Blog
Recent
August 12, 2010 16:58

Snort 2.9 Essentials: The DAQ

The recently released Snort 2.9 Beta introduces the Data AcQuisition library (DAQ), for packet I/O. The DAQ replaces direct calls into packet capture libraries like PCAP with an abstraction layer that make it easy to add additional software or hardware packet capture implementati

August 10, 2010 17:06

Quick analysis of a webpage leveraging CVE-2010-1885 (aka the help and support center vulnerability)

In a previous blog post I was writing about an increase in attacks against an at the time, un-patched vulnerability. Microsoft patched it on July 13, which doesn't mean that people aren't still trying to own un-patched machines.goodgirlsbadguys.com (213.155.12.144) is a d

August 10, 2010 15:31

Rule Release for Today, Tuesday August 10th, 2010

Microsoft Security Advisory MS10-046: Microsoft Windows Shell contains a vulnerability that may allow a remote attacker to execute code on an affected system. Previously released rules to detect attacks targeting these vulnerabilities have been updated with the appropriate refer

August 3, 2010 18:13

Rule Release for Today, Tuesday August 3rd, 2010

A dded and modified multiple rules in the exploit, ftp, imap, mysql, netbios, rpc, specific-threats, sql, web-activex, web-client, web-iis, web-misc and web-php rule sets. Check here for details: http://www.snort.org/vrt/advisories/2010/08/03/vrt-rules-2010-08-03.html

July 22, 2010 18:05

Sourcefire VRT DI is Hiring

Here's your chance to become part of the Intelligence unit that powers the Vulnerability Research Team. We know all, we see all and we say almost nothing to anyone about anything. Kinda. Alright, not really. We get the data, we manage the data, we mine the data, we give out i

July 22, 2010 15:19

Rule Release for Today, Thursday July 22nd, 2010

Two main vulnerabilities covered in this release. Microsoft Windows Shell shortcut vulnerability (CVE-2010-2568) and the Siemens Simatic WinCC and PCS 7 SCADA vuln (CVE-2010-2772). Both of these are being actively used by the Stuxnet worm. More details are available here: http:/

July 20, 2010 21:15

Innovation -- You Keep Using That Word...

So, this week, the OISF has been on a media blitz about Suricata, their open-source Intrusion Detection System.  As always, my preference is for you to review the information yourself, so before I give you my thoughts about the state of Suricata, here are some links: http://www.

July 19, 2010 13:22

The Power of Scapy

There is a special place in my heart for someone who accidentally causes all the Macs in the office to repeatably crash at the Grey Screen of Death. If you too like fun "accidents" or need to craft up some packets check out Judy Novak's SANS class on Scapy. This is

July 15, 2010 17:11

Vulnerability Report - July 2010

Sourcefire VRT Vulnerability Report July 2010 from Sourcefire VRT on Vimeo.