<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: This is sorta scary&#8230;</title>
	<atom:link href="http://www.3nailsministries.org/2006/01/09/this-is-sorta-scary/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.3nailsministries.org/2006/01/09/this-is-sorta-scary/</link>
	<description>Walking the walk, sometimes crawling, often falling</description>
	<lastBuildDate>Thu, 10 Sep 2009 22:22:08 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: pilgrim</title>
		<link>http://www.3nailsministries.org/2006/01/09/this-is-sorta-scary/comment-page-1/#comment-25817</link>
		<dc:creator>pilgrim</dc:creator>
		<pubDate>Tue, 10 Jan 2006 12:48:07 +0000</pubDate>
		<guid isPermaLink="false">http://3nailsministries.org/?p=241#comment-25817</guid>
		<description>and since the vulnerability is a design feature of the WMF spec, there&#039;s not much you can do about it.  I believe M$&#039;s patch was pretty well localized to the GDI32.dll and that other one that escapes me at the moment.  If apps, like Outlook, have their own engine for interpreting this format the problem begins to grow.

</description>
		<content:encoded><![CDATA[<p>and since the vulnerability is a design feature of the WMF spec, there&#8217;s not much you can do about it.  I believe M$&#8217;s patch was pretty well localized to the GDI32.dll and that other one that escapes me at the moment.  If apps, like Outlook, have their own engine for interpreting this format the problem begins to grow.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Knox</title>
		<link>http://www.3nailsministries.org/2006/01/09/this-is-sorta-scary/comment-page-1/#comment-25798</link>
		<dc:creator>Knox</dc:creator>
		<pubDate>Tue, 10 Jan 2006 10:32:35 +0000</pubDate>
		<guid isPermaLink="false">http://3nailsministries.org/?p=241#comment-25798</guid>
		<description>It&#039;s frightening to think how much code looks at WMF&#039;s and makes decisions about how to handle embedded software calls.  When I disabled the DLL for the first WMF exploit, Outlook would still show me WMF files, so it was using its engine to do so.  </description>
		<content:encoded><![CDATA[<p>It&#8217;s frightening to think how much code looks at WMF&#8217;s and makes decisions about how to handle embedded software calls.  When I disabled the DLL for the first WMF exploit, Outlook would still show me WMF files, so it was using its engine to do so.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
