<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Browser Rootkits</title>
	<atom:link href="http://www.gnucitizen.org/blog/browser-rootkits/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/browser-rootkits/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Thu, 11 Mar 2010 22:49:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Detection and Removal of Rootkits!</title>
		<link>http://www.gnucitizen.org/blog/browser-rootkits/comment-page-1/#comment-128175</link>
		<dc:creator>Detection and Removal of Rootkits!</dc:creator>
		<pubDate>Thu, 25 Feb 2010 07:22:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/browser-rootkits#comment-128175</guid>
		<description>[...] Browser Rootkits [...]</description>
		<content:encoded><![CDATA[<p>[...] Browser Rootkits [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Harder, Better, Faster, Stronger - The Malware &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/browser-rootkits/comment-page-1/#comment-124427</link>
		<dc:creator>Harder, Better, Faster, Stronger - The Malware &#124; GNUCITIZEN</dc:creator>
		<pubDate>Sat, 22 Nov 2008 18:49:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/browser-rootkits#comment-124427</guid>
		<description>[...] blogged about these stuff before, but my question still remains. What if the malware does not persist on [...]</description>
		<content:encoded><![CDATA[<p>[...] blogged about these stuff before, but my question still remains. What if the malware does not persist on [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: shabnam</title>
		<link>http://www.gnucitizen.org/blog/browser-rootkits/comment-page-1/#comment-116444</link>
		<dc:creator>shabnam</dc:creator>
		<pubDate>Sat, 15 Mar 2008 19:39:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/browser-rootkits#comment-116444</guid>
		<description>Great! thanks :)</description>
		<content:encoded><![CDATA[<p>Great! thanks :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sicurezza, ICT ed altro &#187; Blog Archive &#187; Browser rootkits</title>
		<link>http://www.gnucitizen.org/blog/browser-rootkits/comment-page-1/#comment-63825</link>
		<dc:creator>Sicurezza, ICT ed altro &#187; Blog Archive &#187; Browser rootkits</dc:creator>
		<pubDate>Thu, 01 Nov 2007 16:16:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/browser-rootkits#comment-63825</guid>
		<description>[...] post ben scritto che mette ancora una volta in evidenza la criticità dei browser, che qui vengono [...]</description>
		<content:encoded><![CDATA[<p>[...] post ben scritto che mette ancora una volta in evidenza la criticità dei browser, che qui vengono [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 艾克索夫實驗室 &#187; RE:RE: Browser Rootkits</title>
		<link>http://www.gnucitizen.org/blog/browser-rootkits/comment-page-1/#comment-62777</link>
		<dc:creator>艾克索夫實驗室 &#187; RE:RE: Browser Rootkits</dc:creator>
		<pubDate>Mon, 29 Oct 2007 16:25:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/browser-rootkits#comment-62777</guid>
		<description>[...] &#8220;Browser Rootkits&#8221; 作為關鍵字, 可以在 Google 裡面找到 一篇 Protect your browser: Browser rootkits, Virtual appliances and Network Admission Control , 裡面提到的幾個觀念, 和我的想法不謀而合. [...]</description>
		<content:encoded><![CDATA[<p>[...] &#8220;Browser Rootkits&#8221; 作為關鍵字, 可以在 Google 裡面找到 一篇 Protect your browser: Browser rootkits, Virtual appliances and Network Admission Control , 裡面提到的幾個觀念, 和我的想法不謀而合. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 艾克索夫實驗室 &#187; RE: Browser Rootkits</title>
		<link>http://www.gnucitizen.org/blog/browser-rootkits/comment-page-1/#comment-61353</link>
		<dc:creator>艾克索夫實驗室 &#187; RE: Browser Rootkits</dc:creator>
		<pubDate>Thu, 25 Oct 2007 06:06:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/browser-rootkits#comment-61353</guid>
		<description>[...] 發了一篇文章介紹了 Browser Rootkits; Joanna 的回應是Thoughts On Browser [...]</description>
		<content:encoded><![CDATA[<p>[...] 發了一篇文章介紹了 Browser Rootkits; Joanna 的回應是Thoughts On Browser [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackathology</title>
		<link>http://www.gnucitizen.org/blog/browser-rootkits/comment-page-1/#comment-59402</link>
		<dc:creator>hackathology</dc:creator>
		<pubDate>Thu, 18 Oct 2007 13:33:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/browser-rootkits#comment-59402</guid>
		<description>Great article pdp</description>
		<content:encoded><![CDATA[<p>Great article pdp</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gustavo Bittencourt</title>
		<link>http://www.gnucitizen.org/blog/browser-rootkits/comment-page-1/#comment-59321</link>
		<dc:creator>Gustavo Bittencourt</dc:creator>
		<pubDate>Thu, 18 Oct 2007 02:35:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/browser-rootkits#comment-59321</guid>
		<description>This article is really interesting. With its inspiration, I wrote an article about Browser Botnets: http://english.gustavobittencourt.com/2007/10/browser-botnets.html

Thank you
Gustavo Bittencourt</description>
		<content:encoded><![CDATA[<p>This article is really interesting. With its inspiration, I wrote an article about Browser Botnets: <a href="http://english.gustavobittencourt.com/2007/10/browser-botnets.html" rel="nofollow">http://english.gustavobittenco.....tnets.html</a></p>
<p>Thank you<br />
Gustavo Bittencourt</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Inseguridad a nivel del navegador &#124; Share the information</title>
		<link>http://www.gnucitizen.org/blog/browser-rootkits/comment-page-1/#comment-59297</link>
		<dc:creator>Inseguridad a nivel del navegador &#124; Share the information</dc:creator>
		<pubDate>Wed, 17 Oct 2007 23:56:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/browser-rootkits#comment-59297</guid>
		<description>[...] a colación este tema gracias a un artículo de dpd colocado el día de ayer en Gnucitizen llamado Browsers Rootkits y quice hablar del tema dado que realmente la seguridad muchas veces no es tan detallista como se [...]</description>
		<content:encoded><![CDATA[<p>[...] a colación este tema gracias a un artículo de dpd colocado el día de ayer en Gnucitizen llamado Browsers Rootkits y quice hablar del tema dado que realmente la seguridad muchas veces no es tan detallista como se [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Liquidmatrix Security Digest &#187; Security Briefing: October 17th</title>
		<link>http://www.gnucitizen.org/blog/browser-rootkits/comment-page-1/#comment-59129</link>
		<dc:creator>Liquidmatrix Security Digest &#187; Security Briefing: October 17th</dc:creator>
		<pubDate>Wed, 17 Oct 2007 10:38:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/browser-rootkits#comment-59129</guid>
		<description>[...] Browser Rootkits [...]</description>
		<content:encoded><![CDATA[<p>[...] Browser Rootkits [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/browser-rootkits/comment-page-1/#comment-58906</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Tue, 16 Oct 2007 22:06:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/browser-rootkits#comment-58906</guid>
		<description>Hugh, unfortunately that cannot be done on our side, but you can easily modify your browser settings to server your needs.</description>
		<content:encoded><![CDATA[<p>Hugh, unfortunately that cannot be done on our side, but you can easily modify your browser settings to server your needs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hugh Mungus</title>
		<link>http://www.gnucitizen.org/blog/browser-rootkits/comment-page-1/#comment-58890</link>
		<dc:creator>Hugh Mungus</dc:creator>
		<pubDate>Tue, 16 Oct 2007 21:33:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/browser-rootkits#comment-58890</guid>
		<description>I wonder if it might be possible to make the text font color a shade darker. That way, it will be impossible to read your blog at all.</description>
		<content:encoded><![CDATA[<p>I wonder if it might be possible to make the text font color a shade darker. That way, it will be impossible to read your blog at all.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://www.gnucitizen.org/blog/browser-rootkits/comment-page-1/#comment-58803</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Tue, 16 Oct 2007 16:11:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/browser-rootkits#comment-58803</guid>
		<description>I look forward to seeing some of this talk put into action.</description>
		<content:encoded><![CDATA[<p>I look forward to seeing some of this talk put into action.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Web Tarayıcıları için Rootkit &#171; eren@home ~ $</title>
		<link>http://www.gnucitizen.org/blog/browser-rootkits/comment-page-1/#comment-58796</link>
		<dc:creator>Web Tarayıcıları için Rootkit &#171; eren@home ~ $</dc:creator>
		<pubDate>Tue, 16 Oct 2007 15:17:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/browser-rootkits#comment-58796</guid>
		<description>[...] Tarayıcıları için&#160;Rootkit  16 10 2007   Petko D. Petkov blogunda yayınladığı yazı insanı bu konuda gerçekten düşündürmeye yöneltiyor. Üzgünüm ki metnin tamamını [...]</description>
		<content:encoded><![CDATA[<p>[...] Tarayıcıları için&nbsp;Rootkit  16 10 2007   Petko D. Petkov blogunda yayınladığı yazı insanı bu konuda gerçekten düşündürmeye yöneltiyor. Üzgünüm ki metnin tamamını [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sp0oKeR</title>
		<link>http://www.gnucitizen.org/blog/browser-rootkits/comment-page-1/#comment-58779</link>
		<dc:creator>Sp0oKeR</dc:creator>
		<pubDate>Tue, 16 Oct 2007 13:49:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/browser-rootkits#comment-58779</guid>
		<description>I think metafisher is kind of that already . It&#039;s for IE and use Hel Objects if I&#039;m not wrong.
  Nice post.

Regards,

Sp0oKeR</description>
		<content:encoded><![CDATA[<p>I think metafisher is kind of that already . It&#8217;s for IE and use Hel Objects if I&#8217;m not wrong.<br />
  Nice post.</p>
<p>Regards,</p>
<p>Sp0oKeR</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/browser-rootkits/comment-page-1/#comment-58773</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Tue, 16 Oct 2007 13:26:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/browser-rootkits#comment-58773</guid>
		<description>can I ping you privately? or you can ping me privately with the information provided on the &lt;a href=&quot;http://www.gnucitizen.org/contact&quot; rel=&quot;nofollow&quot;&gt;contact&lt;/a&gt; page. cheers :)</description>
		<content:encoded><![CDATA[<p>can I ping you privately? or you can ping me privately with the information provided on the <a href="http://www.gnucitizen.org/contact" rel="nofollow">contact</a> page. cheers :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fazed</title>
		<link>http://www.gnucitizen.org/blog/browser-rootkits/comment-page-1/#comment-58771</link>
		<dc:creator>fazed</dc:creator>
		<pubDate>Tue, 16 Oct 2007 13:19:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/browser-rootkits#comment-58771</guid>
		<description>Nice write up, I agree that they will become more common place in the future. You could combine it with a browser exploit for your point of access and drop A exe which overwrites the browser.jar file with your own code. sorry if thats a bit off-topic. would you be interested in giving a talk about it on the upcomming darkstar e-conference?

-fazed</description>
		<content:encoded><![CDATA[<p>Nice write up, I agree that they will become more common place in the future. You could combine it with a browser exploit for your point of access and drop A exe which overwrites the browser.jar file with your own code. sorry if thats a bit off-topic. would you be interested in giving a talk about it on the upcomming darkstar e-conference?</p>
<p>-fazed</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/browser-rootkits/comment-page-1/#comment-58760</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Tue, 16 Oct 2007 12:41:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/browser-rootkits#comment-58760</guid>
		<description>Jipe, you are right... the hidden field only works if you install the extension globally but as you suggested it is trivial to overlay the addons windows and as such remove the presence of the extension from the list.</description>
		<content:encoded><![CDATA[<p>Jipe, you are right&#8230; the hidden field only works if you install the extension globally but as you suggested it is trivial to overlay the addons windows and as such remove the presence of the extension from the list.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jipe</title>
		<link>http://www.gnucitizen.org/blog/browser-rootkits/comment-page-1/#comment-58752</link>
		<dc:creator>Jipe</dc:creator>
		<pubDate>Tue, 16 Oct 2007 12:06:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/browser-rootkits#comment-58752</guid>
		<description>Regarding the hidden capabilities of firefox extensions.

The hidden field of the install manifest only works for extensions installed in a restricted access area (so it does not work for add-ons installed in the profile).

However, as an extension extends the browser it will be trivial to it to remove itself from the extension list (just browse the list and remove the one which match the extension name)...

2c</description>
		<content:encoded><![CDATA[<p>Regarding the hidden capabilities of firefox extensions.</p>
<p>The hidden field of the install manifest only works for extensions installed in a restricted access area (so it does not work for add-ons installed in the profile).</p>
<p>However, as an extension extends the browser it will be trivial to it to remove itself from the extension list (just browse the list and remove the one which match the extension name)&#8230;</p>
<p>2c</p>
]]></content:encoded>
	</item>
</channel>
</rss>
