]></category>
		<category><![CDATA[recover usb drive data]]></category>
		<category><![CDATA[usb drive recovery]]></category>
		<category><![CDATA[usb forensics]]></category>
		<category><![CDATA[word metadata]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3174</guid>
		<description><![CDATA[There were other more technical and probably relevant stories to report on today, but for some reason I just found this story very odd and strangely fascinating. Now here a strange case, a man climbs into a young girls bedroom in the middle of the night, threatens her with a baseball bat and then chains [...]]]></description>
			<content:encoded><![CDATA[<p>There were other more technical and probably relevant stories to report on today, but for some reason I just found this story very odd and strangely fascinating.</p>
<p>Now here a strange case, a man climbs into a young girls bedroom in the middle of the night, threatens her with a baseball bat and then chains a bomb to her neck. His random instructions include e-mailing to a <a href="http://www.darknet.org.uk/tag/gmail/">Gmail</a> account and he leaves a &#8216;soft copy&#8217; version of the ransom note on a pen-drive with the girl.</p>
<p>You can find the court docs here &#8211; <a href="http://www.scribd.com/doc/62526127/Collar-Bomber-Complaint">Collar Bomber Complaint</a></p>
<blockquote><p>The man who claimed to have attached a bomb collar to an Australian high school student two weeks ago thought it would be a good idea to leave a ransom note on a USB stick looped around her neck. What he probably didn&#8217;t realize is that he also left his name, hidden deep in the device&#8217;s memory.</p>
<p>Court documents unsealed Tuesday describe the harrowing Aug. 3 incident, which began when a man broke into Madeline Pulver&#8217;s bedroom wearing a striped balaclava and wielding a black aluminum baseball bat. He told her to sit down and chained a black box around her neck.</p>
<p>He also draped a purple lanyard over the terrified girl with a note saying that the black box was a bomb. The note included ransom instructions for Pulver&#8217;s family, telling them to e-mail a Google address &#8212; dirkstraun1840@gmail.com &#8212; for further instructions. Also on the lanyard was a 4GB USB stick that contained a digital version of the note, saved as a pdf file.</p>
<p>The next 10 hours were a gruelling ordeal for the girl before a Sydney police bomb squad was able to determined that the threat was a hoax. But a closer look at the USB drive turned up a couple of files that the criminal thought he&#8217;d deleted. One of them, a version of the ransom note written in Microsoft Word, contained metadata about the document&#8217;s author, including his name: &#8220;Paul P.&#8221;</p>
<p>On Monday, U.S. authorities arrested Paul &#8220;Doug&#8221; Peters, 50, in La Grange, Kentucky, seeking to extradite him to Australia to face kidnapping and breaking-and-entering charges. It&#8217;s not clear why Peters attempted such a bizarre crime, but U.S. prosecutors say he once worked for a company linked to Pulver&#8217;s family. The girl&#8217;s father, Bill Pulver, is the CEO of voice recognition software company Appen Butler Hill. </p></blockquote>
<p>There are plenty of metadata extraction tools such as <a href="http://www.darknet.org.uk/2007/10/metagoofil-12-metadata-extractor-tool/">Metagoofil</a> and <a href="http://www.darknet.org.uk/2008/01/the-revisionist-metadata-retrieval-tool/" title="The Revisionist – Metadata Retrieval Tool">The Revisionist</a>. And well even without those, after recovering the file you can just open it in Word and view the metadata.</p>
<p>I&#8217;m guessing this Paul Peters chap wasn&#8217;t so familiar with wear levelling and metadata. He should have known better, and well he was doing this for a ransom..so really he should have just bought a new pen-drive for the job. </p>
<p>But as we know well, these people don&#8217;t think like we do &#8211; that&#8217;s why they end up in the news.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Police collected footage from surveillance cameras in a library where a computer was used to access the Gmail account. The footage, along with the USB drive and circumstantial evidence, such as purchases made around the time of the incident, link Peters to the crime, prosecutors say.</p>
<p>Even if the collar bomber had known his name was on the USB drive, it would have been very hard to remove it, according to Frank McClain, an independent computer forensics expert.</p>
<p>As computer geeks and investigators know, when users delete a file from a computer the file isn&#8217;t deleted immediately from the hard drive. Instead, the computer takes note that the area of the disk where the file is stored is now available to be written over. So investigators can often recover at least snippets of data from files that are supposed to have been deleted.</p>
<p>With flash drives things are more complex, thanks to mechanisms built into the drives to prolong their lifespan. Because flash memory cells stop working after they&#8217;ve been overwritten too many times, flash devices use tricks called &#8220;wear leveling&#8221; to even out how the memory cells are used. A side effect of wear levelling is that it is &#8220;almost impossible&#8221; to completely erase data from a flash device, McClain said.</p>
<p>That can come in handy for people trying to recover photos or other files they&#8217;ve accidentally deleted, and there are many tools, some of them free, to help recover their data.</p>
<p>The collar bomber&#8217;s first mistake was thinking he could delete something completely from his USB stick. But he also erred by not altering the metadata in his Word document. When Word saves a document, it automatically saves data, such as the user&#8217;s login name, as part of the file. Office 2007 users can see this metadata by hitting the Office button, then &#8220;Prepare&#8221; and &#8220;Properties.&#8221; </p></blockquote>
<p>Well there you go, an interesting mid-week story &#8211; not entirely sure what is going to happen to this guy. Doesn&#8217;t seem like a really strong case for extradition &#8211; he just seems like a complete nutcase.</p>
<p>He had a decent enough idea for extortion I suppose, just a really poor execution. Perhaps he&#8217;s been watching to o many Hollywood movies where these things seem really easy and nothing even goes wrong.</p>
<p>BTW if any of you readers out there see any cool new tools/techniques or news tidbits that I may have missed, I always welcome a heads-up so just hit me up on the <a href="http://www.darknet.org.uk/contact-darknet/" title="Contact Darknet">Contact Page here</a>.</p>
<p>Source: <a href="http://www.networkworld.com/news/2011/081711-the-collar-bombers-explosive-tech-249844.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Collar+Bomber+Gets+Owned+By+Word+Metadata+%26+USB+Drive+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3174+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/08/collar-bomber-gets-owned-by-word-metadata-usb-drive/&amp;t=Collar+Bomber+Gets+Owned+By+Word+Metadata+%26+USB+Drive" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/08/collar-bomber-gets-owned-by-word-metadata-usb-drive/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/08/collar-bomber-gets-owned-by-word-metadata-usb-drive/&amp;title=Collar+Bomber+Gets+Owned+By+Word+Metadata+%26+USB+Drive" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/08/collar-bomber-gets-owned-by-word-metadata-usb-drive/&amp;title=Collar+Bomber+Gets+Owned+By+Word+Metadata+%26+USB+Drive" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/08/collar-bomber-gets-owned-by-word-metadata-usb-drive/&amp;title=Collar+Bomber+Gets+Owned+By+Word+Metadata+%26+USB+Drive" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/08/collar-bomber-gets-owned-by-word-metadata-usb-drive/&amp;title=Collar+Bomber+Gets+Owned+By+Word+Metadata+%26+USB+Drive" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F08%2Fcollar-bomber-gets-owned-by-word-metadata-usb-drive%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/08/collar-bomber-gets-owned-by-word-metadata-usb-drive/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Microsoft Word 0-day Exploits &#8211; QUESTION.DOC</title>
		<link>http://www.darknet.org.uk/2007/01/microsoft-word-0-day-exploits-questiondoc/</link>
		<comments>http://www.darknet.org.uk/2007/01/microsoft-word-0-day-exploits-questiondoc/#comments</comments>
		<pubDate>Thu, 11 Jan 2007 05:30:39 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[hacking-word]]></category>
		<category><![CDATA[microsoft-exploit]]></category>
		<category><![CDATA[microsoft-hacking]]></category>
		<category><![CDATA[microsoft-word]]></category>
		<category><![CDATA[word]]></category>
		<category><![CDATA[word-vulnerability]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/01/microsoft-word-0-day-exploits-questiondoc/</guid>
		<description><![CDATA[There&#8217;s been quite a few Microsoft related exploits recently, but not in Windows, people have moved their focus towards the application layer and the top of the OSI stack. This time it was a 0-day Vulnerability in Microsoft Word. The original news comes from SANS Internet Storm Center Diary (ISC). Microsoft has reported Word 2003, [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>There&#8217;s been quite a few Microsoft related exploits recently, but not in Windows, people have moved their focus towards the application layer and the top of the OSI stack.</p>
<p>This time it was a 0-day Vulnerability in Microsoft Word.</p>
<p>The original news comes from <a href="http://isc.sans.org/diary.html?storyid=1925">SANS Internet Storm Center Diary (ISC)</a>.</p>
<p>Microsoft has reported Word 2003, Word 2002, Word 2000 and Word Viewer 2003 are reportedly affected.</p>
<p>The vulnerability is being exploited in the wild, the malicious document is called <em>QUESTION.DOC</em>.</p>
<p>Password stealing Trojan spreads with this vulnerability, link to the McAfee <a href="http://vil.nai.com/vil/content/v_141057.htm">PWS-Agent.g</a> writeup.</p>
<p></p>
<p>US-CERT reported today that &#8220;Word fails to properly handle malformed data structures allowing memory corruption to occur&#8221;. This vulnerability is public <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6456">CVE-2006-6456</a> now.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+Word+0-day+Exploits+%E2%80%93+QUESTION.DOC+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D413+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/01/microsoft-word-0-day-exploits-questiondoc/&amp;t=Microsoft+Word+0-day+Exploits+%E2%80%93+QUESTION.DOC" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/01/microsoft-word-0-day-exploits-questiondoc/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/01/microsoft-word-0-day-exploits-questiondoc/&amp;title=Microsoft+Word+0-day+Exploits+%E2%80%93+QUESTION.DOC" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/01/microsoft-word-0-day-exploits-questiondoc/&amp;title=Microsoft+Word+0-day+Exploits+%E2%80%93+QUESTION.DOC" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/01/microsoft-word-0-day-exploits-questiondoc/&amp;title=Microsoft+Word+0-day+Exploits+%E2%80%93+QUESTION.DOC" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/01/microsoft-word-0-day-exploits-questiondoc/&amp;title=Microsoft+Word+0-day+Exploits+%E2%80%93+QUESTION.DOC" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F01%2Fmicrosoft-word-0-day-exploits-questiondoc%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/01/microsoft-word-0-day-exploits-questiondoc/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Trojan for the Word Vulnerability in the Wild</title>
		<link>http://www.darknet.org.uk/2006/05/trojan-for-the-word-vulnerability-in-the-wild/</link>
		<comments>http://www.darknet.org.uk/2006/05/trojan-for-the-word-vulnerability-in-the-wild/#comments</comments>
		<pubDate>Tue, 23 May 2006 03:59:13 +0000</pubDate>
		<dc:creator>Tiago Faria</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[gouki]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[microsoft-word]]></category>
		<category><![CDATA[office]]></category>
		<category><![CDATA[word-exploit]]></category>
		<category><![CDATA[word-vulnerability]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/05/trojan-for-the-word-vulnerability-in-the-wild/</guid>
		<description><![CDATA[We all knew it was just a matter of time until the &#8216;thing&#8217; was out. PandaLabs has detected the appearance of 1Table.A, a malicious code that exploits a recently detected critical vulnerability in Microsoft Word, and which also affects versions of MS Office 2003 and XP. Microsoft confirmed today the existence of this vulnerability and [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>We all knew it was just a matter of time until the &#8216;thing&#8217; was out. </p>
<blockquote><p>PandaLabs has detected the appearance of 1Table.A, a malicious code that exploits a recently detected critical vulnerability in Microsoft Word, and which also affects versions of MS Office 2003 and XP.</p></blockquote>
<p>Microsoft <a href="http://www.msfn.org/comments.php?shownews=17204">confirmed</a> today the existence of this vulnerability and apparently is <a href="http://www.scmagazine.com/uk/news/index.cfm?fuseaction=XCK.News.Article&amp;nNewsID=560353">working</a> on a hotfix. </p>
<blockquote><p>This security problem allows the execution of code on affected systems and, more dangerously, allows the construction of malicious code which is indistinguishable at first glance from a normal Word file.</p></blockquote>
<p>That&#8217;s more than enough to get 70%* of the people who use Microsoft Office to download and execute the file. If they open .BAT, .COM and .EXE, opening a .DOC is everyday work.</p>
<p>This attack is not limited to .DOC files, still, they will be the most used extension. It can take place with a .XLS file with an embedded Word document.</p>
<p>1Table.A &#8211; the new trojan &#8211; is detected by most of the antivirus software, however, user&#8217;s should have they&#8217;r eyes open until patch is released by Microsoft <em>(even if they <a href="http://blogs.technet.com/msrc/archive/2006/05/20/429612.aspx">don&#8217;t consider it critical</a>)</em></p>
<p><strong>Source:</strong> <a href="http://www.net-security.org/virus_news.php?id=639">NHS</a></p>
<p><em>* 80% of the statistics are made on the spot!</em></p>
<p></p>
<p><a href="http://digg.com/security/Trojan_for_Word_Exploit_IN_THE_WILD_">Digg This Article</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Trojan+for+the+Word+Vulnerability+in+the+Wild+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D207+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/05/trojan-for-the-word-vulnerability-in-the-wild/&amp;t=Trojan+for+the+Word+Vulnerability+in+the+Wild" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/05/trojan-for-the-word-vulnerability-in-the-wild/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/05/trojan-for-the-word-vulnerability-in-the-wild/&amp;title=Trojan+for+the+Word+Vulnerability+in+the+Wild" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/05/trojan-for-the-word-vulnerability-in-the-wild/&amp;title=Trojan+for+the+Word+Vulnerability+in+the+Wild" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/05/trojan-for-the-word-vulnerability-in-the-wild/&amp;title=Trojan+for+the+Word+Vulnerability+in+the+Wild" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/05/trojan-for-the-word-vulnerability-in-the-wild/&amp;title=Trojan+for+the+Word+Vulnerability+in+the+Wild" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F05%2Ftrojan-for-the-word-vulnerability-in-the-wild%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/05/trojan-for-the-word-vulnerability-in-the-wild/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

