<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Angels of security &#187; IE7</title>
	<atom:link href="http://angelsofsecurity.com/blog/tag/ie7/feed/" rel="self" type="application/rss+xml" />
	<link>http://angelsofsecurity.com/blog</link>
	<description>Musings of an infosec renegade</description>
	<lastBuildDate>Tue, 02 Aug 2011 19:01:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>MS09-002 reverse engineered</title>
		<link>http://angelsofsecurity.com/blog/2009/02/17/ms09-002-reverse-engineered/</link>
		<comments>http://angelsofsecurity.com/blog/2009/02/17/ms09-002-reverse-engineered/#comments</comments>
		<pubDate>Tue, 17 Feb 2009 20:42:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[disclosure]]></category>
		<category><![CDATA[IE7]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[patch]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2009/02/17/ms09-002-reverse-engineered/</guid>
		<description><![CDATA[ISC is reporting that they&#8217;re seeing exploits of MS09-002 in the wild. MS09-002 is an exploit which allows for remote code execution on IE7. The vulnerability was first reported to MS in October of 2007 by the Zero Day Initiative. Microsoft issued the patch a week ago. Given this, ISC is also claiming that it [...]]]></description>
			<content:encoded><![CDATA[<p>ISC is <a href="http://isc.sans.org/diary.html?storyid=5884">reporting</a> that they&#8217;re seeing exploits of <a href="http://www.microsoft.com/technet/security/bulletin/MS09-002.mspx">MS09-002</a> in the wild. MS09-002 is an exploit which allows for remote code execution on IE7. The vulnerability was first <a href="http://www.zerodayinitiative.com/advisories/ZDI-09-012/">reported to MS</a> in October of 2007 by the Zero Day Initiative. Microsoft issued the patch a week ago. Given this, ISC is also claiming that it is likely that the patch was reverse engineered to find the vulnerability, and I would have to agree. I&#8217;m sure the anti-disclosure crowd will be using this one as proof positive for their position in the future.</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2009/02/17/ms09-002-reverse-engineered/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

