Blog
Recent
December 8, 2009 11:17

Actual Conversation - botnets explained

[11:04] <[?] someone > Pusscat: basically im trying to walk an non-technical person though a simple irc bot [11:04] <[?] someone > my goal was for my mom to be able to accurately describe a botnet [11:04] <[?] someone > like code chunk - this is the c&c inte

December 2, 2009 13:56

Hand Parsing Packets for False Negative Glory

Yesterday, on the Snort-Sigs mailing list, we had a report of a potential false-negative in an older Snort rule. While he was unable to provide a full packet capture at the time, the author of the email was able to provide a copy-paste of the packet data. A lot of times, Alex Kir

December 1, 2009 16:29

require_3whs and the Mystery of the Four-Way Handshake

So, Tod Beardsley over at Breakingpoint Labs decided to kick around RFC793 some, and came across the "simultaneous connection". You can read the RFC at http://www.faqs.org/rfcs/rfc793.html, check around page 32 or look for the phrase "Simultaneous initiation".

December 1, 2009 09:31

Hacker2Hacker and the State of Computer Security in Brazil

I was lucky enough to attend the 6th Annual Hacker2Hacker Conference this weekend in Sao Paulo, Brazil as a speaker sent by Sourcefire. As it was my first time in South America, the trip was an enlightening one - not only did I learn all about the awesomeness that are caipirinhas

November 25, 2009 13:28

Rule release for today - November 25th, 2009

Extra coverage for the Microsoft Internet Explorer tag issue. Changelogs etc, available here http://www.snort.org/vrt/advisories/2009/11/25/vrt-rules-2009-11-25.html

November 23, 2009 18:15

Rule release for today - November 23rd, 2009

Microsoft Internet Explorer suffers from a programming error that may allow a remote attacker to execute code on an affected system. Advisory and changelog here: http://www.snort.org/vrt/advisories/2009/11/23/vrt-rules-2009-11-23.html

November 23, 2009 12:13

Help us help you

Remember how you've been hearing for years that cybercriminals would start targeting smartphones "soon"? Well, we've seen 2 iPhone worms this month alone. The first worm is "rickrolling" jailbroken iPhones in Austria Australia. The worm uses a simple h

November 18, 2009 16:34

Rule release for today - November 18th, 2009

Rules added and modified in several categories. As usual, go here: http://www.snort.org/vrt/advisories/2009/11/18/vrt-rules-2009-11-18.html for the changelog.

November 11, 2009 19:53

November 2009 Vulnerability Report

Sourcefire VRT Vulnerability Report November 2009 from Sourcefire VRT on Vimeo. November Vulnerability Report. This month, Alain Zidouemba talks about Microsoft Patch Tuesday, the SSL renegotiation flaw and the iPhone worm.