SSL: Another reason not to ignore IPv6, (Fri, May 17th)
Currently, many public web sites that allow access via IPv6 do so via proxies. This is seen as the "quick fix", as it requires minimum changes to the site itself. As far as the web application is...
View ArticleISC StormCast for Monday, May 20th 2013...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleSysinternals Updates for Accesschk, Procdump, RAMMap and Strings...
----------- Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot edu (c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleUbuntu Package available to submit firewall logs to DShield, (Mon, May 20th)
I put together a simple .deb package to install our DShield iptables client on Ubuntu. The package is our standard perl client to submit iptables logs, but it is pre-configured for Ubuntu 12.04 LTS....
View ArticlePort 51616 - Got Packets?, (Sun, May 19th)
We're looking for any info or packets that target port 51616. After witnessing a spike yesterday on his network and checking that our port data [1] corroborated his event, Andrew has written in...
View ArticleSafe - Tools, Tactics and Techniques, (Mon, May 20th)
Trend Micro published a report last week on a spear-phishing emails campaign that contain a malicious attachment exploiting a Microsoft Office vulnerability (CVE-2012-0158). This paper identified...
View ArticleISC StormCast for Tuesday, May 21st 2013...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleChrome 27 stable released http://googlechromereleases.blogspot.ca/ some...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleMoore, Oklahoma tornado charitable organization scams, malware, and...
I find it sad that in times when people are facing disaster, many have died, others missing, and the survivors facing having lost everything that there are scumbags who will try to take advantage. Be...
View ArticleISC StormCast for Wednesday, May 22nd 2013...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticlePrivilege escalation, why should I care?, (Wed, May 22nd)
In my day job I spend about 90% of my time on the red team, performing vulnerability assessment and penetration testing. The rest is spent on threat research, incident response, and digital forensics....
View ArticleWireshark 1.8.7 and 1.6.15 Released...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleApple QuickTime 7.7.4 for Windows updated, MANY security vulnerabilities:...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleChrome 24.0.1312.52 has been updated for Windows, Mac, Linux, and Chrome...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleWireshark 1.10.0rc2 is now available http://www.wireshark.org/download.html,...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleMoVP II, (Thu, May 23rd)
Volatility is a Python framework for performing memory forensics. If you haven't tried it yet I highly recommend it. The Volatility Month of Volatility Plugins II is on! As announced here:...
View ArticleISC StormCast for Thursday, May 23rd 2013...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleUDP port 1434 directed attack to AS13489 IP ranges, (Fri, May 24th)
We have seen today a big rise of incoming packets of what appears to be a SQL Slammer attacks. Some of the detected packets are: We have seen a sustained rate in many nodes inside AS13489 and AS27989...
View ArticleISC StormCast for Monday, May 27th 2013...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleNuclear Scientists, Pandas and EMET Keeping Me Honest, (Mon, May 27th)
Following is a guest post from TJ O'Connor, @ViolentPython, (http://www.linkedin.com/pub/tj-oconnor/43/37/81b), author of Violent Python SANS Technical Institute graduate, and GSE . What do Nuclear...
View Article