Following us at tumblr
We now have an additional feed of our blog, our twittering and our upcoming video channel all rolled into one at tumblr. Check it out at http://vrt-sourcefire.tumblr.com/. We aren't going to publish other content at that blog that doesn't appear here, rather it is meant
Rule Performance Part One: Content Matches
One of the many things that occupy the time of the VRT is reviewing rule performance data, whether that data is internally generated from one of our test environments or received from customer reports. In the “Rule Performance” series of blog posts, we’ll look at the set of issue
Microsoft Video ActiveX Control rule coverage
So, a bit of a problem with an ActiveX control that can be leveraged via a webpage, without any user interaction required. Who would've expected that? Microsoft Security Advisory (972890): The Microsoft Video ActiveX control contains a vulnerability that may allow a remote a
Rule release for today - July 1st 2009
Well, we've continued the work on modifying netbios rules to take advantage of the new dcerpc preprocessor and changed a bunch of the shared object rules. Here's a mapping of modified and replaced rules: Replacement Rule(s) (GID 3) Replaced Shared Object Rules (GID 3) 14
DojoSec Adobe bug fixed
Well I've been busy, AFA 2009 CyberSpace Symposium, tracking down cool crashes, booking DefCon travel, and my job (herding cats at Sourcefire World Domination HQ). But better late than never right? June 9th, Adobe released http://www.adobe.com/support/security/bulletins/aps
DoJoSec meeting - July 2nd
Not happening. Some Federal holiday getting in the way of this month's meeting. Firework day or similar apparently. Next one will be the first Thursday in August, right after DefCon. We'll see you there, assuming we make it back from Vegas in time. Check http://dojosec.c
Fun with Shell Scripts and OS X
Recently, more malware targeting OS X has been released. This is exciting stuff, and one such sample is RSPlug. The overall premise of RSPlug's operation isn't very sexy, as in the end it's just a malicious script that an unsuspecting user is tricked into running on t
Rule release for today - June 22nd 2009
We've been busy making things faster. This release has some modifications to rules to improve performance. Details are available here: http://www.snort.org/vrt/advisories/2009/06/22/vrt-rules-2009-06-22.html
Rule release for today - June 16th 2009
A maintenance release this one, few new rules, performance improvements, etc.. Details are available here: http://www.snort.org/vrt/advisories/2009/06/16/vrt-rules-2009-06-16.html/