Blog
Recent
June 12, 2009 22:30

Rule release for today - June 12th 2009

Adobe Acrobat and Reader Remote Vulnerability (CVE-2009-1859): Adobe Acrobat and Acrobat Reader contain programming errors that may allow a remote attacker to execute code on a vulnerable system. The errors occur in the processing of embedded image files in a PDF document. A rul

June 9, 2009 16:25

Microsoft Tuesday Coverage for June

Wow, lots of stuff in today's release from Microsoft. Here are the highlights: Microsoft Security Advisory MS09-018: The Microsoft Windows LDAP implementation contains programming errors that may allow a remote attacker to execute code on an affected system. Rules to detect

June 5, 2009 11:41

ClamAV DoJoSec Talk Addendum

Just a quick note to clarify something I said yesterday at DoJoSec. During my talk, I mentioned that ClamAV is supports a variety of operating systems, including Linux, Solaris, BSD, OS X, etc. Packages are made available by third-parties for some of those. However, you can build

June 5, 2009 11:04

DoJoSec roundup

Last nights DoJoSec meeting was most excellent. We were treated to talks from: * Alain Zidouemba - What to do with the Unknown * Richard Goldberg- How not to get pwnd by your clients * Joe Klein - IPv6 security issues * Eoghan Casey - Getting Physical with Mobi

June 3, 2009 11:45

Tweeting from DoJoSec

We'll be tweeting from DoJoSec tomorrow night. Follow us at: http://twitter.com/VRT_Sourcefire. For everyone already following us who will get this posting on twitter soon, pay attention tomorrow evening. Event starts around 6:00 pm EDT. If we can get pictures, we will.

June 2, 2009 17:07

IDA Pro 5.5 Alpha

This just in: http://hexblog.com/2009/06/ida_pro_55_goes_alpha.html SWEET!

May 28, 2009 13:49

DoJoSec Meeting - June 4th

The DoJoSec lineup for the June meeting has been announced and our own Alain Zidouemba will be giving a presentation entitled "What to do with the Unknown". Alain will be demonstrating what options are available to the administrator when an unknown piece of malware is

May 22, 2009 13:54

Gumblar and More On Javascript Obfuscation

A couple of months ago I put together a post on detection of obfuscated JavaScript. Not surprisingly, that topic has popped back up on the VRT radar screen this week, this time in the context of something much more interesting - Gumblar, the new worm that everyone is talkingabout

May 20, 2009 11:54

Winamp MAKI Parsing Vulnerability Details

About two months ago, we found a vulnerability in the Winamp 5.55 MAKI script parsing module. We reported our findings to AOL. AOL then released Winamp version 5.552 with the fix. Here are the details: Winamp MAKI Parsing Integer Overflow Vulnerability Vendor: AOL/Nullsoft Sev