<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The IPS Guy &#187; Intrusion re</title>
	<atom:link href="http://theipsguy.com/tag/intrusion-re/feed/" rel="self" type="application/rss+xml" />
	<link>http://theipsguy.com</link>
	<description>Intrusion Prevention/Detection technologies.</description>
	<lastBuildDate>Thu, 19 Aug 2010 17:25:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Gumblar is back or never left</title>
		<link>http://theipsguy.com/gumblar-is-back-or-never-left/</link>
		<comments>http://theipsguy.com/gumblar-is-back-or-never-left/#comments</comments>
		<pubDate>Thu, 22 Oct 2009 19:48:10 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>
		<category><![CDATA[Intrusion re]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=90</guid>
		<description><![CDATA[ISS X-Force has raised the AlertCon to 2 because of increased Gumblar activity. Gumblar has updated the exploits it uses to take advantage of recent Adobe and Microsoft vulnerabilities. Unlike the previous version, the new and improved version hosts the exploits on the compromised web server and infects clients as they visit the website. Microsoft [...]]]></description>
			<content:encoded><![CDATA[<p><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<h5>ISS X-Force has raised the AlertCon to 2 because of increased Gumblar activity. Gumblar has updated the exploits it uses to take advantage of recent Adobe and Microsoft vulnerabilities. Unlike the previous version, the new and improved version hosts the exploits on the compromised web server and infects clients as they visit the website.</h5>
<h5>Microsoft October Bulletins</p>
<p>http://bit.ly/jg0jh</h5>
<h5>Adobe Updates</p>
<p>http://bit.ly/49Y6nA</h5>
<h5>IBM/ISS Signatures to detect Gumblar</p>
<p>http://bit.ly/18avBV</h5>
<h5>PDF_JavaScript_Exploit<br />
PDF_Obfuscated_Stream<br />
PDF_Encoded_JavaScript_Tag<br />
PDF_JavaScript_Hex<br />
PDF_JavaScript_Detected<br />
PDF_Shellcode_Detected<br />
Multimedia_File_Overflow<br />
JavaScript_Obfuscation_Rue (PDF obfuscation)<br />
Swf_Suspicious_ActionScript (Flash obfuscation)</h5>
]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/gumblar-is-back-or-never-left/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
