Tuesday, December 16, 2014

Snort Subscriber Rule Set Update for 12/16/2014

Just released:
Snort Subscriber Rule Set Update for 12/16/2014


We welcome the introduction of the newest rule release from Talos. In this release we introduced 61 new rules and made modifications to 18 additional rules.

There were no changes made to the snort.conf in this release.

Talos would like to thank the following individuals for their contributions, their rules are included in the Community Ruleset:

Yaser Mansour
32823
32824
32825
32826
32827

Talos's rule release:
Talos has added and modified multiple rules in the blacklist, browser-ie, exploit-kit, file-flash, file-image, file-pdf, malware-cnc, malware-other and server-other rule sets to provide coverage for emerging threats from these technologies.

In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://www.snort.org/products. Make sure and stay up to date to catch the most emerging threats!

Snort++ Extras

Snort++ Extras

Snort++ is all about plugins. It has over 140 by default and makes it easy to add more in C++ or LuaJIT. This post will walk you through building and running a set of extra example plugins. If you haven't installed and verified Snort++, you will need to do that first. We will cover the following topics:
  • Overview
  • Download
  • Build Extras
  • Run Extras
  • Next Steps

OVERVIEW

The following things are pluggable in Snort++:
  • codec - decode and encode support for a given protocol
  • data - additional configuration for inspectors
  • inspector - replaces Snort preprocessors
  • ips_option - IPS rule option like content and byte_test
  • ips_action - IPS rule action like alert and block
  • search_engine - fast pattern matcher
  • logger - event handers
  • SO rules - dynamic rules

DOWNLOAD

There are two extra tarballs, once for autotools and one for cmake:
    snort_extra-1.0.0-a1-130-auto.tar.gz
    snort_extra-1.0.0-a1-130-cmake.tar.gz

BUILD EXTRAS

To build the example plugins, first do these setup steps:

    tar zxf extra-tarball
    cd snort_extra-1.0.0*
    export PKG_CONFIG_PATH=$my_path/lib/pkgconfig

Then do one of the following:
  • To build with autotools, simply do the usual from the top level directory:
    ./configure --prefix=$my_path --with-snort-includes=$my_path/include/snort
    make -j 8 install
  • To build with cmake, do the following:
    mkdir build && cd build
    cmake ..
    make -j 8 install

RUN EXTRAS

  • The following demonstrates a C++ logger and a LuaJIT logger:
    $my_path/bin/snort -c $my_path/etc/snort/snort.lua -R $my_path/etc/snort/sample.rules \
        -r pcap --plugin-path $my_path/lib/snort_extra -A alert_ex
    $my_path/bin/snort -c $my_path/etc/snort/snort.lua -R $my_path/etc/snort/sample.rules \
        -r pcap --script-path $my_path/lib/snort_extra -A lualert
  • You can edit $my_path/lib/snort_extra/loggers/alert.lua to tweak the output format and rerun the above command to try it out.
  • The last example demonstrates a LuaJIT rule option called find. The rule, supplied on stdin, uses the Lua [[ multiline string ]] delimiters to avoid shell escape issues:
    echo 'alert tcp any any -> any 80 ( sid:1; msg:"test"; http_method; find:"pat = [[GET]]"; )' | \
        $my_path/bin/snort -c $my_path/etc/snort/snort.lua -r pcap \
            -A cmg --script-path $my_path/lib/snort_extra --stdin-rules

NEXT STEPS o")~

There is no design guide yet but you can develop your own plugins in C++ by using the examples as a starting point. In addition, IPS options and loggers can also be written in LuaJIT. The API may change going forward, but you are encouraged to roll your own now and let us know how it goes so we can incorporate any suggestions in the final design.

Thursday, December 11, 2014

Snort Subscriber Rule Set Update for 12/11/2014

Just released:
Snort Subscriber Rule Set Update for 12/11/2014


We welcome the introduction of the newest rule release from Talos. In this release we introduced 53 new rules and made modifications to 52 additional rules.

There were no changes made to the snort.conf in this release.

Talos would like to thank the following individuals for their contributions, their rules are included in the Community Ruleset:

Yaser Mansour
32776

Avery Tarasov
32670

Tony Robinson
32665
32666
32667
32670


Talos's rule release:
Talos is aware of a vulnerability affecting Microsoft Internet Explorer. 
Details: 
CVE-2014-8967: Microsoft Internet Explorer suffers from a programming error that may lead to remote code execution. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 32777 through 32778. 
Talos has also added and modified multiple rules in the blacklist, browser-ie, browser-plugins, file-flash, file-multimedia, file-office, file-other, file-pdf, malware-cnc, malware-other, os-windows, policy-other, server-iis, server-other and sql rule sets to provide coverage for emerging threats from these technologies.

In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://www.snort.org/products. Make sure and stay up to date to catch the most emerging threats!

Project Snort++, a.k.a. Snort 3.0

Snort++

The Snort++ project has been hard at work for a while now and we are finally ready to release the first alpha of the next generation Snort IPS (Intrusion Prevention System). This post will show you what Snort++ has to offer and guide you through the steps from download to demo. If you are unfamiliar with Snort you should take a look at the Snort documentation first. We will cover the following topics:
  • Overview
  • Dependencies
  • Download
  • Build Snort
  • Run Snort
  • Documentation
  • Squeal


OVERVIEW

This first alpha release is based on early Snort 2.9.6 and excludes all but one of Snort's dynamic preprocessors (ftp_telnet). Work is underway to port that functionality and sync with 2.9.7; those updates will be rolled out as they become available.

    Project = Snort++
    Binary = snort
    Version = 3.0.0-a1

Here are some key features in this alpha release:
  • Support multiple packet processing threads
  • Use a shared configuration and attribute table
  • Use a simple, scriptable configuration
  • Make key components pluggable
  • Autodetect services for portless configuration
  • Support sticky buffers in rules
  • Autogenerate reference documentation
  • Provide better cross platform support
Additional features on the roadmap include:
  • Use a shared network map
  • Support pipelining of packet processing
  • Support hardware offload and data plane integration
  • Rewrite critical modules like TCP reassembly and HTTP inspection
  • Support proxy mode
  • Facilitate component testing
  • Simplify memory management
  • Provide all of Snort's functionality


DEPENDENCIES

If you already build Snort, you may have everything you need. If not, grab the latest:
  • autotools or cmake to build from source
  • g++ >= 4.8 or other C++11 compiler
  • daq from http://www.snort.org for packet IO
  • dnet from http://code.google.com/p/libdnet/ for network utility functions
  • LuaJIT from http://luajit.org for configuration and scripting
  • pcap from http://www.tcpdump.org for tcpdump style logging
  • pcre from http://www.pcre.org for regular expression pattern matching
  • zlib from http://www.zlib.net for decompression
  • pkgconfig from http://www.freedesktop.org to build the example plugins


DOWNLOAD

There are two source tarballs, once for autotools and one for cmake:
    snort-3.0.0-a1-130-auto.tar.gz
    snort-3.0.0-a1-130-cmake.tar.gz


BUILD SNORT

First do these setup steps:

    export my_path=/path/to/snorty
    tar zxf snort-tarball
    cd snort-3.0.0*

Then do one of the following:
  • To build with autotools, simply do the usual from the top level directory:
    ./configure --prefix=$my_path
    make -j 8 install
  • To build with cmake and make, run configure_cmake.sh. It will automatically create and populate a new subdirectory named 'build'.
    ./configure_cmake.sh --prefix=$my_path
    cd build
    make -j 8 install

Note:
  • If you can do src/snort -V you built successfully.
  • If you are familiar with cmake, you can run cmake/ccmake instead of configure_cmake.sh.
  • cmake --help will list any available generators, such as Xcode. Feel free to use one, however help with those will be provided in a later post.


RUN SNORT

First set up the environment:

    export LUA_PATH=$my_path/include/snort/lua/\?.lua\;\;
    export SNORT_LUA_PATH=$my_path/etc/snort

Then give it a go:
  • Snort++ provides lots of help from the command line. Here are some examples:
    $my_path/bin/snort --help
    $my_path/bin/snort --help-module suppress
    $my_path/bin/snort --help-config | grep thread
  • Examine and dump a pcap:
    $my_path/bin/snort -r pcap
    $my_path/bin/snort -K text -d -e -q -r pcap
  • Verify a config, with or w/o rules:
    $my_path/bin/snort -c $my_path/etc/snort/snort.lua
    $my_path/bin/snort -c $my_path/etc/snort/snort.lua -R $my_path/etc/snort/sample.rules
  • Run IDS mode. In the following, replace a.pcap with your favorite. pcaps/ is a directory with one or more *.pcap files:
    $my_path/bin/snort -c $my_path/etc/snort/snort.lua -R $my_path/etc/snort/sample.rules \
        -r a.pcap -A alert_test -n 100000
  • Let's suppress 1:2123. We could edit the conf or just do this:
    $my_path/bin/snort -c $my_path/etc/snort/snort.lua -R $my_path/etc/snort/sample.rules \
        -r a.pcap -A alert_test -n 100000 --lua "suppress = { { gid = 1, sid = 2123 } }"
  • Go whole hog on a directory with multiple packet threads:
    $my_path/bin/snort -c $my_path/etc/snort/snort.lua -R $my_path/etc/snort/sample.rules \
        --pcap-filter \*.pcap --pcap-dir pcaps/ -A alert_fast --max-packet-threads 8


DOCUMENTATION

Take a look at the manual, parts of which are generated by the code so it stays up to date:

    $my_path/share/doc/snort/snort_manual.pdf
    $my_path/share/doc/snort/snort_manual.html
    $my_path/share/doc/snort/snort_manual/index.html

It does not yet have much on the how and why, but it does have all the currently available configuration, etc. Some key changes to rules:
  • you must use comma separated content sub options like this: content:"foo", nocase;
  • buffer selectors must appear before the content and remain in effect until changed
  • pcre buffer selectors were deleted
  • check the manual for more on Snort++ vs Snort
  • check the manual reference section to understand how parameters are defined, etc.
It also covers new features not demonstrated here:
  • snort2lua, a tool to convert Snort 2.X conf and rules to the new form
  • a new HTTP inspector, new_http_inspect - incomplete but off to a good start
  • a binder, for mapping configuration to traffic
  • a wizard for port-independent configuration
  • improved rule parsing - arbitrary whitespace, C style comments, #begin/#end comments
  • local and remote command line shell


SQUEAL o")~

We hope you are as excited about Snort++ as we are. Although a lot of work remains, we wanted to give you a chance to try it out and let us know what you think on the snort-users list. In the meantime, we'll keep our snout to the grindstone.

Introducing Snort 3.0

Over the past year our development team has led two lives. 

One life was spent maintaining the code base of Snort, which secures most of the Internet with well over 5 million downloads.  Snort has not only become the standard in intrusion detection, but the Snort rules language is used by network researchers to communicate with each other to detect bad traffic.  We’ve been releasing new features into the code base all along to push the envelope of detection farther and faster.

The other life initially emerged back in 2005 with the conceptual introduction of Snort 3.0. Marty Roesch, the original author of Snort and the founder of Sourcefire, started to rethink the concepts and architecture of Snort.  This resulted in a beta release of what we now call “SnortSP”, or the Snort Security Platform.  Some of the ideas in the original SnortSP project have made their way into the main code base of Snort over the past few releases.  Reloading without restarting, OpenAppId, gzip decompression, IP blacklisting, etc.    However, there were ideas that we’ve been playing with that we couldn’t fold into the current code base without a complete rewrite. 

So that’s what we’ve done.

We took Marty’s initial rethinking and expanded beyond that, testing different concepts of multithreading, detection, interaction, programmatic interfaces, etc. This all now culminates in the alpha release of project “Snort++”, which will become version Snort 3.0.

This Alpha release is for you to play with.  It’s for you to break, it’s for you to test and get back to us about.  We need you to break it; we want you to break it. This is not ready for production and should not be used for production, so that gives us the full freedom to work with our community to make Snort 3.0 as strong as possible.

Over the development of the project we’ll be rolling out new blog posts, white papers, webinars, documents with updates, and code all for you to test and use.  We plan on releasing often and early.  Some fantastic new features are in this new version of Snort.  I’ll list a few here, and we'll expand on all of these in the next few months.


  • User-friendly design
    • We wanted to make it as easy as possible for people to learn and run Snort – that means no more configuring memory, ports, arguments, etc. 
    • Built-in Documentation
    • Built-in configuration
    • Error and Multi error support
    • Verification of configuration on startup (no more having to run “-T” for test mode)
  • Simpler rule language
    • We’re making it simpler to write rules.
    • Sticky buffers
    • Custom http buffers
    • Auto-Detection of all protocols
  • Command Line Shell
    • Secured to localhost
    • Allows someone to reload a configuration
    • Allows you to pause and resume detection
  • Multithreaded and Multi-core
    • All new design for multithreading, maintaining a single persistent configuration for many threads.

This is just a start, we have even more code and ideas we are going to build into this! We’ll be releasing consistently with new features and code over that same amount of time, and due to popular demand, our code will be public, hosted on Github. We’re excited to hear what you have to say about it and working with you as we move the ball forward.  Please stay tuned to the Snort Blog, Snort's Twitter account, and of course the Snort 3.0 webpage on Snort.org!

Please read on to Russ's Blog post about how to download it, set it up, and get the alpha working!

Tuesday, December 9, 2014

Snort Subscriber Rule Set Update for 12/09/2014, MSTuesday

Just released:
Snort Subscriber Rule Set Update for 12/09/2014


We welcome the introduction of the newest rule release from Talos. In this release we introduced 51 new rules and made modifications to 3 additional rules.

There were no changes made to the snort.conf in this release.


Talos's rule release:
Talos is aware of vulnerabilities affecting products from Microsoft
Corporation.

Details:
Microsoft Security Bulletin MS14-075:
Coding deficiencies exist in Microsoft Exchange Server that may lead to
an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 32681 through 32682
and 32705.

Microsoft Security Bulletin MS14-080:
Microsoft Internet Explorer suffers from programming errors that may
lead to remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 32679 through 32680,
32685 through 32686, 32689 through 32694, 32703 through 32704, 32709
through 32710, 32713 through 32717, and 32720 through 32725.

Microsoft Security Bulletin MS14-081:
Programming errors exist in Microsoft Word and Microsoft Office Web
Apps that may lead to remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 32707 through 32708
and 32711 through 32712.

Microsoft Security Bulletin MS14-082:
A coding deficiency exists in Microsoft Office that may lead to remote
code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 32687 through 32688.

Microsoft Security Bulletin MS14-083:
A coding deficiency exists in Microsoft Excel that may lead to remote
code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 32683 through 32684
and 32718 through 32719.

Microsoft Security Bulletin MS14-084:
A coding deficiency exists in Microsoft VBScript scripting engine that
may lead to remote code execution.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 1, SID 32709.

Microsoft Security Bulletin MS14-085:
A coding deficiency exists in Microsoft Graphics Component that may
lead to information disclosure.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 32695 through 32702.

Talos has also added and modified multiple rules in the blacklist,
browser-ie, browser-other, deleted, file-office, malware-cnc,
os-windows and server-webapp rule sets to provide coverage for emerging
threats from these technologies.

In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://www.snort.org/products. Make sure and stay up to date to catch the most emerging threats!

Friday, December 5, 2014

Snort.org network access

We are currently working with Snort.org, sorry for the immediate notice.  We need to make some network changes to the site, and during this time you may receive some SSL errors on access or download.  We apologize for the inconvenience.

Thursday, December 4, 2014

Snort Subscriber Rule Set Update for 12/04/2014

Just released:
Snort Subscriber Rule Set Update for 12/04/2014

We welcome the introduction of the newest rule release from Talos. In this release we introduced 33 new rules and made modifications to 26 additional rules.

There were no changes made to the snort.conf in this release.

Talos's rule release:
Talks has added and modified multiple rules in the blacklist, browser-ie, browser-plugins, file-flash, file-identify, file-office, file-other, indicator-compromise, malware-cnc, os-windows and server-other rule sets to provide coverage for emerging threats from these technologies.


In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://www.snort.org/products. Make sure and stay up to date to catch the most emerging threats!

Tuesday, December 2, 2014

Snort Subscriber Rule Set Update for 12/02/2014

Just released:
Snort Subscriber Rule Set Update for 12/02/2014

We welcome the introduction of the newest rule release from Talos. In this release we introduced 14 new rules and made modifications to 4 additional rules.

There were no changes made to the snort.conf in this release.


Talos's rule release:
Talos has added and modified multiple rules in the browser-ie, browser-plugins, exploit-kit, file-other, netbios, os-windows, protocol-tftp and server-webapp rule sets to provide coverage for emerging threats from these technologies.


In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://www.snort.org/products. Make sure and stay up to date to catch the most emerging threats!

Monday, December 1, 2014

Snort OpenAppID Detectors have been updated!

An update has been released today for the Snort OpenAppID Detector content.

This release, build 225, includes

  • A total of 2,613 detectors.
  • One fix that was also reported by the Open Source community about showing some appid's categorized as __error.
  • Improvements over our Minecraft server detection.


Available now for download from our downloads page, we look forward to you downloading and using the new features of 2.9.7.0's OpenAppId preprocessor and sharing your experiences with the community.

The OpenAppId community has a mailing list specifically dedicated to the exchange and discussion of detector content.  Please visit the mailing lists page to sign up.