Rule release for today - July 21st 2009
A few new rules and some modifications to improve rule performance in today's release. Apple iTunes Buffer Overflow (CVE-2009-0950): Apple iTunes contains a programming error that may allow a remote attacker to execute code on a vulnerable system. Rules to detect attacks ta
Vulnerability Report July 2009
This is a Beta version of our Vulnerability Report. We haven't done this, or anything like it before and we got it together pretty quickly. We're learning as we go. We would really appreciate some thoughts, tips and suggestions on it.
How do I become a Ninja?
Earlier this week, we posted this blog item: Ask the VRT a question. We had a few people write in and ask us questions about Snort, Snort rules and the other obvious Snort related questions. Then, we got something interesting... mish asks "How do I become a Ninja?" (H
Rule release for today - July 16th 2009
For those of you following our twitter feed, you now know why we were laughing last night... ISC DHCLIENT Buffer Overflow (CVE-2009-0692): The ISC DHCLIENT daemon suffers from a programming error that may allow a remote attacker to capitalize on a stack overflow and execute code
Rule release for today - July 15th 2009
Couple of Mozilla Firefox issues that need to be addressed... Mozilla Firefox Remote Code Execution: Mozilla Firefox contains a programming error that may allow a remote attacker to execute code on an affected system. A failed attempt will cause a Denial of Service against the a
Why I'd Dress LIke a Cheerleader
Twitter, the Internet’s biggest game of telephone, occasionally yields some interesting material. Yesterday, as an example, Lurene got a tweet that someone was upset about the Saphead’s write up of their work in this year’s DefCon CTF qualifier. The imagery they used to convey th
Rule release for today - July 14th 2009
A number of issues for Microsoft products this month, here are some selections... Microsoft Security Advisory (MS09-028): Microsoft DirectShow contains programming errors that may allow a remote attacker to execute code on an affected system. Rules to detect attacks targeting t
Sourcefire VRT firebreathing pig
Here's our video of the firebreathing pig. We made this in December of 2007. Now that we have a good camera, maybe we should reshoot the video.
Ask the VRT a question
We are extending the opportunity for you, the reader, to ask us questions. We will select the best question(s) each week and publish them, along with the answers we give, here. "What kind of questions can I ask?" Well, thanks for asking, you can ask us anything. It ca