Blog
Recent
March 10, 2009 15:43

Behold the Glory of Mattland

Like many other groups, the VRT has a morning routine. Generally it involves comparing kill board stats or raiding tips on whatever game is hot, a quick run down on the work of the day (sometimes as broad as “go break something”, sometimes more specific), and then some time set a

March 10, 2009 14:04

Microsoft Tuesday Coverage for March MS09-006, MS09-008

Microsoft Security Bulletin MS09-006: A programming error in the Microsoft Windows kernel may allow a remote attacker to execute code with system level privileges. This may be exploited when specially crafted EMF files are viewed using Microsoft Internet Explorer. A rule to dete

March 6, 2009 11:15

Generating Virus Signatures - The Automated Way

A common characteristic of malware distributed as an executable is to use a PE packer, such as UPX or Petite, to compress and obfuscate the malicious content. Once a file has been determined to be malware by our analysts and is using a PE packer that ClamAV does not currently unp

March 3, 2009 16:54

Rule release for today - March 3rd 2009

Specific threats, ActiveX and web-client have new rules. Major rule updates to other, older rules. Details: http://www.snort.org/vrt/advisories/vrt-rules-2009-03-03.html

February 27, 2009 15:02

Rule release for today - February 27th 2009

We've been busy again... Microsoft Excel Code Execution (CVE-2009-0238): Microsoft Excel contains a programming error that may allow a remote attacker to execute code on a vulnerable system. The problem occurs when Excel attempts to process a specially crafted document with

February 25, 2009 14:48

Conficker variant B - Still detected

As with all malware, variants eventually float to the surface of the threat landscape. Conficker is no different. The latest variant imaginatively named Conficker B, still uses the same propagation methods the original used. That is, it still attempts to exploit the vulnerability

February 24, 2009 09:39

Detecting Silly Javascript Obfuscation Techniques

Last week I got an e-mail from Edward Fjellskål, Senior Security Analyst at Sourcefire's new Norwegian partner Redpill Linpro. He'd run across a strange piece of obfuscated Javascript at hxxp://bizoplata.ru/pay.html (WARNING: CONTAINS LIVE MALWARE), and he wanted to know

February 22, 2009 12:55

Homebrew patch for Adobe AcroReader 9

People seemed a bit worred about the Adobe Reader bug, so I figured I'd take a bit of time this morning and create a home brew patch for people to protect themselves with until March 11th rolls around. The patch is just a replacement DLL - AcroRd32.dll to be precise. Take th

February 20, 2009 19:44

Adobe Acrobat and Reader Buffer Overflow Snort Rules

As promised earlier this evening we are releasing rules to detect attacks targeting this vulnerability. More rule details are available at http://www.snort.org/vrt/advisories/vrt-rules-2009-02-20.html Ur welcom.