Blog
Recent
January 2, 2009 14:07

Md5 actually harmful

You probably shouldn't take any other view of this vulnerability into consideration. Some amazing research and dedication went into proving this vulnerability is realistic and viable. You should note that detection of it is not really feasible; the bad certs look exactly like

December 29, 2008 15:33

The vuln before Christmas

* T'was the night before Christmas, and all through the net, * not a hacker was stirring, not even FX, * the servers all hummed in post-purchase daze, * to await the deluge of gift-card traffic craze, * * The VRT was drinking, three sheets to the wi

December 24, 2008 22:32

MS-SQL Quickie update

Hey folks, Since MS chose today to speak on this issue (see http://www.microsoft.com/technet/security/advisory/961040.mspx) We wanted to remind you that we released coverage for this rule on the 9th of December. The following SIDs address this issue: 15127, 15128, 15129, 15130

December 23, 2008 17:41

Rule release for today - December 23 2008

Mostly a maintenance release this one, some new rules in web-activex, web-client, backdoor and specific-threats. Check out the information here: http://www.snort.org/vrt/advisories/vrt-rules-2008-12-23.html

December 18, 2008 16:27

Snort Rule Coverage for MS08-078

A critical vulnerability in Microsoft Internet Explorer outlined in Microsoft Security Bulletin MS08-078, is covered by a previously released rule. The rule to detect attacks targeting this vulnerability was included in the release on 2008-12-11 and is identified with GID 1, SID

December 18, 2008 14:31

Rootkit takes advantage of MS08-078 vulnerability

On December 17 2008, Microsoft released security update MS08-078 to patch a vulnerability found in several versions of Microsoft Internet Explorer. The root cause for this vulnerability was found to be the incorrect handling of certain XML tags in Internet Explorer that reference

December 16, 2008 16:00

SPAN, The Heap, and esoteric memory buggery…

Have you ever heard someone say they needed a pointer that pointed to itself and was also a nop? Maybe one they could write to? No? Where are you hanging out? For the rest of you, I'll explain why this set of properties can be useful, and when you might want to make use of

December 16, 2008 14:26

Rule release for today

Today's VRT Certified Rule release has coverage for a vulnerability in Oracle Internet Directory and CUPS. There are also a few new rules added in chat.rules and others. Oracle Internet Directory Denial of Service (CVE-2008-2595): Oracle Internet Directory contains a program

December 11, 2008 16:55

Out of band Microsoft Security Advisory for Internet Explorer CVE-2008-4844 and SQL Server vulnerability CVE-2008-5416

Today, Microsoft released a security advisory for Internet Explorer. Microsoft SQL server also has a problem with a stored procedure. In response, we released some new rules to detect attacks against these two products. Details on the rules are here http://www.snort.org/vrt/advis