Monday, February 28, 2011

Snort 2.9.0.4 Build 111 Posted

We have had a number of users writing in to report a simple http bug. In order to assist the open source community, we have reissued a patched version of the Snort 2.9.0.4 release. There are no other changes to Snort that would warrant a change in the version number, so we have updated the build number to 111.

Additionally, Snort 2.9.0.5 already includes the fix for this bug and is still planned for release in Q1 of 2011.

Thursday, February 24, 2011

Shared Object Rule Platform Support - Upcoming Changes

Next week, with the usual rule release from the VRT, the following shared object platforms will be retired:

  • Fedora Core 9 i386
  • Fedora Core 9 x86-64
  • Fedora Core 11 i386

The following platform support will be added:

  • Fedora Core 12 x86-64
  • Fedora Core 14 i386
  • Fedora Core 14 x86-64

As always, please refer to the pre-compiled shared object rule page to view which platforms and operating systems are currently supported in Certified VRT Rule Releases.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Wednesday, February 23, 2011

VRT Rule Update for 2/23/2011

Just updated, is a rule release for today from the VRT. This rule release only contains a couple updates.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Sunday, February 20, 2011

Snort Data Acquisition Library from the Internet Storm Center

Snort Data Acquisition Library

In the above post Handler Guy Bruneau over at the Internet Storm Center has a post that talks about his upgrade from Snort 2.8.6 to Snort 2.9.0.2, and some tweaks he found for DAQ.

Those of you preparing to upgrade or experiencing problems with upgrade to Snort 2.9.0.x may want to take a look at his post and see if it solves any problems for them.

Thanks Guy!

Friday, February 18, 2011

Improving your Custom Snort Rules -- New Whitepaper Posted

Originally posted in December's hackin9 magazine, Leon Ward authored this paper entitled "Improving your Custom Snort Rules".  We've just added this document to the http://www.snort.org/docs page under "Snort Related Whitepapers".

So be sure and check it out.

Thanks go out to Leon Ward, Alex Kirk, and Dave Venman of Sourcefire for this document.

Thursday, February 17, 2011

VRT Rule Update for 2/17/2011

Just updated, is a rule release for today from the VRT.  This rule release only contains a couple updates.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store.  Make sure and stay up to date to catch the most emerging threats!

Wednesday, February 16, 2011

FreeBSD 8.1 x86-64 and 7.3 x86-64 Platforms are now supported

In addition to the rule update that went out yesterday, the rulepack also introduced support for:
  • FreeBSD 8.1 x86-64
  • FreeBSD 7.3 x86-64
platforms as well.

Please see the Shared Object Rule page (This is a new link!  People complained that the old one was hard to find.) for the complete list of supported Shared Object rule platforms in the VRT rule build.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store.  Make sure and stay up to date to catch the most emerging threats!

Thanks!

Sourcefire wins Best IDS/IPS - SC Magazine US

This week out at RSA, SC Magazine gives away their annual "best of" awards. Sourcefire won this award, citing our innovation, detection, and of course our wonderful 300,000+ strong Snort community (you all!).

While it mentions in the article that Sourcefire is "based  on Snort".  Our detection engine IS Snort.  It's the ease of use, other technologies, and GUIs that set Sourcefire apart.

We'd like to thank the Snort Community for all the bugs they file, the false positive reports, the ideas, and the criticisms. This only serves to make our IPS, community, and detection better.

Thank you all!

Best IDS/IPS - SC Magazine US

Tuesday, February 15, 2011

VRT Rule Update for 2/15/2011

Just updated, is a rule release for today from the VRT.  This rule release contains many updates in several categories, however, the highlight for this release is the following:

Microsoft Windows Server 2003 contains a programming error that may allow a remote attacker to execute code on an affected system.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 18462.


In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store.  Make sure and stay up to date to catch the most emerging threats!

Reminder: Oklahoma City ISSA Meeting tomorrow

Mitch Russell, a member of the Snort Community is giving a talk about Snort at the Oklahoma City ISSA Meeting tomorrow, February 16, 2011.

The meeting will take place at Noon CST, at the Spaghetti Warehouse at 101 East Sheridan, Oklahoma City.

If you are in the area, you are encouraged to attend!

If you know of a Snort speaking event, or if you are giving one, please let me know, and we'll put it up on the Snort.org website on the Snort Speaking Events page, and we'll publicize it on the Snort.org blog for you as well.