Archive for May, 2006

The MS Word 0-day Snort RuleSet

Posted: May 27, 2006 in Security

Though an IPS / IDS shouldnt be the one filtering this, an AV is the one who should be able to detect the potentially harmfull files (since that is what they are designed to do) but untill the AV vendors release there updated virus definitions, there had to be some workaround for the increasing automated [...]

The MS-Word Zero Day

Posted: May 23, 2006 in Reverse Engineering

Dang! went my snort with an alert. Oh these false positives can be so confusing at times; i thought, i had just re-configured my snort rules, and reformatted my laptop last week. "wat could be wrong" i thought. Hesitating (due to my laziness) i fired up Process View, TCPView and ethereal to monitor my traffic [...]

My Desktop Screenshot

Posted: May 16, 2006 in My Grafix

Yahoo Widgets + GoogleDesktop. A larger version can be found here.

Detecting Virtualization

Posted: May 14, 2006 in Virtualisation

From time to time it is handy to be able to detect whether your binary / script / program / software is running under a virtual machine and / or a similar controlled environment. For example: You have a network of nodes where you want your binary to run but you want it to behave [...]