[Guest Diary] Leveraging CNNs and Entropy-Based Feature Selection to Identify Potential Malware Artifacts of Interest, (Wed, Mar 26th)

[This is a Guest Diary by Wee Ki Joon, an ISC intern as part of the SANS.edu Bachelor's Degree in Applied Cybersecurity (BACS) program [1].]

Continue reading [Guest Diary] Leveraging CNNs and Entropy-Based Feature Selection to Identify Potential Malware Artifacts of Interest, (Wed, Mar 26th)

Posted in Uncategorized

X-Wiki Search Vulnerability exploit attempts (CVE-2024-3721), (Tue, Mar 25th)

Creating a secure Wiki is hard. The purpose of a wiki is to allow “random” users to edit web pages. A good Wiki provides users with great flexibility, but with great flexibility comes an even “greater” attack surface. File uploads and markup (or markdown) are all well-known security issues affecting various Wikis in the past.

Continue reading X-Wiki Search Vulnerability exploit attempts (CVE-2024-3721), (Tue, Mar 25th)

Posted in Uncategorized

Privacy Aware Bots, (Mon, Mar 24th)

Staring long enough at honeypot logs, I am sure you will come across one or the other “oddity.” Something that at first does not make any sense, but then, in some way, does make sense. After looking at the Next.js issue yesterday, I looked through our logs for other odd headers I may spot. I came across a header that is somewhat normal, but not usually used by bot:

Continue reading Privacy Aware Bots, (Mon, Mar 24th)

Posted in Uncategorized

Let’s Talk About HTTP Headers., (Sun, Mar 23rd)

Walking my dog earlier, I came across the sign on the right. Having just looked at yet another middleware/HTTP header issue (the Next.js problem that became public this weekend) [;1];, I figured I should write something about HTTP headers. We all know HTTP headers. But it appears some do not know them well enough. Just like this sign, proxies and other middleboxes hardly ever stop unsafe behaviors.Â; ;

Continue reading Let’s Talk About HTTP Headers., (Sun, Mar 23rd)

Posted in Uncategorized

Some new Data Feeds, and a little “incident”., (Thu, Mar 20th)

Our API (https://isc.sans.edu/api) continues to be quite popular. One query we see a lot is lookups for individual IP addresses. Running many queries as you go through a log may cause you to get locked out by our rate limit. To help with that, we now offer additional “summary feeds” that include all data recently received. You may download these feeds and import them in your database of choice (or grep the text file for records). This will make bulk lookups a lot easier and faster.

Continue reading Some new Data Feeds, and a little “incident”., (Thu, Mar 20th)

Posted in Uncategorized