Blog
Recent
May 20, 2009 09:43

Rules to detect IIS 6.0 WebDAV exploit

Thanks for the inquiries. Here are rules that detect attacks against IIS 6.0 with WebDAV enabled. (see yesterdays post for details) alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"WEB-IIS Microsoft IIS 6.0 WebDAV COPY remote authentication bypass attempt"

May 19, 2009 17:19

Snort protection against IIS 6.0 WebDAV exploit

Microsoft Security Advisory (971491) published on May 18, 2009 concerns a vulnerability in IIS that may allow unauthorized access to an area of a website that would normally be protected. An attack against IIS 6.0 with WebDAV enabled was published at milw0rm (http://www.milw0rm.

May 13, 2009 15:53

IP Blacklisting in Snort

Our Supreme Overlord and Benevolent Dictator, Marty Roesch, had a little free time on his hands over the weekend and spent some of it writing a new preprocessor for Snort 2.8.4.1 that implements IP blocklisting. This should help a great deal with performance for those folks who l

May 12, 2009 16:00

Microsoft Tuesday Coverage for May MS09-017

Microsoft Security Advisory MS09-017: Microsoft PowerPoint contains several programming errors that may allow a remote attacker to execute code on a vulnerable system via a specially crafted PowerPoint file. Rules to detect attacks targeting these vulnerabilities are included in

May 12, 2009 13:25

Exploit Development Class

Want to impress your friends, colleagues, girls, boys, employer, future employer? Want to become more attractive to the opposite sex? Want to make your past employer and/or ex-(girlfriend|boyfriend|spouse) jealous? Then you need to get dangerous and become awesome. We're run

May 11, 2009 10:12

Estimating Time

One of the developers here at Sourcefire, Andrew Williams, has written what we think is an interesting piece on Estimating Time for project planning. Take a look at it here: http://www.baltdad.com/2009/05/estimation/

May 8, 2009 13:08

Snort and Neural Networks

Jacson Rodrigues Correia da Silva just finished his Bachelors degree in computer science. As part of his final project, he came up with an implementation that allows you to use Snort with JavaNNS. (see http://www.cis.cau.edu/675/javasnns.html). This means, you could use Snort in

May 8, 2009 13:01

DoJoSec and dnssnarf

One of our IT guys, (total security geek Christopher McBee) found some interesting information from last nights DoJoSec meeting. Here's what he has to say: During Sean Wilkerson's talk at last nights DojoSec meeting (http://www.dojosec.com), Sean discussed some simple op

May 5, 2009 15:51

Rule release for today - May 5th 2009

Adobe Reader Code Execution (CVE-2009-1492): The JavaScript API in Adobe Reader may allow a remote attacker to execute code on an affected system. The problem occurs when specially crafted JavaScript uses the getAnnots method in a PDF document. A rule to detect attacks targeting