<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;DEcGQX47fip7ImA9WhRUF0s.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853</id><updated>2012-01-28T13:53:40.006-02:00</updated><category term="netfilter" /><category term="podcast" /><category term="vrt" /><category term="webinar" /><category term="blackhat" /><category term="gts" /><category term="metasploit" /><category term="razorback" /><category term="naopod" /><category term="http" /><category term="issa" /><category term="insecure" /><category term="pdf" /><category term="snortando" /><category term="h2hc" /><category term="ysts" /><category term="vegas" /><category term="srw" /><category term="spiderlabs" /><category term="antivirus" /><category term="et" /><category term="suricata" /><category term="ips" /><category term="malwares" /><category term="ids" /><category term="twitter" /><category term="regras" /><category term="nrt" /><category term="owasp" /><category term="virus" /><category term="waf" /><category term="gter" /><category term="defcon" /><category term="ossec" /><category term="pentest" /><category term="conferences" /><category term="snort" /><title>Sp0oKeR Labs</title><subtitle type="html">Here I will post some security tips, articles / paper mine or from other blogs that I think interested . I Iove computer subjects related in special:

- Penetration Tests
- Network Intrusion Detection and Prevention
- Network Behaviour
- SIEM
- Network Security Monitoring (NSM)
- Incident Response
- Firewall,
- Host Intrusion Detection System
- The Open Web Application Security Project (OWASP) - Capitulo Brasil
- fuzzing
- Vulnerability
- Packet Analisys
- Log Analysis
- Beer =)</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://spookerlabs.blogspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>82</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/Sp0okerLabs" /><feedburner:info uri="sp0okerlabs" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;D0YCSH84eip7ImA9WhRUFE4.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-7277551794127149416</id><published>2012-01-24T17:59:00.003-02:00</published><updated>2012-01-24T17:59:29.132-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-24T17:59:29.132-02:00</app:edited><title>Let's make TCP faster (Google researchers)</title><content type="html">Post e pesquisa bem interessante pelo time do google&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://googlecode.blogspot.com/2012/01/lets-make-tcp-faster.html"&gt;http://googlecode.blogspot.com/2012/01/lets-make-tcp-faster.html&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Abs!&lt;br /&gt;
&lt;br /&gt;
Rodrigo "Sp0oKeR" Montoro&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-7277551794127149416?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/y865qFFVtes" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/7277551794127149416/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=7277551794127149416" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/7277551794127149416?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/7277551794127149416?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/y865qFFVtes/lets-make-tcp-faster-google-researchers.html" title="Let's make TCP faster (Google researchers)" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2012/01/lets-make-tcp-faster-google-researchers.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkEGRns_eyp7ImA9WhRUEkU.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-6905960110889531140</id><published>2012-01-22T23:03:00.000-02:00</published><updated>2012-01-22T23:03:47.543-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-22T23:03:47.543-02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="snortando" /><category scheme="http://www.blogger.com/atom/ns#" term="snort" /><category scheme="http://www.blogger.com/atom/ns#" term="ids" /><title>Agenda da Serie Snortando</title><content type="html">Caros,&lt;br /&gt;
&lt;br /&gt;
Essa semana postarei o post inicial da serie e logicamente será com o básico explicando o funcionamento do snort . Abaixo montei a agenda do que pretendo escrever, não necessariamente falarei nessa ordem exata (logicamente algumas coisas tem que ser na ordem) e caso necessário adicionarei artigos, bem como novidades que deverão aparecer no decorrer da serie.&lt;br /&gt;
&lt;br /&gt;
Pretendo atualizar/postar a cada semana ou no máximo 10 dias sendo que alguns posts serão maiores e mais complexos e alguns mais simples.&lt;br /&gt;
&lt;br /&gt;
Agenda:&lt;br /&gt;
&lt;br /&gt;
1-) Introdução Snort&lt;br /&gt;
2-) DAQ - Data Aquisition&lt;br /&gt;
3-) Entendendo básico do snort.conf&lt;br /&gt;
4-) Introdução Decoders&lt;br /&gt;
5-) Introdução Pre-Processadores (após a introdução cada pre-processador será um artigo)&lt;br /&gt;
6-) Preproc Rules&lt;br /&gt;
7-) Stream5&lt;br /&gt;
8-) Frag3&lt;br /&gt;
9-) Reputation&lt;br /&gt;
10-) SMTP&lt;br /&gt;
11-) Pop / Imap&lt;br /&gt;
12-) FTP/Telnet&lt;br /&gt;
13-) SFPortScan&lt;br /&gt;
14-) http_inspect&lt;br /&gt;
15-) Sensitive Data&lt;br /&gt;
16-) Performance (PerfProfiling)&lt;br /&gt;
17-) dcerpc2&lt;br /&gt;
18-) Razorback&lt;br /&gt;
19-) SSL/SSH&lt;br /&gt;
20-) Introdução Regras Snort&lt;br /&gt;
21-) Básico Criação de Regras&lt;br /&gt;
22-) Laboratorio Básico&lt;br /&gt;
23-) Tags avançadas&lt;br /&gt;
24-) Laboratorio Tags avançadas&lt;br /&gt;
25-) Host Attribute Table&lt;br /&gt;
26-) IPv6&lt;br /&gt;
27-) Posicionamento&lt;br /&gt;
28-) Interfaces de Gerenciamento (Snorby / BASE)&lt;br /&gt;
&lt;br /&gt;
Como podemos observar será uma serie longa mas que visa realmente explicar o funcionamento da ferramenta para que possamos tirar o maximo proveito da ferramenta.&lt;br /&gt;
&lt;br /&gt;
Tentarei se possivel fazer webex de alguns assuntos que fiquem muito complexo escrever e tentarei ao maximo sempre criar ferramentas para demonstrar na pratica a importancia da configuracao correta.&lt;br /&gt;
&lt;br /&gt;
Espero que todos acompanhem! Essa semana postarei a introdução!&lt;br /&gt;
&lt;br /&gt;
Happy Snorting!&lt;br /&gt;
&lt;br /&gt;
Rodrigo "Sp0oKeR" Montoro!&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-6905960110889531140?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/QgnGyj_wjyY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/6905960110889531140/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=6905960110889531140" title="9 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/6905960110889531140?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/6905960110889531140?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/QgnGyj_wjyY/agenda-da-serie-snortando.html" title="Agenda da Serie Snortando" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>9</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2012/01/agenda-da-serie-snortando.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEUDQnY6eSp7ImA9WhRUEE0.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-9065697064888420108</id><published>2012-01-19T17:44:00.002-02:00</published><updated>2012-01-19T17:44:33.811-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-19T17:44:33.811-02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="snort" /><category scheme="http://www.blogger.com/atom/ns#" term="ids" /><title>[Snort-devel] Snort 2.9.2.1 Now Available</title><content type="html">Snort 2.9.2.1 is now available on &lt;a href="http://snort.org/" target="_blank"&gt;snort.org&lt;/a&gt;, at&lt;br /&gt;
&lt;a href="http://www.snort.org/snort-downloads/" target="_blank"&gt;http://www.snort.org/snort-&lt;wbr&gt;&lt;/wbr&gt;downloads/&lt;/a&gt; in the Latest Release section.&lt;br /&gt;
&lt;br /&gt;
2.9.0 RC &amp;amp; later packages are signed with a new PGP key&lt;br /&gt;
(that is signed with the previous key).&lt;br /&gt;
&lt;br /&gt;
Snort 2.9.2.1 includes the following updates and improvements:&lt;br /&gt;
&amp;nbsp; * Added new alerts for HTTP (undefined methods &amp;amp; HTTP 0.9 simple&lt;br /&gt;
&amp;nbsp; &amp;nbsp; requests).&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; * Updates to Stream preprocessor in TCP session tracking to avoid&lt;br /&gt;
&amp;nbsp; &amp;nbsp; re-queuing retransmitted data that was already flushed. &amp;nbsp;Also&lt;br /&gt;
&amp;nbsp; &amp;nbsp; various tweaks for PAF flushing.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; * Updates to reputation preprocessor to handle shared memory&lt;br /&gt;
&amp;nbsp; &amp;nbsp; switching.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; * Updates to the SCADA preprocessors in their handling of PAF&lt;br /&gt;
&amp;nbsp; &amp;nbsp; flushing and Modbus request/response length checking. &amp;nbsp;Also tweaks&lt;br /&gt;
&amp;nbsp; &amp;nbsp; in alerts for reserved DNP3 functions.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; * Updates to flowbit groups to always use the group when some rules&lt;br /&gt;
&amp;nbsp; &amp;nbsp; refer to a flow group while others do not refer to a group for the&lt;br /&gt;
&amp;nbsp; &amp;nbsp; same flowbit.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; * Updates to GTP preprocessor to check invalid extension header&lt;br /&gt;
&amp;nbsp; &amp;nbsp; length for GTPv1.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; * Updates to sfrt library, used in reputation preprocessor and target&lt;br /&gt;
&amp;nbsp; &amp;nbsp; based configuration, when calculating memory allocated and support&lt;br /&gt;
&amp;nbsp; &amp;nbsp; for IPv6.&lt;br /&gt;
&lt;br /&gt;
Please see the Release Notes and ChangeLog for more details.&lt;br /&gt;
&lt;br /&gt;
Please submit bugs, questions, and feedback to &lt;a href="mailto:bugs@snort.org"&gt;bugs@snort.org&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Happy Snorting!&lt;br /&gt;
The Snort Release Team&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-9065697064888420108?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/ciB7xYTMx8I" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/9065697064888420108/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=9065697064888420108" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/9065697064888420108?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/9065697064888420108?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/ciB7xYTMx8I/snort-devel-snort-2921-now-available.html" title="[Snort-devel] Snort 2.9.2.1 Now Available" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2012/01/snort-devel-snort-2921-now-available.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEcBSXs-cSp7ImA9WhRVGUQ.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-7812396373475719419</id><published>2012-01-19T16:00:00.000-02:00</published><updated>2012-01-19T16:00:58.559-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-19T16:00:58.559-02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="suricata" /><category scheme="http://www.blogger.com/atom/ns#" term="ids" /><title>[Emerging-Sigs] Suricata 1.2 Available!</title><content type="html">The OISF development team is proud to announce Suricata 1.2. This release brings HTTP file inspection and extraction and a whole lot more.&lt;br /&gt;
&lt;br /&gt;
Get the new release here:&lt;br /&gt;
&lt;a href="http://www.openinfosecfoundation.org/download/suricata-1.2.tar.gz" target="_blank"&gt;http://www.&lt;wbr&gt;&lt;/wbr&gt;openinfosecfoundation.org/&lt;wbr&gt;&lt;/wbr&gt;download/suricata-1.2.tar.gz&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
The configuration file has evolved but backward compatibility is provided. We thus encourage you to update your suricata configuration file. Upgrade guidance is provided here:&lt;br /&gt;
&lt;a href="https://redmine.openinfosecfoundation.org/projects/suricata/wiki/Upgrading_Suricata_11_to_Suricata_12" target="_blank"&gt;https://redmine.&lt;wbr&gt;&lt;/wbr&gt;openinfosecfoundation.org/&lt;wbr&gt;&lt;/wbr&gt;projects/suricata/wiki/&lt;wbr&gt;&lt;/wbr&gt;Upgrading_Suricata_11_to_&lt;wbr&gt;&lt;/wbr&gt;Suricata_12&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
New features&lt;br /&gt;
&lt;br /&gt;
- file name, type inspection and extraction for HTTP&lt;br /&gt;
- filename, fileext, filemagic and filestore keywords added&lt;br /&gt;
- "file" output for storing extracted files to disk&lt;br /&gt;
- file_data keyword support, inspecting normalized, dechunked, decompressed HTTP response body (feature #241)&lt;br /&gt;
- new keyword http_server_body, pcre regex /S option&lt;br /&gt;
- option to enable/disable core dumping from the suricata.yaml (enabled by default)&lt;br /&gt;
- human readable size limit settings in suricata.yaml (bug #333)&lt;br /&gt;
- PF_RING bpf support (required PF_RING &amp;gt;= 5.2) (feature #334)&lt;br /&gt;
- tos keyword support (feature #364)&lt;br /&gt;
- IPFW IPS mode does now support multiple divert sockets&lt;br /&gt;
- new IPS running modes, Linux and FreeBSD do now support "worker" and "autofp"&lt;br /&gt;
- app-layer-events keyword: similar to the decoder-events and stream-events, this will allow matching on HTTP and SMTP events&lt;br /&gt;
- auto detection of checksum offloading per interface (#311)&lt;br /&gt;
- urilen options to match on raw or normalised URI (#341)&lt;br /&gt;
- flow keyword option "only_stream" and "no_stream"&lt;br /&gt;
- unixsock output options for all outputs except unified2 (PoC python script in the qa/ dir) (#250)&lt;br /&gt;
- http_header and http_raw_header now also inspect HTTP response headers (#389, #397)&lt;br /&gt;
&lt;br /&gt;
Improvements&lt;br /&gt;
&lt;br /&gt;
- general performance improvements&lt;br /&gt;
- improved alert accuracy in autofp and single runmodes&lt;br /&gt;
- major performance optimizations for the ac-gfbs pattern matcher implementation&lt;br /&gt;
- unified2 output fixes&lt;br /&gt;
- PF_RING supports privilege dropping now (bug #367)&lt;br /&gt;
- improved detection of duplicate signatures&lt;br /&gt;
- improved performance in virtual machines (bug #382)&lt;br /&gt;
- PCRE-JIT is now enabled by default if available (#356)&lt;br /&gt;
- flowbits and flowints are now modified in a post-match action list&lt;br /&gt;
- bundled libhtp updated to 0.2.7&lt;br /&gt;
- fixed parsing really high sid numbers &amp;gt;2 Billion (#393)&lt;br /&gt;
- fixed ICMPv6 not matching in IP-only sigs (#363)&lt;br /&gt;
&lt;br /&gt;
Fixes since 1.2rc1&lt;br /&gt;
&lt;br /&gt;
- improved Windows/CYGWIN path handling (#387)&lt;br /&gt;
- fixed some issues with passing an interface or ip address with -i&lt;br /&gt;
- make live worker runmode threads adhere to the 'detect' cpu affinity settings&lt;br /&gt;
&lt;br /&gt;
Known issues &amp;amp; missing features&lt;br /&gt;
&lt;br /&gt;
If you encounter issues, please let us know! As always, we are doing our best to make you aware of continuing development and items within the engine that are not yet complete or optimal. &amp;nbsp;With this in mind, please notice the list we have included of known items we are working on.&lt;br /&gt;
&lt;br /&gt;
See &lt;a href="http://redmine.openinfosecfoundation.org/projects/suricata/issues" target="_blank"&gt;http://redmine.&lt;wbr&gt;&lt;/wbr&gt;openinfosecfoundation.org/&lt;wbr&gt;&lt;/wbr&gt;projects/suricata/issues&lt;/a&gt; for an up to date list and to report new issues.&lt;br /&gt;
&lt;br /&gt;
See&lt;a href="http://redmine.openinfosecfoundation.org/projects/suricata/wiki/Known_issues" target="_blank"&gt; http://redmine.&lt;wbr&gt;&lt;/wbr&gt;openinfosecfoundation.org/&lt;wbr&gt;&lt;/wbr&gt;projects/suricata/wiki/Known_&lt;wbr&gt;&lt;/wbr&gt;issues&lt;/a&gt;&lt;br /&gt;
for a discussion and time line for the major issues.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Happy Detection!&lt;br /&gt;
&lt;br /&gt;
Rodrigo Montoro&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-7812396373475719419?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/JK9NTXCT1uM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/7812396373475719419/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=7812396373475719419" title="1 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/7812396373475719419?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/7812396373475719419?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/JK9NTXCT1uM/emerging-sigs-suricata-12-available.html" title="[Emerging-Sigs] Suricata 1.2 Available!" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2012/01/emerging-sigs-suricata-12-available.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkQFSH84fSp7ImA9WhRVGUU.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-1165362094059266543</id><published>2012-01-19T12:45:00.000-02:00</published><updated>2012-01-19T12:45:19.135-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-19T12:45:19.135-02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="malwares" /><title>Paper interessante Analise Estatica de Malwares (Ingles)</title><content type="html">Paper básico mas bem legal no Exploit-DB "Malware Reverse Engineering part1 of 2. Static analysis"&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;&lt;b&gt;Table of Contents&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
1. Scope&lt;br /&gt;
2. Investigation goals &lt;br /&gt;
3. Malware samples analyzed &lt;br /&gt;
4 Malware analysis methodology, software, and secure lab setup .&lt;br /&gt;
5. General function and functionality of the malware&lt;br /&gt;
6. Behavioral patterns of the malware and local system interaction &lt;br /&gt;
7. Files and registry keys created, modified and accessed &lt;br /&gt;
8. Network behavior (including hosts, domains and ip’s accessed)&lt;br /&gt;
9. Time and local system dependant features &lt;br /&gt;
10. Method and means of communication &lt;br /&gt;
11. Original infection vector and propogation methodology &lt;br /&gt;
12. Use of encryption for storage, delivery and or communication &lt;br /&gt;
13. Use of self modifying/replicating or encrypted code &lt;br /&gt;
14. Any information concerning development of malware (compiler type, packer used, country of origin, author, names/handles, etc&lt;br /&gt;
15. Key questions and answers&lt;br /&gt;
&lt;br /&gt;
Para baixá-lo:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.exploit-db.com/download_pdf/18387"&gt;http://www.exploit-db.com/download_pdf/18387&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Happy Detection!&lt;br /&gt;
&lt;br /&gt;
Rodrigo Montoro&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-1165362094059266543?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/aEV6RWWvOi8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/1165362094059266543/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=1165362094059266543" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/1165362094059266543?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/1165362094059266543?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/aEV6RWWvOi8/paper-interessante-analise-estatica-de.html" title="Paper interessante Analise Estatica de Malwares (Ingles)" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2012/01/paper-interessante-analise-estatica-de.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0UHQ3g_eyp7ImA9WhRVGU4.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-4104416606646765443</id><published>2012-01-18T22:00:00.000-02:00</published><updated>2012-01-18T22:00:32.643-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-18T22:00:32.643-02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="snortando" /><category scheme="http://www.blogger.com/atom/ns#" term="snort" /><title>Serie Snortando - Usando e Entendendo o Snort</title><content type="html">Caros,&lt;br /&gt;
&lt;br /&gt;
Iniciarei uma série que chamarei de "Snortando". Minha idéia aqui é semanalmente fazer um post sobre funcionalidades do snort no geral . Entre os assuntos abordarei bastante coisa de pre-processadores (logicamente 1 pre-processador por post visto que a ideia é explicar para o bom uso) entre outras funções:&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;&lt;b&gt;dcerpc2&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;decode&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;decoder_preproc_rules&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;dnp3&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;dns&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;filters&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;flowbits&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;frag3&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;ftptelnet&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;gre&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;GTP&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;http_inspect&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;imap&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;ipip&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;ipv6&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;modbus&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;multipleconfigs&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;normalize&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;PerfProfiling&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;pop&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;ppm&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;reload&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;reputation&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;rzb_saac&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;sensitive_data&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;sfportscan&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;sip&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;SMTP&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;ssh&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;ssl&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;stream5&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;br /&gt;
Também postarei sobre criação de regras, explicação snort.conf , dicas de instalação e deploy, ferramentas para testes dos pre-processadores , teste de performance de regras, dicas gerais entre outras coisas/idéias que surgirem durante o ano. &lt;br /&gt;
&lt;br /&gt;
Em paralelo a isso também lançaremos via EaD da Dynsec treinamento de análise de pacotes, snort básico, snort avançado e criação de regras .&lt;br /&gt;
&lt;br /&gt;
Acompanhe a nova serie "Snortando". Caso tenha alguma sugestão entre em contato. Possivelmente junto com o primeiro post tentarei colocar uma mini-agenda .&lt;br /&gt;
&lt;br /&gt;
Quem sabe no final não temos um mini howto em pt_BR =)&lt;br /&gt;
&lt;br /&gt;
Em paralelo continuarei postando sobre Deteção de Intrusos e Malwares no geral também . &lt;br /&gt;
&lt;br /&gt;
Happy Snorting!&lt;br /&gt;
&lt;br /&gt;
Rodrigo "Sp0oKeR" Montoro&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-4104416606646765443?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/sq5nkE08tss" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/4104416606646765443/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=4104416606646765443" title="2 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/4104416606646765443?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/4104416606646765443?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/sq5nkE08tss/serie-snortando-usando-e-entendendo-o.html" title="Serie Snortando - Usando e Entendendo o Snort" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>2</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2012/01/serie-snortando-usando-e-entendendo-o.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkIGSX0yeip7ImA9WhRVE0o.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-2210416321285057181</id><published>2012-01-12T11:22:00.000-02:00</published><updated>2012-01-12T11:22:08.392-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-12T11:22:08.392-02:00</app:edited><title>CAIS-Alerta: resumo dos Boletins de Segurança Microsoft - Jan/2012</title><content type="html">-----BEGIN PGP SIGNED MESSAGE-----&lt;br /&gt;
&lt;br /&gt;
Prezados,&lt;br /&gt;
&lt;br /&gt;
A Microsoft publicou 7 boletins de segurança em 11 de janeiro que abordam&lt;br /&gt;
ao todo 8 vulnerabilidades em produtos da empresa. A exploração destas&lt;br /&gt;
vulnerabilidades permitem execução remota de código, desvio de recurso de&lt;br /&gt;
segurança, elevação de privilégio e divulgação não autorizada de&lt;br /&gt;
informação.&lt;br /&gt;
&lt;br /&gt;
SEVERIDADE&lt;br /&gt;
&lt;br /&gt;
. Crítica&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;- MS12-004 - Vulnerabilidades no Windows Media podem permitir a execução&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;remota de código&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
. Importante&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;- MS12-001 - Vulnerabilidade no kernel do Windows pode permitir o desvio&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;do recurso de segurança&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;- MS12-002 - Vulnerabilidade no Windows Object Packager pode permitir a&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;execução remota de código&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;- MS12-003 - Vulnerabilidade no Windows Client/Server Run-time Subsystem&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;pode permitir elevação de privilégio&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;- MS12-005 - Vulnerabilidade no Microsoft Windows pode permitir a&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;execução remota de código&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;- MS12-006 - Vulnerabilidade no SSL/TLS pode permitir divulgação não&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;autorizada de informações&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;- MS12-007 - Vulnerabilidade na AntiXSS pode permitir a divulgação não&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;autorizada de informações&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
. Moderada&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;- Nenhum boletim&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
. Baixa&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;- Nenhum boletim&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
O sistema de classificação de severidade das vulnerabilidades adotado pelo&lt;br /&gt;
CAIS neste resumo é o da própria Microsoft. O CAIS recomenda que se&lt;br /&gt;
aplique, minimamente, as correções para vulnerabilidades classificadas&lt;br /&gt;
como crítica e importante. No caso de correções para vulnerabilidades&lt;br /&gt;
classificadas como moderadas o CAIS recomenda que ao menos as&lt;br /&gt;
recomendações de mitigação sejam seguidas.&lt;br /&gt;
&lt;br /&gt;
. Crítica - Vulnerabilidades cuja exploração possa permitir a propagação&lt;br /&gt;
&amp;nbsp;de um worm sem a necessidade de interação com o usuário.&lt;br /&gt;
&lt;br /&gt;
. Importante - Vulnerabilidades cuja exploração possa resultar no&lt;br /&gt;
&amp;nbsp;comprometimento de confidencialidade, integridade ou disponibilidade&lt;br /&gt;
&amp;nbsp;de dados de usuários ou a integridade ou disponibilidade de recursos&lt;br /&gt;
&amp;nbsp;de processamento.&lt;br /&gt;
&lt;br /&gt;
. Moderada - exploração é mitigada significativamente por fatores como&lt;br /&gt;
&amp;nbsp;configuração padrão, auditoria ou dificuldade de exploração.&lt;br /&gt;
&lt;br /&gt;
. Baixa - uma vulnerabilidade cuja exploração seja extremamente difícil&lt;br /&gt;
&amp;nbsp;ou cujo impacto seja mínimo.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
CORREÇÕES DISPONÍVEIS&lt;br /&gt;
&lt;br /&gt;
Recomenda-se atualizar os sistemas para as versões disponíveis em:&lt;br /&gt;
&lt;br /&gt;
. Microsoft Update&lt;br /&gt;
&amp;nbsp;&lt;a href="https://www.update.microsoft.com/microsoftupdate/" target="_blank"&gt;https://www.update.microsoft.&lt;wbr&gt;&lt;/wbr&gt;com/microsoftupdate/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
. Windows Server Update Services&lt;br /&gt;
&amp;nbsp;&lt;a href="http://www.microsoft.com/windowsserversystem/updateservices/default.mspx" target="_blank"&gt;http://www.microsoft.com/&lt;wbr&gt;&lt;/wbr&gt;windowsserversystem/&lt;wbr&gt;&lt;/wbr&gt;updateservices/default.mspx&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
MAIS INFORMAÇÕES&lt;br /&gt;
&lt;br /&gt;
. Resumo do Boletim de Segurança da Microsoft de janeiro 2012&lt;br /&gt;
&amp;nbsp;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms12-jan" target="_blank"&gt;http://www.microsoft.com/&lt;wbr&gt;&lt;/wbr&gt;technet/security/bulletin/&lt;wbr&gt;&lt;/wbr&gt;ms12-jan&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
. Microsoft TechCenter de Segurança&lt;br /&gt;
&amp;nbsp;&lt;a href="http://technet.microsoft.com/pt-br/security/" target="_blank"&gt;http://technet.microsoft.com/&lt;wbr&gt;&lt;/wbr&gt;pt-br/security/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
. Microsoft Security Response Center - MSRC&lt;br /&gt;
&amp;nbsp;&lt;a href="http://www.microsoft.com/security/msrc/" target="_blank"&gt;http://www.microsoft.com/&lt;wbr&gt;&lt;/wbr&gt;security/msrc/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
. Microsoft Security Research&amp;amp;Defense - MSRD&lt;br /&gt;
&amp;nbsp;&lt;a href="http://blogs.technet.com/srd/" target="_blank"&gt;http://blogs.technet.com/srd/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
. Segurança Microsoft&lt;br /&gt;
&amp;nbsp;&lt;a href="http://www.microsoft.com/brasil/security/" target="_blank"&gt;http://www.microsoft.com/&lt;wbr&gt;&lt;/wbr&gt;brasil/security/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
. MS12-001 - Vulnerabilidade no kernel do Windows pode permitir o desvio&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; do recurso de segurança&lt;br /&gt;
&amp;nbsp;&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-001" target="_blank"&gt;http://technet.microsoft.com/&lt;wbr&gt;&lt;/wbr&gt;en-us/security/bulletin/ms12-&lt;wbr&gt;&lt;/wbr&gt;001&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
. MS12-002 - Vulnerabilidade no Windows Object Packager pode permitir a&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; execução remota de código&lt;br /&gt;
&amp;nbsp;&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-002" target="_blank"&gt;http://technet.microsoft.com/&lt;wbr&gt;&lt;/wbr&gt;en-us/security/bulletin/ms12-&lt;wbr&gt;&lt;/wbr&gt;002&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
. MS12-003 - Vulnerabilidade no Windows Client/Server Run-time Subsystem&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; pode permitir elevação de privilégio&lt;br /&gt;
&amp;nbsp;&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-003" target="_blank"&gt;http://technet.microsoft.com/&lt;wbr&gt;&lt;/wbr&gt;en-us/security/bulletin/ms12-&lt;wbr&gt;&lt;/wbr&gt;003&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
. MS12-004 - Vulnerabilidades no Windows Media podem permitir a execução&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; remota de código&lt;br /&gt;
&amp;nbsp;&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-004" target="_blank"&gt;http://technet.microsoft.com/&lt;wbr&gt;&lt;/wbr&gt;en-us/security/bulletin/ms12-&lt;wbr&gt;&lt;/wbr&gt;004&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
. MS12-005 - Vulnerabilidade no Microsoft Windows pode permitir a execução&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; remota de código&lt;br /&gt;
&amp;nbsp;&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-005" target="_blank"&gt;http://technet.microsoft.com/&lt;wbr&gt;&lt;/wbr&gt;en-us/security/bulletin/ms12-&lt;wbr&gt;&lt;/wbr&gt;005&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
. MS12-006 - Vulnerabilidade no SSL/TLS pode permitir divulgação não&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; autorizada de informações&lt;br /&gt;
&amp;nbsp;&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-006" target="_blank"&gt;http://technet.microsoft.com/&lt;wbr&gt;&lt;/wbr&gt;en-us/security/bulletin/ms12-&lt;wbr&gt;&lt;/wbr&gt;006&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
. MS12-007 - Vulnerabilidade na AntiXSS pode permitir a divulgação não&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; autorizada de informações&lt;br /&gt;
&amp;nbsp;&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-007" target="_blank"&gt;http://technet.microsoft.com/&lt;wbr&gt;&lt;/wbr&gt;en-us/security/bulletin/ms12-&lt;wbr&gt;&lt;/wbr&gt;007&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Identificador CVE (&lt;a href="http://cve.mitre.org/" target="_blank"&gt;http://cve.mitre.org&lt;/a&gt;):&lt;br /&gt;
&lt;br /&gt;
CVE-2011-3389, CVE-2012-0001, CVE-2012-0009, CVE-2012-0005,&lt;br /&gt;
CVE-2012-0003, CVE-2012-0004, CVE-2012-0013, CVE-2012-0007&lt;br /&gt;
&lt;br /&gt;
O CAIS recomenda que os administradores mantenham seus sistemas e&lt;br /&gt;
aplicativos sempre atualizados, de acordo com as últimas versões e&lt;br /&gt;
correções oferecidas pelos fabricantes.&lt;br /&gt;
&lt;br /&gt;
Os Alertas do CAIS também são oferecidos no formato RSS/RDF e no Twitter:&lt;br /&gt;
&lt;a href="http://www.rnp.br/cais/alertas/rss.xml" target="_blank"&gt;http://www.rnp.br/cais/&lt;wbr&gt;&lt;/wbr&gt;alertas/rss.xml&lt;/a&gt;&lt;br /&gt;
Siga @caisrnp&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Atenciosamente,&lt;br /&gt;
Equipe do CAIS/RNP&lt;br /&gt;
&lt;br /&gt;
##############################&lt;br /&gt;
&lt;div id=":77z"&gt;&lt;wbr&gt;&lt;/wbr&gt;##############################&lt;wbr&gt;&lt;/wbr&gt;####&lt;br /&gt;
# &amp;nbsp; CENTRO DE ATENDIMENTO A INCIDENTES DE SEGURANCA (CAIS) &amp;nbsp; &amp;nbsp; #&lt;br /&gt;
# &amp;nbsp; &amp;nbsp; &amp;nbsp; Rede Nacional de Ensino e Pesquisa (RNP) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #&lt;br /&gt;
# &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;br /&gt;
# &lt;a href="mailto:cais@cais.rnp.br"&gt;cais@cais.rnp.br&lt;/a&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href="http://www.cais.rnp.br/" target="_blank"&gt;http://www.cais.rnp.br&lt;/a&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#&lt;br /&gt;
# Tel. 019-37873300 &amp;nbsp; &amp;nbsp; &amp;nbsp;Fax. 019-37873301 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #&lt;br /&gt;
# Chave PGP disponivel &amp;nbsp; &lt;a href="http://www.rnp.br/cais/cais-pgp.key" target="_blank"&gt;http://www.rnp.br/cais/cais-&lt;wbr&gt;&lt;/wbr&gt;pgp.key&lt;/a&gt; &amp;nbsp; #&lt;br /&gt;
##############################&lt;wbr&gt;&lt;/wbr&gt;##############################&lt;wbr&gt;&lt;/wbr&gt;####&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-2210416321285057181?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/aUVaFqkOszo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/2210416321285057181/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=2210416321285057181" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/2210416321285057181?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/2210416321285057181?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/aUVaFqkOszo/cais-alerta-resumo-dos-boletins-de.html" title="CAIS-Alerta: resumo dos Boletins de Segurança Microsoft - Jan/2012" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2012/01/cais-alerta-resumo-dos-boletins-de.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUUARHw5cSp7ImA9WhRVEk8.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-2809076335112033963</id><published>2012-01-10T17:20:00.000-02:00</published><updated>2012-01-10T17:20:45.229-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-10T17:20:45.229-02:00</app:edited><title>De volta ao blog .... 2012 novo ano =)</title><content type="html">Caros,&lt;br /&gt;
&lt;br /&gt;
Fiquei um tempo sumido do blog mas agora voltarei a postar regularmente por aqui com dicas, pesquisas e assuntos relacionados a segurança.&lt;br /&gt;
&lt;br /&gt;
Se tiverem assuntos que acham interessante fiquem a vontade para sugerir, se for do meu conhecimento terei prazer em publicar algo. &lt;br /&gt;
&lt;br /&gt;
Logo mais posts a caminho.&lt;br /&gt;
&lt;br /&gt;
Happy Intrusion Detection!&lt;br /&gt;
&lt;br /&gt;
Rodrigo "Sp0oKeR" Montoro&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-2809076335112033963?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/DUJx8z7GtjQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/2809076335112033963/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=2809076335112033963" title="1 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/2809076335112033963?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/2809076335112033963?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/DUJx8z7GtjQ/de-volta-ao-blog-2012-novo-ano.html" title="De volta ao blog .... 2012 novo ano =)" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2012/01/de-volta-ao-blog-2012-novo-ano.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0EGSH88fCp7ImA9WhdbFUQ.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-323891412545571105</id><published>2011-10-14T09:33:00.000-03:00</published><updated>2011-10-14T09:33:49.174-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-14T09:33:49.174-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="http" /><category scheme="http://www.blogger.com/atom/ns#" term="ysts" /><category scheme="http://www.blogger.com/atom/ns#" term="conferences" /><title>Silver Bullet - Novo Evento de Segurança em São Paulo</title><content type="html">A grade parcial das palestras do Silver Bullet já está no ar. Confira os detalhes dos palestrantes abaixo no link&lt;a href="http://www.sbconference.com.br/noticias" target="_blank"&gt; http://www.&lt;span class="il"&gt;sbconference&lt;/span&gt;.com.&lt;wbr&gt;&lt;/wbr&gt;br/noticias&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
- Henrique Takaki – Membro do Advisory Board do PCI Council&lt;br /&gt;
- Nelson Novaes Neto – CSO Uol Diveo&lt;br /&gt;
- Anderson Ramos - FLIPSIDE Smart Content Provider, Senior Lead&lt;br /&gt;
Instructor do (ISC)2&lt;br /&gt;
- Nelson Murilo - Profissonal de segurança de instituição financeira e&lt;br /&gt;
co-fundador da STS Produções&lt;br /&gt;
- Chris Nickerson - CEO of LARES&lt;br /&gt;
- Dr. Renato Opice Blum – Opice Blum Advogados&lt;br /&gt;
- Fioravante Souza - Coordenador do laboratório regional da Trend&lt;br /&gt;
Micro para a América Latina e fundador do projeto Beer Hacking&lt;br /&gt;
- Wendel Guglielmetti Henrique - Security Consultant at Trustwave's SpiderLabs&lt;br /&gt;
- Eduardo Neves – Consultor de Risk Management e membro do Owasp&lt;br /&gt;
Global Education Committee&lt;br /&gt;
- Suzely Espadoni - Instituto Nacional do Seguro Social – INSS&lt;br /&gt;
- Fosforo - Consultor Independente&lt;br /&gt;
&lt;b&gt; - Rodrigo "Sp0oKeR" Montoro - Spiderlabs, Brazilian Snort Communirty&lt;/b&gt;&lt;br /&gt;
- Marcelo Carvalho, CISSP, CISA, CRISC&lt;br /&gt;
- Anchises Moraes de Paula - Idefense&lt;br /&gt;
- Rodrigo Antão - Techbiz&lt;br /&gt;
- Joaquim Espinhara - Cipher&lt;br /&gt;
- Derneval Cunha - Barata Elétrica&lt;br /&gt;
- Alberto Fabiano - Quanta Tecnologia&lt;br /&gt;
- Ronaldo Vasconcellos - Dragon Research Group (DRG)&lt;br /&gt;
- Altieres Rohr - Linha Defensiva&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Estarei lá palestrando sobre HTTP Header Hunter , uma nova maneira de detectar tráfego malicioso baseado nos cabeçalhos do protocolo HTTP . &lt;br /&gt;
&lt;br /&gt;
Siga-nos no Twitter: &lt;a href="https://twitter.com/silverbulletcon"&gt;@silverbulletcon&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Vai perder ? Nos vemos por lá! =)&lt;br /&gt;
&lt;br /&gt;
Para se inscrever: &lt;a href="http://sbconference.com.br/inscricoes"&gt;http://sbconference.com.br/inscricoes&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Happy Hacking!&lt;br /&gt;
&lt;br /&gt;
Rodrigo Montoro&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-323891412545571105?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/nOFqB1WqcWs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/323891412545571105/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=323891412545571105" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/323891412545571105?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/323891412545571105?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/nOFqB1WqcWs/silver-bullet-novo-evento-de-seguranca.html" title="Silver Bullet - Novo Evento de Segurança em São Paulo" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2011/10/silver-bullet-novo-evento-de-seguranca.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEUAR3o7eSp7ImA9WhZUGUw.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-8675796338304057514</id><published>2011-06-12T19:03:00.001-03:00</published><updated>2011-06-12T19:04:06.401-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-12T19:04:06.401-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="webinar" /><category scheme="http://www.blogger.com/atom/ns#" term="snort" /><category scheme="http://www.blogger.com/atom/ns#" term="malwares" /><title>Local Threats - O webinar de ameaças brasileiras ( Edição Inicial )</title><content type="html">&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; A idéia do webinar será um bate papo quinzenal do grupo &lt;a href="http://www.snort.org.br/"&gt;Snort-BR&lt;/a&gt; e &lt;a href="http://malwaresbr.blogspot.com/"&gt;Malwares-BR&lt;/a&gt; apoiado pela &lt;a href="https://www.trustwave.com/"&gt;Trustwave&lt;/a&gt;  via Webex sendo o mesmo aberto ao público no geral sendo necessário a  inscrição antecipada no link que será publicado em listas e sites. O  evento terá como coordenador Rodrigo Montoro (Sp0oKeR) mas não  necessariamente ele que estará palestrando/batendo papo virtual sempre.  Teremos convidados de outras empresas que se encaixem nas pautas e  assuntos tratados e logicamente sempre em português . O grande foco  também é falar sobre malwares e tendências para América Latina em  especial Brasil e possiveis/correspondente proteções/mitigações .&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Mais informações e como se inscrever:&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://malwaresbr.blogspot.com/2011/06/local-threats-o-webinar-de-ameacas.html"&gt; http://malwaresbr.blogspot.com/2011/06/local-threats-o-webinar-de-ameacas.html&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;Espero voces por lá!&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;Rodrigo Montoro&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-8675796338304057514?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/6pdhzPme4UY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/8675796338304057514/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=8675796338304057514" title="1 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/8675796338304057514?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/8675796338304057514?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/6pdhzPme4UY/local-threats-o-webinar-de-ameacas.html" title="Local Threats - O webinar de ameaças brasileiras ( Edição Inicial )" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2011/06/local-threats-o-webinar-de-ameacas.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0YERH08cSp7ImA9Wx9VE0Q.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-7277517005772630894</id><published>2011-01-30T12:51:00.000-02:00</published><updated>2011-01-30T12:51:45.379-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-01-30T12:51:45.379-02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="spiderlabs" /><category scheme="http://www.blogger.com/atom/ns#" term="snort" /><title>LOIC DDoS Analysis and Detection</title><content type="html">Caros,&lt;br /&gt;
&lt;br /&gt;
Fiz uma analise basica do LOIC,&amp;nbsp; ferramenta utilizada para os ataques de DDoS/DoS em prol do Wikileaks . Postwi alguns pontos e regras do snort no blog do &lt;a href="http://www.trustwave.com/spiderlabs"&gt;Spiderlabs&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://blog.spiderlabs.com/2011/01/loic-ddos-analysis-and-detection.html"&gt;http://blog.spiderlabs.com/2011/01/loic-ddos-analysis-and-detection.html&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Happy Snorting!&lt;br /&gt;
&lt;br /&gt;
Rodrigo Montoro (Sp0oKeR)&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-7277517005772630894?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/jeMETAWYVGs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/7277517005772630894/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=7277517005772630894" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/7277517005772630894?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/7277517005772630894?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/jeMETAWYVGs/loic-ddos-analysis-and-detection.html" title="LOIC DDoS Analysis and Detection" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2011/01/loic-ddos-analysis-and-detection.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEUEQ348cSp7ImA9Wx9XGU8.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-1480522956975314214</id><published>2011-01-13T11:42:00.001-02:00</published><updated>2011-01-13T11:43:22.079-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-01-13T11:43:22.079-02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="owasp" /><title>[Owasp-brazilian] OWASP - Encontro do Capítulo São Paulo - 17 de Janeiro 2011</title><content type="html">&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Pessoal,&lt;br /&gt;
&lt;br /&gt;
Quero convidar a todos para participar do primeiro encontro do capítulo São Paulo da OWASP.&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;br /&gt;
O espaço foi gentilmente cedido pela Editora Abril e o objetivo é discutir as ações do capítulo.&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;&lt;b&gt;Data:&lt;/b&gt;&lt;/u&gt; 17 de Janeiro de 2011 das 19:30 às 22:00 hrs.&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt; Endereço:&lt;/u&gt;&lt;/b&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt;Avenida das Nações Unidas, 7221 Sala Contigo no espaço Victor Civita.&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt; Estacionamento:&lt;/u&gt;&lt;/b&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt;&amp;nbsp;Rua Sumidouro ou Gilberto Sabino.&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;br /&gt;
Aproveito para pedir a todos interessados que assinem a lista de discussão do capítulo São Paulo.&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://lists.owasp.org/mailman/listinfo/owasp-Sao_Paulo" target="_blank"&gt;https://lists.owasp.org/&lt;wbr&gt;&lt;/wbr&gt;mailman/listinfo/owasp-Sao_&lt;wbr&gt;&lt;/wbr&gt;Paulo&lt;/a&gt;&lt;/span&gt;  &lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
Por favor, mande um e-mail confirmando a presença para o email:&lt;a href="mailto:wagner.elias@owasp.org"&gt; wagner.elias@owasp.org&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt; Dados: Nome e RG&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Isto é para autorizar a entrada na Editora Abril. &lt;/span&gt;   &lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="font-family: Arial,Helvetica,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Grato&lt;br /&gt;
&lt;br /&gt;
--&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;
Wagner Elias - OWASP Chapter Leader São Paulo&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-1480522956975314214?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/8GnAJ-yBtYw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/1480522956975314214/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=1480522956975314214" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/1480522956975314214?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/1480522956975314214?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/8GnAJ-yBtYw/owasp-brazilian-owasp-encontro-do.html" title="[Owasp-brazilian] OWASP - Encontro do Capítulo São Paulo - 17 de Janeiro 2011" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2011/01/owasp-brazilian-owasp-encontro-do.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CE8HRHY-fip7ImA9Wx9QEU4.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-2140391411284388298</id><published>2010-12-23T17:01:00.003-02:00</published><updated>2010-12-23T17:33:55.856-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-12-23T17:33:55.856-02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="vrt" /><category scheme="http://www.blogger.com/atom/ns#" term="snort" /><category scheme="http://www.blogger.com/atom/ns#" term="et" /><title>Emerging Threats x VRT Rules - Enable versus Classtype</title><content type="html">&lt;span style="font-size: small;"&gt;Playing with bot ruleset I start to analyze some differences between them in special enable x disable rules based on classtype or category . As base I'm using VRT tarball from Nov 23th and ET emerging-all from Dec 22nd .&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;u&gt;&lt;b&gt;About VRT (I only analyzed plain-text rules):&lt;/b&gt;&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;Total Plain-text Rules: 16301&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;Total Enable: 4597&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;Total Disable: 11704&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;u&gt;&lt;b&gt;Enable rules x Category/Classtype&lt;/b&gt;&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp; 1370 Status: Enable Category: attempted-user&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 925 Status: Enable Category: misc-activity&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 646 Status: Enable Category: trojan-activity&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 419 Status: Enable Category: attempted-admin&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 287 Status: Enable Category: successful-recon-limited&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 249 Status: Enable Category: protocol-command-decode&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 114 Status: Enable Category: attempted-dos&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 111 Status: Enable Category: misc-attack&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 108 Status: Enable Category: rpc-portmap-decode&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 106 Status: Enable Category: policy-violation&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 77 Status: Enable Category: attempted-recon&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 42 Status: Enable Category: shellcode-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 34 Status: Enable Category: bad-unknown&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 32 Status: Enable Category: web-application-attack&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 16 Status: Enable Category: denial-of-service&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 13 Status: Enable Category: suspicious-filename-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12 Status: Enable Category: suspicious-login&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 Status: Enable Category: unsuccessful-user&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6 Status: Enable Category: web-application-activity&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 Status: Enable Category: successful-admin&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4 Status: Enable Category: system-call-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4 Status: Enable Category: string-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4 Status: Enable Category: network-scan&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 Status: Enable Category: unknown&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 Status: Enable Category: successful-user&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 Status: Enable Category: not-suspicious&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;u&gt;&lt;b&gt;General Category/Classtype&lt;/b&gt;&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp; 3764&amp;nbsp; attempted-user&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp; 3612&amp;nbsp; attempted-admin&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp; 3516&amp;nbsp; protocol-command-decode&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp; 1228&amp;nbsp; misc-activity&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp; 1119&amp;nbsp; trojan-activity&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 520&amp;nbsp; web-application-activity&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 425&amp;nbsp; web-application-attack&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 358&amp;nbsp; attempted-recon&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 328&amp;nbsp; bad-unknown&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 308&amp;nbsp; successful-recon-limited&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 301&amp;nbsp; policy-violation&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 266&amp;nbsp; attempted-dos&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 198&amp;nbsp; misc-attack&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 133&amp;nbsp; rpc-portmap-decode&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 67&amp;nbsp; shellcode-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 35&amp;nbsp; suspicious-filename-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 32&amp;nbsp; denial-of-service&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 19&amp;nbsp; suspicious-login&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15&amp;nbsp; not-suspicious&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12&amp;nbsp; unsuccessful-user&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9&amp;nbsp; successful-admin&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8&amp;nbsp; non-standard-protocol&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&amp;nbsp; default-login-attempt&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&amp;nbsp; system-call-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&amp;nbsp; network-scan&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp; unknown&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp; string-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&amp;nbsp; unusual-client-port-connection&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; successful-user&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;u&gt;&lt;b&gt;About ET&amp;nbsp;&lt;/b&gt;&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;Total Plain-text Rules: 11517&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;Total Enable: 9644&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;Total Disable: 1873&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;u&gt;Enable rules x Category/Classtype&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp; 5049 Status: Enable Category: web-application-attack&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp; 1617 Status: Enable Category: trojan-activity&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 474 Status: Enable Category: attempted-user&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 376 Status: Enable Category:&amp;nbsp; trojan-activity&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 339 Status: Enable Category: protocol-command-decode&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 295 Status: Enable Category: attempted-admin&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 265 Status: Enable Category: policy-violation&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 206 Status: Enable Category:&amp;nbsp; policy-violation&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 176 Status: Enable Category: attempted-recon&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 167 Status: Enable Category: bad-unknown&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 102 Status: Enable Category: misc-attack&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 81 Status: Enable Category: misc-activity&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 81 Status: Enable Category: attempted-dos&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 80 Status: Enable Category: rpc-portmap-decode&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 54 Status: Enable Category: web-application-activity&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 40 Status: Enable Category:&amp;nbsp; misc-activity&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 32 Status: Enable Category:&amp;nbsp; web-application-attack&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30 Status: Enable Category: shellcode-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 16 Status: Enable Category: denial-of-service&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 16 Status: Enable Category:&amp;nbsp; attempted-recon&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 13 Status: Enable Category: not-suspicious&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12 Status: Enable Category: suspicious-filename-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12 Status: Enable Category:&amp;nbsp; attempted-admin&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11 Status: Enable Category: unsuccessful-user&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11 Status: Enable Category:&amp;nbsp; misc-attack&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 Status: Enable Category: successful-admin&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 Status: Enable Category:&amp;nbsp; string-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 Status: Enable Category:&amp;nbsp; attempted-dos&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9 Status: Enable Category: suspicious-login&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 Status: Enable Category: default-login-attempt&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4 Status: Enable Category: unknown&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4 Status: Enable Category:&amp;nbsp; suspicious-login&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4 Status: Enable Category: successful-user&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4 Status: Enable Category: non-standard-protocol&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4 Status: Enable Category: network-scan&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3 Status: Enable Category:&amp;nbsp; web-application-activity&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3 Status: Enable Category: system-call-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3 Status: Enable Category: successful-recon-limited&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3 Status: Enable Category: successful-dos&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3 Status: Enable Category:&amp;nbsp; bad-unknown&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 Status: Enable Category: unusual-client-port-connection&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 Status: Enable Category:&amp;nbsp; not-suspicious&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 Status: Enable Category:&amp;nbsp; successful-admin&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 Status: Enable Category: string-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 Status: Enable Category:&amp;nbsp; shellcode-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 Status: Enable Category:&amp;nbsp; denial-of-service&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 Status: Enable Category:&amp;nbsp; attempted-user&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;u&gt;&lt;b&gt;General Category/Classtype&lt;/b&gt;&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp; 5213&amp;nbsp; web-application-attack&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp; 1799&amp;nbsp; trojan-activity&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 643&amp;nbsp; attempted-user&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 568&amp;nbsp; policy-violation&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 410&amp;nbsp;&amp;nbsp; trojan-activity&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 384&amp;nbsp; protocol-command-decode&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 373&amp;nbsp; attempted-admin&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 300&amp;nbsp; misc-activity&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 276&amp;nbsp; attempted-recon&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 268&amp;nbsp;&amp;nbsp; policy-violation&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 238&amp;nbsp; bad-unknown&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 137&amp;nbsp; shellcode-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 136&amp;nbsp; attempted-dos&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 134&amp;nbsp; misc-attack&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 95&amp;nbsp; web-application-activity&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 88&amp;nbsp; rpc-portmap-decode&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 80&amp;nbsp;&amp;nbsp; misc-activity&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 39&amp;nbsp; not-suspicious&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 36&amp;nbsp;&amp;nbsp; web-application-attack&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 27&amp;nbsp; successful-user&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 25&amp;nbsp;&amp;nbsp; attempted-recon&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20&amp;nbsp; unusual-client-port-connection&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 17&amp;nbsp;&amp;nbsp; misc-attack&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 17&amp;nbsp; denial-of-service&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 16&amp;nbsp; suspicious-filename-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 16&amp;nbsp;&amp;nbsp; attempted-admin&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 14&amp;nbsp; successful-admin&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 13&amp;nbsp;&amp;nbsp; attempted-dos&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12&amp;nbsp;&amp;nbsp; bad-unknown&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11&amp;nbsp; unsuccessful-user&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11&amp;nbsp; unknown&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11&amp;nbsp; suspicious-login&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11&amp;nbsp;&amp;nbsp; string-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10&amp;nbsp;&amp;nbsp; not-suspicious&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10&amp;nbsp; non-standard-protocol&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; default-login-attempt&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&amp;nbsp; system-call-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&amp;nbsp; successful-recon-limited&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&amp;nbsp; network-scan&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp;&amp;nbsp; web-application-activity&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp;&amp;nbsp; suspicious-login&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp;&amp;nbsp; suspicious-filename-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp;&amp;nbsp; shellcode-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp;&amp;nbsp; attempted-user&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&amp;nbsp; successful-dos&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&amp;nbsp; string-detect&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&amp;nbsp;&amp;nbsp; denial-of-service&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp; successful-admin&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp; non-standard-protocol&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;u&gt;In summary:&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;- ET has almost double rules enable by default&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;- VRT most enable rules focus on attempted-user&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;- ET most enable rules focus on web-application-attack and trojan-activity&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;- Rules from ET and VRT target different protections what you should analyze where you will seat your sensor for best decision or using both and mixing them &lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;I just did some basic scripting and my numbers could not be accurate but it's a good base .&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;Happy Snorting!&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;Rodrigo Montoro (Sp0oKeR)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-2140391411284388298?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/yiaWMUdmMB0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/2140391411284388298/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=2140391411284388298" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/2140391411284388298?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/2140391411284388298?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/yiaWMUdmMB0/emerging-threats-x-vrt-rules-enable.html" title="Emerging Threats x VRT Rules - Enable versus Classtype" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2010/12/emerging-threats-x-vrt-rules-enable.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkMERncyfip7ImA9Wx5VFE0.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-6570600211570881202</id><published>2010-10-06T18:26:00.000-03:00</published><updated>2010-10-06T18:26:47.996-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-10-06T18:26:47.996-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="waf" /><category scheme="http://www.blogger.com/atom/ns#" term="pdf" /><category scheme="http://www.blogger.com/atom/ns#" term="owasp" /><category scheme="http://www.blogger.com/atom/ns#" term="h2hc" /><category scheme="http://www.blogger.com/atom/ns#" term="malwares" /><title>Palestras no Brasil - OWASP e H2HC</title><content type="html">Caros,&lt;br /&gt;
&lt;br /&gt;
Faz um tempo desde o último post mas a vida anda corrida por esses lados .&amp;nbsp; Faço esse post para comentar mais 2 palestras aceitas só que agora no Brasil felizmente .&lt;br /&gt;
&lt;br /&gt;
A primeira ocorrerá no OWASP AppSec Brasil que acontecerá em Campinas onde falarei do uso do Modsecurity WAF para Virtual Patching ( &lt;a href="http://www.owasp.org/index.php/AppSec_Brasil_2010#tab=Speakers"&gt;http://www.owasp.org/index.php/AppSec_Brasil_2010#tab=Speakers&lt;/a&gt;)&lt;br /&gt;
&lt;br /&gt;
Mais info: &lt;a href="http://www.owasp.org/index.php/AppSec_Brasil_2010#tab=Calls"&gt;http://www.owasp.org/index.php/AppSec_Brasil_2010#tab=Calls&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Outra que tive o prazer de ser aceito e falarei pela primeira vez sera a Hackers to Hackers Conference aka H2HC . Nela falarei sobre minha pdf de scoring da estrutura do pdf o que me deixa bem feliz de falar sobre ela por aqui também.&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
Mais info: &lt;a href="http://www.h2hc.com.br/"&gt;http://www.h2hc.com.br&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Espero encontrar com vocês lá .&lt;br /&gt;
&lt;br /&gt;
Happy Hacking!&lt;br /&gt;
&lt;br /&gt;
Rodrigo "Sp0oKeR" Montoro&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-6570600211570881202?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/g2XLB6ELybY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/6570600211570881202/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=6570600211570881202" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/6570600211570881202?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/6570600211570881202?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/g2XLB6ELybY/palestras-no-brasil-owasp-e-h2hc.html" title="Palestras no Brasil - OWASP e H2HC" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2010/10/palestras-no-brasil-owasp-e-h2hc.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkMARXYzcCp7ImA9Wx5QGUk.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-6798250604125363285</id><published>2010-09-08T09:20:00.000-03:00</published><updated>2010-09-08T09:20:44.888-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-09-08T09:20:44.888-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="spiderlabs" /><category scheme="http://www.blogger.com/atom/ns#" term="pdf" /><category scheme="http://www.blogger.com/atom/ns#" term="conferences" /><title>PDF Talk Accepted at Toorcon San Diego</title><content type="html">I'm very excited that my talk was accepted at &lt;a href="http://www.toorcon.org/"&gt;Toorcon San Diego&lt;/a&gt;. About the conference:&lt;br /&gt;
&lt;br /&gt;
Who:&amp;nbsp;&amp;nbsp;&amp;nbsp; Hackers Like You.&lt;br /&gt;
What:&amp;nbsp;&amp;nbsp; ToorCon 12&lt;br /&gt;
When:&amp;nbsp;&amp;nbsp; OCT 22rd-24th&lt;br /&gt;
Where:&amp;nbsp; San Diego Convention Center&lt;br /&gt;
Why:&amp;nbsp;&amp;nbsp;&amp;nbsp; What Could possibly go wrong?&lt;br /&gt;
&lt;br /&gt;
I'll be talking about part of my research at &lt;a href="https://www.trustwave.com/spiderlabs"&gt;Trustwave Spiderlabs Research&lt;/a&gt; where we are doing a new way to detect malicious pdf files . The title for my talk: "&lt;strong&gt;Scoring PDF structure to detect malicious files&lt;/strong&gt;"&lt;br /&gt;
&lt;br /&gt;
Preliminary Agenda for Toorcon:&lt;a href="http://sandiego.toorcon.org/index.php?option=com_content&amp;amp;task=section&amp;amp;id=3&amp;amp;Itemid=9#lineup"&gt; http://sandiego.toorcon.org/index.php?option=com_content&amp;amp;task=section&amp;amp;id=3&amp;amp;Itemid=9#lineup&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you there!&lt;br /&gt;
&lt;br /&gt;
Rodrigo "Sp0oKeR" Montoro&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-6798250604125363285?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/QUjV5ONVZYo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/6798250604125363285/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=6798250604125363285" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/6798250604125363285?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/6798250604125363285?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/QUjV5ONVZYo/pdf-talk-accepted-at-toorcon-san-diego.html" title="PDF Talk Accepted at Toorcon San Diego" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2010/09/pdf-talk-accepted-at-toorcon-san-diego.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUEEQH05fCp7ImA9Wx5QFEk.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-4289754718782817358</id><published>2010-09-02T12:07:00.002-03:00</published><updated>2010-09-02T13:06:41.324-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-09-02T13:06:41.324-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="snort" /><title>Snort Rules - Using content:"GET "; or not ?</title><content type="html">I'm doing some tests with different rules since I'm creating a rules test labs and based on some old read/thread and one simple test here I started to look why do we use content:"GET "; in a lot of rules since it'll not be the first match mostly.&lt;br /&gt;
&lt;br /&gt;
My first test that I started to notice what I read before was about using http_method or not with engine 2.8.6 .&lt;br /&gt;
&lt;br /&gt;
My pcap I created a very simple GET / (packet &amp;nbsp;5)&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;$ tshark -r get-NoHost.pcap&lt;br /&gt;
&lt;/i&gt; &lt;i&gt;  &amp;nbsp;1 &amp;nbsp; 0.000000 192.168.21.1 -&amp;gt; 192.168.21.131 TCP 61599 &amp;gt; http [SYN]&lt;br /&gt;
Seq=0 Win=65535 Len=0 MSS=1460 WS=3 TSV=534894464 TSER=0&lt;br /&gt;
&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;2 &amp;nbsp; 0.001384 192.168.21.1 -&amp;gt; 192.168.21.131 TCP 61599 &amp;gt; http [ACK]&lt;br /&gt;
Seq=1 Ack=1 Win=524280 Len=0 TSV=534894464 TSER=134793051&lt;br /&gt;
&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp;3 &amp;nbsp; 3.798825 192.168.21.1 -&amp;gt; 192.168.21.131 TCP [TCP Dup ACK 2#1]&lt;br /&gt;
61599 &amp;gt; http [ACK] Seq=1 Ack=1 Win=524280 Len=0 TSV=534894502&lt;br /&gt;
TSER=134794001&lt;br /&gt;
&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp;4 &amp;nbsp; 7.348575 192.168.21.1 -&amp;gt; 192.168.21.131 TCP [TCP segment of a&lt;br /&gt;
reassembled PDU]&lt;br /&gt;
&lt;b style="color: red;"&gt;&amp;nbsp;&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;b style="color: red;"&gt;&amp;nbsp;5 &amp;nbsp; 7.892566 192.168.21.1 -&amp;gt; 192.168.21.131 HTTP GET / HTTP/1.0&lt;/b&gt;&lt;br /&gt;
&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp;6 &amp;nbsp; 8.197800 192.168.21.1 -&amp;gt; 192.168.21.131 TCP 61599 &amp;gt; http [ACK]&lt;br /&gt;
Seq=19 Ack=325 Win=524280 Len=0 TSV=534894546 TSER=134795100&lt;br /&gt;
&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp;7 &amp;nbsp; 8.202863 192.168.21.1 -&amp;gt; 192.168.21.131 TCP 61599 &amp;gt; http [ACK]&lt;br /&gt;
Seq=19 Ack=326 Win=524280 Len=0 TSV=534894546 TSER=134795102&lt;br /&gt;
&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&amp;nbsp;8 &amp;nbsp; 8.202895 192.168.21.1 -&amp;gt; 192.168.21.131 TCP 61599 &amp;gt; http [FIN,&lt;br /&gt;
ACK] Seq=19 Ack=326 Win=524280 Len=0 TSV=534894546 TSER=134795102&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
I used those rules for testing the basics in my lab:&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET $HTTP_PORTS (msg:"New Rule One - GET";content:"GET";http_&lt;/span&gt;&lt;br /&gt;
&lt;div id=":6dj"&gt;&lt;wbr&gt;&lt;/wbr&gt;&lt;span style="font-size: x-small;"&gt;method;content:"attack";sid:&lt;/span&gt;&lt;wbr&gt;&lt;/wbr&gt;&lt;span style="font-size: x-small;"&gt;123456;)&lt;br /&gt;
&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div id=":6dj"&gt;&lt;span style="font-size: x-small;"&gt;alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET $HTTP_PORTS (msg:"New Rule Two - POST";content:"POST";http_&lt;/span&gt;&lt;wbr&gt;&lt;/wbr&gt;&lt;span style="font-size: x-small;"&gt;method;content:"index";sid:&lt;/span&gt;&lt;wbr&gt;&lt;/wbr&gt;&lt;span style="font-size: x-small;"&gt;654321;)&lt;br /&gt;
&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div id=":6dj"&gt;&lt;span style="font-size: x-small;"&gt;alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET $HTTP_PORTS (msg:"New Rule Three GET without&lt;br /&gt;
http_method";content:"GET";&lt;/span&gt;&lt;wbr&gt;&lt;/wbr&gt;&lt;span style="font-size: x-small;"&gt;content:"ABCDE";sid:23465324;)&lt;br /&gt;
&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div id=":6dj"&gt;&lt;span style="font-size: x-small;"&gt;alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET $HTTP_PORTS (msg:"New Rule Four GET without http_method but using fast_pattern";content:"GET";&lt;/span&gt;&lt;wbr&gt;&lt;/wbr&gt;&lt;span style="font-size: x-small;"&gt;fast_pattern;content:"ABCDE";&lt;/span&gt;&lt;wbr&gt;&lt;/wbr&gt;&lt;span style="font-size: x-small;"&gt;sid:9845324;)&lt;/span&gt;&lt;/div&gt;&lt;div id=":6dj"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;
alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET $HTTP_PORTS (msg:"New Rule Five GET without http_method and only content";content:"GET";sid:&lt;/span&gt;&lt;wbr&gt;&lt;/wbr&gt;&lt;span style="font-size: x-small;"&gt;4365324;)&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
And as result I got&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;&lt;span style="font-size: x-small;"&gt;$ perl &lt;a href="http://rule-test-check.pl/" target="_blank"&gt;rule-test-check.pl&lt;/a&gt; get-NoHost.pcap rules-samples/rules-new.rules snort.conf&lt;br /&gt;
&lt;br /&gt;
SpiderLabs Rules Test version 0.1 Alpha&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;
&lt;br /&gt;
Result: &lt;span style="color: lime;"&gt;Checked&lt;/span&gt; 123456 alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET $HTTP_PORTS (msg:"New Rule One - GET";content:"GET";http_&lt;/span&gt; &lt;/i&gt; &lt;wbr&gt;&lt;/wbr&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;method;content:"attack";sid:&lt;/span&gt;&lt;/i&gt;&lt;wbr&gt;&lt;/wbr&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;123456;)&lt;br /&gt;
&lt;br /&gt;
Result: &lt;span style="color: red;"&gt;NoCheck&lt;/span&gt; 654321 alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET $HTTP_PORTS (msg:"New Rule Two - POST";content:"POST";http_&lt;/span&gt; &lt;/i&gt;&lt;wbr&gt;&lt;/wbr&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;method;content:"index";sid:&lt;/span&gt;&lt;/i&gt;&lt;wbr&gt;&lt;/wbr&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;654321;)&lt;br /&gt;
&lt;br /&gt;
Result: &lt;span style="color: red;"&gt;NoCheck&lt;/span&gt; 23465324 alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET $HTTP_PORTS (msg:"New Rule Three GET without http_method";content:"GET";&lt;/span&gt; &lt;/i&gt;&lt;wbr&gt;&lt;/wbr&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;content:"ABCDE";sid:23465324;)&lt;br /&gt;
&lt;br /&gt;
Result: &lt;span style="color: lime;"&gt;Checked&lt;/span&gt; 9845324 alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET $HTTP_PORTS (msg:"New Rule Four GET without http_method but using fast_pattern";content:"GET";&lt;/span&gt; &lt;/i&gt;&lt;wbr&gt;&lt;/wbr&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;fast_pattern;content:"ABCDE";&lt;/span&gt;&lt;/i&gt;&lt;wbr&gt;&lt;/wbr&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;sid:9845324;)&lt;br /&gt;
&lt;br /&gt;
Result: &lt;span style="color: lime;"&gt;Checked&lt;/span&gt; 4365324 alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET $HTTP_PORTS (msg:"New Rule Five GET without http_method and only content";content:"GET";sid:&lt;/span&gt; &lt;/i&gt;&lt;wbr&gt;&lt;/wbr&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;4365324;)&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
Count Summary&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Checked: 3&lt;br /&gt;
NotChecked: 2&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Where:&lt;br /&gt;
&lt;br /&gt;
Checked means that there is some output for this sid for one basic check at least (I'm using as base content GET since we have the packet number 5 with it) .&lt;br /&gt;
&lt;br /&gt;
Based on that I remembered a good thread where Will Metacalf and Steve discuss some new features and http_modifiers use&lt;a href="http://sourceforge.net/mailarchive/message.php?msg_name=c13e433a1003092015v2d86f9a7x2eb73a2528df09f3%40mail.gmail.com" target="_blank"&gt; http://sourceforge.net/&lt;wbr&gt;&lt;/wbr&gt;mailarchive/message.php?msg_&lt;wbr&gt;&lt;/wbr&gt;name=&lt;wbr&gt;&lt;/wbr&gt;c13e433a1003092015v2d86f9a7x2e&lt;wbr&gt;&lt;/wbr&gt;b73a2528df09f3%40mail.gmail.&lt;wbr&gt;&lt;/wbr&gt;com&lt;/a&gt; .&lt;br /&gt;
&lt;br /&gt;
So I tested based on some very basic grep at emerging-all.rules &amp;nbsp;"grep content:"GET " emerging-all.rules " . Using the rules that were output I ran my test against those rules (around 1047 rules) and the summary results:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Checked: 4&lt;br /&gt;
NotChecked: 1043&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
I started to figured out that content:"GET "; when we use that is tobe the first match BUT if you don't specify fast_pattern by default it'll be the bigger content to match (&lt;a href="http://vrt-sourcefire.blogspot.com/2009/07/rule-performance-part-one-content.html" target="_blank"&gt; http://vrt-sourcefire.&lt;wbr&gt;&lt;/wbr&gt;blogspot.com/2009/07/rule-&lt;wbr&gt;&lt;/wbr&gt;performance-part-one-content.&lt;wbr&gt;&lt;/wbr&gt;html&lt;/a&gt; ) . So with another basic sed I changed the rules a little bit " sed -e 's/content:"GET ";/content:"GET ";fast_pattern;/g' " where it change for example:&lt;br /&gt;
&lt;br /&gt;
Original&lt;br /&gt;
&lt;br /&gt;
alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET $HTTP_PORTS (msg:"ET CURRENT_EVENTS Zeus Bot / Zbot Checkin (/us01d/in.php)"; flow:established,to_server; content:"GET "; nocase; depth:4; uricontent:"/us01d/in.php"; reference:url,&lt;a href="http://garwarner.blogspot.com/2010/01/american-bankers-association-version-of.html" target="_blank"&gt;garwarner.&lt;wbr&gt;&lt;/wbr&gt;blogspot.com/2010/01/american-&lt;wbr&gt;&lt;/wbr&gt;bankers-association-version-&lt;wbr&gt;&lt;/wbr&gt;of.html&lt;/a&gt;; reference:url,&lt;a href="http://doc.emergingthreats.net/2010729" target="_blank"&gt;doc.&lt;wbr&gt;&lt;/wbr&gt;emergingthreats.net/2010729&lt;/a&gt;; reference:url,&lt;a href="http://www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/CURRENT_EVENTS/CURRENT_Zeus" target="_blank"&gt;www.&lt;wbr&gt;&lt;/wbr&gt;emergingthreats.net/cgi-bin/&lt;wbr&gt;&lt;/wbr&gt;cvsweb.cgi/sigs/CURRENT_&lt;wbr&gt;&lt;/wbr&gt;EVENTS/CURRENT_Zeus&lt;/a&gt;; classtype:trojan-activity; sid:2010729; rev:3;)&lt;/div&gt;&lt;div id=":6dj"&gt;&lt;/div&gt;&lt;div id=":6dj"&gt;&lt;div class="kl" dir="ltr" id=":68y"&gt;&lt;/div&gt;&lt;div class="kl" dir="ltr" id=":68y"&gt;&lt;/div&gt;&lt;div class="kl" dir="ltr" id=":68y"&gt;&lt;/div&gt;&lt;div class="kl" dir="ltr" id=":68y"&gt;fast_pattern debug choosing the biggest content found&lt;/div&gt;&lt;div class="kl" dir="ltr" id=":68y"&gt;&lt;/div&gt;&lt;div class="kl" dir="ltr" id=":68y"&gt;&amp;nbsp;Fast pattern matcher: URI content&lt;br /&gt;
&lt;b style="color: red;"&gt; &amp;nbsp;Fast pattern set: no&lt;/b&gt;&lt;br /&gt;
&amp;nbsp;Fast pattern only: no&lt;br /&gt;
&amp;nbsp;Negated: no&lt;br /&gt;
&amp;nbsp;Pattern offset,length: none&lt;br /&gt;
&amp;nbsp;Pattern truncated: no&lt;br /&gt;
&amp;nbsp;Original pattern&lt;br /&gt;
&amp;nbsp; &amp;nbsp;"/us01d/in.php"&lt;br /&gt;
&amp;nbsp;Final pattern&lt;br /&gt;
&amp;nbsp; &amp;nbsp;"/us01d/in.php"&lt;/div&gt;&lt;br /&gt;
After sed&lt;br /&gt;
&lt;br /&gt;
alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET $HTTP_PORTS (msg:"ET CURRENT_EVENTS Zeus Bot / Zbot Checkin (/us01d/in.php)"; flow:established,to_server; content:"GET ";fast_pattern; nocase; depth:4; uricontent:"/us01d/in.php"; reference:url,&lt;a href="http://garwarner.blogspot.com/2010/01/american-bankers-association-version-of.html" target="_blank"&gt;garwarner.&lt;wbr&gt;&lt;/wbr&gt;blogspot.com/2010/01/american-&lt;wbr&gt;&lt;/wbr&gt;bankers-association-version-&lt;wbr&gt;&lt;/wbr&gt;of.html&lt;/a&gt;; reference:url,&lt;a href="http://doc.emergingthreats.net/2010729" target="_blank"&gt;doc.&lt;wbr&gt;&lt;/wbr&gt;emergingthreats.net/2010729&lt;/a&gt;; reference:url,&lt;a href="http://www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/CURRENT_EVENTS/CURRENT_Zeus" target="_blank"&gt;www.&lt;wbr&gt;&lt;/wbr&gt;emergingthreats.net/cgi-bin/&lt;wbr&gt;&lt;/wbr&gt;cvsweb.cgi/sigs/CURRENT_&lt;wbr&gt;&lt;/wbr&gt;EVENTS/CURRENT_Zeus&lt;/a&gt;; classtype:trojan-activity; sid:2010729; rev:3;)&lt;br /&gt;
&lt;div class="kl" dir="ltr" id=":696"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="kl" dir="ltr" id=":696"&gt;Rules fast_pattern debug using this option&lt;/div&gt;&lt;div class="kl" dir="ltr" id=":694"&gt;&lt;br /&gt;
&amp;nbsp;Fast pattern matcher: Content&lt;br /&gt;
&lt;b style="color: red;"&gt; &amp;nbsp;Fast pattern set: yes&lt;/b&gt;&lt;br /&gt;
&amp;nbsp;Fast pattern only: no&lt;br /&gt;
&amp;nbsp;Negated: no&lt;br /&gt;
&amp;nbsp;Pattern offset,length: none&lt;br /&gt;
&amp;nbsp;Pattern truncated: no&lt;br /&gt;
&amp;nbsp;Original pattern&lt;br /&gt;
&amp;nbsp; &amp;nbsp;"GET|20|"&lt;br /&gt;
&amp;nbsp;Final pattern&lt;br /&gt;
&amp;nbsp; &amp;nbsp;"GET|20|"&lt;/div&gt;&lt;br /&gt;
I rerun the same test and I got:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Checked: 976&lt;br /&gt;
NotChecked: 71&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="color: red; font-size: x-small;"&gt;&lt;i&gt;* Where NotChecked are mostly some GET content in a different way since I'm doing pretty basic grep/sed and not being so accurate =) .&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
The last test I changed fast_pattern to http_method but http_method only receive the normalize buffer but the default fast_pattern is the same , that's mean bigger content &amp;nbsp;so no change from the first result.&lt;br /&gt;
&lt;br /&gt;
So my question is: &amp;nbsp;do we really need to analyze GET or POST (probably the same behavior since it's a short name) ? Did somebody try/test something like this before ? am I getting nuts talking about this? =D&lt;br /&gt;
&lt;br /&gt;
In my opinion we could remove content:"GET ";&amp;nbsp; from the rules since it'll only use some checks and "decrease" the performance . I think we already have lot of point that make sure that it's a http traffic since using $HTTP_PORTS , flow , uricontent that comes from http_inspect and so on.&lt;/div&gt;&lt;div id=":6dj"&gt;&lt;/div&gt;&lt;div id=":6dj"&gt;Some friends that I discussed about this told some point as : "maybe the attack can only be done using GET so it's good to specify since using POST will generate a false positive". My argument is the opposite since most rules we are not sure if that works with GET and/or POST only if we don't use them as part of the rule we will mitigate False Negatives and maybe save lot of CPU's cycle (but we need test to make sure about that) . I really prefer couple of FP than FN's .&lt;br /&gt;
&lt;/div&gt;&lt;div id=":6dj"&gt;&lt;/div&gt;&lt;div id=":6dj"&gt;What do you think ?&lt;/div&gt;&lt;div id=":6dj"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div id=":6dj"&gt;Regards,&lt;/div&gt;&lt;div id=":6dj"&gt;&lt;/div&gt;&lt;div id=":6dj"&gt;Rodrigo "Sp0oKeR" Montoro&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-4289754718782817358?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/CH1ZMQO3Mgk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/4289754718782817358/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=4289754718782817358" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/4289754718782817358?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/4289754718782817358?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/CH1ZMQO3Mgk/snort-rules-using-contentget-or-not.html" title="Snort Rules - Using content:&quot;GET &quot;; or not ?" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2010/09/snort-rules-using-contentget-or-not.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUEDQHY9fip7ImA9Wx5QE0o.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-5751430070676902915</id><published>2010-09-01T18:47:00.001-03:00</published><updated>2010-09-01T18:47:51.866-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-09-01T18:47:51.866-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="insecure" /><title>(IN)Secure Magazine Issue 17 released</title><content type="html">New release of this awesome digital and free magazine&lt;br /&gt;
&lt;br /&gt;
&lt;div align="left"&gt;&lt;ul&gt;&lt;li class="style2"&gt;Review: BlockMaster SafeStick secure USB flash drive&lt;/li&gt;
&lt;li class="style2"&gt;The devil is in the details: Securing the enterprise against the cloud&lt;/li&gt;
&lt;li class="style2"&gt;Cybercrime may be on the rise, but authentication evolves to defeat it&lt;/li&gt;
&lt;li class="style2"&gt;Learning from bruteforcers&lt;/li&gt;
&lt;li class="style2"&gt;PCI DSS v1.3: Vital to the emerging demand for virtualization and cloud security&lt;/li&gt;
&lt;li class="style2"&gt;Security testing - the key to software quality&lt;/li&gt;
&lt;li class="style2"&gt;A brief history of security and the mobile enterprise&lt;/li&gt;
&lt;li class="style2"&gt;Payment card security: Risk and control assessments&lt;/li&gt;
&lt;li class="style2"&gt;Security as a process: Does your security team fuzz?&lt;/li&gt;
&lt;li class="style2"&gt;Book review: Designing Network Security, 2nd Edition&lt;/li&gt;
&lt;li class="style2"&gt;Intelligent security: Countering sophisticated fraud&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
To download it:&amp;nbsp; &lt;a href="http://www.net-security.org/insecuremag.php"&gt;http://www.net-security.org/insecuremag.php&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Regards,&lt;br /&gt;
&lt;br /&gt;
Rodrigo "Sp0oKeR" Montoro&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-5751430070676902915?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/rMkBNVL0Ri8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/5751430070676902915/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=5751430070676902915" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/5751430070676902915?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/5751430070676902915?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/rMkBNVL0Ri8/insecure-magazine-issue-17-released.html" title="(IN)Secure Magazine Issue 17 released" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2010/09/insecure-magazine-issue-17-released.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUUER3w-fyp7ImA9Wx5RGUw.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-7525833482192906655</id><published>2010-08-27T10:53:00.000-03:00</published><updated>2010-08-27T10:53:26.257-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-08-27T10:53:26.257-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="issa" /><category scheme="http://www.blogger.com/atom/ns#" term="blackhat" /><category scheme="http://www.blogger.com/atom/ns#" term="defcon" /><title>ISSA Day Julho com Conviso falando Blackhat/Defcon/B-Sides</title><content type="html">O Capítulo Brasil da ISSA convida a todos os interessados a participar do ISSA Day de&amp;nbsp;Agosto 2010.&lt;br /&gt;
O evento é gratuito e aberto a qualquer interessado e tem o apoio da empresa &lt;a href="http://www.conviso.com.br/"&gt;Conviso IT Security&lt;/a&gt;.&lt;br /&gt;
&lt;div style="text-align: center;"&gt;&lt;img alt="Conviso IT Security" class="alignnone" height="46" src="http://www.conviso.com.br/wp-content/uploads/Logotipo-Conviso-2009-Cor1.png" title="Conviso IT Security" width="200" /&gt;&lt;/div&gt;&lt;strong&gt;Data:&lt;/strong&gt; 31 de&amp;nbsp;Agosto de 2010, das 19:00h às 22:00h&lt;br /&gt;
&lt;strong&gt; &lt;/strong&gt;&lt;strong&gt;Agenda:&lt;/strong&gt;&lt;br /&gt;
19h00 – Credenciamento,&lt;br /&gt;
19h30 – Palestra da&amp;nbsp;ISSA&amp;nbsp;- Por que ser&amp;nbsp;ISSA?&lt;br /&gt;
20h00 – Abertura falando sobre a Conviso.&lt;br /&gt;
20h15 – O processo de segurança em desenvolvimento, que não é ISO 15.408&lt;br /&gt;
21h00 – Palestra sobre a Black Hat e Defcon&lt;br /&gt;
21h45 – Sorteio de Treinamento Conviso e Encerramento – Com HH&lt;br /&gt;
&lt;strong&gt; &lt;/strong&gt;&lt;strong&gt;Local:&lt;/strong&gt;&lt;br /&gt;
&lt;a href="http://www.genuinochopp.com.br/"&gt;Bar Genoino&lt;/a&gt;.&lt;br /&gt;
Rua Joaquim Távora 1217,&amp;nbsp; Vila Mariana – São Paulo – SP&lt;br /&gt;
&lt;br /&gt;
Para se inscrever: &lt;a href="http://www.issabrasil.org/2010/08/24/issa-day-agosto-2010/%20"&gt;http://www.issabrasil.org/2010/08/24/issa-day-agosto-2010/ &lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Estarei lá certamente =)!&lt;br /&gt;
&lt;br /&gt;
Happy Hacking!&lt;br /&gt;
&lt;br /&gt;
Rodrigo "Sp0oKeR" Montoro&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-7525833482192906655?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/RTL1FlEx8_c" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/7525833482192906655/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=7525833482192906655" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/7525833482192906655?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/7525833482192906655?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/RTL1FlEx8_c/issa-day-julho-com-conviso-falando.html" title="ISSA Day Julho com Conviso falando Blackhat/Defcon/B-Sides" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2010/08/issa-day-julho-com-conviso-falando.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkQGQX46cCp7ImA9Wx5REUk.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-1551799274781480259</id><published>2010-08-18T12:12:00.000-03:00</published><updated>2010-08-18T12:12:00.018-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-08-18T12:12:00.018-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="virus" /><category scheme="http://www.blogger.com/atom/ns#" term="malwares" /><title>Updated some info for SET (Social Engineer Toolkit) PDF’s x AntiVirus &amp; Scoring System</title><content type="html">Virus Total Public API will make my live much easier . Look previous post about it &lt;a href="http://spookerlabs.blogspot.com/2010/08/virus-total-public-api.html"&gt;http://spookerlabs.blogspot.com/2010/08/virus-total-public-api.html&lt;/a&gt; .&lt;br /&gt;
&lt;br /&gt;
Some results really surprised me . Take a look and do your all conclusions .&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;&lt;b&gt;Best AntiVirus to detect SET Malicious PDF (higher is better):&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "Sophos"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "Microsoft"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "GData"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "F-Secure"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "F-Prot"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "ClamAV"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "BitDefender"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "Avast5"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "Avast"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&amp;nbsp; "Sunbelt"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6 "nProtect"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&amp;nbsp; "McAfee-GW-Edition"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&amp;nbsp; "eTrust-Vet"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&amp;nbsp; "Symantec"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&amp;nbsp; "PCTools"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp; "eSafe"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&amp;nbsp; "NOD32"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&amp;nbsp; "Kaspersky"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&amp;nbsp; "Ikarus"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&amp;nbsp; "Emsisoft"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&amp;nbsp; "Antiy-AVL"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&amp;nbsp; "McAfee"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; "VBA32"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; "Panda"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; "AVG"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; "Authentium"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; "AntiVir"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; "AhnLab-V3"&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;&lt;b&gt;Missed PDF detection for SET malicious PDF's (higher is worst) :&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; 7&amp;nbsp; "VirusBuster"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "ViRobot"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "TrendMicro-HouseCall"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "TrendMicro"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "TheHacker"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "SUPERAntiSpyware"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "Rising"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "Prevx"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "Norman"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "Jiangmin"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "Fortinet"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "DrWeb"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "Comodo"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp; "CAT-QuickHeal"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&amp;nbsp; "VBA32"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&amp;nbsp; "Panda"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&amp;nbsp; "AVG"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&amp;nbsp; "Authentium"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&amp;nbsp; "AntiVir"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&amp;nbsp; "AhnLab-V3"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&amp;nbsp; "McAfee"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp; "NOD32"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp; "Kaspersky"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp; "Ikarus"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp; "Emsisoft"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp; "Antiy-AVL"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&amp;nbsp; "eSafe"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&amp;nbsp; "Symantec"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&amp;nbsp; "PCTools"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; "Sunbelt"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 "nProtect"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; "McAfee-GW-Edition"&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; "eTrust-Vet"&lt;br /&gt;
&lt;br /&gt;
As we can see lot of AntiVirus missed all PDF from SET what is a big problem for companies . Some AntiVirus have some methods that VirusTotal doesn't emulate and possible those methods could detect them .&lt;br /&gt;
&lt;br /&gt;
I'll do a big analysis against all my pdf's and share the results .&lt;br /&gt;
&lt;br /&gt;
Happy Hacking!&lt;br /&gt;
&lt;br /&gt;
Rodrigo "Sp0oKeR" Montoro&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-1551799274781480259?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/ZLePFFJG5W8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/1551799274781480259/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=1551799274781480259" title="1 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/1551799274781480259?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/1551799274781480259?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/ZLePFFJG5W8/updated-some-info-for-set-social.html" title="Updated some info for SET (Social Engineer Toolkit) PDF’s x AntiVirus &amp; Scoring System" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2010/08/updated-some-info-for-set-social.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEIGRXk6fCp7ImA9Wx5REEQ.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-7643037535627593162</id><published>2010-08-17T21:45:00.001-03:00</published><updated>2010-08-17T21:48:44.714-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-08-17T21:48:44.714-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="virus" /><category scheme="http://www.blogger.com/atom/ns#" term="antivirus" /><category scheme="http://www.blogger.com/atom/ns#" term="malwares" /><title>Virus Total Public API</title><content type="html">Today I started to play with Virus Total Public API &lt;a href="http://www.virustotal.com/advanced.html"&gt;http://www.virustotal.com/advanced.html&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
My initial idea was to send files using command line and get the results quickly so I don't need a web browser and spend time uploading the file .&lt;br /&gt;
&lt;br /&gt;
I read their inital &lt;a href="http://www.virustotal.com/advanced.html"&gt;samples/docs&lt;/a&gt; and build a mix of codes using python (most retrieve from their samples) and perl (only language I can try somehting) . By now what I have :&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;&lt;b&gt;$ perl vt-auto.pl /LABS/pdf-basics/samples/AdamSamples/15&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
Sending file /LABS/pdf-basics/samples/AdamSamples/15 to Virus Total ...&lt;br /&gt;
Response from VT with resource "86ee2f99a207d31ea2b69198dc2bf5e7c7946eeae7dacdd6032f2c050525bc07-1282091669" &lt;br /&gt;
&lt;br /&gt;
Waiting 120 seconds to wait file /LABS/pdf-basics/samples/AdamSamples/15 be scanned ...&lt;br /&gt;
&lt;br /&gt;
Sending request fo Virus Total about /LABS/pdf-basics/samples/AdamSamples/15 with resource "86ee2f99a207d31ea2b69198dc2bf5e7c7946eeae7dacdd6032f2c050525bc07-1282091669"&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Report Results for /LABS/pdf-basics/samples/AdamSamples/15 :&lt;/b&gt;&lt;br /&gt;
"nProtect": "Trojan-Exploit/W32.Pidief.16718.AV" &lt;br /&gt;
&amp;nbsp;"CAT-QuickHeal": "" &lt;br /&gt;
&amp;nbsp;"McAfee": "Exploit-PDF.b.gen" &lt;br /&gt;
&amp;nbsp;"TheHacker": "" &lt;br /&gt;
&amp;nbsp;"VirusBuster": "JS.Crypt.BSP" &lt;br /&gt;
&amp;nbsp;"NOD32": "PDF/Exploit.Pidief.AUT" &lt;br /&gt;
&amp;nbsp;"F-Prot": "JS/Psyme.HU" &lt;br /&gt;
&amp;nbsp;"Symantec": "Trojan.Pidief.D" &lt;br /&gt;
&amp;nbsp;"Norman": "JS/Shellcode.GS" &lt;br /&gt;
&amp;nbsp;"TrendMicro-HouseCall": "TROJ_PIDIEF.ADY" &lt;br /&gt;
&amp;nbsp;"Avast": "JS:Pdfka-PO" &lt;br /&gt;
&amp;nbsp;"eSafe": "PDF.Exploit.2" &lt;br /&gt;
&amp;nbsp;"ClamAV": "Suspect.PDF.ObfuscatedJS-5" &lt;br /&gt;
&amp;nbsp;"Kaspersky": "Exploit.Win32.Pidief.aut" &lt;br /&gt;
&amp;nbsp;"BitDefender": "Exploit.PDF-JS.Gen" &lt;br /&gt;
&amp;nbsp;"ViRobot": "" &lt;br /&gt;
&amp;nbsp;"Sophos": "Mal/PdfEx-C" &lt;br /&gt;
&amp;nbsp;"Comodo": "TrojWare.Win32.Exploit.Pidief.aut" &lt;br /&gt;
&amp;nbsp;"F-Secure": "Exploit.PDF-JS.Gen" &lt;br /&gt;
&amp;nbsp;"DrWeb": "Exploit.PDF.166" &lt;br /&gt;
&amp;nbsp;"AntiVir": "EXP/Pidief.JX" &lt;br /&gt;
&amp;nbsp;"TrendMicro": "TROJ_PIDIEF.ADY" &lt;br /&gt;
&amp;nbsp;"Emsisoft": "Exploit.Pidief!IK" &lt;br /&gt;
&amp;nbsp;"eTrust-Vet": "PDF/Pidief.IQ" &lt;br /&gt;
&amp;nbsp;"Authentium": "PDF/Obfusc.D!Camelot" &lt;br /&gt;
&amp;nbsp;"Jiangmin": "" &lt;br /&gt;
&amp;nbsp;"Antiy-AVL": "Exploit/Win32.Pidief" &lt;br /&gt;
&amp;nbsp;"Microsoft": "Exploit:Win32/Pdfjsc.AS" &lt;br /&gt;
&amp;nbsp;"SUPERAntiSpyware": "" &lt;br /&gt;
&amp;nbsp;"Prevx": "" &lt;br /&gt;
&amp;nbsp;"GData": "Exploit.PDF-JS.Gen" &lt;br /&gt;
&amp;nbsp;"AhnLab-V3": "PDF/Shellcode" &lt;br /&gt;
&amp;nbsp;"VBA32": "" &lt;br /&gt;
&amp;nbsp;"Sunbelt": "Exploit.PDF-JS.Gen (v)" &lt;br /&gt;
&amp;nbsp;"PCTools": "Trojan.Pidief" &lt;br /&gt;
&amp;nbsp;"Rising": "" &lt;br /&gt;
&amp;nbsp;"Ikarus": "Exploit.Pidief" &lt;br /&gt;
&amp;nbsp;"Fortinet": "" &lt;br /&gt;
&amp;nbsp;"AVG": "Exploit" &lt;br /&gt;
&amp;nbsp;"Panda": "" &lt;br /&gt;
&amp;nbsp;"Avast5": "JS:Pdfka-PO" &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Detection : (31/41)&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
I'll improve and fix the code so I can share because now it's impossible . That 120 seconds that I wait is just to make sure that the scan will finish before I try to retrive the results but sometimes depending on file size it'll probably fail .&lt;br /&gt;
&lt;br /&gt;
Nice resource from VirusTotal Team , congratulations! &lt;br /&gt;
&lt;br /&gt;
Happy Hacking!&lt;br /&gt;
&lt;br /&gt;
Rodrigo "Sp0oKeR" Montoro&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-7643037535627593162?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/PvSKOKFxdkg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/7643037535627593162/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=7643037535627593162" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/7643037535627593162?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/7643037535627593162?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/PvSKOKFxdkg/virus-total-public-api.html" title="Virus Total Public API" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2010/08/virus-total-public-api.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0QFRX4_fip7ImA9Wx5SGUU.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-5784300989865935332</id><published>2010-08-16T15:59:00.001-03:00</published><updated>2010-08-16T16:01:54.046-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-08-16T16:01:54.046-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="pentest" /><category scheme="http://www.blogger.com/atom/ns#" term="pdf" /><category scheme="http://www.blogger.com/atom/ns#" term="malwares" /><title>SET (Social Engineer Toolkit) PDF’s x AntiVirus &amp; Scoring System</title><content type="html">Since Social Engineer Toolkit aka SET is being using in the wild I solved to create their pdf’s and tests against AntiVirus Vendors and against&amp;nbsp; new detection scoring based on &lt;a href="http://www.trustwave.com/spiderlabs"&gt;Spiderlabs Research&lt;/a&gt; .&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; [---]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The Social-Engineer Toolkit (SET)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [---]&lt;br /&gt;
&amp;nbsp; [---]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Written by David Kennedy (ReL1K)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [---]&lt;br /&gt;
&amp;nbsp; [---]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Version: 0.6.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [---]&lt;br /&gt;
&amp;nbsp; [---]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Codename: 'Arnold Palmer'&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [---]&lt;br /&gt;
&amp;nbsp; [---]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Report bugs to: davek@social-engineer.org&amp;nbsp;&amp;nbsp;&amp;nbsp; [---]&lt;br /&gt;
&amp;nbsp; [---]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Java Applet Written by: Thomas Werth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [---]&lt;br /&gt;
&amp;nbsp; [---]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Homepage: &lt;a href="http://www.secmaniac.com/"&gt;http://www.secmaniac.com&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [---]&lt;br /&gt;
&amp;nbsp; [---]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Framework: &lt;a href="http://www.social-engineer.org/"&gt;http://www.social-engineer.org&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; [---]&lt;br /&gt;
&amp;nbsp; [---]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;span style="color: red;"&gt;Over 1 million downloads and counting.&lt;/span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [---]&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&amp;nbsp; Welcome to the Social-Engineer Toolkit (SET). Your one&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; stop shop for all of your social-engineering needs..&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Follow me on Twitter: dave_rel1k&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DerbyCon 2011 Sep29-Oct02 - A new era begins...&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; http://www.derbycon.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Select from the menu on what you would like to do:&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: red;"&gt;1.&amp;nbsp; Spear-Phishing Attack Vectors&lt;/b&gt;&lt;br /&gt;
2.&amp;nbsp; Website Attack Vectors&lt;br /&gt;
3.&amp;nbsp; Infectious Media Generator &lt;br /&gt;
4.&amp;nbsp; Create a Payload and Listener&lt;br /&gt;
5.&amp;nbsp; Mass Mailer Attack&lt;br /&gt;
6.&amp;nbsp; Teensy USB HID Attack Vector&lt;br /&gt;
7&amp;nbsp;&amp;nbsp; Update the Metasploit Framework&lt;br /&gt;
8.&amp;nbsp; Update the Social-Engineer Toolkit&lt;br /&gt;
9.&amp;nbsp; Help, Credits, and About&lt;br /&gt;
10. Exit the Social-Engineer Toolkit&lt;br /&gt;
&lt;br /&gt;
Enter your choice: 1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="color: red;"&gt;1. Perform a Mass Email Attack&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
2. Create a FileFormat Payload&lt;br /&gt;
3. Create a Social-Engineering Template&lt;br /&gt;
4. Return to Main Menu&lt;br /&gt;
&lt;br /&gt;
Enter your choice: 1&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: red;"&gt;1. Adobe Flash Player 'newfunction' Invalid Pointer Use&lt;br /&gt;
2. Adobe Collab.collectEmailInfo Buffer Overflow&lt;br /&gt;
3. Adobe Collab.getIcon Buffer Overflow&lt;br /&gt;
4. Adobe JBIG2Decode Memory Corruption Exploit&lt;br /&gt;
5. Adobe PDF Embedded EXE Social Engineering&lt;br /&gt;
6. Adobe util.printf() Buffer Overflow&lt;/b&gt;&lt;br /&gt;
7. Custom EXE to VBA (sent via RAR) (RAR required) &lt;br /&gt;
&lt;b&gt;&lt;span style="color: red;"&gt;8. Adobe U3D CLODProgressiveMeshDeclaration Array Overrun &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Enter the number you want (press enter for default): &lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: red;"&gt;1. Windows Reverse TCP Shell&lt;/b&gt;&lt;br /&gt;
2. Windows Meterpreter Reverse_TCP&lt;br /&gt;
3. Windows Reverse VNC&lt;br /&gt;
4. Windows Reverse TCP Shell (x64) &lt;br /&gt;
5. Windows Meterpreter Reverse_TCP (X64)&lt;br /&gt;
6. Windows Shell Bind_TCP (X64)&lt;br /&gt;
&lt;br /&gt;
Enter the payload you want (press enter for default): &lt;br /&gt;
&lt;br /&gt;
* All payload 1 – Windows Reverse TCP Shell with port 2345&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;&lt;b&gt;1. Adobe Flash Player 'newfunction' Invalid Pointer Use&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.virustotal.com/file-scan/report.html?id=377ba41782bbeb25c9816d76ec190fb6f4b88c7bbaecc26653a4a6ecc479f3ea-1281835639"&gt;http://www.virustotal.com/file-scan/report.html?id=377ba41782bbeb25c9816d76ec190fb6f4b88c7bbaecc26653a4a6ecc479f3ea-1281835639&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
File name:flashplayer-newfunction.pdf&lt;br /&gt;
Submission date: 2010-08-15 01:27:19 (UTC)&lt;br /&gt;
&lt;b&gt;&lt;i&gt;Result: 15/ 42 (35.7%)&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
$ pdf-analisys.pl -s1 -f flashplayer-newfunction.pdf &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;flashplayer-newfunction.pdf Malicious PDF Detected&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;&lt;b&gt;2. Adobe Collab.collectEmailInfo Buffer Overflow&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.virustotal.com/file-scan/report.html?id=a4ac73a6efee530a05ea05eeeaa3d8efc137e4eb3bcf4d492c2b318264da2f77-1281836155"&gt;http://www.virustotal.com/file-scan/report.html?id=a4ac73a6efee530a05ea05eeeaa3d8efc137e4eb3bcf4d492c2b318264da2f77-1281836155&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
File name: collab-collectEmailInfo.pdf&lt;br /&gt;
Submission date: 2010-08-15 01:35:55 (UTC)&lt;br /&gt;
&lt;i&gt;&lt;b&gt;Result: 17/ 42 (40.5%)&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
$ pdf-analisys.pl -s1 -f collab-collectEmailInfo.pdf &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;collab-collectEmailInfo.pdf Malicious PDF Detected &lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;&lt;b&gt;3. Adobe Collab.getIcon Buffer Overflow&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.virustotal.com/file-scan/report.html?id=631893cd75bcf60ec82a3f59d3bd3f7f166874641a4ed62ceee28852889ec6e2-1281836494"&gt;http://www.virustotal.com/file-scan/report.html?id=631893cd75bcf60ec82a3f59d3bd3f7f166874641a4ed62ceee28852889ec6e2-1281836494&lt;/a&gt;&lt;br /&gt;
File name: collab-getIcon.pdf&lt;br /&gt;
Submission date: 2010-08-15 01:41:34 (UTC)&lt;br /&gt;
&lt;b&gt;&lt;i&gt;Result: 15/ 42 (35.7%)&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
pdf-analisys.pl -s1 -f collab-getIcon.pdf &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;collab-getIcon.pdf Malicious PDF Detected &lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;&lt;b&gt;4. Adobe JBIG2Decode Memory Corruption Exploit&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
http://www.virustotal.com/file-scan/report.html?id=814f20d28de287e76dbfacb14d90dbfab8e0b1e11e16212b88ca3216f2189117-1281836756&lt;br /&gt;
&lt;br /&gt;
File name: JBIG2Decode.pdf&lt;br /&gt;
Submission date: 2010-08-15 01:45:56 (UTC)&lt;br /&gt;
&lt;i&gt;&lt;b&gt;Result: 15/ 42 (35.7%)&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
$ pdf-analisys.pl -s1 -f JBIG2Decode.pdf &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;JBIG2Decode.pdf Malicious PDF Detected &lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;&lt;b&gt;5. Adobe PDF Embedded EXE Social Engineering&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.virustotal.com/file-scan/report.html?id=484ba7800fd549b82b6ac4dab5100f3017a0995cc47be13977703a168d1bcef3-1281837936"&gt;http://www.virustotal.com/file-scan/report.html?id=484ba7800fd549b82b6ac4dab5100f3017a0995cc47be13977703a168d1bcef3-1281837936&lt;/a&gt;&lt;br /&gt;
File name: embeddedfile.pdf&lt;br /&gt;
Submission date: 2010-08-15 02:05:36 (UTC)&lt;br /&gt;
&lt;i&gt;&lt;b&gt;Result: 15/ 41 (36.6%)&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
$ pdf-analisys.pl -s1 -f embeddedfile.pdf &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;embeddedfile.pdf Malicious PDF Detected &lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;&lt;b&gt;6. Adobe util.printf() Buffer Overflow&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.virustotal.com/file-scan/report.html?id=99e01802391f77c5c93cdf52cb2eacb5673e6acf7ac90776d477948a7fa1222d-1281838414"&gt;http://www.virustotal.com/file-scan/report.html?id=99e01802391f77c5c93cdf52cb2eacb5673e6acf7ac90776d477948a7fa1222d-1281838414&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
File name: utilprintf.pdf&lt;br /&gt;
Submission date: 2010-08-15 02:13:34 (UTC)&lt;br /&gt;
&lt;i&gt;&lt;b&gt;Result: 16/ 42 (38.1%)&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
$ pdf-analisys.pl -s1 -f utilprintf.pdf &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;utilprintf.pdf Malicious PDF Detected &lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
8. Adobe U3D CLODProgressiveMeshDeclaration Array Overrun &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.virustotal.com/file-scan/report.html?id=0ce18c65373f113916b108508b3afc481e460f77353d1e3ddd259dbd29bab5a1-1281838713"&gt;http://www.virustotal.com/file-scan/report.html?id=0ce18c65373f113916b108508b3afc481e460f77353d1e3ddd259dbd29bab5a1-1281838713&lt;/a&gt;&lt;br /&gt;
File name: U3D.pdf&lt;br /&gt;
Submission date: 2010-08-15 02:18:33 (UTC)&lt;br /&gt;
&lt;i&gt;&lt;b&gt;Result: 11/ 42 (26.2%)&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
pdf-analisys.pl -s1 -f U3D.pdf &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;U3D.pdf Malicious PDF Detected &lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;&lt;b&gt;Clamav Results&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
collab-collectEmailInfo.pdf: OK&lt;br /&gt;
collab-getIcon.pdf: OK&lt;br /&gt;
embeddedfile.pdf: Exploit.PDF-22612 FOUND&lt;br /&gt;
flashplayer-newfunction.pdf: OK&lt;br /&gt;
JBIG2Decode.pdf: OK&lt;br /&gt;
U3D.pdf: OK&lt;br /&gt;
utilprintf.pdf: OK&lt;br /&gt;
&lt;br /&gt;
----------- SCAN SUMMARY -----------&lt;br /&gt;
Known viruses: 813894&lt;br /&gt;
Engine version: 0.96.1&lt;br /&gt;
&lt;span style="color: red;"&gt;Scanned files: 7&lt;/span&gt;&lt;br /&gt;
&lt;span style="color: red;"&gt;Infected files: 1&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
* Clamav just updated to new engine 0.96.2 that detected all 7 samples as malicious so UPDATE your engine ASAP .&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;&lt;b&gt;Virus Total Results&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
Result: 15/ 42 (35.7%)&lt;br /&gt;
Result: 17/ 42 (40.5%)&lt;br /&gt;
Result: 15/ 42 (35.7%)&lt;br /&gt;
Result: 15/ 42 (35.7%)&lt;br /&gt;
Result: 15/ 41 (36.6%)&lt;br /&gt;
Result: 16/ 42 (38.1%)&lt;br /&gt;
Result: 11/ 42 (26.2%)&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: red;"&gt;Average Detection: 14,85 / 42 or 35,37%&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;&lt;b&gt;Top5* AntiVirus Results&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_W4YrpOrtnEQ/TGmKFXUeYAI/AAAAAAAAHp8/3WlL9-WD07I/s1600/av-results-set.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="150" src="http://3.bp.blogspot.com/_W4YrpOrtnEQ/TGmKFXUeYAI/AAAAAAAAHp8/3WlL9-WD07I/s400/av-results-set.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;* Top5 antivirus based on most common names not in detection rates&lt;br /&gt;
&lt;br /&gt;
** Payloads listed bellow:&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;1. Adobe Flash Player 'newfunction' Invalid Pointer Use&lt;br /&gt;
2. Adobe Collab.collectEmailInfo Buffer Overflow&lt;br /&gt;
3. Adobe Collab.getIcon Buffer Overflow&lt;br /&gt;
4. Adobe JBIG2Decode Memory Corruption Exploit&lt;br /&gt;
5. Adobe PDF Embedded EXE Social Engineering&lt;br /&gt;
6. Adobe util.printf() Buffer Overflow&lt;br /&gt;
8. Adobe U3D CLODProgressiveMeshDeclaration Array Overrun &lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;&lt;b&gt;Scoring System Results&amp;nbsp;&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
collab-collectEmailInfo.pdf &lt;b&gt;Malicious PDF Detected&lt;/b&gt;&lt;br /&gt;
collab-getIcon.pdf &lt;b&gt;Malicious PDF Detected&lt;/b&gt; &lt;br /&gt;
embeddedfile.pdf &lt;b&gt;Malicious PDF Detected&lt;/b&gt; &lt;br /&gt;
flashplayer-newfunction.pdf &lt;b&gt;Malicious PDF Detected&lt;/b&gt; &lt;br /&gt;
JBIG2Decode.pdf &lt;b&gt;Malicious PDF Detected&lt;/b&gt; &lt;br /&gt;
U3D.pdf Malicious &lt;b&gt;PDF Detected &lt;/b&gt;&lt;br /&gt;
utilprintf.pdf Malicious &lt;b&gt;PDF Detected&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We sent some papers to a couple of conferences to star to share those information . I’ll let you know if we get approve and where =) .&lt;br /&gt;
&lt;br /&gt;
Let’s keep improving our research and sharing each time more and more information. In the future we’ll share all the information , scoring and parser .&lt;br /&gt;
&lt;br /&gt;
Regards,&lt;br /&gt;
&lt;br /&gt;
Rodrigo "Sp0oKeR" Montoro&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-5784300989865935332?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/CX6kMORcLHs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/5784300989865935332/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=5784300989865935332" title="3 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/5784300989865935332?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/5784300989865935332?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/CX6kMORcLHs/set-social-engineer-toolkit-pdfs-x.html" title="SET (Social Engineer Toolkit) PDF’s x AntiVirus &amp; Scoring System" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_W4YrpOrtnEQ/TGmKFXUeYAI/AAAAAAAAHp8/3WlL9-WD07I/s72-c/av-results-set.png" height="72" width="72" /><thr:total>3</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2010/08/set-social-engineer-toolkit-pdfs-x.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEIMSXs6eyp7ImA9Wx5TGUU.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-8601775190467669396</id><published>2010-08-05T02:30:00.003-03:00</published><updated>2010-08-05T02:36:28.513-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-08-05T02:36:28.513-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="blackhat" /><title>Pic from Vegas/Blackhat/Caesar</title><content type="html">Only picture with part of Brazilian friends in Vegas in front of Caesars after Blackhat 2010&lt;br /&gt;
&lt;br /&gt;
&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_W4YrpOrtnEQ/TFpLt_7NgHI/AAAAAAAAHfM/pMrbpM_gpBQ/s1600/brasil-bh.JPG" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="424" src="http://1.bp.blogspot.com/_W4YrpOrtnEQ/TFpLt_7NgHI/AAAAAAAAHfM/pMrbpM_gpBQ/s640/brasil-bh.JPG" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;Mab ,&amp;nbsp; Rodrigo , Wendel , Bruno and Fio&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;
Nice Blackhat staff shirt no ? =D&lt;br /&gt;
&lt;br /&gt;
I'll write a post about Blackhat/Defcon/Spiderlabs meeting during this week yet =)&lt;br /&gt;
&lt;br /&gt;
Regards,&lt;br /&gt;
&lt;br /&gt;
Rodrigo Montoro (Sp0oKeR)&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-8601775190467669396?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/NE8nEMJ88-k" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/8601775190467669396/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=8601775190467669396" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/8601775190467669396?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/8601775190467669396?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/NE8nEMJ88-k/pic-from-vegasblackhatcaesar.html" title="Pic from Vegas/Blackhat/Caesar" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_W4YrpOrtnEQ/TFpLt_7NgHI/AAAAAAAAHfM/pMrbpM_gpBQ/s72-c/brasil-bh.JPG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2010/08/pic-from-vegasblackhatcaesar.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CE4EQHo4eyp7ImA9Wx5TGUk.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-8417382320356696128</id><published>2010-08-04T14:27:00.001-03:00</published><updated>2010-08-04T14:28:21.433-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-08-04T14:28:21.433-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="razorback" /><category scheme="http://www.blogger.com/atom/ns#" term="snort" /><category scheme="http://www.blogger.com/atom/ns#" term="nrt" /><title>RazorBack - New Sourcefire VRT Project</title><content type="html">VRT guys just released at Defcon 18 version 0.1 for RazorBack . The project is REALLY interesting and it's targeting client-side attack mostly since that's currently where most attacks are .&lt;br /&gt;
&lt;br /&gt;
What is RazorBack ?&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Project Razorback™&lt;/b&gt; is an undertaking by the Sourcefire VRT. &lt;br /&gt;
&lt;div class="indent1"&gt;Razorback is a framework for an intelligence driven security solution.  It consists of a Dispatcher at the core of the system, surrounded by  Nuggets of varying types. &lt;/div&gt;&lt;br /&gt;
The project page could be found here : &lt;a href="http://labs.snort.org/razorback/"&gt;http://labs.snort.org/razorback/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
There you will find the slides, papers,&amp;nbsp; 0.1 files version. Besides that they created a new channel at irc.freenode.net #razorback .&lt;br /&gt;
&lt;br /&gt;
I'll try to do lot of test in next week and post about those here .&lt;br /&gt;
&lt;br /&gt;
For sure this project will grow a lot quickly and kickass in the future . Get involved . I'll for sure .&lt;br /&gt;
&lt;br /&gt;
Happy Snorting!&lt;br /&gt;
&lt;br /&gt;
Rodrigo Montoro (Sp0oKeR)&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-8417382320356696128?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/G2xHx4j1h6E" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/8417382320356696128/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=8417382320356696128" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/8417382320356696128?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/8417382320356696128?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/G2xHx4j1h6E/razorback-new-sourcefire-vrt-project.html" title="RazorBack - New Sourcefire VRT Project" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2010/08/razorback-new-sourcefire-vrt-project.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkEBSX89eSp7ImA9Wx5TEks.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-6549743459031725766</id><published>2010-07-27T18:04:00.000-03:00</published><updated>2010-07-27T18:04:18.161-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-07-27T18:04:18.161-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="snort" /><title>Snort 2.9.0 Beta Available</title><content type="html">Awesome new features coming with snort 2.9.0 . I'll do lot of tests after Blackhat/Defcon .&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
A beta version of Snort 2.9.0 is now available on &lt;a href="http://snort.org/" target="_blank"&gt;snort.org&lt;/a&gt;, at&lt;br /&gt;
&lt;a href="http://www.snort.org/snort-downloads/" target="_blank"&gt;http://www.snort.org/snort-&lt;wbr&gt;&lt;/wbr&gt;downloads/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Snort 2.9.0 introduces:&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; * Feature rich IPS mode including improvements to Stream for&lt;br /&gt;
&amp;nbsp; &amp;nbsp; inline deployments. &amp;nbsp;Additionally a common active response API is&lt;br /&gt;
&amp;nbsp; &amp;nbsp; used for all packet responses, including those from Stream,&lt;br /&gt;
&amp;nbsp; &amp;nbsp; Respond, or React. &amp;nbsp;A new response module, respond3, supports the&lt;br /&gt;
&amp;nbsp; &amp;nbsp; syntax of both resp &amp;amp; resp2, including strafing for passive&lt;br /&gt;
&amp;nbsp; &amp;nbsp; deployments. &amp;nbsp;When Snort is deployed inline, a new preprocessor&lt;br /&gt;
&amp;nbsp; &amp;nbsp; has been added to handle packet normalization to allow Snort&lt;br /&gt;
&amp;nbsp; &amp;nbsp; to interpret a packet the same way as the receiving host.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; * Use of a Data Acquisition API (DAQ) that supports many different&lt;br /&gt;
&amp;nbsp; &amp;nbsp; packet access methods including libpcap, netfilterq, IPFW, and&lt;br /&gt;
&amp;nbsp; &amp;nbsp; afpacket. &amp;nbsp;For libpcap, version 1.0 or higher is now required.&lt;br /&gt;
&amp;nbsp; &amp;nbsp; The DAQ library can be updated independently from Snort and is&lt;br /&gt;
&amp;nbsp; &amp;nbsp; a separate module that Snort links. &amp;nbsp;See README.daq for details&lt;br /&gt;
&amp;nbsp; &amp;nbsp; on using Snort and the new DAQ.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; * Updates to HTTP Inspect to extract and log IP addresses from&lt;br /&gt;
&amp;nbsp; &amp;nbsp; X-Forward-For and True-Client-IP header fields when Snort generates&lt;br /&gt;
&amp;nbsp; &amp;nbsp; events on HTTP traffic.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; * A new rule option 'byte_extract' that allows extracted values to&lt;br /&gt;
&amp;nbsp; &amp;nbsp; be used in subsequent rule options for isdataat, byte_test,&lt;br /&gt;
&amp;nbsp; &amp;nbsp; byte_jump, and content distance/within/depth/offset.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; * Updates to SMTP preprocessor to support MIME attachment decoding&lt;br /&gt;
&amp;nbsp; &amp;nbsp; across multiple packets.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; * Ability to "test" drop rules using Inline Test Mode. &amp;nbsp;Snort will&lt;br /&gt;
&amp;nbsp; &amp;nbsp; indicate a packet would have been dropped in the unified2 or&lt;br /&gt;
&amp;nbsp; &amp;nbsp; console event log if policy mode was set to inline.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; * Two new rule options to support base64 decoding of certain pieces&lt;br /&gt;
&amp;nbsp; &amp;nbsp; of data and inspection of the base64 data via subsequent rule&lt;br /&gt;
&amp;nbsp; &amp;nbsp; options.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; * Updates to the Snort packet decoders for IPv6 for improvements to&lt;br /&gt;
&amp;nbsp; &amp;nbsp; anomaly detection.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; * Added a new pattern matcher that supports Intel's Quick Assist&lt;br /&gt;
&amp;nbsp; &amp;nbsp; Technology for improved performance on supported hardware&lt;br /&gt;
&amp;nbsp; &amp;nbsp; platforms. &amp;nbsp;Visit &lt;a href="http://www.intel.com/" target="_blank"&gt;http://www.intel.com&lt;/a&gt; to find out more about&lt;br /&gt;
&amp;nbsp; &amp;nbsp; Intel Quick Assist. &amp;nbsp;The following document describes Snort's&lt;br /&gt;
&amp;nbsp; &amp;nbsp; integration with the Quick Assist Technology&lt;br /&gt;
&lt;a href="http://download.intel.com/embedded/applications/networksecurity/324029.pdf" target="_blank"&gt;http://download.intel.com/&lt;wbr&gt;&lt;/wbr&gt;embedded/applications/&lt;wbr&gt;&lt;/wbr&gt;networksecurity/324029.pdf&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; * Reference applications for reading unified2 output that handle&lt;br /&gt;
&amp;nbsp; &amp;nbsp; all unified2 record formats used by Snort.&lt;br /&gt;
&lt;br /&gt;
Please see the Release Notes and ChangeLog for more details.&lt;br /&gt;
&lt;br /&gt;
Please submit bugs, questions, and feedback to &lt;a href="mailto:snort-beta@sourcefire.com"&gt;snort-beta@sourcefire.com&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Happy Snorting!&lt;br /&gt;
The Snort Release Team&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-6549743459031725766?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/HSNnKrmB4ys" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/6549743459031725766/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=6549743459031725766" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/6549743459031725766?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/6549743459031725766?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/HSNnKrmB4ys/snort-290-beta-available.html" title="Snort 2.9.0 Beta Available" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2010/07/snort-290-beta-available.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0ACR34yfyp7ImA9WxFaGEU.&quot;"><id>tag:blogger.com,1999:blog-920941880988420853.post-232727538498352243</id><published>2010-07-23T07:42:00.000-03:00</published><updated>2010-07-23T07:42:46.097-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-07-23T07:42:46.097-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="pdf" /><category scheme="http://www.blogger.com/atom/ns#" term="malwares" /><title>Updates/New Features at ViCheck and VirusTotal</title><content type="html">&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;This week those nice online tools made great enhancements specially &lt;a href="http://www.vicheck.ca/"&gt;ViCheck&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;b&gt;From ViCheck Blog: &lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;h3 class="post-title entry-title" style="font-weight: normal;"&gt; &lt;span style="font-size: small;"&gt;Report  page enhancements and Email Report&amp;nbsp;&lt;/span&gt; &lt;/h3&gt;&lt;div class="post-header"&gt;  &lt;/div&gt;&lt;span style="font-size: small;"&gt; For recently processed documents such as PDF or MS Office (engine  &amp;gt;=193) we are now highlighting more information about the embedded  executable such as the encryption/cipher method and information about  the key.&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;To read and see samples about those:&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;a href="http://vicheck.blogspot.com/2010/07/email-report-enhancements.html"&gt;&lt;span style="font-size: small;"&gt;http://vicheck.blogspot.com/2010/07/email-report-enhancements.html&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;a href="http://vicheck.blogspot.com/2010/07/report-page-enhancements.html"&gt;http://vicheck.blogspot.com/2010/07/report-page-enhancements.html&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;b&gt;&lt;span style="font-size: small;"&gt;From Virus Total Blog:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-size: small;"&gt;They added new engine from SUPERAntiSpyware ( &lt;a href="http://www.superantispyware.com/"&gt;http://www.superantispyware.com/&lt;/a&gt; ) what I help to improve the AV detection rates. Hope it's something not too static only . I really never heard about this engine before .&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt; &lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;To read about this: &lt;a href="http://blog.hispasec.com/virustotal/49"&gt;http://blog.hispasec.com/virustotal/49&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&amp;nbsp;Happy Hacking!&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: small;"&gt;Rodrigo Montoro (Sp0oKeR)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;Sp0oKeR Labs&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/920941880988420853-232727538498352243?l=spookerlabs.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Sp0okerLabs/~4/HrxxULloZCI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://spookerlabs.blogspot.com/feeds/232727538498352243/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=920941880988420853&amp;postID=232727538498352243" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/232727538498352243?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/920941880988420853/posts/default/232727538498352243?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Sp0okerLabs/~3/HrxxULloZCI/updatesnew-features-at-vicheck-and.html" title="Updates/New Features at ViCheck and VirusTotal" /><author><name>Rodrigo "Sp0oKeR" Montoro</name><uri>http://www.blogger.com/profile/14384077948639226635</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://spookerlabs.blogspot.com/2010/07/updatesnew-features-at-vicheck-and.html</feedburner:origLink></entry></feed>

