Rule release for today - June 12th 2009
Adobe Acrobat and Reader Remote Vulnerability (CVE-2009-1859): Adobe Acrobat and Acrobat Reader contain programming errors that may allow a remote attacker to execute code on a vulnerable system. The errors occur in the processing of embedded image files in a PDF document. A rul
Microsoft Tuesday Coverage for June
Wow, lots of stuff in today's release from Microsoft. Here are the highlights: Microsoft Security Advisory MS09-018: The Microsoft Windows LDAP implementation contains programming errors that may allow a remote attacker to execute code on an affected system. Rules to detect
ClamAV DoJoSec Talk Addendum
Just a quick note to clarify something I said yesterday at DoJoSec. During my talk, I mentioned that ClamAV is supports a variety of operating systems, including Linux, Solaris, BSD, OS X, etc. Packages are made available by third-parties for some of those. However, you can build
DoJoSec roundup
Last nights DoJoSec meeting was most excellent. We were treated to talks from: * Alain Zidouemba - What to do with the Unknown * Richard Goldberg- How not to get pwnd by your clients * Joe Klein - IPv6 security issues * Eoghan Casey - Getting Physical with Mobi
Tweeting from DoJoSec
We'll be tweeting from DoJoSec tomorrow night. Follow us at: http://twitter.com/VRT_Sourcefire. For everyone already following us who will get this posting on twitter soon, pay attention tomorrow evening. Event starts around 6:00 pm EDT. If we can get pictures, we will.
IDA Pro 5.5 Alpha
This just in: http://hexblog.com/2009/06/ida_pro_55_goes_alpha.html SWEET!
DoJoSec Meeting - June 4th
The DoJoSec lineup for the June meeting has been announced and our own Alain Zidouemba will be giving a presentation entitled "What to do with the Unknown". Alain will be demonstrating what options are available to the administrator when an unknown piece of malware is
Gumblar and More On Javascript Obfuscation
A couple of months ago I put together a post on detection of obfuscated JavaScript. Not surprisingly, that topic has popped back up on the VRT radar screen this week, this time in the context of something much more interesting - Gumblar, the new worm that everyone is talkingabout
Winamp MAKI Parsing Vulnerability Details
About two months ago, we found a vulnerability in the Winamp 5.55 MAKI script parsing module. We reported our findings to AOL. AOL then released Winamp version 5.552 with the fix. Here are the details: Winamp MAKI Parsing Integer Overflow Vulnerability Vendor: AOL/Nullsoft Sev