Showing posts with label updates. Show all posts
Showing posts with label updates. Show all posts

Wednesday, May 20, 2020

Snort 3 installation guide update for Ubuntu 18 & 19

By Noah Dietrich.

Today, we released Noah's installation guide for the newest version of Snort 3 for Ubuntu 18 and 19. We've provided some highlights below, but you can view the full log of changes, along with a guide of setting up Snort 3 on Ubuntu, here.

Major changes in this release:
  • Tested with Snort 3.0.1 b2
  • Ubuntu 20 LTS support added
  • Ubuntu 19 support removed
  • Removed old environmental variables
  • Added new IP commands to replace ipconfig on Ubuntu 20 
Minor Changes:
  • SafeC updated to 3.5.1
  • Gperftools updated from 2.7.0 to 2.7.90
  • Boost headers updated from 1.71.0 to 1.72.0
  • Hyperscan updated from 5.2.0 to 5.2.1
  • Flatbuffers updated from 1.11 to 1.12
  • Updated openAppId to 12159
  • Replaced community rules with registered rules
  • Updated from Splunk 7.x to Splunk 8.x
  • Configure Splunk startup to use systemD rather than init.
  • Added libcmocka-dev libraries to support DAQ requirements.

Thursday, April 16, 2020

To all PFsense users: Please update your "Rules Update Start Time"

Attention Pfsense users:

We recently were in touch with the package maintainer for Snort on pfsense, to which he was so kind to update the "Rules Update Start Time" to be random on install in version v3.2.9.10_3.

For more information about this update, please check out Bill's forum post here.

This update randomizes the start time of the Rules Update for every installation so that we don't have every installation of pfsense in the world simultaneously hitting Snort.org to check for updates all in the same second. As you can imagine, this causes quite a bit of a traffic spike on the site.

What we'd like is for all pfsense users is to either update their package, or to change the "Rules Update Start Time" entry to some random minute in the hour.  Obviously not all at :15, :30 or :45, but pick a more random time.

This will help up tremendously to load balance out the amount of traffic headed to Snort.org.


Friday, October 11, 2019

Snort document updates

A couple updates to SNORTⓇ installation guides for Snort 3 have hit our documentation page, and we want to take a minute and personally thank the community members that spend their time writing documentation, quality checking it, testing it, and putting it out there with their name attached to it — all in the interest of making the Snort community a better place.

So, thanks go to the following individuals:

  • Noah Dietrich
  • Yaser Mansour
  • Milad Rezaei

First, we have an updated guide to Snort 2.9.14.1 on CentOS. This guide should work fine for our recently posted 2.9.15.0 release, simply by changing "2.9.14.1" to "2.9.15" where appropriate.

Next, there's an updated guide to Snort 3 installation on CentOS 8.

And we updated the guide to Snort 3 installation on Ubuntu 18 & 19.

As a reminder, our setup and installation guides can be found on Snort's documentation page under "Snort Setup Guides." While you are there, feel free to check out all the other documentation, such as Deployment Guides, startup scripts, and the official Snort manual.

Thursday, November 8, 2018

Snort rule update for Nov. 8, 2018

Just released:
Snort Subscriber Rule Set Update for Nov. 8, 2018

We welcome the introduction of the newest rule release from Talos. In this release, we introduced 60 new rules, four of which are shared object rules. There are also three modified rules, of which one is a shared object rule.

This update contains coverage for the recently discovered GreyEnergy malware, which is believed to be the successor to the BlackEnergy attack.

There were no changes made to the snort.conf in this release.

Talos's rule release:
Talos has added and modified multiple rules in the file-other, indicator-obfuscation, malware-cnc, protocol-voip and server-webapp rule sets to provide coverage for emerging threats from these technologies.
You can subscribe to Talos' newest rule detection functionality for as low as $29 a year with a personal account. Be sure and see our business pricing as well here. Make sure and stay up to date to catch the most emerging threats.

Thursday, October 25, 2018

Snort rule update for Oct. 25, 2018

Just released:
Snort Subscriber Rule Set Update for Oct. 25, 2018

The newest SNORTⓇ rule release from Cisco Talos is here. In this release, we introduced 19 new rules, two of which are shared object rules. There are also two modified shared object rules.

This release provides coverage for an out-of-bounds write flaw in the processing of Vorbis audio data, as well as a vulnerability in the Simple Network Management Protocol input packet processor of Cisco NX-OS Software.

Tuesday, October 9, 2018

Snort rule update for Oct. 9 — Microsoft Patch Tuesday

Just released:
Snort Subscriber Rule Set Update for Oct. 9, 2018

The newest SNORTⓇ rule set from Cisco Talos is here, covering the numerous vulnerabilities disclosed as part of Microsoft Patch Tuesday.

In this release, we introduced 29 new rules, of which four are shared object rules. There are no modified rules.

If you would like to know more about the monthly security update from Microsoft, visit the Talos blog here.

There were no changes made to the snort.conf in this release.

Talos's rule release:
Microsoft Vulnerability CVE-2010-3190: A coding deficiency exists in MFC that may lead to remote code execution.

Previously released rules will detect attacks targeting these vulnerabilities and have been updated with the appropriate reference information. They are also included in this release and are identified with GID 1, SIDs 18619 through 18623 and 18625 through 18629.

Microsoft Vulnerability CVE-2018-8333: A coding deficiency exists in Microsoft Filter Manager that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 48055 through 48056.

Microsoft Vulnerability CVE-2018-8411: A coding deficiency exists in NTFS that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 48057 through 48058.

Microsoft Vulnerability CVE-2018-8413: A coding deficiency exists in Microsoft Windows Theme API that may lead to remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 48059 through 48060.

Microsoft Vulnerability CVE-2018-8423: A coding deficiency exists in Microsoft JET Database Engine that may lead to remote code execution.

Previously released rules will detect attacks targeting these vulnerabilities and have been updated with the appropriate reference information. They are also included in this release and are identified with GID 1, SIDs 47885 through 47888.

Microsoft Vulnerability CVE-2018-8453: A coding deficiency exists in Microsoft Win32k that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 48072 through 48073.

Microsoft Vulnerability CVE-2018-8460: Microsoft Internet Explorer suffers from programming errors that may lead to remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 48045 through 48046.

Microsoft Vulnerability CVE-2018-8486: A coding deficiency exists in DirectX Graphics Kernel that may lead to information disclosure.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 48047 through 48048.

Microsoft Vulnerability CVE-2018-8491: Microsoft Internet Explorer suffers from programming errors that may lead to remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 48049 through 48050.

Microsoft Vulnerability CVE-2018-8492: A coding deficiency exists in Microsoft Device Guard that may lead to a security feature bypass.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 48062 through 48063.

Microsoft Vulnerability CVE-2018-8495: A coding deficiency exists in Microsoft Windows Shell that may lead to remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 48053 through 48054.

Microsoft Vulnerability CVE-2018-8505: A coding deficiency exists in Microsoft Chakra Scripting Engine that may lead to remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 48051 through 48052.

Talos also has added and modified multiple rules in the browser-ie, file-executable, file-other and server-webapp rule sets to provide coverage for emerging threats from these technologies.
In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 U.S. a year for personal users. Be sure and see our business pricing as well at https://snort.org/products#rule_subscriptions. Make sure and stay up to date to catch the most emerging threats.

Friday, December 9, 2016

Snort 2.9.9.0 is prepping for release!

We're preparing for our newest release of Snort, version 2.9.9.0.

As always, I try to let you all know as soon as I can on major version upgrades, as the release of 2.9.9.0 will activate the 90 day EOL trigger for 2.9.7.6.  Since 2.9.7.6 is what we consider our Long Term Support or "LTS" version, and there are about 150,000 users on this version, there are a ton of people that need to upgrade.

Snort 2.9.8.3 will take over as our LTS version as 2.9.9.x marches forward, and as always, we encourage people to stay on the most current version.

Snort 2.9.7.6 was released September 30th of 2015, with no less than 144 rule updates in that year.

So, for those of you on 2.9.7.6, if you do not want to move to the "edge" version of Snort (2.9.9.x) when it is released, I suggest you start moving to 2.9.8.3 now.

Following an upgrade and prior to turning off support, I'll send out an email to all the people who are downloading older versions of Snort rules, and encourage them to upgrade.

Start your upgrades!

Monday, September 16, 2013

Snort 2.9.5.5 is now available on Snort.org

Snort 2.9.5.5 is now available on Snort.org!

https://www.snort.org/downloads in the Latest Release section.


2013-09-12 - Snort 2.9.5.5

[*] Improvements
* Address issue with SMTP preprocessor and the ignore_tls_data configuration
to correctly stop inspection after an SMTP session is encrypted.  
(Thanks Bram!)

* Disable all rule evaluation (as opposed to just rules with fast patterns)
for packets on a previously blocked session.

* Corrected when perfmon preprocessor writes stats to occur as soon as
both the time and packet count criteria are met.

* Enforce same restrictions on relative PCRE for HTTP buffers from
shared library rules as already existed with text rules.


Please submit bugs, questions, and feedback to bugs@snort.org.


Happy Snorting!

The Snort Release Team

Tuesday, July 30, 2013

Snort 2.9.5.3 is now available!

Snort 2.9.5.3 is now available on snort.org, at https://www.snort.org/downloads in the Latest Release section.

2013-07-30 - Snort 2.9.5.3

[*] Improvements
* Performance improvements to eliminate some unnecessary work, reduction
of sizes of data structures, and cleanup of processing for HTTP
normalized buffers.


* Cap the number of expected connections (eg FTP data channel) to
prevent memory growth


* Address issue with reloading reputation lookup tables when more
addresses are added.


* Address issue with potential hang during shutdown of control socket
config reload processing thread.


See the Release Notes and ChangeLog for more details.

Please submit bugs, questions, and feedback to bugs@snort.org.

Happy Snorting!
The Snort Release Team

Monday, July 1, 2013

Snort Manual has been updated to 2.9.5.0

The PDF documentation available at http://www.snort.org/docs as well as the HTTP manual at http://manual.snort.org have been updated to Snort 2.9.5.0.

Tuesday, May 14, 2013

Barnyard v.2.1-13 has been released!

We are happy to announce the latest STABLE release v2.1-13 which was tagged a few hours ago (https://github.com/firnsy/barnyard2/tags)

This release is a bug fix release that also introduce a few new features and enhancements.


UPGRADE REQUIREMENTS

If you are upgrading to barnyard2 2-1.13 (build 327) or above from a previous version and using output database.

You will need to delete every row in your sig_reference table. (DELETE FROM sig_reference;)

The table will be re-populated at startup, and has no impact on historical data.


FEATURE REQUESTS
Phil Daws - add interface and hostname field to spo_alert_csv if specified.
Jorge Pinto - spo_syslog_full support for ASCII,BASE64 payload
Jason Brvenik - variables ... (a long time ago, sorry :P)
Martin Olsson - remove some useless verbosity unless ./configure --enable-debug is specified and proper flag are used (spo_database and sid-msg.mapv2)
All other barnyard2 users who help and contribute.

BUG REPORTS
Martin Olsson - bug in sig_reference generation and good discussions. Rewrote the code & al
John Eure and others - autogen.sh could cause some issue on some system so [autoreconf -fv --install] is not set to autoreconf -fvi
John Naggets - spo_database: could stop barnyard2 from processing new event if some packets with ip option where processed and option_len was null.
Fäbu Hufi - spo_syslog_full: in complete mode was printing wrong ip version information and ip header length.
Jeremy Hoel - identified issue with suppression range in 2-1.13-BETA (fixed in release)
Bill Green - identified is with signature insertion mainly preprocessor in 2-1.13-BETA (fixed in release)
All other barnyard2 users who help and contribute.

NEW FEATURES
1. Support for sid-msg.map version 2 format.

A new sig-msg.map format can be generated by pulledpok (upcomming release, already in svn).

Detection of sid-msg.map version is done by a simple header in the file that shouldn't be altered if you want it to be processed correctly.

The sig-msg.map version 2 format extends the information already present in the sid-msg.map file created from rules.

This new format version allow signature pre-population if users are using output database method with barnyard2 2-1.13 and above.


sid-msg.map v1 format:

SID || MSG || REF 1 || REF N

sid := integer
msg := string
ref := string

sid-msg.map v2 format:

GID || SID || REV || CLASSIFICATION || PRIORITY || MSG || REF 1 || REF N

gid := integer
sid := integer
rev := integer
classification := string (if NULL set to NOCLASS)
priority := integer (if prio == 0, classification priority is used)
msg := string
ref := string

=====================
generator (GID, gen-msg.map) are defaulted to the following value
if their information is not overruled in sid-msg.map v2 file via processing of preprocessor.rules:

revision 1
classification 0
priority 3

If generator message is present in the sid-msg.map v2 file, and gen-msg.map message are longer
(more comprehensive by string length),
gen-msg.map messages are used instead of sid-msg.map v2 file generator messages.
=====================


2. Signature/event logging suppression at spooler level.

Read doc/README.sig_suppression


3. Configuration file variables.

You can now use [var VARNAME value] in the barnyard2 configuration file and every instance of $VARNAME will get replaced by value.

Note that variable declaration order is important only you include a variable with in a variable.

EX (is VALID):
var INTERFACE ethX
var PATH /var/log/IDS
var LOG $PATH/$INTERFACE/log
var ARCHIVE $PATH/$INTERFACE/archive

EX (is INVALID):
var LOG $PATH/$INTERFACE/log
var ARCHIVE $PATH/$INTERFACE/archive
var INTERFACE ethX
var PATH /var/log/IDS


4. New output database configuration keyword.

Keywords connection_limit and reconnect_sleep_time where added in 2-1.10 but where "undocumented" and shouldn't be modified unless you encounter an issue.

connection_limit : default 10
The maximum number of time that barnyard2 will tolerate a transaction faillure and or database connection failure.

reconnect_sleep_time : default 5
The number of seconds to sleep betwen connection retry.

disable_signature_reference_table
Tell the output plugin not to synchronize the sig_reference table in the schema.

Note: This option will speedup the process, especialy if you use sid-msg.mapv2 file or have alot of signature already in databases. (Make sure that you do not need that information before enabling this)


So we hope you enjoy the new release, as a side note the RELEASE.NOTES file has not been updated and will be removed in the next version. It's honestly the most laborious part of release time ;)

Regards,

The barnyard2 team.

Wednesday, April 24, 2013

Snort 2.9.4.6 has been released!

Snort 2.9.4.6 is now available on snort.org, at
https://www.snort.org/downloads in the Latest Release section.

Snort 2.9.4.6 includes changes for the following:

[*] Improvements

* Improved support for DAQ verdicts of whitelist and blacklist for 6in4 and 4in6 encapsulated traffic (similar to Teredo & GTP). See the Snort manual for configuration details.

* Avoid changing the length of IP options in frag3 when receiving duplicate 0-offset fragments that have IP options.

See the Release Notes and ChangeLog for more details.

Please submit bugs, questions, and feedback to bugs@snort.org.

Happy Snorting!
The Snort Release Team

Friday, April 5, 2013

Snort 2.9.4.5 install docs have been updated!

Thanks to William Parker, again, working tirelessly until his documentation is updated, I just posted all the 2.9.4.5 install docs that he makes, now available at the only official Snort Documentation site.

There are docs for the following Operating Systems:


  • CentOs 6.x
  • NetBSD 6.0
  • NetBSD 5.1.x
  • Fedora 17
  • Fedora 18
  • OpenSuSE 14
  • OpenSuSe 12
  • FreeBSD 8.2
  • FreeBSD 9.0
  • OpenBSD 5.1

Wednesday, April 3, 2013

Snort 2.9.4.5 is now available

Snort 2.9.4.5 is now available on snort.org, at
https://www.snort.org/downloads in the Latest Release section.

******
Please Note:
We understand that there may be some confusion by moving from 2.9.4.1
to 2.9.4.5, and we apologize for that. We are aligning our internal
build numbers with our open source build versions to make versioning
and distribution easier on the backend. This will help us in ensuring
that the correct versions of rules are available for the supported
versions of Snort.
******

Snort 2.9.4.5 includes changes for the following:

[*] Improvements

* Removed proxy information from HTTP URI searching so that the URI
matches are just on the actual URI so that offsets work as expected.

Thanks to L0rd Ch0de1m0rt for reporting the issue.


* Addressed an issue when logging of packet data via unified2 when
alerting on a packet with multiple HTTP PDUs.

* Continue to search for patterns within the HTTP URI until the end of
the URI.

See the Release Notes and ChangeLog for more details.

Please submit bugs, questions, and feedback to bugs@snort.org.

Happy Snorting!
The Snort Release Team

Monday, March 4, 2013

Snort 2.9.4.1 has been released!

We are pleased to announce the immediate availability of Snort 2.9.4.1.

The following is an excerpt from the ChangeLog detailing the changes:

[*] Improvements

* Updated File processing for partial HTTP content and MIME attachments.
* Addition of new config option max_attribute_services_per_host and improve memory usage within attribute table.
* Handle excessive overlaps in frag3.
* Stream API updates to return session key for a session.
* Reduce false positives for TCP window slam events.
* Updates to provide better encoding for TCP packets generated for respond and react. 
* Disable non-ethernet decoders by default for performance reasons. If needed, use --enable-non-ether-decoders with configure.

Snort 2.9.4.1 can be downloaded immediately at: https://www.snort.org/downloads

Thanks for your support of Snort!

Wednesday, December 5, 2012

Snort 2.9.4.0 Installation Guides now posted

Thanks to the tremendous work of our Snort Community, I've posted new install guides for Snort 2.9.4.0 to the website.

These individuals start working on the install guides early on in the process, testing our beta releases, RC code, and finally, retesting when we do the final release.

The Snort Team would like to thank Jason Weir and William Parker for their dedication to keeping their docs current and also for allowing us to host the docs for them.

Please feel free to link to the install guides on Snort.org.  They are there for you!

Check out the new guides here: http://www.snort.org/docs

They are posted for:

  • Fedora 17
  • OpenBSD 5.1
  • Debian 6.0.6
  • OpenSuSE 12.1
  • FreeBSD 8.2
  • FreeBSD 9.0
  • CentOS 6.3

If you'd like to submit Snort documentation for official hosting on the Snort.org website, please send it to me here: joel [at] snort [dot] org.

Thanks!

Joel Esler
Senior Research Engineer, VRT
OpenSource Community Manager
Sourcefire

Wednesday, October 24, 2012

Snort 2.9.4 RC Now Available!

Snort 2.9.4 RC is now available on snort.org, at
https://www.snort.org/downloads in the Latest Release section.

Snort 2.9.4 includes changes for the following:

[*] New additions

 * Consolidation of IPv6 -- now only a single build supports both IPv4 & IPv6, and removal of the IPv4 "only" code paths.

 * File API and improvements to file processing for HTTP downloads and email attachments via SMTP, POP, and IMAP to facilitate broader file support

 * Use of address space ID for tracking Frag & Stream connections when it is available with the DAQ

 * Logging of packet data that triggers PPM for post-analysis via Snort event

 * Decoding of IPv6 with PPPoE

[*] Improvements

 * Update to Stream5 PAF for handling gaps in the sequence numbers of packets being reassembled.

 * Selection of the Stream TCP policy based on the server rather than the destination of first packet seen by Snort

 * Allow disabling of global thresholds via a count of -1

 * Prevent blocking duplicate SYNs when using inline normalization

 * Add SSLv3 backwards compatibility support for SSLv2 ClientHello messages

 * Allow active responses to packets without data (eg, a TCP SYN)

 * Changed logic of option evaluations for shared library rules that use a custom evaluation function to match that of the builtin logic when the NOT_FLAG is used.  The 'NOT' matching now happens within each of the individual rule option evaluation functions.

Please see the Release Notes and ChangeLog for more details.

Please submit bugs, questions, and feedback to bugs@snort.org.

Happy Snorting!
The Snort Release Team

Tuesday, September 25, 2012

Barnyard2 - v2-1.10 has been released

It's my great pleasure to finally announce the next stable release of barnyard2 v2-1.10 build(310).

After almost 20 months of development and continuous testing from the community we are happy to get this one out to the masses (without the beta tag).

This development cycle has seen a lot of changes, refinements and fixes. This will be the last version build arround the old database schema.

The next release of barnyard2 will come with new database output that only support the new schema, native IPv6 support and FULL unified2 support for all output plugin.

I could go on about the changes, but the wait has been long enough. Here's a summary of the more notable changes:
 * Additions
 - spo_database. Support of encrypted connections to postgresql is now available. See README.database for the appropriate options.
 - spo_sguil. Fixed issue with duplication of alerts.
 - Completely re-written database plugin for performance optimisation against the original DB schema. 
NOTE: If you have intentions of running this new version we highly recommended you to clean two databases table for better performance: reference and sig_reference, not doing so will not break anything but could slow the startup caching process).
 - New Bro output plugin (thanks to Seth Hall)
 - A new syslog plugin (syslog_full) that support local and remote TCP and UDP syslog. * Improvements
 - Improved support against the latest Unified 2 format. Extended headers are read, however no plugins use the information currently.
 - Improved core IPv6 support.
 - Compile under cygwin
 - And many, many bugfixes.

 You can download the source in a number of ways:
 - https://github.com/firnsy/barnyard2/tags (as a zip/tarball)
 - git://github.com/firnsy/barnyard2.git (via a git clone)

 I would like to pay a special thanks to Eric Lauzon (the newest member of the core development team) and the many people who have helped along the road: Russell Fulton, Tim Shelton, JJ Cummings. Michael Steele, Brett Edgar, Bill Parker, Miguel Alvarez, Martin Holste, Jason Haar and any others who I may have missed.

Regards,

firnsy

Friday, July 20, 2012

Snort 2.9.3.0 on Debian install guide has been posted

Thanks to Jason Weir, I just posted his Snort 2.9.3.0 Install Guide for Debian 6.0.5.

You may find his updated guide at http://www.snort.org/docs.  We'd like to thank Jason Weir and the rest of the Snort community with their constant support, guides, bug reports, false positive reports, and participation in the mailing lists.

You all are fantastic!

Thanks Jason!

Thursday, June 14, 2012

Sourcefire VRT Certified Snort Rules Update for 06/13/2012

Just released: Sourcefire VRT Certified Snort Rules Update for 06/13/2012

We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 16 new rules and made modifications to 204 additional rules.

There were no changes made to the snort.conf in this release.

In VRT's rule release:
Synopsis: This release adds and modifies rules in several categories. 
Details: The Sourcefire VRT has added and modified multiple rules in the backdoor, botnet-cnc, dns, dos, exploit, file-identify, file-office, file-other, file-pdf, imap, indicator-compromise, misc, mysql, netbios, oracle, policy, policy-other, policy-social, pop3, server-mail, specific-threats, sql, telnet, web-activex and web-misc rule sets to provide coverage for emerging threats from these technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!