Blog
Recent
February 26, 2010 18:34

Rule release for today - February 26th 2010

Microsoft Internet Explorer contains a programming error that may allow a remote attacker to execute commands on a vulnerable system. The attacker needs to supply VBScript to invoke winhlp32.exe, which can then be used to execute commands via a specially crafted .HLP file. http:

February 23, 2010 20:30

Rule release for today - February 23rd 2010

Maintenance release, we added multiple rules to the rpc, specific-threats, web-client, chat, sql and oracle rule sets. A whole bunch of modifications too. http://www.snort.org/vrt/advisories/2010/02/23/vrt-rules-2010-02-23.html

February 23, 2010 18:18

CyberShockWave

There has been a lot of talk about CNN’s special presentation called “Cyber Shockwave” in the past couple of days. The program was an edited presentation of the 4-hour war games exercise that took place at the Mandarin Oriental Hotel in Washington D.C. Designed by Michael Hayden,

February 17, 2010 16:00

Rule release for today - February 17th 2010

A maintenance release, some new rules in the policy, web-misc, web-client, web-activex, sql and exploit rule sets, multiple rule modifications are available too. Details are here: http://www.snort.org/vrt/advisories/2010/02/17/vrt-rules-2010-02-17.html

February 16, 2010 18:42

February 2010 Vulnerability Report

February 2010 Vulnerability Report This month's report covers the Microsoft Tuesday advisories for February 2010 and a whole bunch of Snow at Sourcefire HQ.

February 9, 2010 16:56

Microsoft Tuesday Coverage for February 2010

Well, Microsoft really made up for a light patch in January with a hefty dose of vulnerabilities this month. We had our hands full dealing with this avalanche, we have coverage for the non-local vulnerabilities, only a couple of issues were covered in previously released rules, t

February 3, 2010 11:59

Coming Soon To A Snort User's Group Near You

I was in Chicago last Friday for a meeting of the local Snort Users' Group (Powerpoint presentation available here). While the weather was as crummy as you'd expect out of Chicago in January, overall it was an excellent visit, thanks to the group of people who turned out

January 26, 2010 16:23

Rule release for today - January 26th 2010

A few additions, some modifications. Mostly a maintenance release. Check it out: http://www.snort.org/vrt/advisories/2010/01/26/vrt-rules-2010-01-26.html

January 25, 2010 12:20

Using byte_jump as a Detection Mechanism

This is just a quick tidbit about writing effective snort rules that I thought I would share. I was writing a Snort shared object (SO) rule for demonstration purposes. I was going to use a "vulnerability" where the DATA section, which is the last part of the packet, spe