Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: Diaries by Keyword - SANS Internet Storm Center Diaries by Keyword


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Date Author Title

DOS SAMBA INFORMATION DISCLOSURE

2009-10-04Guy BruneauSamba Security Information Disclosure and DoS

DOS

2019-08-14/a>Brad DuncanRecent example of MedusaHTTP malware
2018-12-29/a>Didier StevensVideo: De-DOSfuscation Example
2018-12-15/a>Didier StevensDe-DOSfuscation Example
2018-12-12/a>Didier StevensYet Another DOSfuscation Sample
2018-09-30/a>Didier StevensWhen DOSfuscation Helps...
2018-07-30/a>Didier StevensMalicious Word documents using DOSfuscation
2017-11-25/a>Guy BruneauExim Remote Code Exploit
2017-10-20/a>Rick WannerOne year Anniversary of Dyn DDOS
2017-07-30/a>Renato MarinhoSMBLoris - the new SMB flaw
2017-07-07/a>Renato MarinhoDDoS Extortion E-mail: Yet Another Bluff?
2016-12-29/a>Rick WannerMore on Protocol 47 denys
2016-12-19/a>John BambenekUPDATED x1: Mirai Scanning for Port 6789 Looking for New Victims / Now hitting tcp/23231
2016-12-09/a>Rick WannerMirai - now with DGA
2016-10-22/a>Guy BruneauRequest for Packets TCP 4786 - CVE-2016-6385
2016-05-29/a>Guy BruneauAnalysis of a Distributed Denial of Service (DDoS)
2016-02-07/a>Rick WannerDDOS is down, but still a concern for ISPs
2015-06-23/a>Kevin ShorttXOR DDOS Mitigation and Analysis
2015-02-27/a>Rick WannerDDOS are way down? Why?
2015-02-19/a>Daniel WesemannDNS-based DDoS
2014-09-16/a>Mark HofmanFreeBSD Denial of Service advisory (CVE-2004-0230)
2014-08-31/a>Rick Wanner1900/UDP (SSDP) Scanning and DDOS
2014-08-25/a>Jim ClausingUDP port 1900 DDoS traffic
2014-08-17/a>Rick WannerPart 1: Is your home network unwittingly contributing to NTP DDOS attacks?
2014-08-17/a>Rick WannerPart 2: Is your home network unwittingly contributing to NTP DDOS attacks?
2014-06-24/a>Kevin ShorttNTP DDoS Counts Have Dropped
2014-06-02/a>Rick WannerUsing nmap to scan for DDOS reflectors
2014-04-30/a>Russ McReeUltraDNS DDOS
2014-03-12/a>Johannes UllrichWordpress "Pingback" DDoS Attacks
2014-02-17/a>Chris MohanNTP reflection attacks continue
2013-11-22/a>Rick WannerPort 0 DDOS
2013-10-24/a>Johannes UllrichAre you a small business that experienced a DoS attack?
2013-10-08/a>Johannes UllrichCSAM: ANY queries used in reflective DoS attack
2013-07-27/a>Scott FendleyDefending Against Web Server Denial of Service Attacks
2013-06-05/a>Richard PorterBIND 9 Update fixing CVE-2013-3919
2013-04-21/a>John BambenekA Chargen-based DDoS? Chargen is still a thing?
2013-03-28/a>John BambenekWhere Were You During the Great DDoS Cybergeddon of 2013?
2013-03-27/a>Rob VandenBrinkSeveral Cisco IOS DOS Issues Resolved
2013-03-18/a>Kevin ShorttSpamhaus DDOS
2012-09-20/a>Russ McReeFinancial sector advisory: attacks and threats against financial institutions
2012-08-15/a>Guy BruneauCisco IOS XR Software Route Processor DoS Vulnerability - http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120530-iosxr
2012-05-21/a>Kevin ShorttDNS ANY Request Cannon - Need More Packets
2012-03-30/a>Daniel WesemannTomorrow, the world will end
2012-03-16/a>Russ McReeMS12-020 RDP vulnerabilities: Patch, Mitigate, Detect
2012-01-22/a>Johannes UllrichJavascript DDoS Tool Analysis
2011-12-28/a>Daniel WesemannHash collisions vulnerability in web servers
2011-08-30/a>Johannes UllrichApache patch out for "byte range" DoS vulnerability http://www.apache.org/dist/httpd/Announcement2.2.html
2011-08-25/a>Kevin ShorttRevival of an Unpatched Apache HTTPD DoS
2011-05-20/a>Guy BruneauDistributed Denial of Service Cheat Sheet
2011-04-05/a>Mark HofmanSony DDOS
2011-04-05/a>Mark HofmanDNS.be DDOS
2011-03-04/a>Mark HofmanDDOS, the new black?
2011-02-12/a>Kevin ListonDDoS Analysis Process
2011-01-29/a>Mark HofmanSourceforge attack
2011-01-27/a>Guy BruneauISC DHCP DHCPv6 Vulnerability
2010-12-22/a>John BambenekIIS 7.5 0-Day DoS (processing FTP requests)
2010-12-09/a>Mark HofmanHaving a look at the DDOS tool used in the attacks today
2010-12-08/a>Rob VandenBrinkInteresting DDOS activity around Wikileaks
2010-09-14/a>Adrien de BeaupreBlackEnergy DDoS
2010-08-16/a>Raul SilesDDOS: State of the Art
2010-08-13/a>Guy BruneauCisco IOS Software 15.1(2)T TCP DoS
2010-08-07/a>Stephen HallDnsMadeEasy under a "quite large and unique" ddos.
2010-08-04/a>Adrien de BeaupreMultiple Cisco Advisories
2010-05-08/a>Guy BruneauWireshark DOCSIS Dissector DoS Vulnerability
2010-02-02/a>Johannes UllrichPushdo Update
2010-01-19/a>Jim Clausing49Gbps DDoS, IPv4 exhaustion, and DNSSEC, oh my!
2010-01-06/a>Johannes UllrichDenial of Service Attack Aftermath (and what did Iran have to do with it?)
2009-12-30/a>Guy BruneauKDC DoS in cross-realm referral processing
2009-12-24/a>Guy BruneauF5 BIG-IP ASM and PSM Remote Buffer Overflow
2009-12-09/a>Swa Frantzenntpd upgrade to prevent spoofed looping
2009-10-04/a>Guy BruneauSamba Security Information Disclosure and DoS
2009-09-09/a>Mark HofmanPossible DDOS on gov.au sites starting tonight?
2009-09-08/a>Guy BruneauCisco Security Advisory TCP DoS
2009-08-08/a>Guy BruneauXML Libraries Data Parsing Vulnerabilities
2009-07-29/a>Bojan ZdrnjaBIND 9 DoS attacks in the wild
2009-07-09/a>John BambenekLatest Updates on Ongoing DDoS on Governmental/Commercial Websites in USA and S. Korea
2009-07-08/a>Marcus SachsRFI: DDoS Against Government and Civilian Web Sites
2009-06-23/a>Bojan ZdrnjaSlowloris and Iranian DDoS attacks
2009-06-21/a>Bojan ZdrnjaApache HTTP DoS tool mitigation
2009-06-18/a>Bojan ZdrnjaApache HTTP DoS tool released
2009-03-08/a>Marcus SachsBehind the Estonia Cyber Attacks
2009-01-31/a>Swa FrantzenDNS DDoS - let's use a long term solution
2009-01-31/a>Swa FrantzenVMware updates
2008-12-03/a>Andre LudwigNew ISC Poll! Has your organization suffered a DDoS (Distributed Denial of Service) attack in the last year?
2008-11-29/a>Pedro BuenoUbuntu users: Time to update!
2008-07-20/a>Kevin ListonDenial of Service Attack Against Georgia-- Are You Participating?
2008-04-10/a>Deborah HaleDSLReports Being Attacked Again

SAMBA

2019-07-10/a>Rob VandenBrinkSamba Project tells us "What's New" - SMBv1 Disabled by Default (finally)
2017-08-01/a>Rob VandenBrinkRooting Out Hosts that Support Older Samba Versions
2017-05-25/a>Xavier MertensCritical Vulnerability in Samba from 3.5.0 onwards
2016-03-06/a>Jim ClausingNovel method for slowing down Locky on Samba server using fail2ban
2014-08-02/a>Chris MohanAll Samba 4.x.x are vulnerable to a remote code execution vulnerability in the nmbd NetBIOS name services daemon
2012-04-10/a>Swa FrantzenSAMBA "root" credential remote code execution.
2012-02-24/a>Guy BruneauBlackBerry PlayBook tablet Samba file sharing Vulnerability - http://www.blackberry.com/btsc/KB29565
2011-08-10/a>Guy BruneauSamba 3.6.0 Released
2009-10-04/a>Guy BruneauSamba Security Information Disclosure and DoS

INFORMATION

2013-02-17/a>Guy BruneauHP ArcSight Connector Appliance and Logger Vulnerabilities
2011-02-05/a>Guy BruneauOpenSSH Legacy Certificate Information Disclosure Vulnerability
2011-01-12/a>Richard PorterHow Many Loyalty Cards do you Carry?
2010-10-22/a>Manuel Humberto Santander PelaezIntypedia project
2010-07-24/a>Manuel Humberto Santander PelaezTransmiting logon information unsecured in the network
2010-06-15/a>Manuel Humberto Santander PelaeziPhone 4 Order Security Breach Exposes Private Information
2010-04-21/a>Guy BruneauGoogle Chrome Security Update v4.1.249.1059 Released: http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html
2010-03-27/a>Guy BruneauHP-UX Running NFS/ONCplus, Inadvertently Enabled NFS
2009-11-29/a>Patrick Nolan A Cloudy Weekend
2009-10-04/a>Guy BruneauSamba Security Information Disclosure and DoS
2009-07-10/a>Guy BruneauWordPress Fixes Multiple vulnerabilities
2009-03-02/a>Swa FrantzenObama's leaked chopper blueprints: anything we can learn?
2008-09-11/a>David GoldsmithCookieMonster is coming to Pown (err, Town)
2008-04-07/a>John BambenekHP USB Keys Shipped with Malware for your Proliant Server

DISCLOSURE

2014-03-26/a>Johannes UllrichFull Disclosure Mailing List is back: http://insecure.org/news/fulldisclosure/
2014-02-07/a>Rob VandenBrinkNew ISO Standards on Vulnerability Handling and Disclosure
2013-02-17/a>Guy BruneauHP ArcSight Connector Appliance and Logger Vulnerabilities
2013-01-08/a>Richard PorterA picture worth a 1000 barcodes?
2012-11-15/a>Jim ClausingAnother month another password disclosure breach
2011-04-03/a>Richard PorterExtreme Disclosure? Not yet but a great trend!
2011-02-14/a>Richard PorterAnonymous Damage Control Anybody?
2011-02-05/a>Guy BruneauOpenSSH Legacy Certificate Information Disclosure Vulnerability
2010-06-24/a>Jason LamHelp your competitor - Advise them of vulnerability
2010-04-26/a>Raul SilesVulnerable Sites Database
2010-04-21/a>Guy BruneauGoogle Chrome Security Update v4.1.249.1059 Released: http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html
2010-03-27/a>Guy BruneauHP-UX Running NFS/ONCplus, Inadvertently Enabled NFS
2009-10-04/a>Guy BruneauSamba Security Information Disclosure and DoS