Blog
Recent
April 15, 2010 14:59

Rule release for today, Thursday April 15th, 2010

Maintenance release, a few new rules and modifications to existing ones. Check here for details.

April 13, 2010 16:23

Rule release for today, Tuesday April 13th, 2010

Microsoft Tuesday and Adobe Quarterly Patch. Details available here. Microsoft Security Advisory (MS10-019): The Microsoft CAB Subject Interface Package (SIP) implementation contains a programming error that may allow a remote attacker to bypass the authentication mechanism. Mi

April 8, 2010 17:47

Rule release for today, Thursday April 8th, 2010

Mostly some small fixes, couple of reference changes and some new rules. Check it out here

April 7, 2010 20:11

WTF, Ubuntu?

I just finished installing Ubuntu 9.10 server edition on a shiny new Dell PowerEdge R805 box, as part of expanding our malware analysis labs. No big deal - half an hour of babysitting an installer, right? Wrong. It took me 5 hours, thanks to some really stupid decisions made by

April 5, 2010 15:00

Matt's Primer for PDF Analysis

For obvious reasons, the VRT has been spending a lot of time on the PDF format lately. While the attack researchers have been concentrating on fuzzing, reverse engineering and data flow analysis, the defense researchers have been automating the backend analysis of PDF submissions

April 1, 2010 14:16

What in the name!...

If you are confused by the naming of ClamAV products, here's a quick breakdown: * ClamAV®: open source (GPL) anti-virus toolkit for UNIX, designed especially for e-mail scanning on mail gateways. Available here. * ClamAV® (Win32 binaries): Win32 port of ClamAV. Availa

April 1, 2010 11:37

New Mac OSX Module for Snort

Today, the VRT is excited to announce a revolutionary new module for the Snort Intrusion Detection System.  The extraordinary capability of Snort to be molded through rules, so_rules, preprocessors and the fact that the entire code base is open gives us unprecedented capability t

March 30, 2010 16:20

Rule release for today - March 30th, 2010

Microsoft Security Advisory (MS10-018): Microsoft Internet Explorer contains several programming errors that may allow a remote attacker to execute code on an affected system. Details here: http://www.snort.org/vrt/advisories/2010/03/30/vrt-rules-2010-03-30.html