Courses:

Offensive Countermeasures: The Art Of Active Defense: SANSFIRE June 15-16, Blackhat USA July 27-28 & 29-30


Defensive Countermeasures: Foundations for Becoming A Devious Defender: Blackhat USA July 27-28 & 29-30


Conferences:

Check out the entire PaulDotCom crew at BsidesRI June 14-15th!



Subscribe:

Blog:
Videos:
Podcast:


PaulDotCom EspaƱol


Hack Naked TV


Hack Naked At Night


Stogie Geeks


Sponsored By:


www.coresecurity.com


www.tenablesecurity.com


www.sans.org



Follow Us On:


twitter.com/pauldotcom

PaulDotCom YouTube Channel


PaulDotCom - WMF Summary Podcast - Jan 5, 2005

|

Even with a patch in general circulation, there are still many aspects to the this vulnerability that we felt deserved some special attention. We cover the full details of the vulnerability, remediation steps, the unofficial patch, and more!

I wanted to provide some updated information about IDS and WMF. The latest Snort signatures do detect the WMF vulnerability (more specifically the escape() function call) and are provided by the bleeding snort folks. The latest rules can be found here.

There are known false positives associated with these rules and they do not detect attacks that have been gzipped. (Thank you Frank Knobbe)

For more information, check out our WMF related blog postings:

The WMF Patch Has Landed
Beating Microsoft to the punch: Ilfak Guilfanov Interview
How Bad is WMF
WMF Vulnerability & Exploits: Just The Facts


Hosts: Larry Pesce, Paul Asadoorian
Email: psw@pauldotcom.com

Audio Direct Download Link

(Bandwidth provided by OSHEAN, they're good, like early release patches)