Blog
Recent
August 7, 2009 11:34

Syntax Checking your Snort Rules

Our friend over in blighty has been at it again. This time, Leon has come up with dumbpig, a tool written in Perl that will check your Snort rules and tell you what, if anything, is wrong with them and what you should do about it. Here's a sample of dumbpig output: torchwoo

August 3, 2009 16:00

DoJoSec meeting - August 6th

This month's DoJoSec meeting features three speakers: Sean Morrissey - "Apple’s File Vault – How Secure is it?" Dale Beauchamp - "The First 120" Matt Fisher - "The Big Picture: Web Risks and Assessments Beyond Scanning" Details are available he

August 3, 2009 14:33

Freakshow Sumo

Patrick Mullen (phoo) and Ryan Pentney (kappa) take each other on in a Sumo match at the IOActive Freakshow party at Defcon 17. Watch closely, the loser of each bout gets tea bagged.

July 30, 2009 14:02

Freakshow

We'll be attending the Freakshow on Saturday, come along and say hello. You can also find us at the Microsoft Security Appreciation Reception tonight at Treasure Island. You can't get in without an invite though, so if you have one and you're going, come find us and

July 28, 2009 16:20

Microsoft Out of Band Patch - 28th July 2009

So, today, Microsoft released an out of band patch, two issue, one for Internet Explorer... Microsoft Security Advisory (MS09-034): Microsoft Internet Explorer contains programming errors that may allow a remote attacker to execute code on a vulnerable system. Rules to detect a

July 27, 2009 11:17

Only whitehat journalists need Metasploit to hack oracle

I'm astounded at the number of crazy articles concerning the release of Oracle exploits for PATCHED vulnerabilities. How is it that oracle in particular gets this kind of response, when Metasploit has been doing this with other vendors for years and years? Never mind the fact

July 24, 2009 12:08

Adobe 0-day update

We love adobe. We love the u30. We love 32 bit values that are encoded as somewhere between 1 and 5 bytes. This is certainly a file format which has outlasted it's day in the sun. (56k modems) Here Adobe mentions a CVE. Keep that in mind. Yesterday, they locked a bug you mi

July 22, 2009 19:42

Rule release for today - July 22nd 2009

Adobe Acrobat and Reader Buffer Overflow: Adobe Acrobat and Adobe Reader suffer from a programming error that may allow a remote attacker to execute code on an affected system. The problem occurs during the processing of a flash file embedded in a pdf document. Rules to detect

July 22, 2009 12:56

Don’t read this post

So Lurene is mad at me, me being Matt W. The reason for this is the following conversation. Me: Hey you guys see the US-CERT notice on ISC dhclient overflow? Lurene: Yup, working on coverage right now for release today. Lurene: You do know this vuln is awesome right? Me: How so?