CERT

CERT/CC Blog


2010 Archives

CERT Basic Fuzzing Framework Update

Hi, folks. We've recently updated the CERT® Basic Fuzzing Framework (BFF). The new BFF 1.1 contains new functionality and improves performance.


Continue reading CERT Basic Fuzzing Framework Update

Study of Malicious Domain Names: TLD Distribution

Hello, folks. This post comes to you courtesy of Aaron Shelmire from the Network Situational Awareness team. Aaron writes:

Recently the Network Situational Awareness team at CERT has been researching the characteristics of malicious network touchpoints. The findings of this initial research are very telling as to the true state of security on the internet.


Continue reading Study of Malicious Domain Names: TLD Distribution

CERT Basic Fuzzing Framework

Hi folks. I've been involved in a fuzzing effort at CERT. One of the ways that I've been able to discover vulnerabilities is through "dumb" or mutational fuzzing. We have developed a framework for performing automated dumb fuzzing. Today we are releasing a simplified version of automated dumb fuzzing, called the Basic Fuzzing Framework (BFF).


Continue reading CERT Basic Fuzzing Framework

Top-10 Top Level and Second Level Domains found in Malicious Software

Hello folks.  This post comes to you courtesy of Ed Stoner and Aaron Shelmire from the Network Situational Awareness group at CERT.  They write:

Recently there have been some statistics published on botnet Command & Control (C2) channels. These statistics claim that 94.58% of botnet C2 channels are under the .com top level domain (TLD). While it's impossible to accurately comment on those statistics without knowing the methodology used to arrive at them, we at CERT have been doing research concerning malicious domain names that arrives at a different result.


Continue reading Top-10 Top Level and Second Level Domains found in Malicious Software