<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ICMPECHO &#187; Panda</title>
	<atom:link href="http://www.icmpecho.com/tag/panda/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.icmpecho.com</link>
	<description>more than your usual type 8&#039;s</description>
	<lastBuildDate>Sat, 04 Feb 2012 19:00:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Panda Security videos in Swedish</title>
		<link>http://www.icmpecho.com/2011/12/27/panda-security-videos-in-swedish/</link>
		<comments>http://www.icmpecho.com/2011/12/27/panda-security-videos-in-swedish/#comments</comments>
		<pubDate>Tue, 27 Dec 2011 12:28:34 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
				<category><![CDATA[Panda Security]]></category>
		<category><![CDATA[work]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[daniel]]></category>
		<category><![CDATA[nyström]]></category>
		<category><![CDATA[Panda]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/?p=2233</guid>
		<description><![CDATA[Hello all It&#8217;s been something like a year, or maybe two, since last time but now I&#8217;m back! I&#8217;m thinking of rebranding the blog and re-shaping it in its entirity. For now, I&#8217;ll give you a sample of what I&#8217;m doing at work atm: Daniel Nyström This is me holding a seminar on the development [...]]]></description>
			<content:encoded><![CDATA[<p>Hello all <img src='http://www.icmpecho.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>It&#8217;s been something like a year, or maybe two, since last time but now I&#8217;m back! I&#8217;m thinking of rebranding the blog and re-shaping it in its entirity.</p>
<p>For now, I&#8217;ll give you a sample of what I&#8217;m doing at work atm:</p>
<p><a href="http://web22.abiliteam.com/ability/show/khcichp/pandaseminarium20111028/mainshow.asp?AUTH_NAME=&#038;AUTH_EMAIL=&#038;AUTH_COMPANY=&#038;AUTH_PHONE=&#038;FOLDERNAME=pandaseminarium20111028&#038;PRODUCER_ID=khcichp&#038;SESSIONID=00000000000000000000000000000000&#038;LIVEID=3534153620696&#038;SHOWRUN_ID=3534153620696&#038;MENU=False&#038;WB_datetime=12/27/2011%201%3A20%3A20%20PM&#038;arrive_TS=12/27/2011%201%3A20%3A20%20PM&#038;AUTH_IP=212.112.188.98&#038;WB_useragent=Mozilla/5.0%20%28Windows%20NT%205.1%3B%20rv%3A8.0%29%20Gecko/20100101%20Firefox/8.0&#038;WB_codename=Mozilla&#038;WB_PLATFORM=WIN&#038;WB_name=Mozilla%20Gecko&#038;WB_versionnumber=20100101&#038;WB_CookieSet=3533723824779&#038;WB_screenwidth=1680&#038;WB_screenheight=1050&#038;WB_Bandwidth=&#038;STREAMID=1&#038;KEY=401955915&#038;CMP=1" title="Daniel Nyström @ Panda Cloud Security Meeting" target="_blank">Daniel Nyström</a><br />
This is me holding a seminar on the development of cloud security solutions, and what we at Panda Security mean by &#8220;cloud security&#8221;. In Swedish.</p>
<p>Panda Sweden people talking (again, in Swedish) about different types of threats that might face home-users today:</p>
<p><iframe width="460" height="315" src="http://www.youtube.com/embed/9-fJ7sKO_JA" frameborder="0" allowfullscreen></iframe><br />
<iframe width="460" height="315" src="http://www.youtube.com/embed/AmpEQku0zHw" frameborder="0" allowfullscreen></iframe><br />
<iframe width="460" height="315" src="http://www.youtube.com/embed/xrLSPTIIde4" frameborder="0" allowfullscreen></iframe><br />
<iframe width="460" height="315" src="http://www.youtube.com/embed/mKi4Q6j4F28" frameborder="0" allowfullscreen></iframe></p>
<p>Thanks for this time, I&#8217;ll be back soon and probably with a bit of changes to this site! <img src='http://www.icmpecho.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>//Daniel</p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2011/12/27/panda-security-videos-in-swedish/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Q.P. &#8211; Random bits</title>
		<link>http://www.icmpecho.com/2009/02/06/qp-random-bits/</link>
		<comments>http://www.icmpecho.com/2009/02/06/qp-random-bits/#comments</comments>
		<pubDate>Thu, 05 Feb 2009 23:39:53 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
				<category><![CDATA[misc]]></category>
		<category><![CDATA[2009]]></category>
		<category><![CDATA[eu]]></category>
		<category><![CDATA[it-securityworld]]></category>
		<category><![CDATA[medina report]]></category>
		<category><![CDATA[Panda]]></category>
		<category><![CDATA[qp]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/?p=1766</guid>
		<description><![CDATA[All was well at IT-SecurityWorld and I got a chance to say hi to Patrik Fältström at the end of the day. That was nice even though he gave me (and Panda ) a small kick for not being IPv6 ready with our services. I have a feeling that we&#8217;re not alone though and all [...]]]></description>
			<content:encoded><![CDATA[<p>All was well at IT-SecurityWorld and I got a chance to say hi to <a href="http://stupid.domain.name">Patrik Fältström</a> at the end of the day. That was nice even though he gave me (and Panda <img src='http://www.icmpecho.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> ) a small kick for not being IPv6 ready with our services. I have a feeling that we&#8217;re not alone though and all the points he keep making in the seminars I&#8217;ve seen him hold has always been very valid. People need to begin make the shift and stop being so comfortable as soon as possible.</p>
<p>In other news, the European parliament is about to vote on the Medina Report, which is going to set the direction for all future IP-rights enforcement work. It suggests, among other things, censorship of uncomfortable sites and traffic throttling. It also names The Pirate Bay as a primary target and this has not been well recieved here in Sweden as it can be considered interfering with an ongoing investigation and trial.</p>
<p>Not very nice. More information about this report and it&#8217;s ramifications can be found here:</p>
<p><a href="http://www.iptegrity.com/index.php?option=com_content&#038;task=view&#038;id=233&#038;Itemid=9">IPTegrity &#8211; A Net dilemma for the European Parliament </a><br />
<a href="http://www.iptegrity.com/index.php?option=com_content&#038;task=view&#038;id=240&#038;Itemid=9">IPTegrity &#8211; Libraries call to reject Medina report</a><br />
<a href="http://www.laquadrature.net/en/copyright-dogmatism-ridiculously-strikes-european-parliament">La Quadrature Du Net &#8211; Copyright dogmatism ridiculously strikes the European Parliament</a></p>
<p>In other &#8220;work news&#8221; I recieved a request for comment on the surfacing issues of states implementing laws that make it legal for police to hack into computers and plant trojans from <a href="http://www.disruptive.se">Christian Rudolf</a> (Swedish site) over at <a href="http://www.mjukvara.se/blogg/antivirus-hemlig-avlyssning/">Mjukvara.se</a> (Swedish site). The question was if we as a security vendor would cooperate with the police in these situations and our position in this matter was summarized nicely internally when we discussed this:</p>
<blockquote><p><em><font color="black">Our position is that we will always detect all trojans to protect our customers, even if they pass a law to make a legal police trojan in Germany or anywhere else. If they take us to court of justice or make any type of pressure to make us whitelist their trojan, we will fight against it.</p>
<p>The americans have a typical phrase that fits well into this situation: &#8220;they&#8217;ll have to pry the detection signature from our cold, dead hands!&#8221;</font></em></p></blockquote>
<p>It&#8217;s nice to see Panda Reseach and Labs have a sober view on this. Not that I didn&#8217;t expect them to, but the silence from some vendors are speaking for itself. The only ones responding to the inquiry on <a href="http://www.mjukvara.se/blogg/antivirus-hemlig-avlyssning/">Mjukvara.se</a> was Panda Security, Symantec and Avast. All of us stating that we would not whitelist any trojans. Ever.</p>
<p>Worth noting though is that <a href="http://en.wikipedia.org/wiki/Magic_Lantern_(software)#Anti-virus_software_designed_to_ignore_Magic_Lantern">there has been some trouble with this earlier with some vendors involving a specialized FBI-trojan called Magic Lantern</a>. Let&#8217;s hope that the vendors that ignored this trojan change and follow up on their current promises.</p>
<p>And one last thing, I&#8217;m in need of some help from someone that knows virtualization (VmWare or similar). Working on setting up a multiple host, multiple network, multiple function solution and I would like to ask someone that knows more about this than me. So if you&#8217;re skilled and feel like giving me some quick A&#8217;s to my Q&#8217;s, please drop me an e-mail (daniel dot nystrom at icmpecho dot com) or comment on this post!</p>
<p>Cheers,</p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2009/02/06/qp-random-bits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My comments on Secunia&#8217;s exploit testing</title>
		<link>http://www.icmpecho.com/2008/10/20/my-comments-on-secunias-exploit-testing/</link>
		<comments>http://www.icmpecho.com/2008/10/20/my-comments-on-secunias-exploit-testing/#comments</comments>
		<pubDate>Mon, 20 Oct 2008 01:22:19 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[work]]></category>
		<category><![CDATA[behavioural]]></category>
		<category><![CDATA[files]]></category>
		<category><![CDATA[Panda]]></category>
		<category><![CDATA[Panda Security]]></category>
		<category><![CDATA[secunia]]></category>
		<category><![CDATA[test]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/?p=966</guid>
		<description><![CDATA[Warning: Panda Security/work related post. This is a personal blog but from time to time I’m posting things may realte to my employer. Read “About this blog”. Photo: EricGjerde on Flickr. Weren&#8217;t going to comment on this really, but after reading up on all the different posts on the issue I&#8217;m feeling that some things [...]]]></description>
			<content:encoded><![CDATA[<p><em><font color="red">Warning: Panda Security/work related post.</font> This is a personal blog but from time to time I’m posting things may realte to my employer. Read “About this blog”.</em></p>
<p><img src="http://www.icmpecho.com/images/testing.jpg" alt="EricGjerde on Flickr - http://flickr.com/photos/origomi/" border=1/><br />
<em>Photo: <a href="http://flickr.com/photos/origomi/">EricGjerde</a> on <a href="http://flickr.com/">Flickr</a>.</em></p>
<p>Weren&#8217;t going to comment on this really, but after <a href="http://research.pandasecurity.com/archive/Exploits-vs-Antivirus-_2D00_-The-Last-Stand.aspx">reading</a> <a href="http://anti-virus-rants.blogspot.com/2008/10/is-secunia-new-consumer-reports.html">up</a> <a href="http://voices.washingtonpost.com/securityfix/2008/10/security_software_suites_vs_cu.html">on</a> <a href="http://www.eset.com/threat-center/blog/?p=156">all</a> <a href="http://sunbeltblog.blogspot.com/2008/10/another-useless-test-grabs-headlines.html">the</a> <a href="http://blogs.zdnet.com/security/?p=2030">different</a> posts on <a href="http://www.theregister.co.uk/2008/10/13/secunia_security_suite_tests/">the issue</a> I&#8217;m feeling that some things are being missed. Specially if looking at <a href="http://secunia.com/blog/30/">Secunias CTOs (Thomas Kristensen) last blog post</a>.</p>
<p>What I&#8217;m reacting to are these comments:</p>
<p><em><strong>Our point is not that Internet Security Suites are useless (they are quite useful for most users). Instead, our point is that they protect insufficiently against hackers and that it is better to prevent attacks by patching rather than  relying on other security measures alone.</strong></em></p>
<p>When have we (the anti-malware vendors) said that our users do not need to patch? Sure we have protections that will catch things pro-actively, but that is meant for 0-day exploits etc. and is not meant as replacement for patches.</p>
<p>Also, our products (Panda Securitys) for home-users will scream bloody murder with annoying (but configurable) pop-ups if you do not have all MS patches installed. And I know that other vendors do this as well. Our corporate products also contain MalwareRadar which by default (not configurable) does inventory of installed patches and includes it in the report.</p>
<p>Next comment from Secunias CTO:</p>
<p><em><strong>In my opinion it would serve the security industry well if AV-vendors would admit that the security provided by their products rely on a reasonably updated and well administrated system. If they really could protect systems without patches, then I&#8217;m quite confident that software vendors would stop making patches and instead provide these fabulous security solutions themselves.</strong></em></p>
<p>Again, who said we do not need patches? Let me translate this to what I&#8217;m actually reading (my parody below):</p>
<p><em>In my opinion it would serve you guys in the anti-malware business good if you could tone down the &#8220;we take all proactively&#8221;-attitude so that we could make some money out of helping people see what needs to be patched. Also, plz be quick or Microsoft will start pushing this attitude as well and then I&#8217;m pretty much screwed.</em></p>
<p>But a bit more seriously. This is a publicity stunt and there&#8217;s no point in discussing it further. A company that publishes a report promoting their solution to a problem that has been incorrectly researched.</p>
<p>And when it comes to the test itself I think the other commentators have been too nice.</p>
<p>The methods used for testing illustrates great lack of knowledge on how to test client security solutions these days, and the worst thing is that I think they knew it. I can&#8217;t imagine the testers at Secunia being so stupid, when they&#8217;ve shown such skill before, that they didn&#8217;t realise that their methodology was flawed.</p>
<p>I mean, testing by scanning a bunch of exploit files? What are they after? That we detect <u>their</u> specific exploits by signature? Who would have anything to gain from that?</p>
<p>They then move on to say that we should detect exploits in a more generic way&#8230; Alright, how do you want us to do that? Look for shellcode in the files? Look for format exploit strings in the files? This is a false positive waiting to happen.</p>
<p>If we were to look for exploits (still, KNOWN EXPLOITS) we would have to first include a lot of new crap in the signature (as if it were not enough) and then implement detection routines that span whole files as we do not know where the crap might be. Good-bye CPU and memory, I&#8217;ll see you when your done&#8230;</p>
<p>The report really shows a total lack of understanding on how AV&#8217;s work today and the problems that we face with signatures.</p>
<p>What we and other has done INSTEAD is to create protections that &#8220;see&#8221; when an application does something it shouldn&#8217;t do or if it does something suspicious. These protections also monitor network traffic and can pro-actively detect and block traffic that shouldn&#8217;t bee there.</p>
<p>This is why a test against 300 files lying on your hard-drive do not give any accurate results whatsoever. Our protection stops genuinely active malicious code or applications that are being actively exploited by looking at the system and stopping things that does not look normal.</p>
<p>Ah well&#8230; Long story short this kinda ruins Secunia for me as an information resource.</p>
<p>For several years I&#8217;ve been using their web-based resources for unbiased information, but I guess that&#8217;s over now.</p>
<hr />
<em>PS. Tired as hell now, so please excuse any linguistic or grammatical errors in the text above. <img src='http://www.icmpecho.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  .DS</em></p>
<hr />
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2008/10/20/my-comments-on-secunias-exploit-testing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Panda AdminSecure version 4.03 to be released&#8230;</title>
		<link>http://www.icmpecho.com/2008/09/08/panda-adminsecure-version-403-to-be-released/</link>
		<comments>http://www.icmpecho.com/2008/09/08/panda-adminsecure-version-403-to-be-released/#comments</comments>
		<pubDate>Mon, 08 Sep 2008 07:46:44 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[work]]></category>
		<category><![CDATA[4.03]]></category>
		<category><![CDATA[adminsecure]]></category>
		<category><![CDATA[anti-malware]]></category>
		<category><![CDATA[Panda]]></category>
		<category><![CDATA[Panda Security]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/?p=416</guid>
		<description><![CDATA[Warning: Panda Security/work related post. &#8230; this week. The main news in the 4.03 release is: * Optimized console performance * Reduced installation package size * More auto-uninstallers for competitor products * Improved update features for mobile users * Full support for XP SP3 and Vista SP1 * Full support for Exchange 2007 SP1 * [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.icmpecho.com/images/pandasecurity01.jpg" alt="Panda Security - From Press graphics kit" /><br />
<em><font color="red">Warning: Panda Security/work related post. <img src='http://www.icmpecho.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </font></em></p>
<p>&#8230; this week.</p>
<p><strong>The main news in the 4.03 release is:</strong></p>
<p><strong>*</strong> Optimized console performance<br />
<strong>*</strong> Reduced installation package size<br />
<strong>*</strong> More auto-uninstallers for competitor products<br />
<strong>*</strong> Improved update features for mobile users<br />
<strong>*</strong> Full support for <a href="http://windowshelp.microsoft.com/Windows/en-US/usingwindowsxp.mspx">XP SP3</a> and <a href="http://www.microsoft.com/windows/windows-vista/default.aspx">Vista SP1</a><br />
<strong>*</strong> Full support for <a href="http://www.microsoft.com/exchange/default.mspx">Exchange 2007</a> SP1<br />
<strong>*</strong> Full <a href="http://www.microsoft.com/windowsserver2008/en/us/nap-product-home.aspx">NAP</a> support in our desktop protections</p>
<p>A lot of other news and bugfixes also included.</p>
<p>Ask you <a href="http://www.pandasecurity.com/homeusers/media/globalsites/?sitepanda=empresas">local Panda office </a>for the complete document of changes.</p>
<p>If you&#8217;re a client you can download the upgrade <a href="http://www.pandasecurity.com/enterprise/downloads/tree/?sitepanda=empresas">here</a>.</p>
<p>Cheers,</p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2008/09/08/panda-adminsecure-version-403-to-be-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Panda RAR-problems and n.runs</title>
		<link>http://www.icmpecho.com/2007/11/22/panda-rar-problems-and-nruns/</link>
		<comments>http://www.icmpecho.com/2007/11/22/panda-rar-problems-and-nruns/#comments</comments>
		<pubDate>Thu, 22 Nov 2007 01:53:58 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[work]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[bypass]]></category>
		<category><![CDATA[Panda]]></category>
		<category><![CDATA[RAR]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/2007/11/22/panda-rar-problems-and-nruns/</guid>
		<description><![CDATA[WARNING: PANDA SECURITY CENTRIC / ANGRY RANTING POST -&#62; See &#8220;About this blog&#8221;. Earlier on this month a potential &#8220;bug/security implication/design flaw/non-issue?&#8221; (the definition is not totally clear in this particular case) was reported to Panda Security by the security firm n.runs. The issue at hand is that if a RAR-file header is formatted in [...]]]></description>
			<content:encoded><![CDATA[<p><font color="#ff0000">WARNING: PANDA SECURITY CENTRIC / ANGRY RANTING POST</font> -&gt; See &#8220;About this blog&#8221;. <img src='http://www.icmpecho.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p><strong>Earlier on this month</strong> a potential &#8220;bug/security implication/design flaw/non-issue?&#8221; (the definition is not totally clear in this particular case) was reported to Panda Security by the security firm <a href="http://www.nruns.com" target="_blank">n.runs</a>.</p>
<p><strong>The issue at hand</strong> is that if a RAR-file header is formatted in a specific way, the contents of the archive cannot be analyzed by the antivirus kernel and as such might pass through perimeter defenses and actually be written to disk. Due to WinRar being extremely tolerant to illegally formatted archive headers (<a href="http://en.wikipedia.org/wiki/Steganography" target="_blank">steganography</a> someone?) this archive can still be opened with WinRar.</p>
<p><strong>However, if the archive is extracted or if a file is run from it</strong>, Panda will have no problems catching it with either the signature based engine or the behavioural analysis engine. Of course there is also the possiblity of us not being able to detect the malware, but then why evade us? Our perimeter products would also catch these kinds of files if not reconfigured from default (content-filter-&gt;Files with inconsistent format, extension or MIME-type). However, if these settings have been changed, I see the attack vector more clearly. And of course, even if this is correctly configured it is not good that something possibly can slip by the signature engine.</p>
<p><strong>This issue being reported is not a problem to us</strong>. It is a good thing and it enables us to provide better protection as we eliminate potential bypass vectors. <strong>What is a problem</strong> though (not only for us I think) is irresponsible disclosure. You can see Pedro&#8217;s thoughts about this <a href="http://research.pandasecurity.com/archive/Vulnerability-found-that-allows-for-_2200_disclosure-policy-bypass_2200_.aspx" target="_blank">here</a>, but I&#8217;d like to share some of my own views as well.</p>
<p><strong>As Pedro points out</strong>, most of the security problems reported to Panda by researchers or security companies are handled seriously and in a timely manner. This was also the case this time. In return for the diligence in response time and issue resolution, we do expect the reporting party to follow common policies for public disclosure, especially if the discussion and investigation of the flaw is still in the lab. This is for several reasons including (but not limited to) <strong>the security of our customers</strong>, <strong>the security of our customers</strong> (yeah, I wrote that twice), <strong>the continued cooperation with the security community in these issues</strong> and <strong>the open communication style used in these cases</strong>.</p>
<p>What <strong>n.runs</strong> did next while this issue was being investigated and its impact clarified was to <a href="http://www.nruns.com/ps/The_Death_of_AV_Defense_in_Depth-Revisiting_Anti-Virus_Software.pdf" target="_blank">publicly disclose the issue</a> complete with technical details. As pointed out in <a href="http://anti-virus-rants.blogspot.com/2007/11/defense-in-depth-revisited.html" target="_blank">this post</a> by Kurt Wismer there are other issues with the document, but I&#8217;ll try to stay out of that discussion. I do however recommend reading his post as he is making some very good points not only in the article but also in the comments that followed.</p>
<p>The timeline for this issue was described in the Panda Research blog as:</p>
<p><em><strong>Nov. 6:    n.runs initial vulnerability report and PoC to Panda<br />
Nov. 7:    Panda acknowledges receipt and starts investigating<br />
Nov. 13:  n.runs publicly discloses Panda as vulnerable<br />
Nov. 16:  Panda sends comments on vulnerability and PoC to n.runs<br />
Nov. 16:  n.runs responds to Panda comments (fails to mention the issue is already public)<br />
Nov. 21:  Panda sends final response to n.runs </strong></em></p>
<p>I understand that if you do not have a final response from the vendor in a reasonable time (that not being less than two month&#8217;s if initial contact is established), you might want to release an advisory or two highlighting the issues to pressure the vendor to provide a fix, but come on. That was surely not the case here.</p>
<p><strong>Anyways, after seeing this behaviour</strong> I can&#8217;t help but wonder what motivated this line in their presentation referenced above:</p>
<p><em>&#8220;The solution developed by n.runs under the code name &#8220;ParsingSafe&#8221; will build on and work together with the customer antivirus products that are already in place or that are planned to be put in place &#8230;.. Based on this, the antivirus vendors are very important technology partners for our solution. The goal of the customer is still primarily to have the highest rate of virus recognition possible &#8230;..&#8221;</em></p>
<p><strong>Could someone please explain to me</strong> how prematurely disclosing an issue like this can help our customers have <em>&#8220;the highest rate of virus recognition possible&#8221;</em> because I do not get it. Of course, the statement was regarding the goal of <strong><em>the customer</em></strong>. Not n.runs.</p>
<p>Whatever, my own opinions are probably just being clouded by me working with security professionally for such a long time. I remember back in the days when I was a kid and me and my &#8220;31337 h4x0rcr3w&#8221; threw out our newfound vulnerabilities as soon as we even saw a wiff of them. That was fun <img src='http://www.icmpecho.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Point made. Have a nice night <img src='http://www.icmpecho.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2007/11/22/panda-rar-problems-and-nruns/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

