<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Puppet Master&#8230; or how to poison Red Pill</title>
	<atom:link href="http://indefinitestudies.org/2009/04/16/puppet-master-or-how-to-poison-red-pill/feed/" rel="self" type="application/rss+xml" />
	<link>http://indefinitestudies.org/2009/04/16/puppet-master-or-how-to-poison-red-pill/</link>
	<description>Academic ramblings about software security.</description>
	<lastBuildDate>Thu, 02 Feb 2012 14:37:29 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: tokki2cut</title>
		<link>http://indefinitestudies.org/2009/04/16/puppet-master-or-how-to-poison-red-pill/#comment-196</link>
		<dc:creator><![CDATA[tokki2cut]]></dc:creator>
		<pubDate>Sun, 20 Sep 2009 17:14:17 +0000</pubDate>
		<guid isPermaLink="false">http://indefinitestudies.org/?p=298#comment-196</guid>
		<description><![CDATA[good job... but... we need puppet master for PIN :)]]></description>
		<content:encoded><![CDATA[<p>good job&#8230; but&#8230; we need puppet master for PIN :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Puppetmaster Strikes Back &#171; Indefinite Studies</title>
		<link>http://indefinitestudies.org/2009/04/16/puppet-master-or-how-to-poison-red-pill/#comment-123</link>
		<dc:creator><![CDATA[Puppetmaster Strikes Back &#171; Indefinite Studies]]></dc:creator>
		<pubDate>Mon, 13 Jul 2009 10:47:05 +0000</pubDate>
		<guid isPermaLink="false">http://indefinitestudies.org/?p=298#comment-123</guid>
		<description><![CDATA[[...]  13 07 2009   Vincent Mussot and I implemented new virtualization counter-countermeasures in puppetmaster. This time we can detect and thwart 6 tests out of 7 in ScoopyNG. In addition to the SIDT test, we [...]]]></description>
		<content:encoded><![CDATA[<p>[...]  13 07 2009   Vincent Mussot and I implemented new virtualization counter-countermeasures in puppetmaster. This time we can detect and thwart 6 tests out of 7 in ScoopyNG. In addition to the SIDT test, we [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Security News &#187; Unpacking samomodyfikujących się aplikacji</title>
		<link>http://indefinitestudies.org/2009/04/16/puppet-master-or-how-to-poison-red-pill/#comment-106</link>
		<dc:creator><![CDATA[Security News &#187; Unpacking samomodyfikujących się aplikacji]]></dc:creator>
		<pubDate>Fri, 19 Jun 2009 13:40:43 +0000</pubDate>
		<guid isPermaLink="false">http://indefinitestudies.org/?p=298#comment-106</guid>
		<description><![CDATA[[...] Piotr Bania opublikował artykuł przedstawiający metodę rozpakowania samomodyfikujących się aplikacji (spakowanych) wykorzystując binarną instrumentację (patrz np. Pin i jego przykładowe wykorzystanie): [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Piotr Bania opublikował artykuł przedstawiający metodę rozpakowania samomodyfikujących się aplikacji (spakowanych) wykorzystując binarną instrumentację (patrz np. Pin i jego przykładowe wykorzystanie): [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff</title>
		<link>http://indefinitestudies.org/2009/04/16/puppet-master-or-how-to-poison-red-pill/#comment-80</link>
		<dc:creator><![CDATA[Jeff]]></dc:creator>
		<pubDate>Fri, 17 Apr 2009 16:15:48 +0000</pubDate>
		<guid isPermaLink="false">http://indefinitestudies.org/?p=298#comment-80</guid>
		<description><![CDATA[&gt;what about Windows systems ?

Use a hypervisor to prevent redpill on windows in kernelmode.]]></description>
		<content:encoded><![CDATA[<p>&gt;what about Windows systems ?</p>
<p>Use a hypervisor to prevent redpill on windows in kernelmode.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dan</title>
		<link>http://indefinitestudies.org/2009/04/16/puppet-master-or-how-to-poison-red-pill/#comment-79</link>
		<dc:creator><![CDATA[dan]]></dc:creator>
		<pubDate>Fri, 17 Apr 2009 08:37:06 +0000</pubDate>
		<guid isPermaLink="false">http://indefinitestudies.org/?p=298#comment-79</guid>
		<description><![CDATA[&gt;Useless when redpill is in kernelland
true

&gt;It’s possible to do the same thing with ptrace
what about Windows systems ?]]></description>
		<content:encoded><![CDATA[<p>&gt;Useless when redpill is in kernelland<br />
true</p>
<p>&gt;It’s possible to do the same thing with ptrace<br />
what about Windows systems ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pouik</title>
		<link>http://indefinitestudies.org/2009/04/16/puppet-master-or-how-to-poison-red-pill/#comment-78</link>
		<dc:creator><![CDATA[Pouik]]></dc:creator>
		<pubDate>Fri, 17 Apr 2009 08:25:59 +0000</pubDate>
		<guid isPermaLink="false">http://indefinitestudies.org/?p=298#comment-78</guid>
		<description><![CDATA[Useless when redpill is in kernelland. It&#039;s possible to do the same thing with ptrace (which is GPL :)).]]></description>
		<content:encoded><![CDATA[<p>Useless when redpill is in kernelland. It&#8217;s possible to do the same thing with ptrace (which is GPL :)).</p>
]]></content:encoded>
	</item>
</channel>
</rss>

