Re: [Full-disclosure] VML Exploit vs. AV/IPS/IDS signatures



Hi,

i.e. I can't afford to buy "specialized" security tools/devices for
"speclialized" attacks unless my company relies heavily on web/content
services.

So, you will buy "specialized" security tools like firewall or
Anti-Virus, but not web content filtering tool?

In our company, we established a information-sharing
network with other security companies. So the real-time exploit-facing
signatures were then subjected to live traffic, honeypots and countless
variants; They seemed to work out pretty well.

I would like to see how your real-time signatures get updated with the
randomization implemented in the new VML metasploit module. Your
"countless" exploit variants will become really innumerable.

The problem is that the signatures are written for the exploit, and
not for the vulnerability.

-- Aviv.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: [Full-disclosure] VML Exploit vs. AV/IPS/IDS signatures
    ... based security solutions, and not exploit based security solutions. ... VML Exploit vs. AV/IPS/IDS signatures ... variants; They seemed to work out pretty well. ... "countless" exploit variants will become really innumerable. ...
    (Full-Disclosure)
  • RE: [Full-disclosure] VML Exploit vs. AV/IPS/IDS signatures
    ... based security solutions, and not exploit based security solutions. ... VML Exploit vs. AV/IPS/IDS signatures ... variants; They seemed to work out pretty well. ... "countless" exploit variants will become really innumerable. ...
    (Bugtraq)
  • Re: [Full-disclosure] VML Exploit vs. AV/IPS/IDS signatures
    ... So the real-time exploit-facing ... variants; They seemed to work out pretty well. ... I would like to see how your real-time signatures get updated with the ... "countless" exploit variants will become really innumerable. ...
    (Full-Disclosure)
  • Re: preventing tampering with tripwire
    ... > With a read-only disk, ... > - install the security tools you want on it ... > update your signatures, and rejumper it, but that's ... Do You Yahoo!? ...
    (FreeBSD-Security)