...
banner
Search
in:
Our Books
banner
Got Root >
3D browser print

Virtual Patch for Hidden Text Exploit
By: Michael Shinn  on: Thu 24 of Apr, 2008 [22:00 UTC]  (540 reads)

SANS ISCexternal link (cache) brings us a reportexternal link (cache) of a new method spammers are using to put links into blogs using hidden text. We don't consider this a WordPress vuln, but rather a class of problems revolving around hidden test. This is very reminiscent of the iframe attacks using hidden iframes. In the spirit of making the world a nicer place, we're publishing Modsec rules to protect against this problem. You can download the rules from here. Right now its one rule, but as we discover other ways to protect against this we'll update the file. If you are running ASL or have a subscription to the real time rules, this is included in the latest update automatically.

Free Modsecurity 2.5 rules released
By: Michael Shinn  on: Tue 18 of Mar, 2008 [15:28 UTC]  (474 reads)

We've been providing 2.5 signatures and rules to our ASL customers for over a year, and are proud to announce the availability of these rules through the GotRoot? lab website. The free rules are delayed 30 days. Want the rules in real time? Well sign up now!external link Its only $79.95 a year for a real time subscription to the most comprehensive and widely used WAF rules on the Internet!

ASL 2.0 final beta out
By: Michael Shinn  on: Tue 05 of Feb, 2008 [00:18 UTC]  (926 reads)
Software Release

We've been been working like mad men on ASL (especially Scott), and we're at the final Beta. 2.0 final is just around the corner. The GUI is slick, tons of new security features, vulnerability scanner, built in support portal and more. Check it out on the ASL websiteexternal link.

Site move complete
By: Michael Shinn  on: Mon 04 of Feb, 2008 [23:47 UTC]  (619 reads)

For anyone that had problems logging into their accounts, I do apologize for the delay fixing the site. The problem was very very very convulted. Ah the joys of moving boxes, upgrading PHP, MYSQL and Javascript. Logins should be working again for everyone.

Virtual Patching talk at SANS CDI
By: Michael Shinn  on: Wed 12 of Dec, 2007 [22:58 UTC]  (758 reads)

Ryan Barnett and I will be giving a talk on Virtual Patching at SANS CDI 2007. Our talk is on December 14th, from 7:30PM to 8:30PM. Drop by and join us, and after please join us for beers and friendly banter.

Heres a link to the official SANS CDI page:

https://www2.sans.org/cdi07/night.php?portal=821dc21b4842373211f7acb46edf6b96external link

Virtual Patching article with SANS
By: Michael Shinn  on: Wed 12 of Dec, 2007 [22:48 UTC]  (808 reads)

I recently put together a tips and advice article for Virtual Patching for SANSexternal link (cache). You can read it here Virtual Patching for Web Applications with ModSecurityexternal link (cache). Technical Review of the article was by Ryan Barnett and GIAC Advisory Board, which I greatly appreciate.

Filter out iframe attacks
By: Michael Shinn  on: Sun 02 of Sep, 2007 [23:44 UTC]  (3922 reads)
Security Tool

iframe attacks seem to be taking a hold with many vulnerable websites. The problem obviously being vulnerable ap plications, which we would all like to see fixed. However, not everyone can be so lucky as to have either perfect applications, or perfect countermeasures against these vulnerabilities. Enter output filtering. We've put together a special set of rules for anyone running apache. This will filter out all your iframe attacks.

Read More (635 bytes) no comments Print
Modsecurity 2.0 compatible rules released
By: Michael Shinn  on: Sun 22 of Oct, 2006 [19:45 UTC]  (2585 reads)

2.0 compatible rules were released today. Consider these beta quality rules until further testing is done. Also, the format of the rules has changed considerably in 2.0, so if you want production quality we recommend you use the 1.9 rules with modsecurity 1.9.4.

Incoming calls problems with Broadvoice and Asterisk
How to fix it
By: Michael Shinn  on: Thu 29 of Jun, 2006 [22:14 UTC]  (5121 reads)

Asterisk users of broadvoice may have noticed a problem with not recieving inbound calls today. It appears that something changed in the way Broadvoice sends their SIP packets, but we have the solution: Just make the following change to your extensions.conf file:

Look for the extensions.conf context for your incoming calls, in our case, its [from-broadvoice], and add this line at the end of your context:

exten => YOURPHONENUMBER,1,Goto(from-broadvoice,1,1)

Make sure you change the "from-broadvoice" to the name of your incoming calls context.

Flaw in Microsoft AntiSpyware Beta 1
By: Casey Priester  on: Wed 25 of Jan, 2006 [22:03 UTC]  ( reads)
Spyware

The current version of Microsoft AntiSpyware? Beta 1 (version 1.0.701) contains a bug which causes issues for multiple users of a Windows XP system.

Symptoms of the issue are: 1) When a user logs in, they recieve an "Unexpected Error; quitting" messagebox. 2) When uninstalling or installing MSAS, the user recieves an "Error 1904.Module C:\Program Files\Microsoft Antispyware\XXXXXXXX.dll failed to (un)register. HRESULT -2147220473" on multiple dlls, even when they are an Administrator.

The issue arises from improper registry key permissions.

We have come up with a non-optimal workaround for the issue (click Read More...), and we are currently working on a more advanced solution.

We have not tested MSAS for the issue on other systems at this time.

Read More (13976 bytes) 3 comments Print
New signatures for Google Hacks and Search engine recons, probes and attacks
By: Michael Shinn  on: Sat 03 of Dec, 2005 [02:26 UTC]  ( reads)

I've added a new ruleset to the collection, "recons.conf" that contains the start of a ruleset to detect and block attacks that originate from, so called, "Google Hacks" - or the art of detecting vulnerable software by simply searching for it with Google. These rules only work with modsecurity 1.9.x and up, as I'm also starting the process of adding ids, revs, severity and msg variables to the rules, so if you are using modsecurity 1.8.x, these rules will not work for you - and may not even load.







Latest Rules (supports modsec 2.5!)

Apache 2.x rules: (gzip)external link
Apache 1.x rules: (modsecurity 2.5 does not support apache 1.x)

Sign up for subscriptionexternal link


Free Rules (Delayed 30 days)

All in one downloads for modsec 2.5
Apache 2.x rules: (gzip)external link
Apache 1.x rules: (modsecurity 2.5 does not support apache 1.x)

All in one downloads for modsec 2.0-2.1

All in one downloads for modsec 1.9


Individual Ruleset downloads for modsec 2.5 (Delayed 30 days)


Individual Ruleset downloads for modsec 2.x


Individual Ruleset downloads for modsec 1.9





Mikes Corner



The Fire Monkey

DateTitleAuthor
19/Nov/2004 02:13Dealing With Phishingfmonkey
10/Nov/2004 10:49I Want Better Bookmarksfmonkey
21/Sep/2004 03:18Cisco's VoIP Securityfmonkey
16/Sep/2004 04:38Choosing A Secure Passwordfmonkey


Steves Wacky Programming

DateTitleAuthor
10/Oct/2004 02:25Compiled Fungesteve
20/Sep/2004 06:033d programming...can it be a Good Thing(TM)?steve

Created by: mshinn19288 points  last modification: Tuesday 22 of April, 2008 [14:14:52 UTC] by mshinn19288 points 

The content on this page is licensed under the terms of the Got Root License.


RSS Wiki RSS Blogs rss Articles RSS Forums
Powered by Tikiwiki CMS/Groupware