<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Delphi developer virus exposes weakness in anti-virus defences</title>
	<atom:link href="http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html</link>
	<description>Tech writing blog</description>
	<lastBuildDate>Thu, 18 Mar 2010 14:46:18 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: SautinSoft</title>
		<link>http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html/comment-page-1#comment-140979</link>
		<dc:creator>SautinSoft</dc:creator>
		<pubDate>Mon, 24 Aug 2009 06:33:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html#comment-140979</guid>
		<description>Eric,

Thanks for noticing about this virus, we&#039;ve fixed the problem. Use this link to download the fixed version of the &lt;a href=&quot;http://www.sautinsoft.com/downloads.php&quot; rel=&quot;nofollow&quot;&gt;RTF-to-HTML DLL component&lt;/a&gt;.

&lt;strong&gt;SautinSoft team&lt;/strong&gt;</description>
		<content:encoded><![CDATA[<p>Eric,</p>
<p>Thanks for noticing about this virus, we&#8217;ve fixed the problem. Use this link to download the fixed version of the <a href="http://www.sautinsoft.com/downloads.php" rel="nofollow">RTF-to-HTML DLL component</a>.</p>
<p><strong>SautinSoft team</strong></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric Fookes</title>
		<link>http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html/comment-page-1#comment-140808</link>
		<dc:creator>Eric Fookes</dc:creator>
		<pubDate>Sat, 22 Aug 2009 19:42:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html#comment-140808</guid>
		<description>Well, we caught the virus after testing the trial version of SautinSoft RTF-to-HTML (www.sautinsoft.com). The date stamp of their demo program was April 1, 2009. It then infected an update of a retail product we released in mid-July.

Of course, our system is well protected and we had scanned our product through an array of anti-virus products before releasing it (www.virustotal.com). At that time, it was a perfectly safe executable. Now we&#039;re flooded with mail from concerned customers getting virus warnings on our reputable software. Although the virus may be harmless, it certainly manages to damage reputation.

Would we have been safer using an offline computer for our development? No, because we rely on third-party components and testing the SautinSoft RTF-to-HTML product on our offline computer would have infected it just the same.</description>
		<content:encoded><![CDATA[<p>Well, we caught the virus after testing the trial version of SautinSoft RTF-to-HTML (www.sautinsoft.com). The date stamp of their demo program was April 1, 2009. It then infected an update of a retail product we released in mid-July.</p>
<p>Of course, our system is well protected and we had scanned our product through an array of anti-virus products before releasing it (www.virustotal.com). At that time, it was a perfectly safe executable. Now we&#8217;re flooded with mail from concerned customers getting virus warnings on our reputable software. Although the virus may be harmless, it certainly manages to damage reputation.</p>
<p>Would we have been safer using an offline computer for our development? No, because we rely on third-party components and testing the SautinSoft RTF-to-HTML product on our offline computer would have infected it just the same.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sig</title>
		<link>http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html/comment-page-1#comment-140693</link>
		<dc:creator>Sig</dc:creator>
		<pubDate>Fri, 21 Aug 2009 14:47:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html#comment-140693</guid>
		<description>yes i found an older project on my VM date 19.02.09.</description>
		<content:encoded><![CDATA[<p>yes i found an older project on my VM date 19.02.09.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Craig</title>
		<link>http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html/comment-page-1#comment-140676</link>
		<dc:creator>Craig</dc:creator>
		<pubDate>Fri, 21 Aug 2009 05:12:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html#comment-140676</guid>
		<description>&quot;The versions of that “Induc” crap only affects old Delphi versions, not the users machines at all.&quot;

One of our biggest banks here (in Australia) are still on Delphi 6.  They are (slowly) replacing their Delphi apps with Java.  But with 4000+ workstations to look after, it takes them a long time to do anything.</description>
		<content:encoded><![CDATA[<p>&#8220;The versions of that “Induc” crap only affects old Delphi versions, not the users machines at all.&#8221;</p>
<p>One of our biggest banks here (in Australia) are still on Delphi 6.  They are (slowly) replacing their Delphi apps with Java.  But with 4000+ workstations to look after, it takes them a long time to do anything.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tim</title>
		<link>http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html/comment-page-1#comment-140658</link>
		<dc:creator>tim</dc:creator>
		<pubDate>Thu, 20 Aug 2009 20:32:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html#comment-140658</guid>
		<description>@Javier well, the problem is a real one even though it won&#039;t affect most users. It&#039;s surprising in a way that Sophos has given so much publicity to its own failure - this malware was around for ages undetected by its software.

Tim</description>
		<content:encoded><![CDATA[<p>@Javier well, the problem is a real one even though it won&#8217;t affect most users. It&#8217;s surprising in a way that Sophos has given so much publicity to its own failure &#8211; this malware was around for ages undetected by its software.</p>
<p>Tim</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Javier Santo Domingo</title>
		<link>http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html/comment-page-1#comment-140654</link>
		<dc:creator>Javier Santo Domingo</dc:creator>
		<pubDate>Thu, 20 Aug 2009 20:11:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html#comment-140654</guid>
		<description>I think you are so mild with SOPHOS, its more than &quot;scaremongering&quot;. SOPHOS report lacks of knowledge, literally. Richard Cohen and Graham Cluley are inventing an issue for the users where there is none. The versions of that &quot;Induc&quot; crap only affects old Delphi versions, not the users machines at all. Its almost defamatory for the Delphi brandname (read the articles). Its a shame, and there is no email to complain to them. Thats coward.
Anyway may be it ends up like free adverstising for Embarcadero heh, but i dont know how good it is...</description>
		<content:encoded><![CDATA[<p>I think you are so mild with SOPHOS, its more than &#8220;scaremongering&#8221;. SOPHOS report lacks of knowledge, literally. Richard Cohen and Graham Cluley are inventing an issue for the users where there is none. The versions of that &#8220;Induc&#8221; crap only affects old Delphi versions, not the users machines at all. Its almost defamatory for the Delphi brandname (read the articles). Its a shame, and there is no email to complain to them. Thats coward.<br />
Anyway may be it ends up like free adverstising for Embarcadero heh, but i dont know how good it is&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Uwe Raabe</title>
		<link>http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html/comment-page-1#comment-140650</link>
		<dc:creator>Uwe Raabe</dc:creator>
		<pubDate>Thu, 20 Aug 2009 17:46:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html#comment-140650</guid>
		<description>One solution is to deploy only executables that are built on a &quot;clean&quot; build system. It may be easier to keep such a system clean than the actual developer system.</description>
		<content:encoded><![CDATA[<p>One solution is to deploy only executables that are built on a &#8220;clean&#8221; build system. It may be easier to keep such a system clean than the actual developer system.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tim</title>
		<link>http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html/comment-page-1#comment-140636</link>
		<dc:creator>tim</dc:creator>
		<pubDate>Thu, 20 Aug 2009 13:33:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html#comment-140636</guid>
		<description>@Alex @Martin all valid issues. In the case I know, there is an isolated 2nd internal network for development - though there must be some manual traffic between that and Internet connected machines. I am not arguing for it, but I can see that is helps reduce some risks.

Tim</description>
		<content:encoded><![CDATA[<p>@Alex @Martin all valid issues. In the case I know, there is an isolated 2nd internal network for development &#8211; though there must be some manual traffic between that and Internet connected machines. I am not arguing for it, but I can see that is helps reduce some risks.</p>
<p>Tim</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex Atkin UK</title>
		<link>http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html/comment-page-1#comment-140628</link>
		<dc:creator>Alex Atkin UK</dc:creator>
		<pubDate>Thu, 20 Aug 2009 11:07:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html#comment-140628</guid>
		<description>So how much hassle is doing software updates if the machine is not connected to the net?

Also, how would that work anyway?  If the code is being developed on a machine that IS on the net (by that I mean any network as even a private LAN increases the risk considerably as any one machine on that LAN may be infected with something), there is always chance of infection from whatever media you are using between that box and the compiler box.  

The fact you are switching files between a net connected box and an isolated box just means your isolated box is open to anything the net box is subjected to, with the added catch it wont have virus protection or the latest OS updates.  Surely that negates the benefit of it being isolated to begin with?

Sure you can probably request all these updates on disk but you are still trusting the source of those disks do not have any infection themselves.

So at the end of the day, is there as much benefit of having an isolated machine as first thought?</description>
		<content:encoded><![CDATA[<p>So how much hassle is doing software updates if the machine is not connected to the net?</p>
<p>Also, how would that work anyway?  If the code is being developed on a machine that IS on the net (by that I mean any network as even a private LAN increases the risk considerably as any one machine on that LAN may be infected with something), there is always chance of infection from whatever media you are using between that box and the compiler box.  </p>
<p>The fact you are switching files between a net connected box and an isolated box just means your isolated box is open to anything the net box is subjected to, with the added catch it wont have virus protection or the latest OS updates.  Surely that negates the benefit of it being isolated to begin with?</p>
<p>Sure you can probably request all these updates on disk but you are still trusting the source of those disks do not have any infection themselves.</p>
<p>So at the end of the day, is there as much benefit of having an isolated machine as first thought?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Martin</title>
		<link>http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html/comment-page-1#comment-140627</link>
		<dc:creator>Martin</dc:creator>
		<pubDate>Thu, 20 Aug 2009 11:04:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/1717-delphi-developer-virus-exposes-weakness-in-anti-virus-defences.html#comment-140627</guid>
		<description>One of our business applications was infected. The .exe was built in May this year. It would seem that one of the development systems was compromised so only .exes built on that machine were shipped with the malicious code in. No one here develops in Delphi so we haven&#039;t suffered any damage, only the inability to use the app after Sophos started picking it up.

As for not connecting development machines to the net - what if you want updates to e.g. subversion, anti-virus, etc? I guess you could have them only on an internal network, but...</description>
		<content:encoded><![CDATA[<p>One of our business applications was infected. The .exe was built in May this year. It would seem that one of the development systems was compromised so only .exes built on that machine were shipped with the malicious code in. No one here develops in Delphi so we haven&#8217;t suffered any damage, only the inability to use the app after Sophos started picking it up.</p>
<p>As for not connecting development machines to the net &#8211; what if you want updates to e.g. subversion, anti-virus, etc? I guess you could have them only on an internal network, but&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
