Actual Conversation - botnets explained
[11:04] <[?] someone > Pusscat: basically im trying to walk an non-technical person though a simple irc bot [11:04] <[?] someone > my goal was for my mom to be able to accurately describe a botnet [11:04] <[?] someone > like code chunk - this is the c&c inte
Hand Parsing Packets for False Negative Glory
Yesterday, on the Snort-Sigs mailing list, we had a report of a potential false-negative in an older Snort rule. While he was unable to provide a full packet capture at the time, the author of the email was able to provide a copy-paste of the packet data. A lot of times, Alex Kir
require_3whs and the Mystery of the Four-Way Handshake
So, Tod Beardsley over at Breakingpoint Labs decided to kick around RFC793 some, and came across the "simultaneous connection". You can read the RFC at http://www.faqs.org/rfcs/rfc793.html, check around page 32 or look for the phrase "Simultaneous initiation".
Hacker2Hacker and the State of Computer Security in Brazil
I was lucky enough to attend the 6th Annual Hacker2Hacker Conference this weekend in Sao Paulo, Brazil as a speaker sent by Sourcefire. As it was my first time in South America, the trip was an enlightening one - not only did I learn all about the awesomeness that are caipirinhas
Rule release for today - November 25th, 2009
Extra coverage for the Microsoft Internet Explorer tag issue. Changelogs etc, available here http://www.snort.org/vrt/advisories/2009/11/25/vrt-rules-2009-11-25.html
Rule release for today - November 23rd, 2009
Microsoft Internet Explorer suffers from a programming error that may allow a remote attacker to execute code on an affected system. Advisory and changelog here: http://www.snort.org/vrt/advisories/2009/11/23/vrt-rules-2009-11-23.html
Help us help you
Remember how you've been hearing for years that cybercriminals would start targeting smartphones "soon"? Well, we've seen 2 iPhone worms this month alone. The first worm is "rickrolling" jailbroken iPhones in Austria Australia. The worm uses a simple h
Rule release for today - November 18th, 2009
Rules added and modified in several categories. As usual, go here: http://www.snort.org/vrt/advisories/2009/11/18/vrt-rules-2009-11-18.html for the changelog.
November 2009 Vulnerability Report
Sourcefire VRT Vulnerability Report November 2009 from Sourcefire VRT on Vimeo. November Vulnerability Report. This month, Alain Zidouemba talks about Microsoft Patch Tuesday, the SSL renegotiation flaw and the iPhone worm.