Twitter
RSS

Posts Tagged ‘adobe’


Security Updates Available for Adobe Reader and Acrobat

Original release date: May 16, 2013 Adobe has released security updates for Adobe Reader and Acrobat to address multiple vulnerabilities. These vulnerabilities could cause a crash and potentially allow an attacker to take control of an affected system

Read More...

ISC StormCast for Thursday, May 16th 2013 http://isc.sans.edu/podcastdetail.html?id=3311, (Thu, May 16th)

(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Read More...

FortiGate Cookbook – IPsec VPN

In this video, you’re going to learn how to configure a secure IPsec VPN connection between two locations. With a FortiGate at each location, properly config…

Read More...

App Security Wins Move at Snail’s Pace

Of 200 enterprise security professionals recently surveyed by Enterprise Strategy Group, 79 percent report Web application security attacks in the past year. In a late April Network World blog on the topic, Jon Oltsik, a principal analyst at ESG, said the study also found thieves attacked Web application features and functions such as application authentication, configuration management, application authorization and session management

Read More...

ISC StormCast for Tuesday, May 14th 2013 http://isc.sans.edu/podcastdetail.html?id=3305, (Tue, May 14th)

(c) SANS Internet Storm Center.

Read More...

So what passwords are those ssh scanners trying?, (Tue, May 14th)

If you run an ssh server (especially if you still run it on the default port), you've no doubt had plenty of folks scan your machine and do password guessing attacks against it.  BTW, you'll never get in mine that way, I only allow public/private key authentication, but that is beside the point here.  I've done a couple of other reports analyzing passwords, and I really like pipal by Robin Wood for much of the analysis (you can grab it from here ).  I've been running a kippo ssh honeypot for the day job for about 2 years and I've done a couple of reports on the password guesses for the ThreatTraq webcast, but then I discovered that in addition to firewall logs and the 404 logs, we also collect kippo logs here at the SANS Internet Storm Center.  Ooh, more data!!  If you'd like contribute, please grab https://isc.sans.edu/kipposcript.pl .  So, without further ado, here is what I've found in our kippo data (as of about 15 April 2013).  I should note here, though, that these are the guesses the bad guys are making.  They've developed their lists most likely based on what has worked for someone at some point, so they will be somewhat different from what you find in analyzing passwords from breaches like my analysis of last year's Yahoo breach .

Read More...

ISC StormCast for Monday, May 13th 2013 http://isc.sans.edu/podcastdetail.html?id=3302, (Mon, May 13th)

(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Read More...

Extracting Digital Signatures from Signed Malware, (Sat, May 11th)

Sometimes attackers digitally sign their malicious software. Examining properties of the signature helps malware analysts understand the context of the incident.

Read More...

Microsoft and Adobe Patch Tuesday Pre-Release, (Fri, May 10th)

Both Adobe and Microsoft released pre-anouncements for next week's patch Tuesday.

Read More...

Adobe Releases 0-day Security Advisory for Coldfusion, Exploit Code Available. Advisory here:…

— John Bambenek bambenek at gmail /dot/ com Bambenek Consulting (c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Read More...