Friday, April 29, 2011

Pcaprr External DAQ has been posted

Today Jeff Murphy submitted to us another external DAQ module for Snort.  I think his email best describes it:

We use Endace DAG cards in our sensors along with regen taps. Those cards don't work with the bonding driver, so merging the two streams from a regen tap isn't possible (unless we use a different tap or fix the drivers to work together). The attached patch creates a new module in the os-daq-modules directory called "pcaprr.c". This module will open multiple devices and then make round-robin reads from the device list (much like the bonding driver would if it worked with the DAG driver).  Modifications made against DAQ 0.5 code.
Thanks Jeff for your contribution, as with any external additions to Snort, it's great to see the community putting code up!

I've placed Jeff's pcaprr DAQ module on the "External-Daq" page on Snort.org.   Enjoy!

PulledPork makes the cover of Linux Pro magazine!

Our own JJ Cummings of Sourcefire and fellow Snort.org blogger is the author of Snort's PulledPork tool, the best way for keeping your rules up to date, was recently featured in an article in Linux Pro's Magazine.

Here's a picture of the cover, with the PulledPork article circled.


The cover says that there are other Snort-related tools discussed as well in the article, unfortunately, I do not have a copy of the magazine so I don't know which ones they are talking about.

If you have a copy of this edition of Linux Pro Magazine, please feel free to leave a comment and let us know what other tools were discussed!

Congratulations to JJ for all of his hard work to give such a great tool away to help people maintain their rule updates!  Thanks JJ!

Awesome.  As noted in the comments, the article has been posted online at Linux Magazine:
http://www.linuxpromagazine.com/Issues/2011/125/Snort-Helpers

Wednesday, April 27, 2011

VRT Rule Update for 04/27/2011

Just released, is a rule release for today from the VRT. In this release we make modifications to 2 rules.

In VRT's rule release:
The Sourcefire VRT has identified possible issues with two shared
object rules. This release contains modifications to those rules that
fix these potential problems.

Details:
A problem has been identified in a shared object rule identified as GID
3 SID 18676. This problem causes Snort to hang in an infinite loop when
the rule is evaluated.

Mitigation:

1. The set of conditions necessary to cause this rule to enter an
infinite loop require a very unique set of content matches to be
present in the data being processed. In the unlikely event that
these conditions occur, the last content match in the set must not
return true.
2. This set of conditions is very unlikely to occur in normal,
non-malicious network traffic.
3. Additionally, if all the conditions in the rule are met, meaning
that a malicious set of traffic was detected, then the rule works
as expected and the infinite loop does not occur.
4. There are currently no known threats available publicly or in the
wild for this vulnerability.

Upon review of other custom shared object rule code, a similar issue was
found in GID 3, SID 17665. The VRT has pro-actively fixed that rule.

The modifications to GID 3, SIDs 18676 and 17665 are included in this release.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Tuesday, April 26, 2011

VRT Rule Update for 04/26/2011

Just released, is a rule release for today from the VRT. In this release we introduce 41 new rules and make modifications to 11 more.

Also as a request from the Snort Community, at the above link, we have started indicating whether the rule is Enabled or Disabled by default.  The policy you select as part of a PulledPork download (if you are using that feature) does override this.

In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the
blacklist, dos, scada, smtp, specific-threats, spyware-put, sql and
web-misc rule sets to provide coverage for emerging threats from these
technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Thursday, April 21, 2011

VRT Rule Update for 04/21/2011

Just released, is a rule release for today from the VRT. In this release we introduce 12 new rules and make modifications to 37 more.

Also as a request from the Snort Community, at the above link, we have started indicating whether the rule is Enabled or Disabled by default.  The policy you select as part of a PulledPork download (if you are using that feature) does override this.

In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the
backdoor, misc, oracle, policy and web-client rule sets to provide
coverage for emerging threats from these technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Tuesday, April 19, 2011

VRT Rule Update for 04/19/2011

Just released, is a rule release for today from the VRT. In this release we introduce 27 new rules and make modifications to 4410 more.

Also as a request from the Snort Community, at the above link, we have started indicating whether the rule is Enabled or Disabled by default.  The policy you select as part of a PulledPork download (if you are using that feature) does override this.

In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the
attack-responses, backdoor, bad-traffic, blacklist, botnet-cnc, chat,
dns, dos, exploit, imap, misc, mysql, netbios, oracle, policy, scan,
snmp, specific-threats, spyware-put, sql, telnet, tftp, web-activex,
web-cgi, web-client, web-coldfusion, web-frontpage, web-misc and x11
rule sets to provide coverage for emerging threats from these
technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Napatech External DAQ Posted

Just posted this morning, Snort community member and the VP of Product Engineering at nPulse Technologies, Randy Caldejon, submitted this External DAQ module for Snort for use with the Napatech Network Adapters.

To build this requires the Napatech ntcommoninterface library, which is bundled with the purchase of each adapter.

I posted it on the "External DAQ" page, ready for your use.

We received a lot of flak when Sourcefire externalized the DAQ out of Snort, however, this is exact reason that we were hoping for!

I'd like to thank Randy for his hard work on this!

Friday, April 15, 2011

Snort 2.9.0.5 setup on Mac OSX Posted

Christoph Murauer, one of the Snort community has written a series of blog posts (in both German and English!) on his site that detail the setup of Snort 2.9.0.5 on Mac OSX.

As always, Sourcefire or Snort.org does not warrantee these results and we have not tested them, so your milage may vary.

We'd like to thank Christoph for the time it took to write these up, and we look forward to seeing even more Snort users on OSX!

PostgreSQL and pgAdmin 3
http://www.mac.ph/www.mac.ph/Blog/Einträge/2011/3/3_EN_PostgreSQL_9.0.3_and_pgAdmin_3_1.12.2.html

DAQ and Snort
http://www.mac.ph/www.mac.ph/Blog/Einträge/2011/3/9_EN_DAQ_0.5_and_Snort_2.9.0.5_with_snort.org_Rulesets.html

ADOdb and BASE
http://www.mac.ph/www.mac.ph/Blog/Einträge/2011/3/14_EN_ADOdb_5.1.1_and_BASE_1.4.5.html

German :

PostgreSQL und pgAdmin 3
http://www.mac.ph/www.mac.ph/Blog/Einträge/2011/3/2_PostgreSQL_9.0.3_und_pgAdmin_3_1.12.2.html

DAQ and Snort
http://www.mac.ph/www.mac.ph/Blog/Einträge/2011/3/8_DAQ_0.5_und_Snort_2.9.0.5_mit_snort.org_Rulesets.html

ADOdb and BASE
http://www.mac.ph/www.mac.ph/Blog/Einträge/2011/3/11_ADOdb_5.1.1_und_BASE_1.4.5.html

Wednesday, April 13, 2011

First 2011 Snort Webcast has been posted!

Today, April 13, 2011, Nick Moore of our Security Engineering group at Sourcefire presented on the Intro to Installing Snort.  This webcast was recorded and is now available for consumption, along with the rest of the past Webcast recordings over at: http://www.snort.org/webcast_series.

Our next webcast is currently scheduled for May 25, 2011 with John Gay, one of our Instructors from the Education department here at Sourcefire.  I'll be sure and post reminders, but be sure and mark your calendars.

Snort 2.9.0.5 Install Guide for Fedora Core 14 is posted

Nick Moore of Sourcefire strikes again, and he has published his guide for installing Snort 2.9.0.5 on Fedora Core 14.  Thanks Nick!  Great job!

Please see http://snort.org/docs for the complete guide.