The defense blues

Mother Nature has been really unfair with me. It has given me two strong interests in life: building things and information security. Once that was done, my doom was sealed and I’ve become a infosec defense guy. Nowadays this is one of the worst fate possible in computer science. Today, this burden is really hard to wear. I know some of you will try to encourage me by saying this like: ...

6 décembre 2012 · 3 min · Regit

Defend your network from Microsoft Word upload with Suricata and Netfilter

Introduction Some times ago, I’ve blogged about new IPS features in Suricata 1.1 and did not find at the time any killer application of the nfq_set_mark keyword. When using Suricata in Netfilter IPS mode, this keyword allows you to set the Netfilter mark on the packet when a rule match. This mark can be used by Netfilter or by other network subsystem to differentiate the treatment to apply to the packet. ...

9 octobre 2012 · 6 min · Regit