Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: Diaries by Keyword Diaries by Keyword

Participate: Learn more about our honeypot network
https://isc.sans.edu/honeypot.html

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Date Author Title

MSFT SP3 WINDOWS XPSP3 BSOD

2008-05-17Lorna HutchesonXP SP3 Issues

MSFT

2018-06-12/a>Johannes UllrichMicrosoft June 2018 Patch Tuesday
2017-01-10/a>Johannes UllrichJanuary 2017 Microsoft Patch Tuesday
2013-10-03/a>Johannes UllrichOctober Patch Tuesday Preview (CVE-2013-3893 patch coming!)
2013-09-10/a>Swa FrantzenMicrosoft September 2013 Black Tuesday Overview
2013-08-13/a>Swa FrantzenMicrosoft August 2013 Black Tuesday Overview
2013-07-09/a>Swa FrantzenMicrosoft July 2013 Black Tuesday Overview
2013-06-11/a>Swa FrantzenMicrosoft June 2013 Black Tuesday Overview
2013-06-11/a>Swa FrantzenOther Microsoft Black Tuesday News
2013-05-14/a>Swa FrantzenMicrosoft May 2013 Black Tuesday Overview
2013-04-09/a>Swa FrantzenMicrosoft April 2013 Black Tuesday Overview
2013-03-12/a>Swa FrantzenMicrosoft March 2013 Black Tuesday Overview
2013-02-12/a>Adam SwangerMicrosoft February 2013 Black Tuesday Update - Overview
2013-01-14/a>Richard PorterJanuary 2013 Microsoft Out of Cycle Patch
2012-12-11/a>John BambenekMicrosoft December 2012 Black Tuesday Update - Overview
2012-11-13/a>Jim ClausingMicrosoft November 2012 Black Tuesday Update - Overview
2012-07-10/a>Swa FrantzenMicrosoft July 2012 Black Tuesday Update - Overview
2012-06-12/a>Swa FrantzenMicrosoft June 2012 Black Tuesday Update - Overview
2012-06-12/a>Swa FrantzenMicrosoft Security Advisory 2719615 - MSXML - CVE-2012-1889
2012-05-08/a>Adam SwangerMicrosoft May 2012 Black Tuesday Update - Overview
2012-04-26/a>Richard PorterPacketstorm Security and Metasploit have Exploit code for MS12-027
2012-04-10/a>Swa FrantzenWindows Vista RIP
2012-04-10/a>Swa FrantzenMicrosoft April 2012 Black Tuesday Update - Overview
2012-01-06/a>Guy BruneauJanuary 2012 Patch Tuesday Pre-release
2011-11-08/a>Swa FrantzenMicrosoft November 2011 Black Tuesday Overview
2011-11-03/a>Guy BruneauNovember 2011 Patch Tuesday Pre-release
2011-10-11/a>Swa FrantzenMicrosoft Black Tuesday Overview October 2011
2011-10-11/a>Swa FrantzenMicrosoft Security Intelligence Report (SIR) - Volume 11
2011-09-13/a>Swa FrantzenMicrosoft September 2011 Black Tuesday
2011-09-13/a>Swa FrantzenMore DigiNotar intermediate certificates blocklisted at Microsoft
2011-08-09/a>Swa FrantzenMicrosoft August 2011 Black Tuesday Overview
2011-07-12/a>Swa FrantzenMicrosoft July 2011 Black Tuesday Overview
2011-06-14/a>Swa FrantzenMicrosoft June 2011 Black Tuesday Overview
2011-01-08/a>Guy BruneauJanuary 2011 Patch Tuesday Pre-release
2010-10-08/a>Rick WannerPatch Tuesday Pre-release -- 16 updates
2010-08-29/a>Swa FrantzenDLL hijacking - what are you doing ?
2010-03-09/a>John BambenekMarch 2010 - Microsoft Patch Tuesday Diary
2009-09-08/a>Guy BruneauMicrosoft September 2009 Black Tuesday Overview
2008-05-17/a>Lorna HutchesonXP SP3 Issues
2006-10-10/a>Johannes UllrichMS06-056: ASP.NET XSS Information Disclosure Vulnerability (moderate)
2006-10-10/a>Johannes UllrichMS06-061: XSLT/MSXML Buffer Overflow Code Execution Vulnerability (moderate)
2006-10-10/a>Kyle HaugsnessMS06-063: Mailslot DoS (Server service)

SP3

2013-10-30/a>Russ McReeSIR v15: Five good reasons to leave Windows XP behind
2008-05-17/a>Lorna HutchesonXP SP3 Issues
2008-05-06/a>John BambenekWindows XP Service Pack 3 Released
2008-04-29/a>Bojan ZdrnjaWindows Service Pack blocker tool
2008-04-22/a>donald smithXP SP3 RC2 Available
2008-04-16/a>William StearnsWindows XP Service Pack 3 - unofficial schedule: Apr 21-28

WINDOWS

2020-09-02/a>Xavier MertensPython and Risky Windows API Calls
2020-09-01/a>Johannes UllrichExposed Windows Domain Controllers Used in CLDAP DDoS Attacks
2020-08-25/a>Xavier MertensKeep An Eye on LOLBins
2020-06-24/a>Jan KoprivaUsing Shell Links as zero-touch downloaders and to initiate network connections
2020-03-30/a>Jan KoprivaCrashing explorer.exe with(out) a click
2020-03-23/a>Didier StevensWindows Zeroday Actively Exploited: Type 1 Font Parsing Remote Code Execution Vulnerability
2020-03-16/a>Jan KoprivaDesktop.ini as a post-exploitation tool
2020-02-18/a>Jan KoprivaDiscovering contents of folders in Windows without permissions
2020-02-17/a>Didier Stevenscurl and SSPI
2020-02-15/a>Didier Stevensbsdtar on Windows 10
2020-01-09/a>Kevin ShorttWindows 7 - End of Life
2019-06-27/a>Rob VandenBrinkFinding the Gold in a Pile of Pennies - Long Tail Analysis in PowerShell
2019-06-06/a>Xavier MertensKeep an Eye on Your WMI Logs
2019-05-22/a>Johannes UllrichAn Update on the Microsoft Windows RDP "Bluekeep" Vulnerability (CVE-2019-0708) [now with pcaps]
2019-03-05/a>Rob VandenBrinkPowershell, Active Directory and the Windows Host Firewall
2019-01-14/a>Rob VandenBrinkStill Running Windows 7? Time to think about that upgrade project!
2018-12-19/a>Xavier MertensRestricting PowerShell Capabilities with NetSh
2018-12-19/a>Xavier MertensMicrosoft OOB Patch for Internet Explorer: Scripting Engine Memory Corruption Vulnerability
2018-06-05/a>Xavier MertensMalicious Post-Exploitation Batch File
2018-05-07/a>Xavier MertensAdding Persistence Via Scheduled Tasks
2018-05-02/a>Russ McReeWindows Commands Reference - An InfoSec Must Have
2018-02-17/a>Xavier MertensMalware Delivered via Windows Installer Files
2017-11-15/a>Xavier MertensIf you want something done right, do it yourself!
2017-11-11/a>Xavier MertensKeep An Eye on your Root Certificates
2017-01-18/a>Rob VandenBrinkMaking Windows 10 a bit less "Creepy" - Common Privacy Settings
2017-01-12/a>Mark BaggettSystem Resource Utilization Monitor
2016-11-18/a>Didier StevensVBA Shellcode and Windows 10
2016-08-29/a>Russ McReeRecommended Reading: Intrusion Detection Using Indicators of Compromise Based on Best Practices and Windows Event Logs
2016-08-02/a>Tom WebbWindows 10 Anniversary Update Available
2016-07-12/a>Xavier MertensHunting for Malicious Files with MISP + OSSEC
2016-05-22/a>Pasquale StirparoThe strange case of WinZip MRU Registry key
2016-05-18/a>Russ McReeResources: Windows Auditing & Monitoring, Linux 2FA
2016-04-15/a>Xavier MertensWindows Command Line Persistence?
2016-03-30/a>Xavier MertensWhat to watch with your FIM?
2016-02-18/a>Xavier MertensHunting for Executable Code in Windows Environments
2016-01-31/a>Guy BruneauWindows 10 and System Protection for DATA Default is OFF
2015-12-09/a>Xavier MertensEnforcing USB Storage Policy with PowerShell
2015-08-12/a>Rob VandenBrinkWindows Service Accounts - Why They're Evil and Why Pentesters Love them!
2014-08-15/a>Tom WebbAppLocker Event Logs with OSSEC 2.8
2014-07-05/a>Guy BruneauJava Support ends for Windows XP
2014-04-06/a>Basil Alawi S.Taher"Power Worm" PowerShell based Malware
2014-04-04/a>Rob VandenBrinkWindows 8.1 Released
2014-03-24/a>Johannes UllrichNew Microsoft Advisory: Unpatched Word Flaw used in Targeted Attacks
2014-03-04/a>Daniel WesemannXPired!
2014-01-10/a>Basil Alawi S.TaherWindows Autorun-3
2014-01-04/a>Tom WebbMonitoring Windows Networks Using Syslog (Part One)
2013-10-30/a>Russ McReeSIR v15: Five good reasons to leave Windows XP behind
2013-03-19/a>Johannes UllrichWindows 7 SP1 and Windows Server 2008 R2 SP1 Being "pushed" today
2013-02-28/a>Daniel WesemannParsing Windows Eventlogs in Powershell
2012-10-24/a>Rob VandenBrinkTime to run Windows Update - - Microsoft Updates KB2755801 for Windows RT / IE10 / Flash Player - http://technet.microsoft.com/en-us/security/advisory/2755801
2012-07-19/a>Mark BaggettDiagnosing Malware with Resource Monitor
2012-06-25/a>Guy BruneauIssues with Windows Update Agent
2012-05-08/a>Bojan ZdrnjaWindows Firewall Bypass Vulnerability and NetBIOS NS
2012-05-06/a>Jim ClausingTool updates and Win 8
2012-04-10/a>Swa FrantzenWindows Vista RIP
2011-12-21/a>Johannes UllrichNew Vulnerability in Windows 7 64 bit
2011-07-09/a>Chris MohanSafer Windows Incident Response
2011-06-30/a>Rob VandenBrinkUpdate for RSA Authentication Manager
2011-06-01/a>Johannes UllrichEnabling Privacy Enhanced Addresses for IPv6
2011-03-27/a>Guy BruneauStrange Shockwave File with Surprising Attachments
2011-03-15/a>Lenny ZeltserLimiting Exploit Capabilities by Using Windows Integrity Levels
2011-02-24/a>Johannes UllrichWindows 7 / 2008 R2 Service Pack 1 Problems
2011-02-23/a>Johannes UllrichWindows 7 Service Pack 1 out
2011-02-16/a>Jason LamWindows 0-day SMB mrxsmb.dll vulnerability
2011-02-10/a>Chris MohanBefriending Windows Security Log Events
2011-01-24/a>Rob VandenBrinkWhere have all the COM Ports Gone? - How enumerating COM ports led to me finding a “misplaced” Microsoft tool
2011-01-04/a>Johannes UllrichMicrosoft Advisory: Vulnerability in Graphics Rendering Engine
2010-11-24/a>Bojan ZdrnjaPrivilege escalation 0-day in almost all Windows versions
2010-08-02/a>Manuel Humberto Santander PelaezSecuring Windows Internet Kiosk
2010-06-15/a>Manuel Humberto Santander PelaezMicrosoft Windows Help and Support Center vulnerability (CVE 2010-1885) exploit in the wild
2010-02-11/a>Deborah HaleThe Mysterious Blue Screen
2009-11-14/a>Adrien de BeaupreMicrosoft advisory for Windows 7 / Windows Server 2008 R2 Remote SMB DoS Exploit released
2009-11-12/a>Rob VandenBrinkWindows 7 / Windows Server 2008 Remote SMB Exploit
2009-10-24/a>Marcus SachsWindows 7 - How is it doing?
2009-09-08/a>Guy BruneauVista/2008/Windows 7 SMB2 BSOD 0Day
2009-08-26/a>Johannes UllrichWSUS 3.0 SP2 released
2009-07-16/a>Guy BruneauChanges in Windows Security Center
2009-07-02/a>Daniel WesemannTime to update updating on PCs for 3rd party apps
2009-04-16/a>Adrien de BeaupreStrange Windows Event Log entry
2009-01-31/a>Swa FrantzenWindows 7 - not so secure ?
2008-08-15/a>Jim ClausingOMFW 2008 reflections
2008-06-12/a>Bojan ZdrnjaSafari on Windows - not looking good
2008-05-17/a>Lorna HutchesonXP SP3 Issues
2008-05-06/a>John BambenekWindows XP Service Pack 3 Released
2008-05-01/a>Adrien de BeaupreWindows XP SteadyState
2008-04-29/a>Bojan ZdrnjaWindows Service Pack blocker tool
2008-04-16/a>William StearnsWindows XP Service Pack 3 - unofficial schedule: Apr 21-28
2007-01-03/a>Toby KohlenbergVLC Media Player udp URL handler Format String Vulnerability

XPSP3

2008-05-17/a>Lorna HutchesonXP SP3 Issues
2008-05-06/a>John BambenekWindows XP Service Pack 3 Released

BSOD

2010-02-19/a>Mark HofmanMS10-015 may cause Windows XP to blue screen (but only if you have malware on it)
2008-05-17/a>Lorna HutchesonXP SP3 Issues