As I mentioned back in this post: http://blog.snort.org/2012/07/2921-eol-notice.html, 2.9.2.2 is now End of Lifed for support and will be removed from future VRT builds.
For further details on our EOL policy, please see: https://www.snort.org/eol
Friday, August 24, 2012
Thursday, August 23, 2012
Sourcefire VRT Certified Snort Rules Update for 08/23/2012
Just released:
Sourcefire VRT Certified Snort Rules Update for 08/23/2012
We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 16 new rules and made modifications to 71 additional rules.
There were no changes made to the
In VRT's rule release:
In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!
Sourcefire VRT Certified Snort Rules Update for 08/23/2012
We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 16 new rules and made modifications to 71 additional rules.
There were no changes made to the
snort.conf in this release.In VRT's rule release:
Synopsis:
This release adds and modifies rules in several categories.
Details:
The Sourcefire VRT has added and modified multiple rules in the
botnet-cnc, dos, file-office, file-other, netbios, scada, smtp,
specific-threats, spyware-put, voip and web-misc rule sets to provide
coverage for emerging threats from these technologies.
In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!
Wednesday, August 22, 2012
Autosnort v1 for Ubuntu 12.04 released
Hello Snort Users!
My name is Tony Robinson, and I often go by da_667 as my handle in cyberspace. Are you sick and tired of people telling you how snort is so hard to set up? That all that work isn’t worth it? How it is pain to gather all the packages, read the (very) well put together documentation or download all the different parts to get a full-blown snort install working? Well, I would like to introduce a little project I’m working on called Autosnort.
Autosnort is a simple script written in bash that will take an Ubuntu 12.04 system (32 or 64-bit) and essentially follow David Gullett’s Ubuntu 12.04 snort installation guide from base install to finish – It installs snort 2.9.3 (can easily be modified to install 2.9.3.1), barnyard 2 and snort report automagically. If you provide the install with a snort rules snapshot tarball that is compatible with the snort release (e.g. snortrules-snapshot-2930.tar.gz – registered user or subscriber edition) the script will copy the 32 or 64-bit Ubuntu precompiled rules (as appropriate) and modify snort.conf to use them. The script will configure the interface you will be running snort against to be brought up at boot and will configure snort and barnyard to run at startup as well. This script will take you from 0 to a full snort in less than an hour!
All you have to do is download the script, run chmod u+x against the script (to make it executable) then run the script as root (sudo su – then ./autosnort.sh or sudo ./autosnort.sh) and follow the on-screen prompts as they come up. The script verifies you ran it as the root user, confirms internet connectivity, confirms it is being ran on Ubuntu 12.04, then goes through the entire install process, ending with a recommendation to reboot the system to apply system updates and changes.
This script is only the beginning. I have a massive to-do list that involves porting the script to run on Debian, CentOS/Redhat, Backtrack 5r2 and r3 in addition to various feature enhancements such as automated inline mode configuration, selection of alternate web frontends (i.e. BASE and snorby in addition to snort report), a barebones, no mysql, no web front-end, syslog only (intended for SIEM integration) configuration, and pulled pork integration in addition to other plans.
If this script sounds like something you are interested in, I’m releasing it as an open-source project under the MIT license at github. So if you want to take a copy of the code and get autosnort to drop a snort install on Gentoo or GNU/HURD by all means, I would love to see it! My e-mail address is deusexmachina667@gmail.com and my twitter is @da_667 happy snorting!
Labels:
snort
Sourcefire VRT Certified Snort Rules Update for 08/21/2012
Just released:
Sourcefire VRT Certified Snort Rules Update for 08/21/2012
We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 20 new rules and made modifications to 6 additional rules.
There were no changes made to the
In VRT's rule release:
In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!
Sourcefire VRT Certified Snort Rules Update for 08/21/2012
We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 20 new rules and made modifications to 6 additional rules.
There were no changes made to the
snort.conf in this release.In VRT's rule release:
Synopsis:
This release adds and modifies rules in several categories.
Details:
The Sourcefire VRT has added and modified multiple rules in the
botnet-cnc, dns, dos, exploit, indicator-obfuscation, oracle, sql,
web-attacks, web-client and web-php rule sets to provide coverage for
emerging threats from these technologies.
In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!
Friday, August 17, 2012
Sourcefire VRT Certified Snort Rules Update for 08/17/2012, DistTrack, Shamoon
Just released:
Sourcefire VRT Certified Snort Rules Update for 08/17/2012
We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 28 new rules and made modifications to 3 additional rules.
There were no changes made to the
In VRT's rule release:
In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!
We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 28 new rules and made modifications to 3 additional rules.
There were no changes made to the
snort.conf in this release.
In VRT's rule release:
This release provides protection against DistTrack/Shamoon's lateral movement across the network via SMB.
In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!
Sourcefire VRT Certified Snort Rules Update for 08/16/2012, DistTrack, Shamoon
Released last night:
Sourcefire VRT Certified Snort Rules Update for 08/16/2012
We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 12 new rules and made more than 2000 modifications to additional rules.
There were no changes made to the
In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!
We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 12 new rules and made more than 2000 modifications to additional rules.
There were no changes made to the
snort.conf in this release.In this release we provided coverage for the DistTrack/Shamoon Trojan, along with a ton of performance and detection related improvements.
In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!
Thursday, August 16, 2012
Sourcefire VRT Certified Snort Rules Update for 08/15/2012
Just released:
Sourcefire VRT Certified Snort Rules Update for 08/15/2012
We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 45 new rules and made modifications to 14 additional rules.
There were no changes made to the
In VRT's rule release:
In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!
Sourcefire VRT Certified Snort Rules Update for 08/15/2012
We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 45 new rules and made modifications to 14 additional rules.
There were no changes made to the
snort.conf in this release.In VRT's rule release:
Synopsis:
This release adds and modifies rules in several categories.
Details:
The Sourcefire VRT has added and modified multiple rules in the
botnet-cnc, deleted, file-identify, file-office, file-other, file-pdf,
smtp, specific-threats, spyware-put, web-activex and web-misc rule sets
to provide coverage for emerging threats from these technologies.
In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!
Tuesday, August 14, 2012
Sourcefire VRT Certified Snort Rules Update for 08/14/2012, MS Tuesday
Just released:
Sourcefire VRT Certified Snort Rules Update for 08/14/2012
We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 51 new rules and made modifications to 1109 additional rules.
There were no changes made to the
In VRT's rule release:
In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!
Sourcefire VRT Certified Snort Rules Update for 08/14/2012
We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 51 new rules and made modifications to 1109 additional rules.
There were no changes made to the
snort.conf in this release.In VRT's rule release:
Synopsis:
The Sourcefire VRT is aware of multiple vulnerabilities affecting
products from Microsoft Corp.
Details:
Microsoft Security Bulletin MS12-052:
Microsoft Internet Explorer contains programming errors that may allow
a remote attacker to execute code on an affected system.
Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 23834, 23835, 23836,
23840 and 23841.
Additionally, a previously released rule identified with GID 1, SID
16506 will also detect attacks.
Microsoft Security Bulletin MS12-053:
Microsoft Remote Desktop contains a programming error that may allow a
remote attacker to execute code on an affected system.
A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 1, SID 23846.
Microsoft Security Bulletin MS12-054:
Some Microsoft Windows Networking Components contain programming errors
that may allow a remote attacker to execute code on an affected system.
Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 3, SID 23847 and GID 1, SIDs
23837, 23838 and 23839.
Microsoft Security Bulletin MS12-056:
The Microsoft JScript and VBScript scripting engines contain
programming errors that may allow a remote attacker to execute code on
an affected system.
Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 23840 and 23841.
Microsoft Security Bulletin MS12-057:
Microsoft Office contains a programming error that may allow a remote
attacker to execute code on an affected system.
Previously released rules, identified with GID 1, SIDs 18200 and 19156
will detect attacks targeting this vulnerability.
Microsoft Security Bulletin MS12-059:
Microsoft Visio contains a programming error that may allow a remote
attacker to execute code on a vulnerable system.
Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 23842 and 23843.
Microsoft Security Bulletin MS12-060:
Microsoft Windows Common Controls contain programming errors that may
allow a remote attacker to execute code on a vulnerable system.
Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 23844 and 23845.
In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!
Friday, August 10, 2012
Historical Archive of Snort Code is available
Recently on the Snort Mailing lists a request was made for the historical archive of the Snort code. So after pulling from several different areas I've assembled as much as I can (on a Friday) here:
Specifically:
There is a directory in there called "Old stuff you shouldn't use".
Seriously, you shouldn't use it. It's there for historical archive as requested.
I'll keep this up moving forward when there's a new release. Some versions missing in there, and I'm working to get those versions up as soon as possible. (Have to go to the backup tapes!)
Sourcefire/Snort/VRT's stance on support does not change, however. https://www.snort.org/eol These are the versions we support. We want people to upgrade because of features, bug fixes, and a plethora of other things. If you write in for support for an older version of Snort, we may be able to help you, but most likely you are going to be asked to Upgrade.
You simply would not believe the amount of requests we receive to troubleshoot stuff in older versions of Snort (like 2.3!?) Most likely, a problem in that old of a version of Snort has been fixed by now. Upgrade, Upgrade, Upgrade. I understand some of you have it baked into your routers and things like that. I know of routers/firewalls running 2.6. That version is about 7 years old now, and we just can't support every version.
The vast majority of our user base is around one version back (2.9.2.3) according to our download stats.
We think this is great. Our latest version, 2.9.3.0, fixes a ton of issues (like logging output of data), and introduces new features like flowbit OR'ing. 2.9.3.1 was released this week and contains some bug fixes and code cleanup that didn't make it into the 2.9.3.0 release.
So I encourage you to look through our archives and see how far we've come in 10+ years. The future is right around the corner, and it's brighter than ever.
Sourcefire VRT Certified Snort Rules Update for 08/09/2012
Just released:
Sourcefire VRT Certified Snort Rules Update for 08/09/2012
We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 6 new rules and made modifications to 135 additional rules.
There were no changes made to the
In VRT's rule release:
In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!
Sourcefire VRT Certified Snort Rules Update for 08/09/2012
We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 6 new rules and made modifications to 135 additional rules.
There were no changes made to the
snort.conf in this release.In VRT's rule release:
Synopsis:
This release adds and modifies rules in several categories.
Details:
The Sourcefire VRT has added and modified multiple rules in the
blacklist, botnet-cnc, misc, oracle, smtp, specific-threats,
spyware-put, sql, web-activex and web-php rule sets to provide coverage
for emerging threats from these technologies.
In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!
Subscribe to:
Posts (Atom)
