Tuesday, April 19, 2011

VRT Rule Update for 04/19/2011

Just released, is a rule release for today from the VRT. In this release we introduce 27 new rules and make modifications to 4410 more.

Also as a request from the Snort Community, at the above link, we have started indicating whether the rule is Enabled or Disabled by default.  The policy you select as part of a PulledPork download (if you are using that feature) does override this.

In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the
attack-responses, backdoor, bad-traffic, blacklist, botnet-cnc, chat,
dns, dos, exploit, imap, misc, mysql, netbios, oracle, policy, scan,
snmp, specific-threats, spyware-put, sql, telnet, tftp, web-activex,
web-cgi, web-client, web-coldfusion, web-frontpage, web-misc and x11
rule sets to provide coverage for emerging threats from these

