<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: Any ANI File Could Infect You!</title>
	<atom:link href="http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/feed/" rel="self" type="application/rss+xml" />
	<link>http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/</link>
	<description>A weblog dedicated to educating the community on security threats that matter</description>
	<lastBuildDate>Wed, 17 Mar 2010 18:21:30 -0400</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Philosophically Secure &#187; Blog Archive &#187; The Microsoft .ANI Vulnerability</title>
		<link>http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/comment-page-1/#comment-225966</link>
		<dc:creator>Philosophically Secure &#187; Blog Archive &#187; The Microsoft .ANI Vulnerability</dc:creator>
		<pubDate>Fri, 04 Sep 2009 18:06:40 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/#comment-225966</guid>
		<description>[...] Arbor Networks sees it being exploited in the wild [...]</description>
		<content:encoded><![CDATA[<p>[...] Arbor Networks sees it being exploited in the wild [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Diane</title>
		<link>http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/comment-page-1/#comment-208325</link>
		<dc:creator>Diane</dc:creator>
		<pubDate>Wed, 06 May 2009 13:07:42 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/#comment-208325</guid>
		<description>It sounds like you&#039;re creating problems yourself by trying to solve this issue instead of looking at why their is a problem in the first place.</description>
		<content:encoded><![CDATA[<p>It sounds like you&#8217;re creating problems yourself by trying to solve this issue instead of looking at why their is a problem in the first place.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jacqui</title>
		<link>http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/comment-page-1/#comment-13123</link>
		<dc:creator>Jacqui</dc:creator>
		<pubDate>Tue, 10 Apr 2007 14:31:25 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/#comment-13123</guid>
		<description>Also this is being hosted on domains yata.com.au and spybiz4u.com and possibly a number of others for use in drive by downloads.  I&#039;ve just found your advisory after coming from an affected forum and confirmed the yata domain by searching for the .exe file on there via a remote program.</description>
		<content:encoded><![CDATA[<p>Also this is being hosted on domains yata.com.au and spybiz4u.com and possibly a number of others for use in drive by downloads.  I&#8217;ve just found your advisory after coming from an affected forum and confirmed the yata domain by searching for the .exe file on there via a remote program.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: R. Kerns</title>
		<link>http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/comment-page-1/#comment-12416</link>
		<dc:creator>R. Kerns</dc:creator>
		<pubDate>Fri, 06 Apr 2007 17:31:01 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/#comment-12416</guid>
		<description>Of course after some review of the discovered exploit code what do I see in reporting TODAY! Really find it funny as I am a World of Warcrack player as well...

From BBC reporting at http://news.bbc.co.uk/2/hi/technology/6526851.stm

&quot;Analysis of that malicious software showed that it lay dormant on a victims machine until they ran World of Warcraft (WoW) at which point it captured login data and sent it to the hacking group. &quot; &quot;Research by security firm Symantec suggests that the raw value of a WoW account is now higher than a credit card and its associated verification data. 

One card can be sold for up to $6 (£3) suggests Symantec, but a WoW account will be worth at least $10. An account that has several high level characters associated with it could be worth far more as the gold and rare items can be sold for real cash. &quot;</description>
		<content:encoded><![CDATA[<p>Of course after some review of the discovered exploit code what do I see in reporting TODAY! Really find it funny as I am a World of Warcrack player as well&#8230;</p>
<p>From BBC reporting at <a href="http://news.bbc.co.uk/2/hi/technology/6526851.stm" rel="nofollow">http://news.bbc.co.uk/2/hi/technology/6526851.stm</a></p>
<p>&#8220;Analysis of that malicious software showed that it lay dormant on a victims machine until they ran World of Warcraft (WoW) at which point it captured login data and sent it to the hacking group. &#8221; &#8220;Research by security firm Symantec suggests that the raw value of a WoW account is now higher than a credit card and its associated verification data. </p>
<p>One card can be sold for up to $6 (£3) suggests Symantec, but a WoW account will be worth at least $10. An account that has several high level characters associated with it could be worth far more as the gold and rare items can be sold for real cash. &#8220;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Magically Delicious &#187; The Microsoft .ANI Vulnerability</title>
		<link>http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/comment-page-1/#comment-12194</link>
		<dc:creator>Magically Delicious &#187; The Microsoft .ANI Vulnerability</dc:creator>
		<pubDate>Thu, 05 Apr 2007 16:35:06 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/#comment-12194</guid>
		<description>[...] Arbor Networks sees it being exploited in the wild [...]</description>
		<content:encoded><![CDATA[<p>[...] Arbor Networks sees it being exploited in the wild [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .:Computer Defense:. &#187; Double Your Pleasure, Double Your Fun. Two MS Tuesdays are Better than One!</title>
		<link>http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/comment-page-1/#comment-11242</link>
		<dc:creator>.:Computer Defense:. &#187; Double Your Pleasure, Double Your Fun. Two MS Tuesdays are Better than One!</dc:creator>
		<pubDate>Mon, 02 Apr 2007 03:33:46 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/#comment-11242</guid>
		<description>[...] So I just checked my email&#8230; (I try to go anti-computer on the weekends these days&#8230; at least for a little while while I unwind and relax) and there&#8217;s an email from Microsoft informing customers that they will be releasing a patch on Tuesday, April 3rd. Now I suppose it could be an April Fool&#8217;s day joke but I don&#8217;t think Microsoft would send out a full blown Advanced Notification for a prank&#8230; I&#8217;m guessing they are pressured by the release of third party patches for the ANI issue by eEye and ZERT. [...]</description>
		<content:encoded><![CDATA[<p>[...] So I just checked my email&#8230; (I try to go anti-computer on the weekends these days&#8230; at least for a little while while I unwind and relax) and there&#8217;s an email from Microsoft informing customers that they will be releasing a patch on Tuesday, April 3rd. Now I suppose it could be an April Fool&#8217;s day joke but I don&#8217;t think Microsoft would send out a full blown Advanced Notification for a prank&#8230; I&#8217;m guessing they are pressured by the release of third party patches for the ANI issue by eEye and ZERT. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Harry Waldron - My IT Forums Blog : ANI based Trojans - Exploit Windows Animated Cursor handling</title>
		<link>http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/comment-page-1/#comment-10707</link>
		<dc:creator>Harry Waldron - My IT Forums Blog : ANI based Trojans - Exploit Windows Animated Cursor handling</dc:creator>
		<pubDate>Fri, 30 Mar 2007 19:04:34 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/#comment-10707</guid>
		<description>[...] ANI based Trojans - Exploit Windows Animated Cursor handling  New trojans have surfaced that exploit a vulnerability in Windows animated cursor handling. This malware uses the ANI extension which has been rarely manipulated by malware in the past.&#160; Corporate admins should add ANI to their email blocking lists.&#160;  Users should be cautious with all HTML based email (use plain text if possible),&#160; They should also be careful to only visit trusted and mainstream websites.&#160; The ANI malware can hide within HTML code. This vulnerability in Windows will lead to a crash of the security system so that other malware will be downloaded and installed on the infected system. Microsoft Security Advisory (935423)Vulnerability in Windows Animated Cursor Handlinghttp://www.microsoft.com/technet/security/advisory/935423.mspx Other Security Advisorieshttp://secunia.com/advisories/24659/http://www.frsirt.com/english/advisories/2007/1151http://www.avertlabs.com/research/blog/?p=230http://www.avertlabs.com/research/blog/?p=233http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/http://research.eeye.com/html/alerts/zeroday/20070328.htmlhttp://www.us-cert.gov/current/current_activity.html#WINANIhttp://www.kb.cert.org/vuls/id/191609 AV Vendorshttp://vil.nai.com/vil/content/v_141860.htmhttp://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FANICMOO%2EAXhttp://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FANICMOO%2EAVhttp://www.sophos.com/sl/va/security/analyses/trojanimoou.htmlhttp://www.f-secure.com/v-descs/exploit_w32_ani_c.shtml   Published Friday, March 30, 2007 8:02 PM by hwaldron [...]</description>
		<content:encoded><![CDATA[<p>[...] ANI based Trojans &#8211; Exploit Windows Animated Cursor handling  New trojans have surfaced that exploit a vulnerability in Windows animated cursor handling. This malware uses the ANI extension which has been rarely manipulated by malware in the past.&nbsp; Corporate admins should add ANI to their email blocking lists.&nbsp;  Users should be cautious with all HTML based email (use plain text if possible),&nbsp; They should also be careful to only visit trusted and mainstream websites.&nbsp; The ANI malware can hide within HTML code. This vulnerability in Windows will lead to a crash of the security system so that other malware will be downloaded and installed on the infected system. Microsoft Security Advisory (935423)Vulnerability in Windows Animated Cursor Handlinghttp://www.microsoft.com/technet/security/advisory/935423.mspx Other Security Advisorieshttp://secunia.com/advisories/24659/http://www.frsirt.com/english/advisories/2007/1151http://www.avertlabs.com/research/blog/?p=230http://www.avertlabs.com/research/blog/?p=233http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/http://research.eeye.com/html/alerts/zeroday/20070328.htmlhttp://www.us-cert.gov/current/current_activity.html#WINANIhttp://www.kb.cert.org/vuls/id/191609 AV Vendorshttp://vil.nai.com/vil/content/v_141860.htmhttp://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FANICMOO%2EAXhttp://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ%5FANICMOO%2EAVhttp://www.sophos.com/sl/va/security/analyses/trojanimoou.htmlhttp://www.f-secure.com/v-descs/exploit_w32_ani_c.shtml   Published Friday, March 30, 2007 8:02 PM by hwaldron [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Internet Security and Programming &#187; Blog Archive &#187; Any ANI File Could Infect You!</title>
		<link>http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/comment-page-1/#comment-10685</link>
		<dc:creator>Internet Security and Programming &#187; Blog Archive &#187; Any ANI File Could Infect You!</dc:creator>
		<pubDate>Fri, 30 Mar 2007 17:29:04 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/#comment-10685</guid>
		<description>[...] category News. You can read any responses through the RSS 2.0 feed. You can give a response, or trackback from your site.    &#171; State Agencies Coordinate Efforts To Combat Cybercrime And EducateStudents, Parents Hello from Black Hat Amsterdam &#187; [...]</description>
		<content:encoded><![CDATA[<p>[...] category News. You can read any responses through the RSS 2.0 feed. You can give a response, or trackback from your site.    &laquo; State Agencies Coordinate Efforts To Combat Cybercrime And EducateStudents, Parents Hello from Black Hat Amsterdam &raquo; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tech Blog &#187; Blog Archive &#187; 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</title>
		<link>http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/comment-page-1/#comment-10646</link>
		<dc:creator>Tech Blog &#187; Blog Archive &#187; 0-day ANI vulnerability in Microsoft Windows (CVE-2007-0038)</dc:creator>
		<pubDate>Fri, 30 Mar 2007 15:10:57 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/#comment-10646</guid>
		<description>[...] It seems like the vulnerability is already exploited in the wild: http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/ [...]</description>
		<content:encoded><![CDATA[<p>[...] It seems like the vulnerability is already exploited in the wild: <a href="http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/" rel="nofollow">http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert Scroggins</title>
		<link>http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/comment-page-1/#comment-10629</link>
		<dc:creator>Robert Scroggins</dc:creator>
		<pubDate>Fri, 30 Mar 2007 13:24:01 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/#comment-10629</guid>
		<description>Eeye has a temporary patch at http://research.eeye.com/html/alerts/zeroday/20070328.html.  They say you should remove it when Microsoft comes out with theirs.

Regards,</description>
		<content:encoded><![CDATA[<p>Eeye has a temporary patch at <a href="http://research.eeye.com/html/alerts/zeroday/20070328.html" rel="nofollow">http://research.eeye.com/html/alerts/zeroday/20070328.html</a>.  They say you should remove it when Microsoft comes out with theirs.</p>
<p>Regards,</p>
]]></content:encoded>
	</item>
</channel>
</rss>
