R-fx Networks

 Linux Software & Blog

RSS Feeds

  • Home
  • Development
  • HowTo
  • My Blog
  • Projects
    • Advanced Policy Firewall
    • Brute Force Detection
    • Incremental rsync
    • Linux Environment Security
    • Linux Malware Detect
    • Linux Socket Monitor
    • Network Socket Inode Validation
    • Process Resource Monitor
    • System Integrity Monitor
    • System Priority
  • About Us

I am Back: Signature Updates

Jun 24th

Posted in Development

1 comment

I am back, fresh off a trip home to Montreal, which I must say was an absolutely amazing time. It has left me reflecting on allot of things, most importantly that there really is no place like home — I miss Montreal more than I can even describe. That said though, time to get back into the mix of things — there is a mountain of malware submissions to review, 91 to be exact. Today I really could not find the energy or time to go through them all but I did process the edge IPS data to extract some More >

lmd, malware

Facebook Inbox Message Disclosure Vulnerability

Jun 23rd

Posted in My Blog

No comments

Title: Facebook Inbox Message Disclosure Vulnerability Published: June 24th 2010 Credit: Ryan MacDonald Severity: Information/Privacy Disclosure Vulnerable: Facebook Messaging System BigPipe Performance Pipelining Summary: A vulnerability exists in facebooks messaging system that allows an attacker to view the addressed users, subject and inbox preview text (120 characters) of message contents for recently sent/received messages (last 6) on a users account. Technical Details: BigPipe Pipeling java script code embedded into the source code of ALL PAGES under the “messages” section on facebook, preloads message data that can be arbitrarily read through malicious client side java script or other client side objects. The offending java script specifically is the More >

disclosure, facebook, vulnerability

rfxn.com In Numbers

May 27th

Posted in Development

No comments

Yup, nothing to see here except numbers…

2,018: Downloads of the newest project, Linux Malware Detect, month to date. 2,294: Signatures for Linux Malware Detect. 6,207: Downloads for all projects for the month to date. 14,176: Google results with link backs to rfxn.com or related domains (i.e: r-fx.org, rfxn.org etc..). 30,061: Active APF installations relative to unique IP’s fetching the reserved.networks file daily. 70,826: Project downloads for the last 12 months, May 2009 – April 2010. 133,931: Total visitor session to rfxn.com, month to date. 258,154: The number of web sites protected by APF (passed unique install IP’s to domainsbyip.com). 1,231,604: Total hits to rfxn.com, month to date.

More >
apf, projects

Linux Malware Detect v1.3.6: Loose Ends

May 24th

Posted in Development

No comments

In LMD 1.3.3 there was allot of changes, 29 to be exact, that made LMD much more robust and especially the monitoring component, much more usable. If that release was about making good things better, then this release is about bringing loose ends together. I spent a couple of days running LMD through its paces along with having many people help me test it and during that process, we brought allot of little things to the surface that needed fixing or revising.

In total, there has been 31 changes, fixes or new additions to LMD since that 1.3.3 release on the More >

bugs, linux, lmd, malware, projects

Let The Rewrites Begin: New Life For PRM

May 24th

Posted in Development

No comments

In my last post, I reflected on the last 7-8 years of projects here at rfxn.com, in doing so I also dug up some statistics on project downloads. I not only did this for my own curiosity but to prioritize the mile long to do list I have for the projects, based on downloads. One of the revealing things was just exactly what people are downloading, in particular that projects like LES , PRM & SIM are still very popular download destinations on the site.

Although a new incarnation of APF & BFD are on the agenda, I thought I would More >

apf, bsd, linux, prm, projects
«12345»...Last »
    • Recent comments
    • Popular posts
    • Archives
    • Tags
    apache apf arin atf backup bfd bogon bsd bugs centos data recovery disclosure facebook incremental ips linux lmd malware nginx prm projects r1soft rsync snort ssh upgrade vulnerability
    • July 2010 (4)
    • June 2010 (3)
    • May 2010 (12)
    • October 2009 (3)
    • June 2009 (1)
    • April 2009 (1)
    • March 2009 (2)
    • Upgrade CentOS 4.8 to 5.3 (9)
    • Linux Malware Detectection (7)
    • Nginx: Caching Proxy (3)
    • (ATF) Aggregate Threat Feed (2)
    • BFD 1.4: Important Security Fix (2)
    • The Test Of Time: 7 Years & Counting… (2)
    • Snorting the Web Farm (1)
    • Out with the old, In with the new! (1)
    • Better Late Than Never: Linux Malware Detect 1.3 (1)
    • Linux Malware Detect v1.3.3: Making good things better (1)
    • Alexander: I'am just made a small donation, and I'll do it again when it will be possible. Your project is...
    • OpenSSH Server Best Security Practices « Otisplus's Blog: [...] Brute Force Detection A modular shell script for parsing application logs and checking for...
    • Mark McKinstry: The Interworx control panel integrates APF and SIM:...
    • Ryan M.: Mike, I made a change to the functions file that I think should fix this, if you are running the...
    • Protect Your Server with APF Firewall: [...] from experience that some solutions are easier, more secure, and more affordable than others....
    • Mike: Hi Ryan, I've been a long time user of APF. I am currently trying to install it with RAB in an...
    • Ryan M.: If you are looking for generic flood protection from SYN/CONNECTION based flooding of port...
    • Mike: Faizan: Hello i did not see antidos feature in APF also did not find ad directory in apf i...
  • Donations

    Read why donations are important!

  • Downloads

     Looking for one of our tools to download?  Check out the Projects page.

    Quick Links: APF | BFD | SIM | IRSYNC | LMD | LES

     Downloads (to date): 663553
     Downloads (month): 6341
  • RSS LMD Malware Updates

    • perl.ircbot.plasa.70.HEX
      Sat, 24 Jul 2010 16:44:36 UTC
    • perl.ircbot.genol.274.MD5
      Sat, 24 Jul 2010 16:44:36 UTC
    • perl.ircbot.fx29.222.MD5
      Sat, 24 Jul 2010 16:44:36 UTC
    • web.malware.unclassed.610.MD5
      Sat, 24 Jul 2010 16:44:35 UTC
    • php.pktflood.unclassed.248.HEX
      Sat, 24 Jul 2010 16:44:35 UTC
    • web.malware.unclassed.602.MD5
      Sat, 24 Jul 2010 16:44:34 UTC
    • perl.ircbot.plasa.310.MD5
      Sat, 24 Jul 2010 16:44:33 UTC
    • php.pktflood.unclassed.539.MD5
      Sat, 24 Jul 2010 16:44:32 UTC
    • web.malware.unclassed.592.MD5
      Sat, 24 Jul 2010 16:44:32 UTC
    • perl.ircbot.plasa.309.MD5
      Sat, 24 Jul 2010 16:44:32 UTC
  • RSS BugTraq Updates

    • Vuln: Mundi Mail Multiple Remote Command Execution Vulnerabilities
    • Vuln: Oracle Java SE and Java for Business Unspecified Vulnerabilities
    • Vuln: Oracle Java SE and Java for Business CVE-2010-0848 Remote Java 2D Vulnerability
    • Vuln: Oracle Java Runtime Environment 'JPEGImageEncoderImpl' Remote Heap Buffer Overflow Vulnerability
    • Bugtraq: [security bulletin] HPSBUX02556 SSRT100014 rev.2 - HP-UX Running rpc.ttdbserver, Remote Execution of Arbitrary Code
    • Bugtraq: CFP NcN 2010
    • Bugtraq: PBBooking 1.0.4_3 Joomla Component Multiple Blind SQL Injection
    • Bugtraq: [ MDVSA-2010:142 ] openldap
    • More rss feeds from SecurityFocus
Mystique theme by digitalnature | Powered by WordPress
RSS Feeds XHTML 1.1 Top