Blog
Recent
July 10, 2009 13:10

Following us at tumblr

We now have an additional feed of our blog, our twittering and our upcoming video channel all rolled into one at tumblr. Check it out at http://vrt-sourcefire.tumblr.com/. We aren't going to publish other content at that blog that doesn't appear here, rather it is meant

July 8, 2009 13:45

Rule Performance Part One: Content Matches

One of the many things that occupy the time of the VRT is reviewing rule performance data, whether that data is internally generated from one of our test environments or received from customer reports. In the “Rule Performance” series of blog posts, we’ll look at the set of issue

July 7, 2009 12:11

Microsoft Video ActiveX Control rule coverage

So, a bit of a problem with an ActiveX control that can be leveraged via a webpage, without any user interaction required. Who would've expected that? Microsoft Security Advisory (972890): The Microsoft Video ActiveX control contains a vulnerability that may allow a remote a

July 1, 2009 15:00

Rule release for today - July 1st 2009

Well, we've continued the work on modifying netbios rules to take advantage of the new dcerpc preprocessor and changed a bunch of the shared object rules. Here's a mapping of modified and replaced rules: Replacement Rule(s) (GID 3) Replaced Shared Object Rules (GID 3) 14

June 30, 2009 17:40

DojoSec Adobe bug fixed

Well I've been busy, AFA 2009 CyberSpace Symposium, tracking down cool crashes, booking DefCon travel, and my job (herding cats at Sourcefire World Domination HQ). But better late than never right? June 9th, Adobe released http://www.adobe.com/support/security/bulletins/aps

June 30, 2009 11:41

DoJoSec meeting - July 2nd

Not happening. Some Federal holiday getting in the way of this month's meeting. Firework day or similar apparently. Next one will be the first Thursday in August, right after DefCon. We'll see you there, assuming we make it back from Vegas in time. Check http://dojosec.c

June 25, 2009 17:01

Fun with Shell Scripts and OS X

Recently, more malware targeting OS X has been released. This is exciting stuff, and one such sample is RSPlug. The overall premise of RSPlug's operation isn't very sexy, as in the end it's just a malicious script that an unsuspecting user is tricked into running on t

June 22, 2009 16:50

Rule release for today - June 22nd 2009

We've been busy making things faster. This release has some modifications to rules to improve performance. Details are available here: http://www.snort.org/vrt/advisories/2009/06/22/vrt-rules-2009-06-22.html

June 16, 2009 17:17

Rule release for today - June 16th 2009

A maintenance release this one, few new rules, performance improvements, etc.. Details are available here: http://www.snort.org/vrt/advisories/2009/06/16/vrt-rules-2009-06-16.html/