Razorback - Whats going on?
Its been almost 3 weeks since I joined the VRT and started working on Razorback. Over that time we have made some good progress with the project and I wanted to share what we have done and what we are going to be working on over the next few weeks. What we have completed so far:
Attack Obfuscation - Not Just For JavaScript
Since his company purchased a Sourcefire IPS setup last summer, I've had a close working relationship with Mickey Lasky, the primary network security analyst at a company (which shall intentionally remain unnamed) that runs a number of public-facing web sites. He sends me PCA
Blocklist.rules, ClamAV, and Data Mining
We've received a number of queries recently about the source of the data in the blocklist.rules category. I'm posting the answer here, since it will be of broad interest to the Sourcefire/Snort user base. One of the side effects of our 2007 acquisition of the ClamAV proj
In which kpyke looks behind the green curtain
From an operations perspective, there is very little that is less useful and more aggravating than vendor magic. What I mean by this is anything that "happens" in the background that you have no visibility into. While many organizations enjoy the simplicity provided by
(Successfully) Building Shared Object Rules (and Snort) under OpenBSD
Here at the VRT, we have been adding support for more platforms and operating systems for shared object rules in the VRT Certified rule packs. Recently we started work on building shared object rules for Snort under OpenBSD. We ran into problems. After careful investigation, I ha
'Tis the Season for 0-days
Hello, all! This is just a quick note that Microsoft has released a bulletin regarding a new 0-day in Internet Explorer versions 7 and 8. You can read all about it in their advisory at http://www.microsoft.com/technet/security/advisory/2488013.mspx as well as the reference for th
ClamAV 3.0 for Windows Open Beta
The public beta for ClamAV for Windows 3.0, which includes full integration of the ClamAV engine into the Immunet Protect product is now open. If you are interested in playing with ClamAV for Windows 3.0 please check out the following link: Beta Announcement The download links
Exim Remote Root
We've heard from a number of Sourcefire customers and open-source Snort users lately, asking us whether we'll be releasing coverage for last week's Exim remote root (CVE-2010-4344 for those keeping score at home). Based on what hit the Exim-dev mailing list, we felt c
Detecting Obfuscated Malicious JavaScript with Snort and Razorback
Unlike most Americans, who were busy recovering from a turkey-induced coma, I spent this past weekend at the Hackers 2 Hackers Conference in Sao Paulo, Brazil. In addition to being a nice respite from the cold weather in DC, the event featured excellent speakers on topics as dive