Blog
Recent
March 23, 2010 14:45

Rule release for today - March 23rd, 2010

Apple Safari RCE (CVE-2010-0049): Apple Safari contains a programming error that may allow a remote atttacker to execute code on an affected system. The issue presents itself when the browser fails to properly process certain HTML elements concerning RTL text. Additionally, as a

March 17, 2010 14:50

Rule release for today - March 17th, 2010

A maintenance release mostly, lots of changes to rules and quite a few deletions. Two new rules added. Check out the changes here

March 16, 2010 13:36

The New Disclosure Debate and the Evil Mr. Moore

So, let's pretend you are Rob, Mr. Head of IT, and that you are sitting in your office on March 9th, working on your fantasy baseball (I hear Albert Pujols is the way to go...) when one of your staff walks in and says that Microsoft has another 0-day running around. Internet

March 10, 2010 22:08

Rule release for today - March 10th, 2010

Microsoft Internet Explorer (2010-0806): Microsoft Internet Explorer contains a programming error that may allow a remote attacker to execute code on an affected system. Check it here Oh, and the rule is a shared object rule, so the changelog won't actually show it. If you

March 9, 2010 19:11

March 2010 Vulnerability Report

This month, Alain discusses the two patches from Microsoft, 0day vulnerabilities in Apache, Opera, Internet Explorer and finishes with VRT activity in March.

March 9, 2010 18:58

Rule release for today - March 9th, 2010

Microsoft Security Advisory (MS10-016): Microsoft Windows Movie Maker contains a programming error that may allow a remote attacker to execute code on an affected system. Microsoft Security Advisory (MS10-017): Microsoft Excel contains several programming errors that may allow a

March 9, 2010 18:54

APT: Should your panties be in a bunch, and how do you un-bunch them?

There is no more predictable group of people than marketers. Once a term reaches a certain tipping point, they grab onto it for dear life and choke it until it means nothing. Apparently, the Advanced Persistent Threat (APT) hit that point somewhere around December. Despite the te

March 4, 2010 17:06

Rule release for today - March 4th, 2010

We added multiple rules to the specific-threats, spyware-put, web-client, backdoor, and web-misc rule sets as well as making a whole lot of modifications to existing rules. Just a bit of a clean up. Details here: http://www.snort.org/vrt/advisories/2010/03/04/vrt-rules-2010-03-0

March 2, 2010 21:12

The Sudden Reappearance of MS03-039

Last Friday, I got into the office and pulled up my email. Among other things, there was an escalation from Sourcefire's support group, where the customer had alerts on SIDs 15512 and 3397, and they wanted an official opinion from Sourcefire as to whether the alerts they were