<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;CkIEQn0yeSp7ImA9WhFSFUs.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657</id><updated>2013-06-18T06:01:43.391-07:00</updated><category term="mobile" /><category term="MS06-014" /><category term="OllyDbg" /><category term="obfuscation" /><category term="javascript" /><category term="blackhole" /><category term="incognito" /><category term="malvertising" /><category term="malcious JavaScript" /><category term="malware" /><category term="Malzilla" /><category term="predictions" /><category term="reverse engineering" /><category term="skype" /><category term="privacy" /><category term="social" /><category term="SWF" /><category term="patches" /><category term="OS X" /><category term="malicious JavaScript" /><category term="Base64 encode/decode" /><category term="Whitepaper" /><category term="encryption" /><category term="SaaS" /><category term="Trends" /><category term="heuristics" /><category term="CWE" /><category term="hacktivism" /><category term="ActiveX" /><category term="IFRAME" /><category term="analysis" /><category term="Fake AV" /><category term="infected" /><category term="spam" /><category term="sports" /><category term="Style tag" /><category term="malcious JavaScrip" /><category term="exploit kits" /><category term="Rogue software" /><category term="wikileaks" /><category term="facebook" /><category term="Malicious Code" /><category term="botnets" /><category term="Olympics" /><category term="decoding" /><category term="SDLC" /><category term="p2p" /><category term="tool" /><category term="internet explorer" /><category term="storm worm" /><category term="Compromised" /><category term="0-day" /><category term="abuse" /><category term="fake flash" /><category term="zulu" /><category term="legal" /><category term="Adobe vulnerabilties" /><category term="cloud" /><category term="Java" /><category term="Fake codec" /><category term="APT" /><category term="phishing" /><category term="captcha" /><category term="antivirus" /><category term="SEO" /><category term="affiliates" /><category term="pharm" /><category term="twitter" /><category term="Flash vulnerabilities" /><category term="ssl" /><category term="worm" /><category term="Trojan" /><category term="PDF exploits" /><category term="diassembly" /><category term="scam" /><category term="plugins" /><category term="exploit" /><category term="CVE" /><category term="google" /><title>Zscaler Research</title><subtitle type="html">The Zscaler Research Team is focused on bleeding edge web security research in the cloud computing era. This blog provides an opportunity for us to share our thoughts and ideas and interact with the community at-large. We welcome your feedback and encourage you to join the dialogue.</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://research.zscaler.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://research.zscaler.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default?start-index=21&amp;max-results=20&amp;redirect=false&amp;v=2" /><author><name>Michael Sutton</name><uri>http://www.blogger.com/profile/12614648693197428321</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>466</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>20</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/zscaler/research" /><feedburner:info uri="zscaler/research" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;D0MGRHo6eCp7ImA9WhFTE0U.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657.post-8428442569893081821</id><published>2013-06-04T15:37:00.000-07:00</published><updated>2013-06-04T15:37:05.410-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-06-04T15:37:05.410-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="phishing" /><title>Phishers target Yahoo users</title><summary type="html">
Yahoo Mail introduced two-factor authentication in December 2011. Two-factor authentication can be used to prevent suspicious access to an account (login from a different country, numerous failed login attempts, etc.) and can be used to verify a user's identity when asking for a password reset.

Two-factor authentication has been in the news a fair bit lately as LinkedIn and Twitter have &lt;img src="http://feeds.feedburner.com/~r/zscaler/research/~4/2LMbN1XBzHs" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://research.zscaler.com/feeds/8428442569893081821/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5262423634906095657&amp;postID=8428442569893081821" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/8428442569893081821?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/8428442569893081821?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/zscaler/research/~3/2LMbN1XBzHs/phishers-target-yahoo-users.html" title="Phishers target Yahoo users" /><author><name>Julien Sobrier</name><uri>http://www.blogger.com/profile/06741851635998994926</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://research.zscaler.com/2013/06/phishers-target-yahoo-users.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkcMQ3gzeCp7ImA9WhFTEk4.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657.post-8983187278732085519</id><published>2013-06-01T10:15:00.000-07:00</published><updated>2013-06-02T20:28:02.680-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-06-02T20:28:02.680-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Java" /><category scheme="http://www.blogger.com/atom/ns#" term="exploit kits" /><category scheme="http://www.blogger.com/atom/ns#" term="infected" /><title>Rise in Red Kit Exploit Kit Activity</title><summary type="html">
This week, a malicious pattern of activity was observed in websites being compromised, which in turn redirected to a Red Kit exploit kit (EK) landing page. Some infected websites that were seen:

neptunebenson[dot]com
route66marathon[dot]com
whitesteeple[dot]com 

(Warning! these sites may still be infected). 

Two different mechanisms were used to infect the websites. The first one being a &lt;img src="http://feeds.feedburner.com/~r/zscaler/research/~4/1nI5FzW3oz0" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://research.zscaler.com/feeds/8983187278732085519/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5262423634906095657&amp;postID=8983187278732085519" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/8983187278732085519?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/8983187278732085519?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/zscaler/research/~3/1nI5FzW3oz0/red-kit-exploit-used-to-carry-out.html" title="Rise in Red Kit Exploit Kit Activity" /><author><name>Krishnan Subramanian</name><uri>http://www.blogger.com/profile/08505781875508446131</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-DGkwrti8x58/UakimYm3xcI/AAAAAAAAAUU/U6Q4iXWHiWo/s72-c/r1.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://research.zscaler.com/2013/06/red-kit-exploit-used-to-carry-out.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkQCRns7fip7ImA9WhBaEUg.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657.post-9004214832485150184</id><published>2013-05-21T07:57:00.000-07:00</published><updated>2013-05-21T10:46:07.506-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-05-21T10:46:07.506-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="malicious JavaScript" /><category scheme="http://www.blogger.com/atom/ns#" term="blackhole" /><category scheme="http://www.blogger.com/atom/ns#" term="Compromised" /><title>Darkleech attack continues to grow</title><summary type="html">
The Apache Darkleech attack has been in the news for quite some time now. The first compromise that we identified in our transactions dates back to mid-March. This Darkleech exploit (aka Linux.Cdorked)  injects malicious redirections into a website that leads to a Blackhole exploit kit (BEK) landing page. Sucuri published up a great write up about the Darkleech infection mechanism on the server &lt;img src="http://feeds.feedburner.com/~r/zscaler/research/~4/MzsH-ROdISM" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://research.zscaler.com/feeds/9004214832485150184/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5262423634906095657&amp;postID=9004214832485150184" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/9004214832485150184?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/9004214832485150184?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/zscaler/research/~3/MzsH-ROdISM/darkleech-attack-continues-to-grow.html" title="Darkleech attack continues to grow" /><author><name>Krishnan Subramanian</name><uri>http://www.blogger.com/profile/08505781875508446131</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-b-2xej8gvN4/UZqfhXp5jfI/AAAAAAAAASE/SGjmxm8yZu4/s72-c/d2.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://research.zscaler.com/2013/05/darkleech-attack-continues-to-grow.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0cGSXgzcSp7ImA9WhBbF04.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657.post-7778216741645880726</id><published>2013-05-16T13:10:00.000-07:00</published><updated>2013-05-16T13:10:28.689-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-05-16T13:10:28.689-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="plugins" /><category scheme="http://www.blogger.com/atom/ns#" term="google" /><title>Fake YouTube page targets Chrome users</title><summary type="html">
Fake YouTube pages are one of the favored ways attackers leverage to get users to click on malicious content. These fake pages often look the same, but the source code can reveal a new twist. This time, a recently encountered fake YouTube page host at http://facebook-java.com targets Google Chrome users only.



Fake YouTube page


We have found a many malicious sites that specifically target &lt;img src="http://feeds.feedburner.com/~r/zscaler/research/~4/RQLgm27gkjg" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://research.zscaler.com/feeds/7778216741645880726/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5262423634906095657&amp;postID=7778216741645880726" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/7778216741645880726?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/7778216741645880726?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/zscaler/research/~3/RQLgm27gkjg/fake-youtube-page-targets-chrome-users.html" title="Fake YouTube page targets Chrome users" /><author><name>Julien Sobrier</name><uri>http://www.blogger.com/profile/06741851635998994926</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://research.zscaler.com/2013/05/fake-youtube-page-targets-chrome-users.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUAFRXk9eyp7ImA9WhBbEEk.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657.post-9049226997094892996</id><published>2013-05-07T15:49:00.000-07:00</published><updated>2013-05-08T13:08:34.763-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-05-08T13:08:34.763-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="phishing" /><category scheme="http://www.blogger.com/atom/ns#" term="scam" /><category scheme="http://www.blogger.com/atom/ns#" term="facebook" /><category scheme="http://www.blogger.com/atom/ns#" term="privacy" /><title>Facebook Scam for Stalkers</title><summary type="html">If you are like me, you might feel bad about leaving your dog home alone all day while you are at work.  So to alleviate his boredom, I've let him sign up for his own Facebook.  Being new to the social media scene has already resulted in one tragedy. Well, my dog has done it again.  This time he was paranoid over whether his girlfriend from across the street was cheating on him.  So of course &lt;img src="http://feeds.feedburner.com/~r/zscaler/research/~4/rvDNcp_2VXE" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://research.zscaler.com/feeds/9049226997094892996/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5262423634906095657&amp;postID=9049226997094892996" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/9049226997094892996?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/9049226997094892996?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/zscaler/research/~3/rvDNcp_2VXE/facebook-scam-for-stalkers.html" title="Facebook Scam for Stalkers" /><author><name>Chris Mannon</name><uri>http://www.blogger.com/profile/14013814933540483983</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-xTI14LOwMEY/UYl_ICvLq8I/AAAAAAAAAFM/zSqOc2XQv9I/s72-c/fbstalkers.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://research.zscaler.com/2013/05/facebook-scam-for-stalkers.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A08NRXk4cSp7ImA9WhBbEUw.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657.post-5636730502743851258</id><published>2013-05-06T14:42:00.000-07:00</published><updated>2013-05-09T10:18:14.739-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-05-09T10:18:14.739-07:00</app:edited><title>Popular Media Sites Involved in Mass Compromise</title><summary type="html">
Update (May 9): OSIRT had the opportunity to review the infected web app code for one of the compromised sites and has a great write-up to explain what was happening from a server-side vantage point.

Today, Zscaler identified yet another mass website compromise, this one impacting a number of popular media sites, including two radio stations in Washington, DC - Federal News Radio and WTOP. It's&lt;img src="http://feeds.feedburner.com/~r/zscaler/research/~4/qS5VgkphhG8" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://research.zscaler.com/feeds/5636730502743851258/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5262423634906095657&amp;postID=5636730502743851258" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/5636730502743851258?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/5636730502743851258?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/zscaler/research/~3/qS5VgkphhG8/popular-media-sites-involved-in-mass.html" title="Popular Media Sites Involved in Mass Compromise" /><author><name>Chris Mannon</name><uri>http://www.blogger.com/profile/14013814933540483983</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-9Z-CeKxFzWU/UYgcBtD5ObI/AAAAAAAABx0/EfXL5SzsbkQ/s72-c/wtop.png" height="72" width="72" /><thr:total>3</thr:total><feedburner:origLink>http://research.zscaler.com/2013/05/popular-media-sites-involved-in-mass.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEYMRH04cCp7ImA9WhBUFkw.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657.post-2345382085657104875</id><published>2013-05-03T14:23:00.000-07:00</published><updated>2013-05-03T14:23:05.338-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-05-03T14:23:05.338-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="malware" /><category scheme="http://www.blogger.com/atom/ns#" term="fake flash" /><title>Fake Flash player on DropBox</title><summary type="html">
Fake Flash updates are leveraged as a very popular trick amongst attackers to fool users into downloading and installing malware. This week we found a three websites distributing Win32.Sanity.N malware disguised as Flash updates:


hxxp://kivancoldu.com/, redirects to hxxp://click-videox.com/




http://kivancoldu.com on 05/02/2013


hxxp://fastcekim.com/, redirects to hxxp://click-videox.com/
&lt;img src="http://feeds.feedburner.com/~r/zscaler/research/~4/jTQLNawjZaY" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://research.zscaler.com/feeds/2345382085657104875/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5262423634906095657&amp;postID=2345382085657104875" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/2345382085657104875?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/2345382085657104875?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/zscaler/research/~3/jTQLNawjZaY/fake-flash-player-on-dropbox.html" title="Fake Flash player on DropBox" /><author><name>Julien Sobrier</name><uri>http://www.blogger.com/profile/06741851635998994926</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://research.zscaler.com/2013/05/fake-flash-player-on-dropbox.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0AARH8yfCp7ImA9WhBaEEQ.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657.post-1681194310008230405</id><published>2013-04-30T13:38:00.006-07:00</published><updated>2013-05-20T16:15:45.194-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-05-20T16:15:45.194-07:00</app:edited><title>More Fake SourceForge Websites Show Up</title><summary type="html">
Two weeks ago we reported on a fake SourceForge website, sourceforgechile.net, which was used to distribute malware. We have since seen more of these fake sites this past week:

sourceforgebulgaria.net, registered on 05/06/2013
sourceforgesweden.net, registered on 05/06/2013
sourceforgecyprus.net, registered on 05/02/2013
sourceforgeniger.net, registered on 05/01/2013
sourceforgeestonia.net, &lt;img src="http://feeds.feedburner.com/~r/zscaler/research/~4/AFx0AUNSxZU" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://research.zscaler.com/feeds/1681194310008230405/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5262423634906095657&amp;postID=1681194310008230405" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/1681194310008230405?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/1681194310008230405?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/zscaler/research/~3/AFx0AUNSxZU/more-fake-sourceforge-websites-show-up.html" title="More Fake SourceForge Websites Show Up" /><author><name>Julien Sobrier</name><uri>http://www.blogger.com/profile/06741851635998994926</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://research.zscaler.com/2013/04/more-fake-sourceforge-websites-show-up.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0AMRH46eip7ImA9WhBUEEw.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657.post-3824221790376220097</id><published>2013-04-26T15:34:00.000-07:00</published><updated>2013-04-26T15:36:25.012-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-26T15:36:25.012-07:00</app:edited><title>scanning binaries for PE format anomalies</title><summary type="html">
After processing tons of malicous binaries, I would like to share my findings about anomalies found in PE binaries. These anomaly information will be helpful for security researchers on suspicious sample validation and sample clustering.


1. Binary strings nearby EP

Of course, EP binary is very popular for AV companies to work out malware signatures. So I put it at first. &lt;img src="http://feeds.feedburner.com/~r/zscaler/research/~4/aQH8qUSReSU" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://research.zscaler.com/feeds/3824221790376220097/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5262423634906095657&amp;postID=3824221790376220097" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/3824221790376220097?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/3824221790376220097?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/zscaler/research/~3/aQH8qUSReSU/scanning-binaries-for-pe-format.html" title="scanning binaries for PE format anomalies" /><author><name>Wei Yan</name><uri>http://www.blogger.com/profile/18362406644974511901</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://research.zscaler.com/2013/04/scanning-binaries-for-pe-format.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D08NSXg9cCp7ImA9WhBUEE0.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657.post-8623522727404767441</id><published>2013-04-26T12:51:00.001-07:00</published><updated>2013-04-26T12:51:38.668-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-26T12:51:38.668-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Compromised" /><title>Bitcoin: Regulations and Security</title><summary type="html">


You have probably heard about Bitcoin, a relatively new virtual currency. It made headlines recently because it is starting to present a real alternative for traditional online payments, and has recently experienced wild swings in value.

One of the advantages of Bitcoin is the lack of regulation, which means it is largely free from the rules and regulations that govern banks and payment &lt;img src="http://feeds.feedburner.com/~r/zscaler/research/~4/7As3ngnzDFg" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://research.zscaler.com/feeds/8623522727404767441/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5262423634906095657&amp;postID=8623522727404767441" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/8623522727404767441?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/8623522727404767441?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/zscaler/research/~3/7As3ngnzDFg/bitcoin-regulations-and-security.html" title="Bitcoin: Regulations and Security" /><author><name>Julien Sobrier</name><uri>http://www.blogger.com/profile/06741851635998994926</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>2</thr:total><feedburner:origLink>http://research.zscaler.com/2013/04/bitcoin-regulations-and-security.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkANSXw_eCp7ImA9WhBVEk4.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657.post-457228297362032456</id><published>2013-04-17T15:46:00.002-07:00</published><updated>2013-04-17T15:46:38.240-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-17T15:46:38.240-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="analysis" /><category scheme="http://www.blogger.com/atom/ns#" term="antivirus" /><title>Fake SourceForge site distributes malware</title><summary type="html">
We spotted malware hosted on hxxp://sourceforgechile.net/ a couple of days ago. The website is not currently responding, but appears to been set up as a fake and malicious version of the popular open-source hosting site SourceForge.

sourceforgechile.net was registered on 04/05/213 in the US and is hosted in the Ukraine.

One of the malicious files downloaded was hxxp://sourceforgechile.net/&lt;img src="http://feeds.feedburner.com/~r/zscaler/research/~4/sUBO-IvYHhA" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://research.zscaler.com/feeds/457228297362032456/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5262423634906095657&amp;postID=457228297362032456" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/457228297362032456?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/457228297362032456?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/zscaler/research/~3/sUBO-IvYHhA/fake-sourceforge-site-distributes.html" title="Fake SourceForge site distributes malware" /><author><name>Julien Sobrier</name><uri>http://www.blogger.com/profile/06741851635998994926</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://research.zscaler.com/2013/04/fake-sourceforge-site-distributes.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Dk8BQHc6fCp7ImA9WhBWFUk.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657.post-1561097659249864902</id><published>2013-04-09T15:00:00.000-07:00</published><updated>2013-04-09T15:00:51.914-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-09T15:00:51.914-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="phishing" /><title>Pinhout: Pinterest clone or phishing site?</title><summary type="html">Recently I stumbled upon pinhout.com. Look familiar?


Pinhout.com looks awfully familiar to...

It looks like a Turkish copy of Pinterest, a growing social network to share web content.


.. Pinterest (home page).


Official site?
I was wondering if this site is a Phishing site, a clone, or an official site from Pinterest. Whois records show that the domain has been registered by a Turkish &lt;img src="http://feeds.feedburner.com/~r/zscaler/research/~4/JMZUMsvYPrI" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://research.zscaler.com/feeds/1561097659249864902/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5262423634906095657&amp;postID=1561097659249864902" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/1561097659249864902?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/1561097659249864902?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/zscaler/research/~3/JMZUMsvYPrI/pinhout-pinterest-clone-or-phishing-site.html" title="Pinhout: Pinterest clone or phishing site?" /><author><name>Julien Sobrier</name><uri>http://www.blogger.com/profile/06741851635998994926</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://research.zscaler.com/2013/04/pinhout-pinterest-clone-or-phishing-site.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEYFR3k7cSp7ImA9WhBWEUQ.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657.post-3681563107738916234</id><published>2013-03-29T16:16:00.000-07:00</published><updated>2013-04-05T14:08:36.709-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-05T14:08:36.709-07:00</app:edited><title>Gone Phishin' on the Facebook</title><summary type="html">Social Media sites are rife for exploitation and malicious intent.  They have become a staple of connectivity between colleagues, family, and friends to the point that they are in many cases the focal point of communication.  Chief among these social media sites, is Facebook.  Not quite professional a network as Linkedin, not quite as informal as Twitter. Facebook is a perfect storm of chat, &lt;img src="http://feeds.feedburner.com/~r/zscaler/research/~4/iYh_uojo-VI" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://research.zscaler.com/feeds/3681563107738916234/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5262423634906095657&amp;postID=3681563107738916234" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/3681563107738916234?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/3681563107738916234?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/zscaler/research/~3/iYh_uojo-VI/gone-phishin-on-facebook.html" title="Gone Phishin' on the Facebook" /><author><name>Chris Mannon</name><uri>http://www.blogger.com/profile/14013814933540483983</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-5uZ8w9pNMa8/UVYK7PaQRLI/AAAAAAAAAEE/E61J8l6YHaE/s72-c/Scam.png" height="72" width="72" /><thr:total>3</thr:total><feedburner:origLink>http://research.zscaler.com/2013/03/gone-phishin-on-facebook.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUMBQ34yfip7ImA9WhBQGE0.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657.post-9055028564638545069</id><published>2013-03-15T14:53:00.000-07:00</published><updated>2013-03-20T11:17:32.096-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-20T11:17:32.096-07:00</app:edited><title>Guess who am I? PE or APK</title><summary type="html">


 



Update: I happened to find this sample. However, it was corrupted.  So I made a demo 
file by myself. Notepad.exe was used as PE stub, and I embedded a 
MALICIOUS APK sample into it. So the magic number was also MZ. It ran 
better than the previous sample since it bypassed zipfile.py and you can
 see its internal apk information. 

If you need this sample, leave your email or drop me a &lt;img src="http://feeds.feedburner.com/~r/zscaler/research/~4/PXC2A13_TAM" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://research.zscaler.com/feeds/9055028564638545069/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5262423634906095657&amp;postID=9055028564638545069" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/9055028564638545069?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/9055028564638545069?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/zscaler/research/~3/PXC2A13_TAM/guess-who-am-i-pe-or-apk.html" title="Guess who am I? PE or APK" /><author><name>Wei Yan</name><uri>http://www.blogger.com/profile/18362406644974511901</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://research.zscaler.com/2013/03/guess-who-am-i-pe-or-apk.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Dk8BQH0_fSp7ImA9WhBQEkU.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657.post-3066109820975633927</id><published>2013-03-13T11:40:00.001-07:00</published><updated>2013-03-14T11:14:11.345-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-14T11:14:11.345-07:00</app:edited><title>Hey AndroGuard, I will crash you or your Python buddy!</title><summary type="html">AndroGuard is a popular tool to be used to analyze android APK files by security professionals.
Quite a few APK analysis tools have been built based on it. They usually call Python library to unzip APK files before reverse-engineering. No wonder some android malware were trying to applied some anti-debugging tricks to crash AndroGuard or Python, just like what PC malware had done on Ollydbg and &lt;img src="http://feeds.feedburner.com/~r/zscaler/research/~4/tFNbdp5PBmk" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://research.zscaler.com/feeds/3066109820975633927/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5262423634906095657&amp;postID=3066109820975633927" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/3066109820975633927?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/3066109820975633927?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/zscaler/research/~3/tFNbdp5PBmk/hey-androguard-i-will-crash-you.html" title="Hey AndroGuard, I will crash you or your Python buddy!" /><author><name>Wei Yan</name><uri>http://www.blogger.com/profile/18362406644974511901</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>3</thr:total><feedburner:origLink>http://research.zscaler.com/2013/03/hey-androguard-i-will-crash-you.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEMGRXw7fip7ImA9WhBWEUQ.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657.post-5186715122546056503</id><published>2013-03-08T19:03:00.000-08:00</published><updated>2013-04-05T14:13:44.206-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-05T14:13:44.206-07:00</app:edited><title>Door-to-Door Worm Cleaner</title><summary type="html">Stop me if you’ve heard this one before.  I’m telling a new acquaintance that I work in IT, particularly the security sector.  “Neat…so my computer has been running slow recently…”  I want to make a good impression so I schedule some time and roll up my sleeves for however long it may take.  Given that this is someone else’s PC, I’m not going to risk plugging in any of my personal equipment to &lt;img src="http://feeds.feedburner.com/~r/zscaler/research/~4/WCuZu3Jval8" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://research.zscaler.com/feeds/5186715122546056503/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5262423634906095657&amp;postID=5186715122546056503" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/5186715122546056503?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/5186715122546056503?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/zscaler/research/~3/WCuZu3Jval8/door-to-door-worm-cleaner.html" title="Door-to-Door Worm Cleaner" /><author><name>Chris Mannon</name><uri>http://www.blogger.com/profile/14013814933540483983</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-KFw1ORLeoQ4/UTpzZXrDs7I/AAAAAAAAADk/X_BpefRvtlE/s72-c/keylog.png" height="72" width="72" /><thr:total>3</thr:total><feedburner:origLink>http://research.zscaler.com/2013/03/door-to-door-worm-cleaner.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEMAQXw8eyp7ImA9WhBRFkU.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657.post-6196772355219177742</id><published>2013-03-07T10:53:00.002-08:00</published><updated>2013-03-07T12:00:40.273-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-07T12:00:40.273-08:00</app:edited><title>Android application obfuscation</title><summary type="html">I had the opportunity to attend 2013 RSA last week. Compared with less than five vendors last year, there were more than 20 vendors focusing on mobile security. I found something interesting on android application obfuscation. Arxan was one of them. This company showcased its Mobile Application Protection Suite to protect code integrity and intellectual property from reversing engineering mobile &lt;img src="http://feeds.feedburner.com/~r/zscaler/research/~4/f9fSjmGj5dc" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://research.zscaler.com/feeds/6196772355219177742/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5262423634906095657&amp;postID=6196772355219177742" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/6196772355219177742?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/6196772355219177742?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/zscaler/research/~3/f9fSjmGj5dc/android-application-obfuscation.html" title="Android application obfuscation" /><author><name>Wei Yan</name><uri>http://www.blogger.com/profile/18362406644974511901</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-XRxWqX4I-Vs/UTU56VIjvcI/AAAAAAAAAAU/FoXTghqsSng/s72-c/1.bmp" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://research.zscaler.com/2013/03/android-application-obfuscation.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEEAQHw-eyp7ImA9WhBSFUs.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657.post-1836377738115461030</id><published>2013-02-22T12:57:00.000-08:00</published><updated>2013-02-22T12:57:21.253-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-02-22T12:57:21.253-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="plugins" /><category scheme="http://www.blogger.com/atom/ns#" term="internet explorer" /><title>The move to plugin-free browsers</title><summary type="html">
Apple was the first major player to offer a browser with no plugins with Safari for iOS. Even the very popular Flash plugin cannot run in the browser. However, no vendor, including Apple, has had such restrictions on their desktop products.

Microsoft has now also gone plugin-free with Internet Explorer 10 Metro. This version of Internet Explorer does not support plugins (except for the embedded&lt;img src="http://feeds.feedburner.com/~r/zscaler/research/~4/xIBPf5mDbLo" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://research.zscaler.com/feeds/1836377738115461030/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5262423634906095657&amp;postID=1836377738115461030" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/1836377738115461030?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/1836377738115461030?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/zscaler/research/~3/xIBPf5mDbLo/the-move-to-plugin-free-browsers.html" title="The move to plugin-free browsers" /><author><name>Julien Sobrier</name><uri>http://www.blogger.com/profile/06741851635998994926</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://research.zscaler.com/2013/02/the-move-to-plugin-free-browsers.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CU4FRns9eCp7ImA9WhBTE0o.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657.post-4793541225284053802</id><published>2013-02-08T17:37:00.000-08:00</published><updated>2013-02-08T17:38:37.560-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-02-08T17:38:37.560-08:00</app:edited><title>“Say cheese!” Let’s take a picture for you guys, packer families.</title><summary type="html">&amp;lt;!--[if gte mso 9]&amp;gt;
 
  Normal
  0
  
  
  
  
  false
  false
  false
  
  EN-US
  ZH-CN
  X-NONE
  
   
   
   
   
   
   
   
   
   
   
   
   
  
  MicrosoftInternetExplorer4
  
   
   
   
   
   
   
   
   
   
   
   
  
&amp;lt;![endif]--&amp;gt;
&amp;lt;!--[if gte mso 9]&amp;gt;
 
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
  
&lt;img src="http://feeds.feedburner.com/~r/zscaler/research/~4/mQkLuZOHVKM" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://research.zscaler.com/feeds/4793541225284053802/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5262423634906095657&amp;postID=4793541225284053802" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/4793541225284053802?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/4793541225284053802?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/zscaler/research/~3/mQkLuZOHVKM/say-cheese-lets-take-picture-for-you.html" title="“Say cheese!” Let’s take a picture for you guys, packer families." /><author><name>Wei Yan</name><uri>http://www.blogger.com/profile/18362406644974511901</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://research.zscaler.com/2013/02/say-cheese-lets-take-picture-for-you.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DU4GRHsyfip7ImA9WhBTE0g.&quot;"><id>tag:blogger.com,1999:blog-5262423634906095657.post-5055701873327185174</id><published>2013-02-08T13:12:00.000-08:00</published><updated>2013-02-08T13:12:05.596-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-02-08T13:12:05.596-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="plugins" /><category scheme="http://www.blogger.com/atom/ns#" term="internet explorer" /><title>HTTPS Everywhere for IE: faster, auto-update enabled</title><summary type="html">
I've released HTTPS Everywhere for Internet Explorer v0.0.0.3. Additional details about the update can be found in the version history of the PDF documentation.

Changes in 0.0.0.3

Faster start up
The start up time is now much faster. You should no longer receive a popup from Internet Explorer asking you to disable certain add-ons. I also switched to a different XML parser to load the HTTPS &lt;img src="http://feeds.feedburner.com/~r/zscaler/research/~4/L4PK14GSYWM" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://research.zscaler.com/feeds/5055701873327185174/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=5262423634906095657&amp;postID=5055701873327185174" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/5055701873327185174?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/5262423634906095657/posts/default/5055701873327185174?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/zscaler/research/~3/L4PK14GSYWM/https-everywhere-for-ie-faster-auto.html" title="HTTPS Everywhere for IE: faster, auto-update enabled" /><author><name>Julien Sobrier</name><uri>http://www.blogger.com/profile/06741851635998994926</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://research.zscaler.com/2013/02/https-everywhere-for-ie-faster-auto.html</feedburner:origLink></entry></feed>
