Quantcast
Channel: SANS Internet Storm Center, InfoCON: green
Browsing all 8337 articles
Browse latest View live

Increase in CryptoWall 3.0 from malicious spam and Angler exploit kit, (Thu,...

Introduction Since Monday2015-05-25(a bitmore than 2 weeks ago), weve seen a significantamount of CryptoWall 3.0 ransomware from">) and theAngler exploit kit (EK). A malspam campaign pushing...

View Article


ISC StormCast for Thursday, June 11th 2015...

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

View Article


Updates to OpenSSL fix vulnerabilities related to Logjam, (Thu, Jun 11th)

An OpenSSL security advisory issued earlier today onThursday2015-06-11 [1]. According to the advisoryusers should upgrade OpenSSL to fix vulnerabliities that could be exploited by a Logjam attack [2]....

View Article

ISC StormCast for Friday, June 12th 2015...

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

View Article

ISC StormCast for Monday, June 15th 2015...

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

View Article


Image may be NSFW.
Clik here to view.

RFC 7540 - HTTP/2 protocol, (Mon, Jun 15th)

RFC 7540 has been out for a month now. What should we expect with this new version? 1. New frame: HTTP/2 implements a binary protocol with the following frame structure: Length: The length of the frame...

View Article

Internet Storm Center state of the internet panel, (Mon, Jun 15th)

If you are at SANSFIRE 2015 in Hilton Baltimore, dont forget to join us today at 7:15 PM EDT for the SANS Internet Storm Center state of the internet panel! Manuel Humberto Santander Pelez SANS...

View Article

ISC StormCast for Tuesday, June 16th 2015...

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

View Article


Odd HTTP User Agents, (Tue, Jun 16th)

Many web application firewalls do block odd user agents. However, decent vulnerability scanners will try to evade these simple protections by trying to emulate the user agent string of commonly used...

View Article


CVE-2014-4114 and an Interesting AV Bypass Technique, (Tue, Jun 16th)

Citizenlabs recently reported on a CVE-2014-4114 campaign against pro-democracy / pro-Tibetian groups in Hong Kong. The attacks happening should not surprise anyone, nor that the attacks were...

View Article

Botnet-based malicious spam seen this week, (Wed, Jun 17th)

Introduction Botnetscontinually send out malicious spam (malspam). As mentioned inprevious diaries, we see botnet-basedmalspamdelivering Dridexand Dyremalwarealmost every day [1, 2]. Recently, someone...

View Article

ISC StormCast for Wednesday, June 17th 2015...

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

View Article

ISC StormCast for Thursday, June 18th 2015...

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

View Article


OS X and iOS Unauthorized Cross Application Resource Access (XARA), (Thu, Jun...

The last couple of days, a paper with details about XARA vulnerabilities in OS X and iOS is getting a lot of attention [1]. If you havent seen the term XARA before, then this is probably because...

View Article

ISC StormCast for Friday, June 19th 2015...

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

View Article


Overlayfs flaw in Ubuntu, (Sat, Jun 20th)

There was a vulnerability released earlier this week that has quite the potential to be a biggie. It is worth noting mainly because Ubuntu is quite prevalent and the propensity to patch systems is...

View Article

ISC StormCast for Monday, June 22nd 2015...

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

View Article


Image may be NSFW.
Clik here to view.

SMTP Brute Forcing, (Mon, Jun 22nd)

Brute forcing SMTP credentials is hardly new. But I have seen a couple of odd patterns lately in one of my mail servers, and was wondering if anybody has any insight into these patterns. For this...

View Article

ISC StormCast for Tuesday, June 23rd 2015...

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

View Article

XOR DDOS Mitigation and Analysis, (Tue, Jun 23rd)

XOR DDOS Trojan Trouble I have struggled over the past recent months with a clients environment becoming infected and reinfected with an XOR DDOS trojan. The disruption and reinfection rates were...

View Article
Browsing all 8337 articles
Browse latest View live


Latest Images