Virut Analysis and Snort Rule
Virut (from virus + trojan) is a family of malware that has been around in since about 2006. Unfortunately for us, it is still around 3 years later with new variants being released on regular basis. We came across a recent Virut sample (MD5:e68c4b9428f41036b1cf890d93bdf390) and t
Some days you just can't walk away.....
I apologize ahead of time for the marketing fluff in this post, I promise the next several posts after this will be much heavier on the tech and the cool. However, I just couldn't let this one go and neither could any of the Sourcefire VRT. Today we got an anonymous email wi
DoJoSec Meeting - May 7th
Here lie the details: http://www.dojosec.com/?p=109 A few of us are planning on attending the meeting, come and say hello. Also, from last month's meeting, our fearless leader and Senior Director of Chaos and Mayhem gave a talk that had something to do with PDFs and Adobe :
Rule release for today - April 21st 2009
A small set of new rules in today's release and a couple of modifications. Here are the highlights: Adobe Flash Player Buffer Overflow (CVE-2009-0520): Adobe Flash Player contains a programming error that may allow a remote attacker to execute code on a vulnerable system via
New Snort.org Website
As many of you know the Snort project recently reached its 10th Anniversary. In honor of this milestone we’re giving Snort a new website to call home. This site update is much more than just a new look and feel. We’re rebuilding the site from the ground up to better serve the nee
Microsoft Tuesday Coverage for April MS09-009, MS09-010, MS09-011, MS09-012, MS09-013, MS09-014, MS09-015, MS09-016
Microsoft Security Advisory MS09-009: A programming error in Microsoft Excel may allow a remote attacker to execute code on a vulnerable system via a specially crafted XLS file. A rule to detect attacks targeting this vulnerability is included in this release and is identified w
Rule release for today - April 10th 2009
Rule for Powerpoint memory corruption bug, CVE-2009-0556, extra rule for MS08-068 and Conficker detection update. More details here: http://www.snort.org/vrt/advisories/vrt-rules-2009-04-10.html
Updating Software
Things to remember when updating software: * Backup what you already have * Use checklists * Read the documentation for the new software (including the INSTALL file and README) you never know what might have changed since the last time you did it * When install
Rule Release for today - April 8th 2009
This release updates the VRT Certified Snort Rules to utilize the new DCE/RPC v2 preprocessor. This change deletes more than 5000 rules in the netbios rule category and replaces them with a much smaller rule set. It aslo contains additional detection for hosts that are currently