Snort 2.9 Essentials: The DAQ
The recently released Snort 2.9 Beta introduces the Data AcQuisition library (DAQ), for packet I/O. The DAQ replaces direct calls into packet capture libraries like PCAP with an abstraction layer that make it easy to add additional software or hardware packet capture implementati
Quick analysis of a webpage leveraging CVE-2010-1885 (aka the help and support center vulnerability)
In a previous blog post I was writing about an increase in attacks against an at the time, un-patched vulnerability. Microsoft patched it on July 13, which doesn't mean that people aren't still trying to own un-patched machines.goodgirlsbadguys.com (213.155.12.144) is a d
Rule Release for Today, Tuesday August 10th, 2010
Microsoft Security Advisory MS10-046: Microsoft Windows Shell contains a vulnerability that may allow a remote attacker to execute code on an affected system. Previously released rules to detect attacks targeting these vulnerabilities have been updated with the appropriate refer
Rule Release for Today, Tuesday August 3rd, 2010
A dded and modified multiple rules in the exploit, ftp, imap, mysql, netbios, rpc, specific-threats, sql, web-activex, web-client, web-iis, web-misc and web-php rule sets. Check here for details: http://www.snort.org/vrt/advisories/2010/08/03/vrt-rules-2010-08-03.html
Sourcefire VRT DI is Hiring
Here's your chance to become part of the Intelligence unit that powers the Vulnerability Research Team. We know all, we see all and we say almost nothing to anyone about anything. Kinda. Alright, not really. We get the data, we manage the data, we mine the data, we give out i
Rule Release for Today, Thursday July 22nd, 2010
Two main vulnerabilities covered in this release. Microsoft Windows Shell shortcut vulnerability (CVE-2010-2568) and the Siemens Simatic WinCC and PCS 7 SCADA vuln (CVE-2010-2772). Both of these are being actively used by the Stuxnet worm. More details are available here: http:/
Innovation -- You Keep Using That Word...
So, this week, the OISF has been on a media blitz about Suricata, their open-source Intrusion Detection System. As always, my preference is for you to review the information yourself, so before I give you my thoughts about the state of Suricata, here are some links: http://www.
The Power of Scapy
There is a special place in my heart for someone who accidentally causes all the Macs in the office to repeatably crash at the Grey Screen of Death. If you too like fun "accidents" or need to craft up some packets check out Judy Novak's SANS class on Scapy. This is
Vulnerability Report - July 2010
Sourcefire VRT Vulnerability Report July 2010 from Sourcefire VRT on Vimeo.