Monday, August 15, 2011

Swinedroid

Two weeks ago at Defcon, several of the VRT were waiting to grab a cab, and the author of this tool saw our Sourcefire shirts and wanted to show us this tool he wrote to be able to monitor Snort alerts on an Android Phone!  So after a business card and email exchange or two, I'd like to introduce you to Swinedroid!


Swinedroid is an Android Snort monitoring application.  It has a client and server-side component, and works for Snort setups logging to PostgreSQL and MySQL.  It's available on the Android market currently, and the source is available here:

https://github.com/Hainish/Swinedroid

Great job Hainish!

Dynamic Preprocessor Starter Kit

Ever since the introduction of dynamic preprocessors there has been a lot of questions and interest over the years on how to get started and develop a dynamic preprocessor for Snort.

Well, today is the day you've been waiting for developers!

Our own Russ Combs has put together the Dynamic Preprocessor Starter Kit, or "dpx" for short, to enable developers to get started writing their own dynamic preprocessors.

Please take a look at the brand new DPX page over on the Snort.org website to get started!

New Snort 3rd Party project is listed: iBlock

The author of this project Roberto Zarrelli wrote me last week while I was at the GFirst conference, and notified me of the listing of his new project "iBlock"'s (For "Intrusion Block") listing on Sourceforge.

A short description of the project:

This tool is a small Linux Daemon that greps the Snort Alert file and blocks the offending hosts via iptables for a given amount of time. iBlock supports the whitelisting of IP addresses so those IPs will never be blocked.
iBlock is now listed on our 3rd Party projects page on Snort.org, and a link to Roberto's project directly on Sourceforge is here.

Thanks Roberto for your submission, we're all hoping that your project does well!

Thanks to all of the 3rd party projects surrounding Snort!

VRT Rule Update for 08/11/2011

Join us as we welcome the introduction of the newest rule release for today from the VRT. In this release we introduce 20 new rules and make modifications to 8 additional rules.

There were no changes made to the snort.conf in this release.

In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the backdoor, botnet-cnc, dos, smtp, specific-threats, spyware-put, tftp, and web-misc rule sets to provide coverage for emerging threats from these technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Tuesday, August 9, 2011

SQueRT 0.9.2 Released

## CHANGELOG:

# Squert 0.9.2

* Added 'last time' indicators to summary tab (see the main screenshot for ex.)
* Fixed display logic when viewing spans on summary tab
* Added record count selector to summary tab
* Changed country and signature charts to donut variant. Cleaner
* Truncate long key entries for country and signature charts
* Countries were not being filtered correctly when added to the
exclude filter. This has been fixed

## Screenshots

http://www.squertproject.org/screenshots

## Demo server:

I have an interested party (Thanks AD). Now just need to bring it online.

## You can download it here:

http://www.squertproject.org/download

VRT Rule Update for 08/09/2011, MS Tuesday, and Adobe Coverage

Join us as we welcome the introduction of the newest rule release for today from the VRT. In this release we introduce 33 new rules and make modifications to 6 additional rules.

There were no changes made to the snort.conf in this release.

In VRT's rule release:
The Sourcefire VRT is aware of vulnerabilities affecting products from Microsoft Corporation and Adobe Inc.

Details:
Microsoft Security Advisory MS11-057:
Microsoft Internet Explorer contains programming errors that may allow a remote attacker to execute code on an affected system.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 19666 through 19672.

Microsoft Security Advisory MS11-058:
The Microsoft implementation of DNS contains a programming error that may allow a remote attacker to execute code on an affected system.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19677.

Microsoft Security Advisory MS11-059:
The Microsoft Data Access Components (MDAC) contains a programming error that may allow a remote attacker to execute code on an affected system.

Rules to detect attacks targeting this vulnerability are included in this release and are identified with GID 1, SIDs 19673 and 19674.

Microsoft Security Advisory MS11-060:
Microsoft Visio contains programming errors that may allow a remote attacker to execute code on an affected system.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 19675 and 19676.

Microsoft Security Advisory MS11-061:
Microsoft Remote Desktop Web Access contains a programming error that may allow a remote attacker to execute a cross site scripting attack.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19665.

Microsoft Security Advisory MS11-062:
The Microsoft Remote Access Service NDISTAPI driver contains a programming error that may allow a remote attacker to gain privileges on an affected system.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19679.

Microsoft Security Advisory MS11-063:
The Microsoft Windows Client/Server Run-time Subsytem contains a programming error that may allow a remote attacker to gain privileges on an affected system.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19680.

Microsoft Security Advisory MS11-064:
The Microsoft implementation of the TCP/IP stack contains programming errors that may allow a remote attacker to cause a Denial of Service (DoS) against an affected system.

A rule to detect attacks targeting these vulnerabilities is included in this release and is identified with GID 1, SID 19678.

Additionally, a previously released rule will detect attacks targeting these vulnerabilities and has been updated with the appropriate reference information. It is included in this release and is identified with GID 1, SID 17410.

Microsoft Security Advisory MS11-066:
A programming error in the Microsoft .NET framework may lead to unauthorized information disclosure.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19694.

Microsoft Security Advisory MS11-067:
Microsoft Report Viewer contains a programming error that may lead to unauthorized information disclosure.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19681.

Adobe Security Bulletin APSB11-21:
Adobe Flash Player contains programming errors that may allow a remote attacker to execute code on an affected system.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 19682 through 19693.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Wednesday, August 3, 2011

VRT Rule Update for 08/03/2011

Join us as we welcome the introduction of the newest rule release for today from the VRT. In this release we introduce 9 new rules and make modifications to an additional rule.

There were no changes made to the snort.conf in this release.

In VRT's rule release:
The Sourcefire VRT is aware of a programming error in the TimThumb plugin for WordPress that may allow a remote attacker to execute code on an affected system. The vulnerability is present in the timthump.php script which does not correctly process user supplied input, allowing a remote attacker to upload content of their choosing into a directory, which can them be executed by the attacker.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19653.

Additionally, the Sourcefire VRT has added and modified multiple rules in the backdoor, botnet-cnc and exploit rule sets to provide coverage for emerging threats from these technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Tuesday, August 2, 2011

VRT Rule Update for 08/02/2011

Join us as we welcome the introduction of the newest rule release for today from the VRT. In this release we introduce 31 new rules and make modifications to an additional 2.

There were no changes made to the snort.conf in this release.

In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the blacklist, botnet-cnc, exploit, policy and web-activex rule sets to provide coverage for emerging threats from these technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Thursday, July 28, 2011

VRT Rule Update for 7/28/2011

Welcome the introduction of the newest rule release for today from the VRT. In this release we introduce 11 new rules and make modifications to 6 more.

There were no changes made to the snort.conf in this release.

In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the backdoor, blacklist and web-client rule sets to provide coverage for emerging threats from these technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Wednesday, July 27, 2011

Barnyard2 sets up a Google Group!

Greetings everyone,

The barnyard2 team want to announce the creation of two Google groups that will be used ease the way for users to report issue or find answers and discuss about barnyard2 related topics.

barnyard2-users and barnyard2-devel.

barnyard2-users@googlegroups.com (for users problems and issues)
barnyard2-devel@googlegroups.com (for development updates, fixes, patches, comments, and more)

We strongly encourage you to join if you have any issues/commenst/questions related to barnyard2.

We would also like to launch a special invitation to UI developers that are willing to improve the future of the database schema and the handling of unified2 EXTRA_DATA event type.

Any comments or question can also be directed to

Ian Firns firnsy@securixlive.com
Eric Lauzon beenph@gmail.com

Eager to see you arround in the barn *wink wink*

Update:  Here is the direct link to the barnyard2 group: http://groups.google.com/groups/dir?lnk=nhpsfg&q=barnyard2.  Thanks Jason!

-The barnyard2 team.