Blog
Recent
February 20, 2009 17:29

Have a nice weekend! (PDF love)

Maybe you read Michael Howard's twitter feed. If so, you may be wondering why you were asked to turn off Javascript in Adobe Acrobat Reader. Well, I'm here to tell you that if you were to load a PDF file with an embedded JBIG2 image stream: << /Type /XObject /Subty

February 19, 2009 14:28

Making Conficker Cough Up the Goods

I'm not a malware gal. I really dislike analyzing the stuff. It could be an artifact of a life spent pulling apart Microsoft binaries. When Microsoft releases a binary, everything looks the same; it's not a challenge to figure out what's going on. The only challenge i

February 18, 2009 11:41

MS09-002 in the wild

Yesterday we came across a website taking advantage of a programming error in Internet Explorer that allows a remote attacker to execute code on a vulnerable system. Microsoft issued an advisory (MS09-002) on February 10, 2009 and released a patched on the same day to mitigate th

February 17, 2009 16:14

Tony Blair has NOT died today

It seems like the Armenian Branch of Nathan Associates Inc (per a whois lookup of the IP address) is hosting a webpage claiming that former UK Prime Minister Tony Blair has died. As far a we know, Tony Blair is well as of February 17, 2009. This page uses the same template as the

February 13, 2009 14:28

Dcerpc2 Ruleset Now Available

Now that the Snort 2.8.4 RC-1 has been released, we at the VRT have been busy putting together a special rules file for use with this version of Snort and the new dcerpc pre-processor. We would like your assistance in testing this ruleset, the new version of Snort and the dcerpc

February 10, 2009 14:53

Microsoft Tuesday Coverage for February MS09-002, MS09-003, MS09-004, MS09-005

Four Microsoft Advisories to cover this month, fortunately, one of them was released in December so that left three... Microsoft Security Advisory MS09-002: Microsoft Internet Explorer contains programming errors that may allow a remote attacker to execute code on a vulnerable s

February 6, 2009 17:31

Important Snort rule changes and the new dcerpc preprocessor

In the very near future, the release of Snort 2.8.4 is going to bring about some major changes to the way that NetBIOS traffic is handled. This is because of the new dcerpc preprocessor. This preprocessor handles all the decoding functions that were previously taken care of usin

February 3, 2009 17:10

Rule release for today - February 3rd 2009

New rules in web-activex, chat and specific threats. Also, modifications to shared object rules for MS08-067, little bit of a performance enhancement. Details are available here: http://www.snort.org/vrt/advisories/vrt-rules-2009-02-03.html

January 30, 2009 16:02

Dial up security woes from East Africa

Two weeks ago, I upgraded my Internet connection at home. I went from a DSL (512 Kb/s download) to a fiber optics (20 Mb/s download) connection. A few days after getting this incredibly fast (and relatively affordable) connection I traveled from the East Coast of the United State