Tuesday, September 13, 2016

Snort Subscriber Rule Set Update for 09/13/2016

Just released:
Snort Subscriber Rule Set Update for 09/13/2016


We welcome the introduction of the newest rule release from Talos. In this release we introduced 31 new rules and made modifications to 2 additional rules.

There were no changes made to the snort.conf in this release.

Talos's rule release:
Talos has added and modified multiple rules in the and file-office rule sets to provide coverage for emerging threats from these technologies.


In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://www.snort.org/products. Make sure and stay up to date to catch the most emerging threats!

Snort Subscriber Rule Set Update for 09/13/2016, MSTuesday

Just released:
Snort Subscriber Rule Set Update for 09/13/2016


We welcome the introduction of the newest rule release from Talos. In this release we introduced 85 new rules and made modifications to 12 additional rules.

There were no changes made to the snort.conf in this release.

Talos's rule release:
Microsoft Security Bulletin MS16-104:
Microsoft Internet Explorer suffers from programming errors that may
lead to remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 40073 through 40074,
40077 through 40078, 40084 through 40095, 40108 through 40109, 40132
through 40133, and 40146.

Microsoft Security Bulletin MS16-105:
A coding deficiency exists in Microsoft Exchange that may lead to
remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 40073 through 40074,
40098 through 40101, 40108 through 40109, 40123 through 40124, and
40134 through 40141.

Microsoft Security Bulletin MS16-106:
A coding deficiency exists in Microsoft Graphics Component that may
lead to remove code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 40096 through 40097
and 40112 through 40113.

Microsoft Security Bulletin MS16-107:
A coding deficiency exists in Microsoft Office that may lead to remote
code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 40075 through 40076,
40079 through 40080, 40082 through 40083, 40102 through 40107, 40116
through 40117, 40121 through 40122, 40142 through 40143, and 40147
through 40148.

Microsoft Security Bulletin MS16-110:
A coding deficiency exists in Microsoft Windows that may lead to remote
code execution.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 1, SID 40129.

Microsoft Security Bulletin MS16-111:
A coding deficiency exists in Microsoft Windows Kernel that may lead to
an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 40110 through 40111,
40114 through 40115, and 40127 through 40128.

Microsoft Security Bulletin MS16-115:
A coding deficiency exists in Microsoft Windows PDF library that may
lead to remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 40144 through 40145.

Microsoft Security Bulletin MS16-116:
A coding deficiency exists in Microsoft OLE Automation VBScript
Scripting Engine that may lead to information disclosure.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 40149 through 40150.

Talos has added and modified multiple rules in the blacklist,
browser-ie, deleted, file-identify, file-image, file-office,
file-other, file-pdf, indicator-compromise, indicator-scan,
malware-cnc, os-other, os-windows, policy-other, protocol-voip and
server-webapp rule sets to provide coverage for emerging threats from
these technologies.


In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://www.snort.org/products. Make sure and stay up to date to catch the most emerging threats!

Friday, September 9, 2016

Snort++ Update

Pushed build 208 to github (snortadmin/snort3):
  • fixed TCP high availability
  • fixed install of file_decomp.h for consistency between Snort and extras
  • added smtp client counters and unit tests
  • ported Smbv2/3 file support
  • ported mpls encode fixes from 2983
  • cleaned up compiler warnings

    Thursday, September 8, 2016

    Snort Subscriber Rule Set Update for 09/08/2016

    Just released:
    Snort Subscriber Rule Set Update for 09/08/2016


    We welcome the introduction of the newest rule release from Talos. In this release we introduced 18 new rules and made modifications to 20 additional rules.

    There were no changes made to the snort.conf in this release.



    Talos's rule release:
    Talos has added and modified multiple rules in the blacklist, browser-ie, file-image, file-other, malware-cnc, malware-other, os-linux and server-webapp rule sets to provide coverage for emerging threats from these technologies.


    In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://www.snort.org/products. Make sure and stay up to date to catch the most emerging threats!

    Wednesday, September 7, 2016

    Snort Subscriber Rule Set Update for 09/06/2016

    Snort Subscriber Rule Set Update for 09/06/2016


    We welcome the introduction of the newest rule release from Talos. In this release we introduced 20 new rules and made modifications to 17 additional rules.

    There were no changes made to the snort.conf in this release.

    Talos would like to thank the following individuals for their contributions, their rules are included in the Community Ruleset:

    rmkml
    40015

    Carriag Stanwyck
    40037


    Talos's rule release:
    Talos has added and modified multiple rules in the browser-ie, exploit-kit, file-flash, file-identify, malware-cnc, pua-adware and server-webapp rule sets to provide coverage for emerging threats from these technologies.


    In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://www.snort.org/products. Make sure and stay up to date to catch the most emerging threats!

    Friday, September 2, 2016

    Snort++ Update

    Pushed build 207 to github (snortadmin/snort3):
    • ported smb file processing
    • ported the 2.9.8 ciscometadata decoder
    • ported the 2.9.8 double and triple vlan tagging changes
    • use sd_pattern as a fast-pattern
    • rewrite and fix the rpc option
    • cleanup fragbits option implementation
    • finish up cutover to the new http_inspect by default
    • added appid counts for rsync
    • added http_inspect alerts for Transfer-Encoding and Content-Encoding abuse
    • moved file capture to offload thread
    • numerous fixes, cleanup, and refactoring for appid
    • numerous fixes, cleanup, and refactoring for high availability
    • fixed regex as fast pattern with hyperscan mpse
    • fixed http_inspect and tcp valgrind errors
    • fixed extra auto build from dist

    Thursday, September 1, 2016

    Snort Subscriber Rule Set Update for 09/01/2016

    Just released:
    Snort Subscriber Rule Set Update for 09/01/2016


    We welcome the introduction of the newest rule release from Talos. In this release we introduced 84 new rules and made modifications to 45 additional rules.

    There were no changes made to the snort.conf in this release.

    Talos's rule release:
    Talos has added and modified multiple rules in the blacklist, browser-firefox, browser-ie, browser-plugins, deleted, exploit-kit, file-flash, file-identify, file-office, file-other, indicator-compromise, malware-cnc, malware-other, policy-other, policy-social, protocol-dns, protocol-snmp and server-webapp rule sets to provide coverage for emerging threats from these technologies.

    In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://www.snort.org/products. Make sure and stay up to date to catch the most emerging threats!

    Tuesday, August 30, 2016

    Snort Subscriber Rule Set Update for 08/30/2016

    Just released:
    Snort Subscriber Rule Set Update for 08/30/2016


    We welcome the introduction of the newest rule release from Talos. In this release we introduced 1 new rules and made modifications to 6 additional rules.

    There were no changes made to the snort.conf in this release.



    Talos's rule release:
    Talos has added and modified multiple rules in the blacklist, file-executable, file-other, file-pdf, malware-cnc, malware-other, os-solaris, protocol-snmp, pua-adware, scada and server-webapp rule sets to provide coverage for emerging threats from these technologies.


    In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://www.snort.org/products. Make sure and stay up to date to catch the most emerging threats!

    Friday, August 26, 2016

    Running Snort on Commodity Hardware - The pitfalls of large receive offload

    While working on Snort integration for another project that does HTTP stream reassembly we came across some very strange behaviour:

    During reassembly, fragments of the stream were missing or incorrectly reassembled.  Large chunks of the stream would be missing even though the packets that covered that piece of the stream's data had been received and processed.

    At first we thought that this was a bug with the hardware checksum offload on the network card so we added '-k none' to the command line arguments. This seemed to resolve the issue, for the moment...

    While testing the integration work we started noticing some very strange HTTP sessions: response codes that were very strange, invalid and missing, or truncated headers. This lead me to look into the issue again. Turning on full packet dumps showed me that the first packet in the reassembled stream coming from the Stream preprocessor was not the first packet in the stream, but instead a part of the response body.

    The next step was to capture a pcap with tcpdump and use Snort in replay mode to reproduce the issue, this is where more strange things happened.  Using the pcap with Snort in replay mode, I could not reproduce the issue, but when watching the live stream it would fail ~3 out of 4 times.

    This let me to look at what hardware acceleration features where enabled on the capture interface. It turned out that the card had large receive offload enabled (LRO) out of the box. This feature will automatically coalesce tcp frames in the same stream into larger frames rewriting all the headers to match the new larger frame.

    Looking at the pcap showed that 2 frames in the stream had been coalesced into a larger 1900 byte frame, this frame was larger than Snort's default snaplen and being truncated. The truncation explained why '-k none' seemed to make it a little more reliable but not much. I tested both disabling LRO and raising the snaplen in Snort, both resolved the stream reassembly issues, and now your wondering which solution is the correct one. The answer is disabling LRO for a number of reasons, chief of which is:
    • LRO changes the stream that Snort sees on the wire, this means it can not do target based re-assembly and correctly detect common IDS avoidance techniques.

    On Linux you can check the status of this feature using the following command, (replace "eth1" with the proper interface you are using as a sniffing interface):

    ethtool -k eth1

    And you can disable the feature as follows:

    ethtool -K eth1 gro off
    ethtool -L eth1 bro off

    On FreeBSD you can see the interface flags in the output of ifconfig, to disable the features you can use the following command (replacing "em0" with the proper interface you are using as a sniffing interface):
    ifconfig em0 -lro

    Thursday, August 25, 2016

    Snort Subscriber Rule Set Update for 08/25/2016

    Just released:
    Snort Subscriber Rule Set Update for 08/25/2016


    We welcome the introduction of the newest rule release from Talos. In this release we introduced 25 new rules and made modifications to 10 additional rules.

    There were no changes made to the snort.conf in this release.

    Talos's rule release:
    Talos has added and modified multiple rules in the blacklist, browser-plugins, file-office, file-pdf, malware-cnc, malware-other, os-linux, protocol-snmp and server-webapp rule sets to provide coverage for emerging threats from these technologies.


    In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://www.snort.org/products. Make sure and stay up to date to catch the most emerging threats!