MS08-067 In The Wild
While sifting through my e-mail this morning, I saw a note from one of Sourcefire's European employees, asking if the VRT could take a look at some PCAPs pulled from a customer sensor - they'd triggered the rules for MS08-067, and our guy didn't think that they were f
OfficeCat Update
New advisories from Microsoft concerning Word. We've updated OfficeCat to provide coverage, more information on OfficeCat here: http://www.snort.org/vrt/tools/officecat.html
Microsoft Tuesday Coverage for December
Today was a busy day, lots of new rules and coverage for the following MS advisories: MS08-070 MS08-071 MS08-072 MS08-073 MS08-074 MS08-075 MS08-076 MS08-077 We have released rules for attack coverage and you can find details at vrt-rules-2008-12-09.html
Twitter Feed Available
We now have a twitter account where we are going to be micro-blogging our rule updates and blog posts. The feed can be found here: http://twitter.com/VRT_Sourcefire.
Fun with SSDT Hooks and DEP
My favorite part of work here at the VRT is how much you can learn from a project that, in the end, doesn’t achieve what you set out to do. This past week, I was looking at the possibility of watching, in the Windows kernel, for attempts to bypass DEP protection. Briefly, DEP is
OpenSSH Plaintext Recovery Attack - nothing to panic about
So, somebody pointed this out to me the other day: http://www.cpni.gov.uk/Docs/Vulnerability_Advisory_SSH.txt which talks about the probability of recovering some plain text from an ssh session. Having seen nothing at all from OpenSSH about this, my first reaction was "OH NO
New rule groups and new rules for SCADA
Today's VRT Certified Rule release sees the introduction of two new rule groupings, scada.rules and web-activex.rules. SCADA Rules: This group contains rules that pertain to the Supervisory Control and Data Acquisition (SCADA) protocol used for computer controlled system mon
VRT Rule Release Feed
We have added a news feed for our rule release advisories, you can get it here: http://www.snort.org/vrt/advisoryfeed.xml It is very basic, but it will help keep track of new snort rule releases.
Microsoft Tuesday Coverage for November
Not a huge month for Microsoft problems this time around. There are two interesting sets vulnerabilities though, one in XML Core Services (MS08-069) and the other in SMB (MS08-068). We have released rules for attack coverage and you can find details at vrt-rules-2008-11-11.html