Snort 2.8.4 is nigh
Back in February, I wrote about having to upgrade Snort pretty soon. Well, the time is upon us. This week, we will be releasing Snort 2.8.4. When this happens, the only way to stay current with detection for anything DCERPC related will be to upgrade Snort. We will not be releasi
New SO Rules For Conficker.C P2P Detection
As part of our ongoing research surrounding everyone's favorite new worm, Conficker, several members of the VRT recently joined the Conficker Working Group, a group of security professionals from a wide range of networking and security-related companies. You may have heard of
Rule release for today - March 31st 2009
A few new rules in this release, here's the highlights: MySQL Denial of Service (CVE-2009-0819): A programming error in MySQL Server may allow a remote attacker to cause a Denial of Service (DoS) against a vulnerable machine. Mozilla Firefox XML Buffer Overflow: A programmi
Rule release for today - March 27th 2009
A couple of interesting vulnerabilities covered in todays release, first one is for Microsoft Windows: Microsoft Windows GDI Buffer Overflow: A programming error in the Microsoft Windows kernel may allow a remote attacker to execute code with system level privileges. This may be
BEA WebLogic plug-in for Apache JSESSION Cookie overflow
Sometimes you forget you reported a vulnerability. Especially when the vendor keeps sending you lots of messages that contain the following: ____________________________________________________ Reporter: Matt Watchinski ("Matt Watchinski" <mwatchinski@sourcefire.co
Conficker.C Purchase tickets now for the April 1st event
Recap. Conficker.C also known as W32/Conficker.C.worm, WORM_DOWNAD.AD,W32.Downadup,Net-Worm.Win32.Kido.cn Still uses MS08-067 to spread itself just like the A and B variants, therefore the detection released on 2008-10-23 still generates events based on this spreading mechanism
Geographic Representation of Snort Events
One of the Sourcefire field engineers has whipped up a Perl script that will take events generated by Snort or a Sourcefire appliance and map them using Google Earth. You can find a write up here at Leon's blog where he has an interesting example relating to worm activity.
Creating new detection coverage : Using SCADA OMRON-FINS as an example
The What In 2008 a lot of reports and press centered around SCADA Networks and their protection, additionally Core Security and several other researchers released vulnerabilities in software related to SCADA networks. The most notorious was the vulnerability in CitectSCADA (http:
Rule release for today - March 17th 2009
We've been busy updating some rules and adding extras, lots of changes to a lot of rules. Mostly a maintenance release with some new scada rules. The scada rule set now includes support for OMRON FINS. Additionally, multiple rules in the specific-threats and content-replace