<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-2672754150485551359.post6594185715836831600..comments</id><updated>2009-05-23T06:26:44.047-04:00</updated><title type='text'>Comments on The Security Shoggoth: Detecting Malicious PDFs</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://secshoggoth.blogspot.com/feeds/6594185715836831600/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2672754150485551359/6594185715836831600/comments/default'/><link rel='alternate' type='text/html' href='http://secshoggoth.blogspot.com/2009/05/detecting-malicious-pdfs.html'/><author><name>Security Shoggoth</name><uri>http://www.blogger.com/profile/15411793726236555303</uri><email>securityshoggoth@gmail.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2672754150485551359.post-4924885140087611299</id><published>2009-05-23T06:26:44.047-04:00</published><updated>2009-05-23T06:26:44.047-04:00</updated><title type='text'>I recommend you drop the &lt;&lt; from the scan: /OpenAc...</title><content type='html'>I recommend you drop the &amp;lt;&amp;lt; from the scan: /OpenAction /JS&lt;br /&gt;&amp;lt;&amp;lt; indicates the start of the dictionary, and keys inside the dictionary can appear in random order.&lt;br /&gt;&lt;br /&gt;And to increase the probability the snort rule only triggers for PDF documents, add %%EOF too.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2672754150485551359/6594185715836831600/comments/default/4924885140087611299'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2672754150485551359/6594185715836831600/comments/default/4924885140087611299'/><link rel='alternate' type='text/html' href='http://secshoggoth.blogspot.com/2009/05/detecting-malicious-pdfs.html?showComment=1243074404047#c4924885140087611299' title=''/><author><name>Didier Stevens</name><uri>http://www.blogger.com/profile/17537511475658709281</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://secshoggoth.blogspot.com/2009/05/detecting-malicious-pdfs.html' ref='tag:blogger.com,1999:blog-2672754150485551359.post-6594185715836831600' source='http://www.blogger.com/feeds/2672754150485551359/posts/default/6594185715836831600' type='text/html'/></entry></feed>