Blog
Recent
November 10, 2008 15:26

Advanced Windows Buffer Overflow 5

Time for more pain. I like this one. It'll be different than the last few, and might involve a bit of a brain stretch for those not familiar with exploit techniques that differ from the norm. It'll hurt. There's a bit of basic reversing, but that's not the proble

October 30, 2008 11:29

White Paper on the MS08-067 vulnerability and the associated malware

Matt Olney, Alain Zidouemba and Lurene Grenier of the Sourcefire VRT have collated their analysis of the DCE/RPC vulnerability announced in Microsoft Security Bulletin MS08-067. A white paper that discusses this issue is now available on snort.org at the following address: http:

October 28, 2008 14:43

Update on Snort and ClamAV for ms08-067

There's been a lot of action on the MS08-067 front over the weekend, so we thought we'd bring you up to date on the bug in general, and how Snort and ClamAV are providing specific detection. Interestingly, things are rolling out about the way we expected them to. We happe

October 24, 2008 15:43

Why 114 rules for MS08-067?

With the release of Sourcefire's coverage for MS08-067, I've heard the same question repeatedly. "Why 114 rules? They were able to do it with just one." Since I wrote these rules, I'm the best to explain my solution. I will not be going over the explicit na

October 23, 2008 18:41

Out of Band Microsoft Security Advisory MS08-067

Today, Microsoft released an out of band patch for a vulnerability concerning DCE/RPC that is being actively exploited by a Trojan. We were busy today :D Details on what we were busy with are available here: http://www.snort.org/vrt/advisories/vrt-rules-2008-10-23.html More de

October 20, 2008 13:54

Introduction to Network Penetration Testing

Overview In an effort to broaden the audience and topic base for the VRT blog, this week we are going to take a very high level view of what a network penetration test looks like from the tester's perspective. Some of the techniques and ideas behind a high-level network pene

October 11, 2008 08:50

Mac Transitions - Fixing Files

In the transition from Linux to Mac, I also ran across a small problem with Mac formatted text files on remote Linux machines. Line endings. I had assumed (and we all know what that means) that the Mac running OS X, being as it's userland roots lie firmly in the BSD camp, wou

October 2, 2008 20:31

Perl Snippet

Recently, I have been moving Perl scripts from BSD and Linux machines onto OS X. Mostly, things are pretty smooth but today I had to change a script slightly so that I could read data from /private/var/tmp/ on OS X. The scripts I had on the other systems would read from /var/tmp/

September 29, 2008 14:44

Guide to AWBO Exercises

Over here at the VRT, we've thoroughly enjoyed sinking our teeth into the awbo exercises. Hopefully, readers who've had the chance to work through these are eagerly anticipating those to come. On the other hand, there may still be some of you who are interested in giving