Internet Storm Center
Sign In
Sign Up
Handler on Duty:
Didier Stevens
Threat Level:
green
Date
Author
Title
XML DOS CODE EXECUTION
2009-08-08
Guy Bruneau
XML Libraries Data Parsing Vulnerabilities
XML
2024-05-16/a>
Rob VandenBrink
Why yq? Adventures in XML
2023-12-11/a>
Rob VandenBrink
What is sitemap.xml, and Why a Pentester Should Care
2022-09-16/a>
Didier Stevens
Word Maldoc With CustomXML and Renamed VBAProject.bin
2022-09-15/a>
Xavier Mertens
Malicious Word Document with a Frameset
2022-03-18/a>
Johannes Ullrich
Scans for Movable Type Vulnerability (CVE-2021-20837)
2021-01-24/a>
Didier Stevens
Video: Doc & RTF Malicious Document
2021-01-23/a>
Didier Stevens
CyberChef: Analyzing OOXML Files for URLs
2020-10-10/a>
Didier Stevens
Open Packaging Conventions
2018-10-26/a>
Xavier Mertens
Dissecting Malicious Office Documents with Linux
2016-02-03/a>
Xavier Mertens
Automating Vulnerability Scans
2014-03-12/a>
Johannes Ullrich
Wordpress "Pingback" DDoS Attacks
2013-11-01/a>
Russ McRee
Secunia's PSI Country Report - Q3 2013
2011-11-10/a>
Rob VandenBrink
Stuff I Learned Scripting - - Parsing XML in a One-Liner
2009-08-08/a>
Kevin Liston
Sun OpenSSO Enterprise/Sun Access Manager XML Vulnerabilities
2009-08-08/a>
Guy Bruneau
XML Libraries Data Parsing Vulnerabilities
2009-02-19/a>
Bojan Zdrnja
MS09-002, XML/DOC and initial infection vector
2009-01-31/a>
Swa Frantzen
VMware updates
2006-11-14/a>
Jim Clausing
MS06-071: MSXML Core Services
2006-09-19/a>
Swa Frantzen
Yet another MSIE 0-day: VML
DOS
2024-09-25/a>
Johannes Ullrich
DNS Reflection Update and Odd Corrupted DNS Requests
2024-07-30/a>
Johannes Ullrich
Apple Patches Everything. July 2024 Edition
2024-04-29/a>
Guy Bruneau
Linux Trojan - Xorddos with Filename eyshcjdmzg
2024-03-05/a>
Johannes Ullrich
Apple Releases iOS/iPadOS Updates with Zero Day Fixes.
2024-01-22/a>
Johannes Ullrich
Apple Updates Everything - New 0 Day in WebKit
2023-12-11/a>
Johannes Ullrich
Apple Patches Everything
2023-11-09/a>
Guy Bruneau
Routers Targeted for Gafgyt Botnet [Guest Diary]
2023-10-25/a>
Johannes Ullrich
Apple Patches Everything. Releases iOS 17.1, MacOS 14.1 and updates for older versions fixing exploited vulnerability
2023-10-09/a>
Didier Stevens
ZIP's DOSTIME & DOSDATE Formats
2023-06-22/a>
Johannes Ullrich
Apple Patches Exploited Vulnerabilities in iOS/iPadOS, macOS, watchOS and Safari
2023-03-27/a>
Johannes Ullrich
Apple Updates Everything (including Studio Display)
2023-01-24/a>
Johannes Ullrich
Apple Updates (almost) Everything: Patch Overview
2022-08-10/a>
Johannes Ullrich
And Here They Come Again: DNS Reflection Attacks
2022-08-02/a>
Johannes Ullrich
A Little DDoS in the Morning - Followup
2022-08-01/a>
Johannes Ullrich
A Little DDoS In the Morning
2022-07-20/a>
Johannes Ullrich
Apple Patches Everything Day
2022-04-13/a>
Jan Kopriva
How is Ukrainian internet holding up during the Russian invasion?
2022-03-31/a>
Johannes Ullrich
Apple Patches Actively Exploited Vulnerability in macOS, iOS and iPadOS,
2022-03-14/a>
Johannes Ullrich
Apple Updates Everything: MacOS 12.3, XCode 13.3, tvOS 15.4, watchOS 8.5, iPadOS 15.4 and more
2022-02-10/a>
Johannes Ullrich
iOS/iPadOS and MacOS Update: Single WebKit 0-Day Vulnerability Patched
2022-01-27/a>
Johannes Ullrich
Apple Patches Everything
2021-07-31/a>
Guy Bruneau
Unsolicited DNS Queries
2020-09-01/a>
Johannes Ullrich
Exposed Windows Domain Controllers Used in CLDAP DDoS Attacks
2020-05-19/a>
Rick Wanner
Cisco Advisories for FTD, ASA, Firepower 1000
2020-03-30/a>
Jan Kopriva
Crashing explorer.exe with(out) a click
2019-08-14/a>
Brad Duncan
Recent example of MedusaHTTP malware
2018-12-29/a>
Didier Stevens
Video: De-DOSfuscation Example
2018-12-15/a>
Didier Stevens
De-DOSfuscation Example
2018-12-12/a>
Didier Stevens
Yet Another DOSfuscation Sample
2018-09-30/a>
Didier Stevens
When DOSfuscation Helps...
2018-07-30/a>
Didier Stevens
Malicious Word documents using DOSfuscation
2017-11-25/a>
Guy Bruneau
Exim Remote Code Exploit
2017-10-20/a>
Rick Wanner
One year Anniversary of Dyn DDOS
2017-07-30/a>
Renato Marinho
SMBLoris - the new SMB flaw
2017-07-07/a>
Renato Marinho
DDoS Extortion E-mail: Yet Another Bluff?
2016-12-29/a>
Rick Wanner
More on Protocol 47 denys
2016-12-19/a>
John Bambenek
UPDATED x1: Mirai Scanning for Port 6789 Looking for New Victims / Now hitting tcp/23231
2016-12-09/a>
Rick Wanner
Mirai - now with DGA
2016-10-22/a>
Guy Bruneau
Request for Packets TCP 4786 - CVE-2016-6385
2016-05-29/a>
Guy Bruneau
Analysis of a Distributed Denial of Service (DDoS)
2016-02-07/a>
Rick Wanner
DDOS is down, but still a concern for ISPs
2015-06-23/a>
Kevin Shortt
XOR DDOS Mitigation and Analysis
2015-02-27/a>
Rick Wanner
DDOS are way down? Why?
2015-02-19/a>
Daniel Wesemann
DNS-based DDoS
2014-09-16/a>
Mark Hofman
FreeBSD Denial of Service advisory (CVE-2004-0230)
2014-08-31/a>
Rick Wanner
1900/UDP (SSDP) Scanning and DDOS
2014-08-25/a>
Jim Clausing
UDP port 1900 DDoS traffic
2014-08-17/a>
Rick Wanner
Part 1: Is your home network unwittingly contributing to NTP DDOS attacks?
2014-08-17/a>
Rick Wanner
Part 2: Is your home network unwittingly contributing to NTP DDOS attacks?
2014-06-24/a>
Kevin Shortt
NTP DDoS Counts Have Dropped
2014-06-02/a>
Rick Wanner
Using nmap to scan for DDOS reflectors
2014-04-30/a>
Russ McRee
UltraDNS DDOS
2014-03-12/a>
Johannes Ullrich
Wordpress "Pingback" DDoS Attacks
2014-02-17/a>
Chris Mohan
NTP reflection attacks continue
2013-11-22/a>
Rick Wanner
Port 0 DDOS
2013-10-24/a>
Johannes Ullrich
Are you a small business that experienced a DoS attack?
2013-10-08/a>
Johannes Ullrich
CSAM: ANY queries used in reflective DoS attack
2013-07-27/a>
Scott Fendley
Defending Against Web Server Denial of Service Attacks
2013-06-05/a>
Richard Porter
BIND 9 Update fixing CVE-2013-3919
2013-04-21/a>
John Bambenek
A Chargen-based DDoS? Chargen is still a thing?
2013-03-28/a>
John Bambenek
Where Were You During the Great DDoS Cybergeddon of 2013?
2013-03-27/a>
Rob VandenBrink
Several Cisco IOS DOS Issues Resolved
2013-03-18/a>
Kevin Shortt
Spamhaus DDOS
2012-09-20/a>
Russ McRee
Financial sector advisory: attacks and threats against financial institutions
2012-08-15/a>
Guy Bruneau
Cisco IOS XR Software Route Processor DoS Vulnerability - http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120530-iosxr
2012-05-21/a>
Kevin Shortt
DNS ANY Request Cannon - Need More Packets
2012-03-30/a>
Daniel Wesemann
Tomorrow, the world will end
2012-03-16/a>
Russ McRee
MS12-020 RDP vulnerabilities: Patch, Mitigate, Detect
2012-01-22/a>
Johannes Ullrich
Javascript DDoS Tool Analysis
2011-12-28/a>
Daniel Wesemann
Hash collisions vulnerability in web servers
2011-08-30/a>
Johannes Ullrich
Apache patch out for "byte range" DoS vulnerability http://www.apache.org/dist/httpd/Announcement2.2.html
2011-08-25/a>
Kevin Shortt
Revival of an Unpatched Apache HTTPD DoS
2011-05-20/a>
Guy Bruneau
Distributed Denial of Service Cheat Sheet
2011-04-05/a>
Mark Hofman
Sony DDOS
2011-04-05/a>
Mark Hofman
DNS.be DDOS
2011-03-04/a>
Mark Hofman
DDOS, the new black?
2011-02-12/a>
Kevin Liston
DDoS Analysis Process
2011-01-29/a>
Mark Hofman
Sourceforge attack
2011-01-27/a>
Guy Bruneau
ISC DHCP DHCPv6 Vulnerability
2010-12-22/a>
John Bambenek
IIS 7.5 0-Day DoS (processing FTP requests)
2010-12-09/a>
Mark Hofman
Having a look at the DDOS tool used in the attacks today
2010-12-08/a>
Rob VandenBrink
Interesting DDOS activity around Wikileaks
2010-09-14/a>
Adrien de Beaupre
BlackEnergy DDoS
2010-08-16/a>
Raul Siles
DDOS: State of the Art
2010-08-13/a>
Guy Bruneau
Cisco IOS Software 15.1(2)T TCP DoS
2010-08-07/a>
Stephen Hall
DnsMadeEasy under a "quite large and unique" ddos.
2010-08-04/a>
Adrien de Beaupre
Multiple Cisco Advisories
2010-05-08/a>
Guy Bruneau
Wireshark DOCSIS Dissector DoS Vulnerability
2010-02-02/a>
Johannes Ullrich
Pushdo Update
2010-01-19/a>
Jim Clausing
49Gbps DDoS, IPv4 exhaustion, and DNSSEC, oh my!
2010-01-06/a>
Johannes Ullrich
Denial of Service Attack Aftermath (and what did Iran have to do with it?)
2009-12-30/a>
Guy Bruneau
KDC DoS in cross-realm referral processing
2009-12-24/a>
Guy Bruneau
F5 BIG-IP ASM and PSM Remote Buffer Overflow
2009-12-09/a>
Swa Frantzen
ntpd upgrade to prevent spoofed looping
2009-10-04/a>
Guy Bruneau
Samba Security Information Disclosure and DoS
2009-09-09/a>
Mark Hofman
Possible DDOS on gov.au sites starting tonight?
2009-09-08/a>
Guy Bruneau
Cisco Security Advisory TCP DoS
2009-08-08/a>
Guy Bruneau
XML Libraries Data Parsing Vulnerabilities
2009-07-29/a>
Bojan Zdrnja
BIND 9 DoS attacks in the wild
2009-07-09/a>
John Bambenek
Latest Updates on Ongoing DDoS on Governmental/Commercial Websites in USA and S. Korea
2009-07-08/a>
Marcus Sachs
RFI: DDoS Against Government and Civilian Web Sites
2009-06-23/a>
Bojan Zdrnja
Slowloris and Iranian DDoS attacks
2009-06-21/a>
Bojan Zdrnja
Apache HTTP DoS tool mitigation
2009-06-18/a>
Bojan Zdrnja
Apache HTTP DoS tool released
2009-03-08/a>
Marcus Sachs
Behind the Estonia Cyber Attacks
2009-01-31/a>
Swa Frantzen
DNS DDoS - let's use a long term solution
2009-01-31/a>
Swa Frantzen
VMware updates
2008-12-03/a>
Andre Ludwig
New ISC Poll! Has your organization suffered a DDoS (Distributed Denial of Service) attack in the last year?
2008-11-29/a>
Pedro Bueno
Ubuntu users: Time to update!
2008-07-20/a>
Kevin Liston
Denial of Service Attack Against Georgia-- Are You Participating?
2008-04-10/a>
Deborah Hale
DSLReports Being Attacked Again
CODE
2024-08-23/a>
Jesse La Grew
Pandas Errors: What encoding are my logs in?
2024-08-19/a>
Xavier Mertens
Do you Like Donuts? Here is a Donut Shellcode Delivered Through PowerShell/Python
2023-12-06/a>
Guy Bruneau
Revealing the Hidden Risks of QR Codes [Guest Diary]
2023-07-28/a>
Xavier Mertens
ShellCode Hidden with Steganography
2023-03-16/a>
Xavier Mertens
Simple Shellcode Dissection
2023-03-07/a>
Johannes Ullrich
Hackers Love This VSCode Extension: What You Can Do to Stay Safe
2022-11-04/a>
Xavier Mertens
Remcos Downloader with Unicode Obfuscation
2022-09-14/a>
Xavier Mertens
Easy Process Injection within Python
2022-05-30/a>
Xavier Mertens
New Microsoft Office Attack Vector via "ms-msdt" Protocol Scheme (CVE-2022-30190)
2022-02-26/a>
Guy Bruneau
Using Snort IDS Rules with NetWitness PacketDecoder
2022-01-22/a>
Xavier Mertens
Mixed VBA & Excel4 Macro In a Targeted Excel Sheet
2022-01-20/a>
Xavier Mertens
RedLine Stealer Delivered Through FTP
2022-01-06/a>
Xavier Mertens
Malicious Python Script Targeting Chinese People
2022-01-05/a>
Xavier Mertens
Code Reuse In the Malware Landscape
2021-12-10/a>
Xavier Mertens
Python Shellcode Injection From JSON Data
2021-10-20/a>
Xavier Mertens
Thanks to COVID-19, New Types of Documents are Lost in The Wild
2021-08-20/a>
Xavier Mertens
Waiting for the C2 to Show Up
2021-02-13/a>
Guy Bruneau
vSphere Replication updates address a command injection vulnerability (CVE-2021-21976) - https://www.vmware.com/security/advisories/VMSA-2021-0001.html
2021-01-18/a>
Didier Stevens
Doc & RTF Malicious Document
2020-10-14/a>
Xavier Mertens
Nicely Obfuscated Python RAT
2020-09-02/a>
Xavier Mertens
Python and Risky Windows API Calls
2020-08-06/a>
Xavier Mertens
A Fork of the FTCode Powershell Ransomware
2020-07-27/a>
Didier Stevens
Analyzing Metasploit ASP .NET Payloads
2019-12-12/a>
Xavier Mertens
Code & Data Reuse in the Malware Ecosystem
2019-10-27/a>
Didier Stevens
Using scdbg to Find Shellcode
2019-07-08/a>
Didier Stevens
Machine Code? No!
2019-07-04/a>
Didier Stevens
Machine Code?
2019-05-31/a>
Didier Stevens
Retrieving Second Stage Payload with Ncat
2019-05-30/a>
Didier Stevens
Analyzing First Stage Shellcode
2019-05-06/a>
Didier Stevens
Text and T
e
x
t
2019-05-01/a>
Xavier Mertens
Another Day, Another Suspicious UDF File
2019-04-23/a>
Didier Stevens
Malicious VBA Office Document Without Source Code
2019-03-24/a>
Didier Stevens
Decoding QR Codes with Python
2019-02-25/a>
Didier Stevens
Sextortion Email Variant: With QR Code
2019-01-02/a>
Didier Stevens
Maldoc with Nonfunctional Shellcode
2018-09-24/a>
Didier Stevens
Analyzing Encoded Shellcode with scdbg
2018-09-08/a>
Didier Stevens
Video: Using scdbg to analyze shellcode
2018-09-03/a>
Didier Stevens
Another quickie: Using scdbg to analyze shellcode
2018-08-31/a>
Jim Clausing
Quickie: Using radare2 to disassemble shellcode
2018-06-04/a>
Rob VandenBrink
Digging into Authenticode Certificates
2017-04-16/a>
Johannes Ullrich
Tool to Detect Active Phishing Attacks Using Unicode Look-Alike Domains
2016-11-24/a>
Didier Stevens
Extracting Shellcode From JavaScript
2016-11-18/a>
Didier Stevens
VBA Shellcode and Windows 10
2016-09-26/a>
Didier Stevens
VBA and P-code
2015-09-21/a>
Xavier Mertens
Detecting XCodeGhost Activity
2015-03-30/a>
Didier Stevens
YARA Rules For Shellcode
2013-10-25/a>
Johannes Ullrich
PHP.net compromise aftermath: Why Code Signing Beats Hashes
2013-08-04/a>
Johannes Ullrich
BBCode tag "[php]" used to inject php code
2013-02-16/a>
Lorna Hutcheson
Fedora RedHat Vulnerabilty Released
2012-07-19/a>
Mark Baggett
A Heap of Overflows?
2012-04-26/a>
Richard Porter
Packetstorm Security and Metasploit have Exploit code for MS12-027
2012-04-25/a>
Daniel Wesemann
Blacole's shell code
2012-03-16/a>
Russ McRee
MS12-020 RDP vulnerabilities: Patch, Mitigate, Detect
2012-03-11/a>
Johannes Ullrich
An Analysis of Jester's QR Code Attack. (Guest Diary)
2011-08-11/a>
Guy Bruneau
BlackBerry Enterprise Server Critical Update
2011-08-03/a>
Johannes Ullrich
Malicious Images: What's a QR Code
2011-03-07/a>
Bojan Zdrnja
Oracle padding attacks (Codegate crypto 400 writeup)
2010-05-12/a>
Rob VandenBrink
Adobe Shockwave Update
2010-03-10/a>
Rob VandenBrink
Microsoft Security Advisory 981374 - Remote Code Execution Vulnerability for IE6 and IE7
2010-02-08/a>
Adrien de Beaupre
When is a 0day not a 0day? Fake OpenSSh exploit, again.
2009-08-08/a>
Guy Bruneau
XML Libraries Data Parsing Vulnerabilities
2009-05-29/a>
Lorna Hutcheson
VMWare Patches Released
2008-07-22/a>
Mari Nichols
‘Cold Boot’ Attack Utility Tools
2008-06-10/a>
Swa Frantzen
Ransomware keybreaking
EXECUTION
2022-05-30/a>
Xavier Mertens
New Microsoft Office Attack Vector via "ms-msdt" Protocol Scheme (CVE-2022-30190)
2021-02-13/a>
Guy Bruneau
vSphere Replication updates address a command injection vulnerability (CVE-2021-21976) - https://www.vmware.com/security/advisories/VMSA-2021-0001.html
2017-11-25/a>
Guy Bruneau
Exim Remote Code Exploit
2015-10-12/a>
Guy Bruneau
Critical Vulnerability in Multiple Cisco Products - Apache Struts 2 Command Execution http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131023-struts2
2013-09-18/a>
Rob VandenBrink
Cisco DCNM Update Released
2013-02-16/a>
Lorna Hutcheson
Fedora RedHat Vulnerabilty Released
2012-03-16/a>
Russ McRee
MS12-020 RDP vulnerabilities: Patch, Mitigate, Detect
2011-08-11/a>
Guy Bruneau
BlackBerry Enterprise Server Critical Update
2010-05-12/a>
Rob VandenBrink
Adobe Shockwave Update
2010-03-10/a>
Rob VandenBrink
Microsoft Security Advisory 981374 - Remote Code Execution Vulnerability for IE6 and IE7
2009-08-08/a>
Guy Bruneau
XML Libraries Data Parsing Vulnerabilities
2009-05-29/a>
Lorna Hutcheson
VMWare Patches Released
Homepage
Diaries
Podcasts
Jobs
Data
TCP/UDP Port Activity
Port Trends
SSH/Telnet Scanning Activity
Weblogs
Threat Feeds Activity
Threat Feeds Map
Useful InfoSec Links
Presentations & Papers
Research Papers
API
Tools
DShield Sensor
DNS Looking Glass
Honeypot (RPi/AWS)
InfoSec Glossary
Contact Us
Contact Us
About Us
Handlers
About Us
Slack Channel
Mastodon
Bluesky
X
Follow updates by subscribing to the handler's
diary RSS feed