<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Windows &#8216;LNK&#8217; Exploit Demonstration</title>
	<atom:link href="http://www.attackvector.org/lnk-exploit-demonstration/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.attackvector.org/lnk-exploit-demonstration/</link>
	<description>Shedding Light on the Dark Side.</description>
	<lastBuildDate>Sun, 18 Dec 2011 16:52:27 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: Emails Being Blocked - Web Hosting</title>
		<link>http://www.attackvector.org/lnk-exploit-demonstration/comment-page-1/#comment-627</link>
		<dc:creator>Emails Being Blocked - Web Hosting</dc:creator>
		<pubDate>Mon, 04 Oct 2010 17:39:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.attackvector.org/?p=457#comment-627</guid>
		<description>[...] allowed per Company security policy   LNK files typically identify the LNKexploit malware attack as discussed here, which was why my earlier post suggested it was rightly filtered as both file type and as Spam [...]</description>
		<content:encoded><![CDATA[<p>[...] allowed per Company security policy   LNK files typically identify the LNKexploit malware attack as discussed here, which was why my earlier post suggested it was rightly filtered as both file type and as Spam [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://www.attackvector.org/lnk-exploit-demonstration/comment-page-1/#comment-347</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Wed, 28 Jul 2010 14:05:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.attackvector.org/?p=457#comment-347</guid>
		<description>@strcmp:  Good point.. maybe it&#039;s time for those who are tired of being jerked around by Microsoft to switch to a better operating system.  Might I suggest Linux? ;-)</description>
		<content:encoded><![CDATA[<p>@strcmp:  Good point.. maybe it&#8217;s time for those who are tired of being jerked around by Microsoft to switch to a better operating system.  Might I suggest Linux? <img src='http://www.attackvector.org/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: strcmp</title>
		<link>http://www.attackvector.org/lnk-exploit-demonstration/comment-page-1/#comment-346</link>
		<dc:creator>strcmp</dc:creator>
		<pubDate>Wed, 28 Jul 2010 04:08:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.attackvector.org/?p=457#comment-346</guid>
		<description>From nemesis.te-home.net:
&quot;This program is a proof of concept and is provided &quot;as is&quot;. Any express or implied warranties are disclaimed. In no event shall the author be liable for any damages caused arising in any way out of the use of this software, even if advised of the possibility of such damage.
License: Creative Commons Attribution.&quot;

After patching, the old shell32.dll is saved as &quot;shell32.backup&quot; in system32\ folder. If you compare shell32.dll with shell32.backup you can notice the patch is only 4 bytes for any Service Pack of Windows XP. Source code for this patch program is included.

If Microsoft no longer provides patches for OS&#039;es that are still in use, we&#039;ll see only 3rd party patches, if any.</description>
		<content:encoded><![CDATA[<p>From nemesis.te-home.net:<br />
&#8220;This program is a proof of concept and is provided &#8220;as is&#8221;. Any express or implied warranties are disclaimed. In no event shall the author be liable for any damages caused arising in any way out of the use of this software, even if advised of the possibility of such damage.<br />
License: Creative Commons Attribution.&#8221;</p>
<p>After patching, the old shell32.dll is saved as &#8220;shell32.backup&#8221; in system32\ folder. If you compare shell32.dll with shell32.backup you can notice the patch is only 4 bytes for any Service Pack of Windows XP. Source code for this patch program is included.</p>
<p>If Microsoft no longer provides patches for OS&#8217;es that are still in use, we&#8217;ll see only 3rd party patches, if any.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://www.attackvector.org/lnk-exploit-demonstration/comment-page-1/#comment-343</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Tue, 27 Jul 2010 15:07:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.attackvector.org/?p=457#comment-343</guid>
		<description>@strcmp:  I get that.. but my concerns would be:

1) Who&#039;s providing the patch?
2) Can the provider be trusted?
3) Do they provide the source code of the patch?
And, ultimately.. 4) Is this thing a backdoor?

To be honest, in most circumstances, I would say using a 3rd party patch to fix this problem might expose you to more risks than not patching it at all.</description>
		<content:encoded><![CDATA[<p>@strcmp:  I get that.. but my concerns would be:</p>
<p>1) Who&#8217;s providing the patch?<br />
2) Can the provider be trusted?<br />
3) Do they provide the source code of the patch?<br />
And, ultimately.. 4) Is this thing a backdoor?</p>
<p>To be honest, in most circumstances, I would say using a 3rd party patch to fix this problem might expose you to more risks than not patching it at all.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: strcmp</title>
		<link>http://www.attackvector.org/lnk-exploit-demonstration/comment-page-1/#comment-342</link>
		<dc:creator>strcmp</dc:creator>
		<pubDate>Tue, 27 Jul 2010 05:23:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.attackvector.org/?p=457#comment-342</guid>
		<description>&quot;I guess I’d be a little apprehensive using something not provided by Microsoft&quot;

The patch applies to OS&#039;es no longer supported by Microsoft.</description>
		<content:encoded><![CDATA[<p>&#8220;I guess I’d be a little apprehensive using something not provided by Microsoft&#8221;</p>
<p>The patch applies to OS&#8217;es no longer supported by Microsoft.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Week 29 in Review – 2010 &#124; Portable Digital Video Recorder</title>
		<link>http://www.attackvector.org/lnk-exploit-demonstration/comment-page-1/#comment-340</link>
		<dc:creator>Week 29 in Review – 2010 &#124; Portable Digital Video Recorder</dc:creator>
		<pubDate>Mon, 26 Jul 2010 05:46:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.attackvector.org/?p=457#comment-340</guid>
		<description>[...] Windows ‘LNK’ Exploit Demonstration &#8211; attackvector.org [...]</description>
		<content:encoded><![CDATA[<p>[...] Windows ‘LNK’ Exploit Demonstration &#8211; attackvector.org [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://www.attackvector.org/lnk-exploit-demonstration/comment-page-1/#comment-339</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Sun, 25 Jul 2010 22:01:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.attackvector.org/?p=457#comment-339</guid>
		<description>@elva:  Unlike the video, try using explorer.exe rather than IE to access the share and see if it works.</description>
		<content:encoded><![CDATA[<p>@elva:  Unlike the video, try using explorer.exe rather than IE to access the share and see if it works.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: elva</title>
		<link>http://www.attackvector.org/lnk-exploit-demonstration/comment-page-1/#comment-335</link>
		<dc:creator>elva</dc:creator>
		<pubDate>Sun, 25 Jul 2010 14:29:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.attackvector.org/?p=457#comment-335</guid>
		<description>i have no exploitation.
after running exploit and i can get a.dll and b.lnk
but no session established.
it stopped at Sending dll payload 192.168.1.16:1065....

windows xp sp2 + ie6.0
i wanna know why and anyone has the same result?</description>
		<content:encoded><![CDATA[<p>i have no exploitation.<br />
after running exploit and i can get a.dll and b.lnk<br />
but no session established.<br />
it stopped at Sending dll payload 192.168.1.16:1065&#8230;.</p>
<p>windows xp sp2 + ie6.0<br />
i wanna know why and anyone has the same result?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://www.attackvector.org/lnk-exploit-demonstration/comment-page-1/#comment-333</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Sat, 24 Jul 2010 13:12:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.attackvector.org/?p=457#comment-333</guid>
		<description>@strcmp:  Nice.. I hadn&#039;t seen that yet.  I guess I&#039;d be a little apprehensive using something not provided by Microsoft, though.</description>
		<content:encoded><![CDATA[<p>@strcmp:  Nice.. I hadn&#8217;t seen that yet.  I guess I&#8217;d be a little apprehensive using something not provided by Microsoft, though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: strcmp</title>
		<link>http://www.attackvector.org/lnk-exploit-demonstration/comment-page-1/#comment-332</link>
		<dc:creator>strcmp</dc:creator>
		<pubDate>Sat, 24 Jul 2010 11:33:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.attackvector.org/?p=457#comment-332</guid>
		<description>There is a patch for shell32.dll and it&#039;s not made by Microsoft.

http://nemesis.te-home.net/News/20100723_Patch_for_0day__LNK_file_handling_vulnerability_up.html</description>
		<content:encoded><![CDATA[<p>There is a patch for shell32.dll and it&#8217;s not made by Microsoft.</p>
<p><a href="http://nemesis.te-home.net/News/20100723_Patch_for_0day__LNK_file_handling_vulnerability_up.html" rel="nofollow">http://nemesis.te-home.net/News/20100723_Patch_for_0day__LNK_file_handling_vulnerability_up.html</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

