Tuesday, March 22, 2011

VRT Rule Update for 03/22/2011

Just released, is a rule release for today from the VRT. In this release we introduce 11 new rules and make modifications to 2 more.

In VRT's rule release:
As a result of ongoing research, the Sourcefire VRT has added and
modified multiple rules in the botnet-cnc, deleted, exploit, misc,
netbios, policy, rpc, smtp, specific-threats, web-activex, web-client
and web-misc rule sets to provide coverage for emerging threats from
these technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Marty speaking at new CyberSecurity Seminar Series at the University of Maryland

Google is now sponsoring a CyberSecurity Seminar Series at the University of Maryland, featuring speakers from the industry, academia, and government, addressing a broad range of topics related to cybersecurity, including technology, policy, and economics.

One of the speakers confirmed for the Seminar Series is our own Martin Roesch!

Check out this excerpt from the press release:

The second seminar will be held on Thursday, April 21, at 5:00 p.m., and will feature Martin Roesch, Chief Technology Officer (CTO) of Sourcefire®, a leader in intelligent cybersecurity solutions. The title of his talk will be "Intrusion Detection and Network Security Perspectives From A Veteran."
With nearly 20 years of industry experience in network security and embedded systems engineering, Roesch has dedicated himself to developing intelligent network security tools and technologies to address evolving threats. A respected authority on intrusion prevention and detection technology and forensics, Roesch has been interviewed as an industry expert in multiple technology publications, as well as print and online news services, such as MSNBC, Wall Street Journal, CNET, ZDNet, and numerous books. Roesch founded Sourcefire® in 2001 and is the author and lead developer of the Snort® Intrusion Prevention and Detection System that forms the foundation for the Sourcefire IPSTM. Roesch has received a host of awards of his technology innovation and vision. Most recently, he was recognized as a 2010 Security Superstar by Everything Channel's CRN magazine for the value his innovations provide partners and customers, and was selected as one of eWeek's Top 100 Most Influential People in IT
I hope you have the opportunity to attend!

Wednesday, March 16, 2011

Snort 2.9.0.1 Shared Object Rules are depreciated

As noted before when we End-Of-Life'd 2.9.0.0 Shared Object rules, 2.9.0.1 rules have now reached EOL and will no longer be released.  People using 2.9.0.1 should update to the newest version of Snort and Shared Object rules at 2.9.0.4.

Towards the end of March, 2.9.0.2 will also be EOL, so it's encouraged that planning begin for the movement off of that patch level if anyone is still on it.

The Shared Object rule builds for 2.8.6.1 are unaffected, however, as a reminder, support for 2.8.6.1 will end at the release of Snort 2.9.1 (+90 days), so those of you on 2.8.6.1 are encouraged to start upgrading.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store.  Make sure and stay up to date to catch the most emerging threats!

Snort Webcast Series is back

When I took over the OpenSource Community Manager position here at Sourcefire, I sent out an email asking for suggestions about what I can do to make things better and provide an awesome community for the OpenSource products.

One of the things that was emailed to me was "Can you put the Snort Webcast Series back up?"  and "Start the webinar series back up!".  So, I did, and we will.

You can find the old series that Mike Guiterman (thanks Mike!) was coordinating back in 2009, re-released and put up on Snort.org.  It's always been available, but over on Sourcefire.com where you had to register to view the content.  This is one of the other complaints I received, that people had to surrender their email to the website in order to gain access to this valuable information.

So I removed that restriction as well.

So, announcing without further ado, the old series is back up, and we're going to be reviving the series soon (probably once a month or so), and putting that information up for consumption as well.  As always I'll post a blog entry when we are going to schedule a webcast, so you may participate live and ask questions of the speakers, and I'll post a blog entry when we put it up on the website for archiving.

You can find the Snort webcast series here, at it's new home, on Snort.org.

Tuesday, March 15, 2011

VRT Rule Update for 03/15/2011, MS Tues

Just released, is a rule release for today from the VRT. In this release we introduce 11 new rules and make modifications to 2 more.

In VRT's rule release:
Details:

Adobe Security Advisory APSA11-01:
Adobe Flash Player contains a programming error that may allow a remote
attacker to execute code on an affected system. This problem affects
the Microsoft Windows, Apple Mac OS, Linux and Solaris operating
systems.

The Sourcefire VRT have reports of this vulnerability being exploited
in the wild via an embedded Flash file in a Microsoft Excel document
delivered via email.

Rules to detect attacks targeting this vulnerability are included in
this release and are identified with GID 3, SID 18543, GID 1, SIDs
18545 through 18554.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Tuesday, March 8, 2011

VRT Rule Update for 03/08/2011

Just released, is a rule release for today from the VRT. In this release we introduce 49 new rules and make modifications to 28 more.

In VRT's rule release:
Details:

Microsoft Security Advisory MS11-015:
Microsoft Windows Media Player contains a programming error that may
allow a remote attacker to execute code on an affected system.

Rules to detect attacks targeting this vulnerability are included in
this release and are identified with GID 3, SIDs 18496, 18497 and
18498.

Microsoft Security Advisory MS11-016:
Microsoft Office Groove contains a programming error that may allow a
remote attacker to execute code on an affected system.

Rules to detect attacks targeting this vulnerability are included in
this release and are identified with GID 3, SIDs 18499 and 18500.

Microsoft Security Advisory MS11-017:
Microsoft Remote Desktop Client contains a programming error that may
allow a remote attacker to execute code on an affected system.

Rules to detect attacks targeting this vulnerability are included in
this release and are identified with GID 3, SIDs 18494 and 18495.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Snort-Users Google Group Feed

On the frontpage of Snort.org, we used to have a feed that pointed at the Snort.org Forums for people to see a quick heads up of the new topics being posted in the forums.  Since we've depreciated the forums on Snort.org and moved to Google Groups (quite successfully I might add!  There is a lot more traffic on the Google Groups as people are able to ask and give questions and answers easier) we need to fix that feed.

So, now when you navigate to Snort.org you'll notice that the three feeds at the bottom of the front page are now:
Snort Blog (this one), VRT Blog, and now Snort-Users Group

Reminder if you haven't signed up for the Google Groups yet, please do so!  http://www.snort.org/community/groups

Thanks!

Thursday, March 3, 2011

VRT Rule Update for 03/03/2011

Just released, is a rule release for today from the VRT. This release is much larger than yesterdays and makes changes to 573 rules.

In VRT's rule release:

Details:

As a result of ongoing research, the Sourcefire VRT has added and modified multiple rules in the backdoor, blacklist, botnet-cnc, chat, deleted, dos, exploit, icmpv6, imap, netbios, policy, scada, smtp, specific-threats, voip-sip, web-activex, web-cgi, web-client, web-misc, and web-php rule sets to provide coverage for emerging threats from these technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Wednesday, March 2, 2011

VRT Rule Update for 03/02/2011

Just updated, is a rule release for today from the VRT. This rule release only contains a couple updates.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Tuesday, March 1, 2011

The end of an era, Snort Forums.

As announced back in the beginning of February, our transition to Google Groups instead of the Snort Forums is now taking place.

The old Snort forums found at https://forums.snort.org, are now depreciated in favor of moving to a more versatile Google Groups solution.

For those of you that haven't yet participated in the Google Groups, the seem to be working out quite well so far, and we encourage everyone to go there and sign up.  Thanks for working with us during this transition.

http://www.snort.org/community/groups/