<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Torrentreactor breach serves potent exploit in Security</title>
<link>http://www.dslreports.com/forum/r22639664</link>
<description></description>
<language>en</language>
<pubDate>Fri, 04 Dec 2009 11:51:54 EDT</pubDate>
<lastBuildDate>Fri, 04 Dec 2009 11:51:54 EDT</lastBuildDate>

<item>
<title>Re: Torrentreactor breach serves potent exploit</title>
<link>http://www.dslreports.com/forum/remark,22649209</link>
<description><![CDATA[<A HREF="/useremail/u/703015"><b>siljaline</b></A> : <b>TorrentReactor Users Suffer Rootkit Attack</b><br>&raquo;<A HREF="http://torrentfreak.com/torrentreactor-users-suffer-rootkit-attack-090702/" >torrentfreak.com/torrentreactor-&middot;&middot;&middot;-090702/</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22649209</guid>
<pubDate>Fri, 03 Jul 2009 11:12:15 EDT</pubDate>
</item>

<item>
<title>Re: Torrentreactor breach serves potent exploit</title>
<link>http://www.dslreports.com/forum/remark,22641849</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : Well there goes another of my bookmarked torrent sites. I haven't visited them in more than a year because I thought the new site style was pretty crappy, and seemed to allow a lot of junk (which likely included fakes) in the categories.<br><br>But I suppose like other iframe injections, if you're using Firefox and NoScript, nothing is going to happen anyway unless you do something dangerous like allow all scripts.<br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22641849</guid>
<pubDate>Wed, 01 Jul 2009 20:06:41 EDT</pubDate>
</item>

<item>
<title>Re: Torrentreactor breach serves potent exploit</title>
<link>http://www.dslreports.com/forum/remark,22641784</link>
<description><![CDATA[<A HREF="/useremail/u/703015"><b>siljaline</b></A> : Let's just chalk it up to a Canada Day, silly moment. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22641784</guid>
<pubDate>Wed, 01 Jul 2009 19:55:41 EDT</pubDate>
</item>

<item>
<title>Re: Torrentreactor breach serves potent exploit</title>
<link>http://www.dslreports.com/forum/remark,22641458</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : Note that this exploit is following the trend of packaging both browser and plugin exploits, hoping to catch something unpatched.<br><br>The browser exploit is for IE6 (MDAC, MS06-014) and Microsoft Office Snapshot Viewer which works on IE6 and I think IE7.<br><br>Both of these have been long since patched.<br><br>The plugin exploits are for Adobe Acrobat Reader and Adobe Shockwave, and of course, will work in any browser.<br><br>These require a vulnerable verision of the application and plugins enabled.<br><br>Pretty typical stuff these days. <br><br>Hopefully everyone is aware of how to protect against this, but I still mention it to people just to be sure.<br><br><br><br>----<br>rich]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22641458</guid>
<pubDate>Wed, 01 Jul 2009 18:45:30 EDT</pubDate>
</item>

<item>
<title>Re: Torrentreactor breach serves potent exploit</title>
<link>http://www.dslreports.com/forum/remark,22640987</link>
<description><![CDATA[<A HREF="/useremail/u/717751"><b>Stem Bolt</b></A> : <div class="bquote"><small>said by  siljaline <A HREF="/useremail/u/703015"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>That is the actually article is more to-the-point in the URL I posted. Sorry if you are/were offended, none intended  ;)<br> </div>I'm not offended. Both articles say the same thing. What did you find "more to the point" in the article you posted? Just curious.<br><small>--<br>Dr. Web 5.0 + ThreatFire + Router/SPI</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22640987</guid>
<pubDate>Wed, 01 Jul 2009 17:18:20 EDT</pubDate>
</item>

<item>
<title>Re: Torrentreactor breach serves potent exploit</title>
<link>http://www.dslreports.com/forum/remark,22640748</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Site seems ok, I cannot see nothing bad there.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22640748</guid>
<pubDate>Wed, 01 Jul 2009 16:54:24 EDT</pubDate>
</item>

<item>
<title>Re: Torrentreactor breach serves potent exploit</title>
<link>http://www.dslreports.com/forum/remark,22640294</link>
<description><![CDATA[<A HREF="/useremail/u/703015"><b>siljaline</b></A> : That is the actually article is more to-the-point in the URL I posted. Sorry if you are/were offended, none intended  ;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22640294</guid>
<pubDate>Wed, 01 Jul 2009 15:04:34 EDT</pubDate>
</item>

<item>
<title>Re: Torrentreactor breach serves potent exploit</title>
<link>http://www.dslreports.com/forum/remark,22640173</link>
<description><![CDATA[<A HREF="/useremail/u/717751"><b>Stem Bolt</b></A> : <div class="bquote"><small>said by  siljaline <A HREF="/useremail/u/703015"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Basically the same here  Stem Bolt <A HREF="/useremail/u/717751"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :)<br>&raquo;<A HREF="http://securitylabs.websense.com/content/Alerts/3430.aspx" >securitylabs.websense.com/conten&middot;&middot;&middot;430.aspx</A><br> </div>Yeah, what's your point? <br><small>--<br>Dr. Web 5.0 + ThreatFire + Router/SPI</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22640173</guid>
<pubDate>Wed, 01 Jul 2009 14:39:32 EDT</pubDate>
</item>

<item>
<title>Re: Torrentreactor breach serves potent exploit</title>
<link>http://www.dslreports.com/forum/remark,22639978</link>
<description><![CDATA[<A HREF="/useremail/u/703015"><b>siljaline</b></A> : Basically the same here  Stem Bolt <A HREF="/useremail/u/717751"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :)<br>&raquo;<A HREF="http://securitylabs.websense.com/content/Alerts/3430.aspx" >securitylabs.websense.com/conten&middot;&middot;&middot;430.aspx</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22639978</guid>
<pubDate>Wed, 01 Jul 2009 14:04:16 EDT</pubDate>
</item>

<item>
<title>Torrentreactor breach serves potent exploit</title>
<link>http://www.dslreports.com/forum/remark,22639664</link>
<description><![CDATA[<A HREF="/useremail/u/717751"><b>Stem Bolt</b></A> : &raquo;<A HREF="http://www.theregister.co.uk/2009/07/01/torrentreactor_breach/" >www.theregister.co.uk/2009/07/01&middot;&middot;&middot;_breach/</A><br> <blockquote><small>quote:</small><hr>Torrentreactor has long been regarded as one of the top bit torrent search engines, and with the demise of The Pirate Bay, it's likely bigger than ever. Now, it's been breached and is serving a potent cocktail of exploits to people browsing the site, Websense Security Labs says.<br><br>Attackers have managed to inject an iframe into the site that scours Torrentreactor visitors' computers from a long list of vulnerable applications, including Adobe's Reader and Shockwave programs and Microsoft's Internet Explorer and Office Snapshot Viewer. When it finds one, it downloads and runs a malicious file.<br><br>According to Websense, the malware has an extremely low detection rate, with just two of 32 anti-virus engines identifying the threat. Once executed, it installs a rootkit on victims' machines.<br><br>The malicious file in the latest compromise communicates with a server at 78.109.29.116, an IP address that web searches suggest has ties to the Russian Business Network. We'll be steering clear of this site for the time being.<hr></blockquote><br><small>--<br>Dr. Web 5.0 + ThreatFire + Router/SPI</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,22639664</guid>
<pubDate>Wed, 01 Jul 2009 13:08:42 EDT</pubDate>
</item>

</channel>
</rss>
