Thursday, December 22, 2016

Snort++ Build 223 Available Now on

Snort++ build 223 is now available on  This is the latest monthly update available for download.  You can also get the latest updates from github (snortadmin/snort3) which is updated weekly.

There are too many changes to list here so check the ChangeLog for details.

  • port 2983 smb active response updates
  • add JavaScript normalization to new http_inspect
  • add MIME file processing to new http_inspect
  • add alternate fast patterns for dce_udp endianness
  • add dce auto detect to wizard
Bug Fixes:
  • fix appid service dispatch handling issue
    thanks to João Soares ; for reporting the issue
  • fix paf-type flushing of single segments
    thanks to João Soares for reporting the issue
  • fix modbus_data handling to not skip options
    thanks to for reporting the issue
  • fix comment in snort.lua re install directory use
    thanks to Yang Wang for sending the pull request
  • fix fast pattern selection when multiple designated
    thanks to for reporting the issue
  • fix image sizes to fit page
    thanks to wyatuestc for reporting the issue
  • change -L to -K in README and manual
    thanks to jncornett for reporting the issue
  • fix demonization
    thanks to João Soares for reporting the issue
Other Changes:
  • appid overhaul to address threading issues, leaks, and sanitizer and analyzer issues
  • fix appid pattern matching for http
  • fix reload crash with file inspector
  • fix various race conditions reported by thread sanitizer
  • fix thread termination segfaults after DAQ module initialization fails
  • several build fixes for non-x86, Illumos, and others
  • create pid file after dropping privileges
  • user manual was reorganized and expanded
Please submit bugs, questions, and feedback to or the Snort-Users mailing list.

Happy Snorting!
The Snort Release Team