<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: We Love You, Rinbot!</title>
	<atom:link href="http://neosmart.net/blog/2007/we-love-you-rinbot/feed/" rel="self" type="application/rss+xml" />
	<link>http://neosmart.net/blog/2007/we-love-you-rinbot/</link>
	<description>Connecting Ideas</description>
	<pubDate>Tue, 02 Dec 2008 08:18:12 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7-RC1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Artem</title>
		<link>http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-42350</link>
		<dc:creator>Artem</dc:creator>
		<pubDate>Sun, 26 Aug 2007 13:20:47 +0000</pubDate>
		<guid isPermaLink="false">http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-42350</guid>
		<description>NOD 32 is the best anyway...</description>
		<content:encoded><![CDATA[<p>NOD 32 is the best anyway&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Allen</title>
		<link>http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-23134</link>
		<dc:creator>Allen</dc:creator>
		<pubDate>Tue, 19 Jun 2007 02:49:17 +0000</pubDate>
		<guid isPermaLink="false">http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-23134</guid>
		<description>You know, I've been using NOD32 for the past year, and still got infected by no less than 2 trojans, a handful of viruses, and various malware, so my experience has been that "It &lt;em&gt;doesn't&lt;/em&gt; work."&#160; I even identified one of the trojans that went unidentified by sniffing my network traffic, then I put the files on a clean VM with NOD32 installed just to make sure it wasn't a pre-existing condition (unlikely, since I installed NOD32 immediately after installing the OS) and it still didn't detect them.&#160; THEN I sent the samples to NOD32 for analysis, and they basically said "We need your logs."&#160; I'd wiped the logs by then, since I reinstalled the OS entirely, but they were basically devoid of any identified threat, so it was meaningless.

On the other hand, Windows Defender actually identified one trojan that NOD32 didn't, and Windows Live OneCare identified several other trojan installers.&#160; Sophos AV identified even more.&#160; That's not to say there aren't significant issues with those platforms either, but NOD32 didn't serve me well at all.&#160; I've been using Sophos for a week, and though it's a bit too restrictive and processor intensive for my taste, it seems to be very effective, even going so far as to block cracks and windows hacks like the max half-open connection patch, which was somewhat annoying.&#160; It also blocked a program because it was "created with malpacker" or something, although I had little reason to question the program in question (which was indeed a hack).&#160; On the other hand, OneCare was causing bluescreens.&#160; I'd like something with the detection rate of Sophos and the configurability of NOD32.
  

At any rate, where network security is concerned, there's no substitute for routinely monitoring and logging your network traffic.
  &#160;
</description>
		<content:encoded><![CDATA[<p>You know, I&#8217;ve been using NOD32 for the past year, and still got infected by no less than 2 trojans, a handful of viruses, and various malware, so my experience has been that &#8220;It <em>doesn&#8217;t</em> work.&#8221;&nbsp; I even identified one of the trojans that went unidentified by sniffing my network traffic, then I put the files on a clean VM with NOD32 installed just to make sure it wasn&#8217;t a pre-existing condition (unlikely, since I installed NOD32 immediately after installing the OS) and it still didn&#8217;t detect them.&nbsp; THEN I sent the samples to NOD32 for analysis, and they basically said &#8220;We need your logs.&#8221;&nbsp; I&#8217;d wiped the logs by then, since I reinstalled the OS entirely, but they were basically devoid of any identified threat, so it was meaningless.</p>
<p>On the other hand, Windows Defender actually identified one trojan that NOD32 didn&#8217;t, and Windows Live OneCare identified several other trojan installers.&nbsp; Sophos AV identified even more.&nbsp; That&#8217;s not to say there aren&#8217;t significant issues with those platforms either, but NOD32 didn&#8217;t serve me well at all.&nbsp; I&#8217;ve been using Sophos for a week, and though it&#8217;s a bit too restrictive and processor intensive for my taste, it seems to be very effective, even going so far as to block cracks and windows hacks like the max half-open connection patch, which was somewhat annoying.&nbsp; It also blocked a program because it was &#8220;created with malpacker&#8221; or something, although I had little reason to question the program in question (which was indeed a hack).&nbsp; On the other hand, OneCare was causing bluescreens.&nbsp; I&#8217;d like something with the detection rate of Sophos and the configurability of NOD32.</p>
<p>At any rate, where network security is concerned, there&#8217;s no substitute for routinely monitoring and logging your network traffic.<br />
  &nbsp;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Delbot (Rinbot) infikoval mateřskou firmu CNN</title>
		<link>http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-17393</link>
		<dc:creator>Delbot (Rinbot) infikoval mateřskou firmu CNN</dc:creator>
		<pubDate>Sun, 22 Apr 2007 17:11:35 +0000</pubDate>
		<guid isPermaLink="false">http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-17393</guid>
		<description>[...] antivirových produktů společnosti Symantec. Další informace naleznete pod následujícími odkazy (1, 2, 3).  -mho-     AKTUÁLNÍ ZPRÁVY:  20.04.2007 IBM Tivoli Monitoring, přetečení bufferu  20.04.2007 [...]</description>
		<content:encoded><![CDATA[<p>[...] antivirových produktů společnosti Symantec. Další informace naleznete pod následujícími odkazy (1, 2, 3).  -mho-     AKTUÁLNÍ ZPRÁVY:  20.04.2007 IBM Tivoli Monitoring, přetečení bufferu  20.04.2007 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: An Information Security Place &#187; Blog Archive &#187; Dealing with Rinbot</title>
		<link>http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-15360</link>
		<dc:creator>An Information Security Place &#187; Blog Archive &#187; Dealing with Rinbot</dc:creator>
		<pubDate>Thu, 05 Apr 2007 13:53:02 +0000</pubDate>
		<guid isPermaLink="false">http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-15360</guid>
		<description>[...] a pretty cool blog post about [...]</description>
		<content:encoded><![CDATA[<p>[...] a pretty cool blog post about [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Techgage</title>
		<link>http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14754</link>
		<dc:creator>Techgage</dc:creator>
		<pubDate>Mon, 19 Mar 2007 17:47:07 +0000</pubDate>
		<guid isPermaLink="false">http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14754</guid>
		<description>&lt;!--%kramer-ref-pre%--&gt;[...]  Neosmart Posted by Rob Williams on March 2, 2007 08:41 AM PST - Permalink  News [...]&lt;!--%kramer-ref-post%--&gt;</description>
		<content:encoded><![CDATA[<p><!--%kramer-ref-pre%-->[...]  Neosmart Posted by Rob Williams on March 2, 2007 08:41 AM PST - Permalink  News [...]<!--%kramer-ref-post%--></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: need to get new antivirus in a few weeks, whats the hottest/latest? - MyUnreal BBS</title>
		<link>http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14751</link>
		<dc:creator>need to get new antivirus in a few weeks, whats the hottest/latest? - MyUnreal BBS</dc:creator>
		<pubDate>Mon, 19 Mar 2007 12:30:12 +0000</pubDate>
		<guid isPermaLink="false">http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14751</guid>
		<description>&lt;!--%kramer-ref-pre%--&gt;[...] is a scathing review of Norton Corporate Ed. :  http://neosmart.net/blog/2007/we-love-you-rinbot/  It also mentions the once-a-week update - Rinbot is a new virus that is targetting Symantec based [...]&lt;!--%kramer-ref-post%--&gt;</description>
		<content:encoded><![CDATA[<p><!--%kramer-ref-pre%-->[...] is a scathing review of Norton Corporate Ed. :  <a href="http://neosmart.net/blog/2007/we-love-you-rinbot/" rel="nofollow">http://neosmart.net/blog/2007/we-love-you-rinbot/</a>  It also mentions the once-a-week update - Rinbot is a new virus that is targetting Symantec based [...]<!--%kramer-ref-post%--></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Untitled Document</title>
		<link>http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14739</link>
		<dc:creator>Untitled Document</dc:creator>
		<pubDate>Sun, 18 Mar 2007 18:23:50 +0000</pubDate>
		<guid isPermaLink="false">http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14739</guid>
		<description>&lt;!--%kramer-ref-pre%--&gt;[...] We Love Rinbot [...]&lt;!--%kramer-ref-post%--&gt;</description>
		<content:encoded><![CDATA[<p><!--%kramer-ref-pre%-->[...] We Love Rinbot [...]<!--%kramer-ref-post%--></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Blue Dot: We Love You, Rinbot! at The NeoSmart Files</title>
		<link>http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14665</link>
		<dc:creator>Blue Dot: We Love You, Rinbot! at The NeoSmart Files</dc:creator>
		<pubDate>Tue, 13 Mar 2007 13:31:44 +0000</pubDate>
		<guid isPermaLink="false">http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14665</guid>
		<description>&lt;!--%kramer-ref-pre%--&gt;[...] "FFFFFF";google_color_link = "106FCE";google_color_text = "464646";google_color_url = "898989";    We Love You, Rinbot! at The NeoSmart Filesfreshmaker13 &#124; Shared With: Everyone - 11 days ago &#124; security, software, computersQuoted: Connecting [...]&lt;!--%kramer-ref-post%--&gt;</description>
		<content:encoded><![CDATA[<p><!--%kramer-ref-pre%-->[...] &#8220;FFFFFF&#8221;;google_color_link = &#8220;106FCE&#8221;;google_color_text = &#8220;464646&#8243;;google_color_url = &#8220;898989&#8243;;    We Love You, Rinbot! at The NeoSmart Filesfreshmaker13 | Shared With: Everyone - 11 days ago | security, software, computersQuoted: Connecting [...]<!--%kramer-ref-post%--></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Computer Guru</title>
		<link>http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14602</link>
		<dc:creator>Computer Guru</dc:creator>
		<pubDate>Sun, 11 Mar 2007 13:28:19 +0000</pubDate>
		<guid isPermaLink="false">http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14602</guid>
		<description>&lt;p&gt;Sure, all articles on The NeoSmart Files are published under the Creative Commons agreement. Our specific licensing style lets you translate articles and host them on your site so long as you let others do the same, and you link back to the original article here, and name NST as the original author.
&lt;/p&gt;
&lt;p&gt;Once you've translated it, please comment here or send a pingback our way, and I'll even link your translation in the main article :)
&lt;/p&gt;</description>
		<content:encoded><![CDATA[<p>Sure, all articles on The NeoSmart Files are published under the Creative Commons agreement. Our specific licensing style lets you translate articles and host them on your site so long as you let others do the same, and you link back to the original article here, and name NST as the original author.
</p>
<p>Once you&#8217;ve translated it, please comment here or send a pingback our way, and I&#8217;ll even link your translation in the main article <img src='http://neosmart.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pozycjonowanie</title>
		<link>http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14595</link>
		<dc:creator>Pozycjonowanie</dc:creator>
		<pubDate>Sun, 11 Mar 2007 11:31:36 +0000</pubDate>
		<guid isPermaLink="false">http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14595</guid>
		<description>Thanks for very interesting article. Can I translate your article into polish and publish at my webblog? I will back here and check your answer. Keep up the good work. Greetings</description>
		<content:encoded><![CDATA[<p>Thanks for very interesting article. Can I translate your article into polish and publish at my webblog? I will back here and check your answer. Keep up the good work. Greetings</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Techpodcasts.com</title>
		<link>http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14525</link>
		<dc:creator>Techpodcasts.com</dc:creator>
		<pubDate>Fri, 09 Mar 2007 15:17:39 +0000</pubDate>
		<guid isPermaLink="false">http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14525</guid>
		<description>&lt;!--%kramer-ref-pre%--&gt;[...] Show Notes: Sony at it again! Digg Corruption CompUSA Trouble RIAA Slams Fair Use Upgrade to XP Netflix Streaming Shortcut Moon Eclipse Saturday Zune Phone? XM Billing 51gb HD-DVD Amazing Careport Apple at NAB TiVo Canceled Julie Amero Sentencing RIAA Boycott Day 1 Jobs Apple insensitive to real consumers RIAA Attacks College Students BackupHDDVD Takedown Ear Scope S3 and Scripting News Preserving Ideas Spotplex ISS Risks Gash in Atlantic Symantec Concerns [...]&lt;!--%kramer-ref-post%--&gt;</description>
		<content:encoded><![CDATA[<p><!--%kramer-ref-pre%-->[...] Show Notes: Sony at it again! Digg Corruption CompUSA Trouble RIAA Slams Fair Use Upgrade to XP Netflix Streaming Shortcut Moon Eclipse Saturday Zune Phone? XM Billing 51gb HD-DVD Amazing Careport Apple at NAB TiVo Canceled Julie Amero Sentencing RIAA Boycott Day 1 Jobs Apple insensitive to real consumers RIAA Attacks College Students BackupHDDVD Takedown Ear Scope S3 and Scripting News Preserving Ideas Spotplex ISS Risks Gash in Atlantic Symantec Concerns [...]<!--%kramer-ref-post%--></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Microsoft&#8217;s Not Like Symantec! at The NeoSmart Files</title>
		<link>http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14505</link>
		<dc:creator>Microsoft&#8217;s Not Like Symantec! at The NeoSmart Files</dc:creator>
		<pubDate>Fri, 09 Mar 2007 07:08:38 +0000</pubDate>
		<guid isPermaLink="false">http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14505</guid>
		<description>[...] God, it looks like Microsoft isn&#8217;t like Symantec! Back in 2006, when Microsoft bought out software vendor Sysinternals (now Windows Sysinternals), [...]</description>
		<content:encoded><![CDATA[<p>[...] God, it looks like Microsoft isn&#8217;t like Symantec! Back in 2006, when Microsoft bought out software vendor Sysinternals (now Windows Sysinternals), [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nirbot - Even Botters Need Attention &#183; Security to the Core &#124; Arbor Networks Security Blog</title>
		<link>http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14392</link>
		<dc:creator>Nirbot - Even Botters Need Attention &#183; Security to the Core &#124; Arbor Networks Security Blog</dc:creator>
		<pubDate>Wed, 07 Mar 2007 21:03:56 +0000</pubDate>
		<guid isPermaLink="false">http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14392</guid>
		<description>[...] We Love You, Rinbot! from the NeoSmart Files [...]</description>
		<content:encoded><![CDATA[<p>[...] We Love You, Rinbot! from the NeoSmart Files [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Computer Guru</title>
		<link>http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14046</link>
		<dc:creator>Computer Guru</dc:creator>
		<pubDate>Mon, 05 Mar 2007 14:30:25 +0000</pubDate>
		<guid isPermaLink="false">http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14046</guid>
		<description>&lt;p&gt;Hey MrJodie,
&lt;/p&gt;
&lt;p&gt;Don't worry about it, I'll add the paragraphs if you like. We've been slashdotted before, but never this bad (200k hits in&#160;just about 2 hours), it completely knocked the server offline.
&lt;/p&gt;</description>
		<content:encoded><![CDATA[<p>Hey MrJodie,
</p>
<p>Don&#8217;t worry about it, I&#8217;ll add the paragraphs if you like. We&#8217;ve been slashdotted before, but never this bad (200k hits in&nbsp;just about 2 hours), it completely knocked the server offline.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MrJodie</title>
		<link>http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14044</link>
		<dc:creator>MrJodie</dc:creator>
		<pubDate>Mon, 05 Mar 2007 14:19:08 +0000</pubDate>
		<guid isPermaLink="false">http://neosmart.net/blog/2007/we-love-you-rinbot/#comment-14044</guid>
		<description>Thanks, George... although, I swear that I &lt;em&gt;did&lt;/em&gt; use paragraphs.&#160; Why the hell did they get reformatted?&#160; In fact, several of the quotes before mine had separate paragraphs when I read them before posting.&#160;&#160;I wonder if the index had to be republished.&#160; If so, it may have ditched the HTML tags.&#160; I noticed the site wasn't accessible for a short while, yesterday.</description>
		<content:encoded><![CDATA[<p>Thanks, George&#8230; although, I swear that I <em>did</em> use paragraphs.&nbsp; Why the hell did they get reformatted?&nbsp; In fact, several of the quotes before mine had separate paragraphs when I read them before posting.&nbsp;&nbsp;I wonder if the index had to be republished.&nbsp; If so, it may have ditched the HTML tags.&nbsp; I noticed the site wasn&#8217;t accessible for a short while, yesterday.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
