Blogs
RHEL CVE Database
Submitted by Shirkdog on Tue, 2012-02-21 11:27Have you ever had to perform a C&A for a system that uses RHEL? Well Redhat has made available a webpage to easily search for CVE's without any additional effort:
- Shirkdog's blog
- Login or register to post comments
MS12-013 PoC with write-up
Submitted by Shirkdog on Wed, 2012-02-15 14:19Byoungyoung Lee provides a PoC with additional information based on the interpretation of this bug by the Microsoft Security Research Center (MSRC)
MS12-013: Vulnerability in C Run-Time Library could allow remote code execution
- Shirkdog's blog
- Login or register to post comments
Nessus 5.0 Released by Tenable Network Security
Submitted by Shirkdog on Wed, 2012-02-15 12:43For those of you that like use Nessus for vulnerability management:
The new version of Nessus incorporates the following key features and updates:
- Shirkdog's blog
- Login or register to post comments
Nortel Networks pwn3d for an entire decade
Submitted by Shirkdog on Tue, 2012-02-14 13:59You would think being in there for almost 10 years they might have made changes to make the network better for their access.
The dangers of backwards thinking on software security
Submitted by Shirkdog on Fri, 2012-02-10 13:12I noticed the following story today:
Offensive security research community helping bad guys
Starting with this quote from Adobe Security Chief Brad Arkin:
"We are involved in a cat-and-mouse game on [the software] engineering side. Every time we come up with something new and build new defenses, it creates incentive for the bad guy to look beyond that."
Climate Change and Information Assurance -- and how they are bullshit
Submitted by Shirkdog on Sat, 2010-05-08 17:09In the course of presenting any form of analysis or research, the details of how you come to your conclusions must be indisputable. The scrutiny faced by your peers should be enough to validate your claims as being reasonable before presenting them in any forum.
But this is not always the case in the lives of professionals, as notoriety can blind the path of virtue. How many of us would trade an honest position, to present an idea that is based on falsehoods, or is an evasion of the truth, to make more money, or gain the spotlight?
Here enters, global warming.
- Shirkdog's blog
- Login or register to post comments
- Read more
Threat Intelligence Project (TIP) Update!
Submitted by enhanced on Tue, 2010-02-09 14:52After much waiting and anticipating, we are excited to announce that we will be releasing a client for those that wish to participate in the TIP project.
The initial release will have the option to obfuscate the IP addresses and potentially the payload, though we don't think that this really is in the spirit of things and does not afford the world the intelligence that could be derived were this data not obfuscated.
Having said all of this in a variety of grammatically incorrect ways, please keep posted for the download and additional details to follow.
We updated our snorby
Submitted by enhanced on Fri, 2010-01-15 10:48- enhanced's blog
- Login or register to post comments
Pulledpork v0.2.5 - Released
Submitted by enhanced on Wed, 2009-10-14 08:53A new and updated version of pulledpork is out, this version adds functionality and also addresses a number of previously reported bugs, a few simple examples:
- Improved and cleaned up code for efficiency and speed
- Do not overwrite local.rules on run
- Do not attempt to copy . and .. as rules files
- Much more...
- enhanced's blog
- Login or register to post comments
- Read more
Snort SID Information URL
Submitted by enhanced on Thu, 2009-06-25 12:24To combat the recent influx of "where is the Snort SID documentation" on the Snort mailing lists, I have created the following URL that you can use to update your BASE or whatever it is that you are using to view your Snort events.
Simply use the following url in your reference config:
http://rootedyour.com/snortsid?sid=xxxxx (where xxxx is the SID number itself)
i.e. http://rootedyour.com/snortsid?sid=234
Thank you for your time,
please drive fast and take chances
E
