ISC StormCast for Tuesday, March 24th 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleRepurposing Logs, (Tue, Mar 24th)
Keeping an eye on your logs is critical (really, its number 14 on the SANS critical list of controls: https://www.sans.org/critical-security-controls/control/14 .) Earlier Rob VandenBrink shared some...
View ArticleISC StormCast for Wednesday, March 25th 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticlePHP 5.5.23 is available, (Wed, Mar 25th)
From the fine folks at php.net: The PHP development team announces the immediate availability of PHP 5.5.23. Several bugs have been fixed as well as CVE-2015-0231, CVE-2015-2305 and CVE-2015-2331. All...
View ArticleF-Secure: FSC-2015-2: PATH TRAVERSAL VULNERABILITY, (Wed, Mar 25th)
F-Secure has announced a security vulnerability affecting their corporate and consumer protection products. The details are available here:https://www.f-secure.com/en/web/labs_global/fsc-2015-2 (c)...
View ArticleNmap/Google Summer of Code, (Wed, Mar 25th)
The Nmap security scanner project is participating again in its 11th Google Summer of Code. We often get queries from students on how they can get into this field, and this is an excellent way to get...
View ArticlePin-up on your Smartphone!, (Thu, Mar 26th)
Yeah, okay, I admit that headline is cheap click bait. Originally, it said Certificate Pinning on Smartphones. If you are more interested in pin-ups on your smartphone, I fear youll have to look...
View ArticleISC StormCast for Thursday, March 26th 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleISC StormCast for Friday, March 27th 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleFriday Digest - 27 MAR 2015, (Fri, Mar 27th)
JS Malware uptick Weve been seeing an uptick in JS malware (TrojanDownloader:JS/Nemucod.K) loosely disguised as .doc files. The JavaScript is reasonably obfuscated but if executed does result in a...
View ArticleMalicious XML: Matryoshka Edition, (Sun, Mar 29th)
A couple of days ago I received another malicious document (078409755.doc B28EF236D901A96CFEFF9A70562C9155). Unlike the XML file I wrote about before, this one does not contain VBA macros: But as you...
View ArticleISC StormCast for Monday, March 30th 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleYARA Rules For Shellcode, (Mon, Mar 30th)
I had a guest diary entry about my XORSearch tool using shellcode detection rules from Frank Boldewins OfficeMalScanner. To detect malicious documents, Frank coded rules to detect shellcode and other...
View ArticleSelect Star from PCAP - Treating Packet Captures as Databases, (Tue, Mar 31st)
Have you ever had to work with a large packet capture, and after getting past the initial stage of being overwhelmed by a few million packets, find that are still a bit overwhelmed? I quite often work...
View ArticleISC StormCast for Tuesday, March 31st 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleRig Exploit Kit Changes Traffic Patterns, (Wed, Apr 1st)
Sometime within the past month, Rig exploit kit (EK) changed URL structure." /> Notice the PHPSSESID and ?req= patterns in the above example." /> Now, we dont see the PHPSSESID and ?req=...
View ArticleISC StormCast for Wednesday, April 1st 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleAngler Exploit Kit - Recent Traffic Patterns, (Thu, Apr 2nd)
Angler exploit kit (EK) has changed URL patterns (again) during the past month. I infected a Windows host so we can take a closer look. Lets see what Angler has been up to." /> The domains and URLs...
View ArticleISC StormCast for Thursday, April 2nd 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleISC StormCast for Friday, April 3rd 2015...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View Article