ISC StormCast for Tuesday, January 14th 2014...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleSpamming and scanning botnets - is there something I can do to block them...
Spamming and scanning botnets - is there something I can do to block them from my site? This question keeps popping up on forums and all places popular with those beleaguer souls despondent of the...
View ArticleMicrosoft Patch Tuesday January 2014, (Tue, Jan 14th)
Overview of the January 2014 Microsoft patches and their status. # Affected Contra Indications - KB Known Exploits Microsoft rating(**) ISC rating(*) clients servers MS14-001 Code Remote Execution...
View ArticleAdobe Patch Tuesday January 2014, (Tue, Jan 14th)
Adobe released two bulletins today: 1 - Reader/Acrobat This bulletin fixes three vulnerabilities. Adobe rates this one "Priority 1" meaning that these vulnerabilities are already exploited in...
View ArticleOracle Critical Patch Update January 2014, (Tue, Jan 14th)
Today we also got Oracle's quarterly "Critical Patch Update". As announced, we got or gross or 144 different patches from Oracle. But remember that these patches affect 47 different products (if I...
View ArticleISC StormCast for Wednesday, January 15th 2014...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleISC StormCast for Thursday, January 16th 2014...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticlePort 4028 - Interesting Activity, (Thu, Jan 16th)
Take a look at port 4028. Thanks to Bill for sharing an analysis that concluded a piece of malware was an Aidra botnet client. His shared analysis asks for a deeper look at port 4028. I found a...
View ArticleISC StormCast for Friday, January 17th 2014...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleNew and updated VMWare security advisories -...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleMassive RFI scans likely a free web app vuln scanner rather than bots, (Fri,...
On 9 JAN, Bojan discussed reports of massive RFI scans. One of the repetitive artifacts consistent with almost all the reports we've received lately is that the attackers are attempting to include...
View ArticleThe Matasano/Square microcontroller CTF - http://bit.ly/1dvP6sa, (Fri, Jan 17th)
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleAnatomy of a Malware distribution campaign, (Sun, Jan 19th)
Starting about 10 days or so ago, a Spam campaign began targeting Pacific Gas and Energy (PG&E), a large U.S. energy provider. PG&E has been aware of this campaign for about a week, and has...
View ArticleISC StormCast for Monday, January 20th 2014...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleYou Can Run, but You Can't Hide (SSH and other open services), (Mon, Jan 20th)
In any study of internet traffic, you'll notice that one of the top activities of attackers is to mount port scans looking for open SSH servers, usually followed by sustained brute-force attacks. On...
View ArticleISC StormCast for Tuesday, January 21st 2014...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleTaking care when publishing Citrix services inside the corporate network or...
Citrix has some interesting products like XenApp, which allow people to access corporate application from tablets, Windows Terminals and also Windows servers and PC. Depending on how are you using...
View ArticleISC StormCast for Wednesday, November 13th 2013...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleISC StormCast for Thursday, November 14th 2013...
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticlePacket Challenge for the Hivemind: What's happening with this Ethernet...
Earlier this week, a user submitted one of those "odd packets" we all like. The packet was acquired with tcpdump, without the "-x" or "-X" option, but still, tcpdump decided to dump the entire packet...
View Article