<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: AVs prove less-effective</title>
	<atom:link href="http://michaeldaw.org/news/news-042407/feed" rel="self" type="application/rss+xml" />
	<link>http://michaeldaw.org/news/news-042407</link>
	<description>Weekly humour</description>
	<lastBuildDate>Thu, 07 May 2009 20:09:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: david.kierznowski</title>
		<link>http://michaeldaw.org/news/news-042407/comment-page-1#comment-26481</link>
		<dc:creator>david.kierznowski</dc:creator>
		<pubDate>Sat, 05 May 2007 14:59:57 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/news/news-042407/#comment-26481</guid>
		<description>Kurt, can you send me the version info and i&#039;ll update the list :)

kk, can&#039;t comment for Julio, don&#039;t really know much about VirusTotal. However, the debate of whether AV engines should detect malicious code is already being done. The debate is more &quot;what&quot; signatures should be added - it seems to be done by risk and personal preference at the moment. This really requires a post on its own.

Thanks for your guys feedback.</description>
		<content:encoded><![CDATA[<p>Kurt, can you send me the version info and i&#8217;ll update the list :)</p>
<p>kk, can&#8217;t comment for Julio, don&#8217;t really know much about VirusTotal. However, the debate of whether AV engines should detect malicious code is already being done. The debate is more &#8220;what&#8221; signatures should be added &#8211; it seems to be done by risk and personal preference at the moment. This really requires a post on its own.</p>
<p>Thanks for your guys feedback.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kurt Grutzmacher</title>
		<link>http://michaeldaw.org/news/news-042407/comment-page-1#comment-25623</link>
		<dc:creator>Kurt Grutzmacher</dc:creator>
		<pubDate>Mon, 30 Apr 2007 17:14:05 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/news/news-042407/#comment-25623</guid>
		<description>Looks like the latest Symantec AV-10 picks up on CFEXEC.CFM now. It can probably be modified to bypass heuristics. :)</description>
		<content:encoded><![CDATA[<p>Looks like the latest Symantec AV-10 picks up on CFEXEC.CFM now. It can probably be modified to bypass heuristics. :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kk</title>
		<link>http://michaeldaw.org/news/news-042407/comment-page-1#comment-25622</link>
		<dc:creator>kk</dc:creator>
		<pubDate>Mon, 30 Apr 2007 17:09:08 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/news/news-042407/#comment-25622</guid>
		<description>Not only are the AV engines in VirusTotal different (perimeter, host, ..) which make &quot;comparing&quot; rather unscientific, but also it&#039;s questionable if these scripts (which anybody can change its contents completely) should be detected by AV signatures or other technologies such as web app IDS/IPS or even web server configuration/filters. This study is not serious, not scientific and, worse of all, not relevant and a waste of time. Spend your time on more useful stuff.</description>
		<content:encoded><![CDATA[<p>Not only are the AV engines in VirusTotal different (perimeter, host, ..) which make &#8220;comparing&#8221; rather unscientific, but also it&#8217;s questionable if these scripts (which anybody can change its contents completely) should be detected by AV signatures or other technologies such as web app IDS/IPS or even web server configuration/filters. This study is not serious, not scientific and, worse of all, not relevant and a waste of time. Spend your time on more useful stuff.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: david.kierznowski</title>
		<link>http://michaeldaw.org/news/news-042407/comment-page-1#comment-25212</link>
		<dc:creator>david.kierznowski</dc:creator>
		<pubDate>Sun, 29 Apr 2007 19:53:37 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/news/news-042407/#comment-25212</guid>
		<description>Julio, don&#039;t really get what your saying?

pp, what is difficult to read, the site in general or a particular post?</description>
		<content:encoded><![CDATA[<p>Julio, don&#8217;t really get what your saying?</p>
<p>pp, what is difficult to read, the site in general or a particular post?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pp</title>
		<link>http://michaeldaw.org/news/news-042407/comment-page-1#comment-22790</link>
		<dc:creator>pp</dc:creator>
		<pubDate>Wed, 25 Apr 2007 07:48:33 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/news/news-042407/#comment-22790</guid>
		<description>White on black is difficult to read. Use black on white.</description>
		<content:encoded><![CDATA[<p>White on black is difficult to read. Use black on white.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Julio Canto</title>
		<link>http://michaeldaw.org/news/news-042407/comment-page-1#comment-22718</link>
		<dc:creator>Julio Canto</dc:creator>
		<pubDate>Wed, 25 Apr 2007 05:35:17 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldaw.org/news/news-042407/#comment-22718</guid>
		<description>Usint VirusTotal for this kind of things is not serious.</description>
		<content:encoded><![CDATA[<p>Usint VirusTotal for this kind of things is not serious.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
