Blog
Recent
July 14, 2010 12:38

New Rule Categories

Three new rule categories were introduced yesterday (Tuesday, 13th July 2010) in SEU 348 and into the VRT Certified Rule packages. I'd like to take a moment to explain what's in these categories, where the data behind them is coming from, and what you should do if you tur

July 13, 2010 17:32

Rule Release for Today, Tuesday July 13th, 2010

Microsoft Security Advisory MS10-042: Microsoft Help and Support Center contains a programming error that may  allow a remote attacker to bypass security restrictions on an affected system. The error occurs when invalid hex-encoded characters are used as a parameter to a search

July 8, 2010 11:14

Fundamentals of Exploit Development Class in VEGAS!

Need some more exploit fun? Want to stay in Vegas a little longer? Need some face time with the VRT? We are holding the fundamentals of exploit development class right after DefCon this year. August 2nd, 3rd and 4th in Las Vegas, NV. For more details and to book your place, take

July 7, 2010 15:58

Increase in attacks on CVE-2010-1885

Microsoft is warning that there has been an increase of attacks against a zero-day vulnerability in Microsoft Help and Support Center. The vulnerability is due to an error when using invalid hexadecimal characters in the search topic parameter of a URI. It can be used to bypass r

July 7, 2010 14:19

Yes, Virginia, There is Cyberwar

DEAR EDITOR: I have been in security for 8 years.  Some of my friends say there is no such thing as cyberwar.  My manager says, "If you see it on the VRT Blog then it's so"  Please tell me the truth; is there cyberwar? Virginia O'Hanlon. 115 West Ninety-Fifth

July 1, 2010 16:51

Rule Release for Today, Thursday July 1st, 2010

Remote code execution in Adobe Acrobat and Reader. Some folks are claiming it's a denial of service, heh, right. RCE is possible, get your rules here: http://www.snort.org/vrt/advisories/2010/07/01/vrt-rules-2010-07-01.html/

June 29, 2010 16:46

Rule Release for Today, Tuesday June 29th, 2010

We added and modified multiple rules in the backdoor, dos, exploit, misc, multimedia, netbios, oracle, pop3, rpc, specific-threats, web-activex, web-client and web-misc rule sets . Information is here: http://www.snort.org/vrt/advisories/2010/06/29/vrt-rules-2010-06-29.html/

June 28, 2010 16:21

IMPORTANT Rule Download Change

Today the Snort Web Team made a change to the way that Snort rules are downloaded from snort.org. Hopefully this will result in faster downloads for most people. The changes are highlighted below: We are changing the way we publish rules. In June 2010 we stopped offering rules i

June 26, 2010 12:20

Smart Grids and the Importance of Smart Security Choices

I got a flyer in my mail a couple of days ago, telling me that my local utility company would be coming out soon to install a smart meter on my house. Like most customers, I didn't think too much about it, until the new meter was installed today. That's when my curiosity