Blog
Recent
June 22, 2010 12:18

ClamAV for Windows

Recently, we released the only official Windows-specific version of ClamAV, appropriately called ClamAV for Windows (http://www.clamav.net/lang/en/about/win32/). It is designed to use little memory and processing speed because it uses an advanced cloud-based protection mechanism,

June 21, 2010 11:29

Defenders of the Faith

Quite recently, Tavis Ormandy released a 0-day vulnerability in a prominent piece of software. For this transgression, both he and his employer received a good deal of bad press. Sadly, very few in the professional security researcher crowd made enough noise about this, and to th

June 17, 2010 16:26

Rule Release for Today - June 17th, 2010

As a result of ongoing research, the Sourcefire VRT has added multiple rules in the dos, exploit, ftp, mysql, policy, rpc, specific-threats, spyware-put, web-activex, web-client, web-misc and web-php rule sets to provide coverage for emerging threats from these technologies. For

June 15, 2010 09:17

National Cyber-Security Emergency and Phenomenal Cosmic Power or Lieberman -- EARN IT

So…you’re at the bar and across the room you see this incredible [insert whatever floats your boat here].You spend an inappropriate amount of your time watching this person and your mind starts to fill in the details that the dark environment masks.  Then they turn around walk to

June 14, 2010 15:20

Rule Release for Today - June 14th, 2010

Apple Safari RCE (CVE-2010-1939), Google Chrome GLUG bypass (CVE-2010-1663). Details available here: http://www.snort.org/vrt/advisories/2010/06/14/vrt-rules-2010-06-14.html/

June 14, 2010 08:46

Sourcefire VRT Expansion Plans (We are Hiring)

One of the hardest things in life is finding the right place to work, where you can spend eight to ten hours a day doing something you enjoy and also pay your bills. I’ve been lucky enough in my life to find this type of place three times: HiverWorld, Farm9, and Sourcefire. Each

June 10, 2010 17:53

Rule Release for Today, June 10th, 2010

Microsoft Help and Support Center Bypass Vulnerability: Microsoft Help and Support Center contains a programming error that may allow a remote attacker to bypass security restrictions on an affected system. The error occurs when invalid hex-encoded characters are used as a param

June 8, 2010 13:30

Rule Release for today - June 8th, 2010

Here we are again, Microsoft Tuesday for June 2010. A number of issues this month and rules to provide coverage for attack detection. Main advisory numbers for IDS/IPS coverage are MS10-033, MS10-034, MS10-035, MS10-038, MS10-039 and MS10-041. Check out the advisory and changelog

June 7, 2010 15:59

Single Threaded Data Processing Pipelines and the Intel Architecture

Or, No Performance for you, go home now. Today's blog post is a guest appearance by our Benevolent Dictator and Glorious Leader, Marty Roesch. We asked Marty for his thoughts on threading, performance and processing network data. Here's what we got: Executive Summary