<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-2620048000216434889</atom:id><lastBuildDate>Fri, 18 May 2012 16:13:12 +0000</lastBuildDate><category>2.9.3.0</category><category>2.9.2.2</category><category>sguil</category><category>rules</category><category>2.9.0.4</category><category>vrt</category><category>news</category><category>2.9.0.0</category><category>development</category><category>immunet</category><category>eol</category><category>2.8.6.1</category><category>perl</category><category>mstues</category><category>community</category><category>2.9.1.1</category><category>adobe</category><category>updates</category><category>squert</category><category>sourcefire</category><category>2.9.0.3</category><category>2.9.1.5</category><category>downloads</category><category>Response</category><category>2.9.2.1</category><category>webcast</category><category>2.9.0.1</category><category>2.9.2.3</category><category>tuning</category><category>guides</category><category>snorby</category><category>rant</category><category>snort</category><category>database</category><category>manual</category><category>pulledpork</category><category>docs</category><category>unified</category><category>mysql</category><category>speaking</category><category>barnyard2</category><category>barnyard</category><category>scholarship</category><category>2.9.1.2</category><category>razorback</category><category>website</category><category>blog</category><category>daq</category><category>Javascript Normalization</category><category>beta</category><category>snort.org</category><category>output</category><category>scada</category><category>2.9.0.5</category><category>unified2</category><category>SnortUnified</category><category>3rdparty</category><category>clamav</category><category>release</category><category>2.9.1.0</category><category>2.9.0.2</category><category>2.9.2.0</category><title>Snort.org Blog</title><description>The Official Blog of the World Leading Open-Source IDS/IPS Snort.</description><link>http://blog.snort.org/</link><managingEditor>noreply@blogger.com (Joel Esler)</managingEditor><generator>Blogger</generator><openSearch:totalResults>288</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/Snort" /><feedburner:info uri="snort" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>Snort</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-299584161029428458</guid><pubDate>Fri, 18 May 2012 16:13:00 +0000</pubDate><atom:updated>2012-05-18T12:13:12.054-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.3</category><category domain="http://www.blogger.com/atom/ns#">docs</category><category domain="http://www.blogger.com/atom/ns#">snort.org</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>Snort 2.9.2.3 Install Guide for Debian 6.0.5 posted!</title><description>Thanks to Jason Weir, I just posted his Snort 2.9.2.3 Install Guide for Debian 6.0.5.&lt;br /&gt;
&lt;br /&gt;
You may find his updated guide at &lt;a href="http://www.snort.org/docs"&gt;http://www.snort.org/docs&lt;/a&gt;. &amp;nbsp;We'd like to thank Jason Weir and the rest of the Snort community with their constant support, guides, bug reports, false positive reports, and participation in the mailing lists.&lt;br /&gt;
&lt;br /&gt;
You all are fantastic!&lt;br /&gt;
&lt;br /&gt;
Thanks Jason!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-299584161029428458?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=Z7mzgZOxO9s:nrW2nmzRRx4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=Z7mzgZOxO9s:nrW2nmzRRx4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=Z7mzgZOxO9s:nrW2nmzRRx4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=Z7mzgZOxO9s:nrW2nmzRRx4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/Z7mzgZOxO9s" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/Z7mzgZOxO9s/snort-2923-install-guide-for-debian-605.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/05/snort-2923-install-guide-for-debian-605.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-8282677178411995647</guid><pubDate>Fri, 18 May 2012 14:29:00 +0000</pubDate><atom:updated>2012-05-18T10:29:27.307-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">2.9.3.0</category><category domain="http://www.blogger.com/atom/ns#">release</category><category domain="http://www.blogger.com/atom/ns#">beta</category><title>Snort 2.9.3 Beta Now Available</title><description>&lt;div class="p1"&gt;Snort 2.9.3 Beta is now available on &lt;a href="http://snort.org/"&gt;&lt;span class="s1"&gt;snort.org&lt;/span&gt;&lt;/a&gt;, at&amp;nbsp;&lt;span class="s2"&gt;&lt;a href="http://www.snort.org/snort-downloads/"&gt;http://www.snort.org/snort-downloads/&lt;/a&gt;&lt;/span&gt;&lt;span class="s3"&gt; in the Latest Development&amp;nbsp;&lt;/span&gt;Release section.&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;2.9.0 RC &amp;amp; later packages are signed with a new PGP key&amp;nbsp;(that is signed with the previous key).&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;Snort 2.9.3 introduces the following new capabilities:&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;[*] New additions&lt;/div&gt;&lt;div class="p1"&gt;&amp;nbsp;* Updates to flowbit rule option to allow for OR and AND&amp;nbsp;of individual bits within a single rule, and allow flowbits&amp;nbsp;to be used in multiple groups. &amp;nbsp;See README.flowbits and&amp;nbsp;the Snort manual for details.&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;&amp;nbsp;* Dynamic output plugin architecture to provide an API that&amp;nbsp;developers can write their own output mechanisms to log alert&amp;nbsp;and packet data from Snort. &amp;nbsp;Some output plugins have been&amp;nbsp;removed as a result of this to be maintained by their&amp;nbsp;respective authors.&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;&amp;nbsp;* Update to dcerpc2 preprocessor for improved accuracy and&amp;nbsp;handling of different OSs for SMB processing. &amp;nbsp;See README.dcerpc2&amp;nbsp;and the Snort manual for details.&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;&amp;nbsp;* Updates to reputation preprocessor for handling of whitlelist&amp;nbsp;and trustlists and zone information. &amp;nbsp;See README.reputation&amp;nbsp;and the Snort manual for details.&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;&amp;nbsp;* Updates to the packet decoders to support pflog v4.&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;[*] Improvements&lt;/div&gt;&lt;div class="p1"&gt;&amp;nbsp;* Update to return error messages through the control socket.&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;&amp;nbsp;* Updates to the processing of email attachments for better&amp;nbsp;handling of non-encoded attachments, and improved memory&amp;nbsp;management for attachment processing.&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;&amp;nbsp;* Improvements in HTTP Inspect for better performance with gzip&amp;nbsp;decompression. &amp;nbsp;Also improvements for handling simple responses,&amp;nbsp;encoded query strings, transfer encoding and chunk encoding&amp;nbsp;processing.&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;&amp;nbsp;* Fix logging of multiple unified2 alerts with reassembled packets.&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;&amp;nbsp;* Compiler warning cleanup across multiple platforms.&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;&amp;nbsp;* Added 116:458 and 116:459 to cover fragmentation issues.&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;Please see the Release Notes and ChangeLog for more details.&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;Please submit bugs, questions, and feedback to &lt;a href="mailto:snort-beta@sourcefire.com"&gt;&lt;span class="s1"&gt;snort-beta@sourcefire.com&lt;/span&gt;&lt;/a&gt;.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-8282677178411995647?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=nl3LV3ku8DI:ewu6HMoIkKY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=nl3LV3ku8DI:ewu6HMoIkKY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=nl3LV3ku8DI:ewu6HMoIkKY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=nl3LV3ku8DI:ewu6HMoIkKY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/nl3LV3ku8DI" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/nl3LV3ku8DI/snort-293-beta-now-available.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/05/snort-293-beta-now-available.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-4278140939639821341</guid><pubDate>Thu, 17 May 2012 20:02:00 +0000</pubDate><atom:updated>2012-05-17T16:02:54.094-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.3</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.2</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.1</category><category domain="http://www.blogger.com/atom/ns#">updates</category><category domain="http://www.blogger.com/atom/ns#">2.9.1.2</category><title>VRT Rule Update for 05/17/2012</title><description>Join us as we welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2012-05-17.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 25 new rules and made modifications to 814 additional rules.&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:&lt;br /&gt;
&lt;blockquote&gt;Synopsis:&lt;br /&gt;
This release adds and modifies rules in several categories.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
The Sourcefire VRT has added and modified multiple rules in the&amp;nbsp;backdoor, blacklist, botnet-cnc, dos, exploit, file-identify,&amp;nbsp;file-office, file-pdf, indicator-compromise, phishing-spam,&amp;nbsp;server-mail, smtp, specific-threats, web-activex and web-misc rule sets&amp;nbsp;to provide coverage for emerging threats from these technologies.&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-4278140939639821341?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=DB6xSjY_PdU:TKRd2pN1I5Q:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=DB6xSjY_PdU:TKRd2pN1I5Q:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=DB6xSjY_PdU:TKRd2pN1I5Q:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=DB6xSjY_PdU:TKRd2pN1I5Q:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/DB6xSjY_PdU" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/DB6xSjY_PdU/vrt-rule-update-for-05172012.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/05/vrt-rule-update-for-05172012.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-6253272238312509883</guid><pubDate>Tue, 15 May 2012 21:20:00 +0000</pubDate><atom:updated>2012-05-15T17:20:22.907-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">release</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>Snort 2.9.2.3 has been released!</title><description>&lt;div class="p1"&gt;Snort 2.9.2.3 is now available on &lt;a href="http://snort.org/"&gt;&lt;span class="s1"&gt;snort.org&lt;/span&gt;&lt;/a&gt;, at&amp;nbsp;&lt;span class="s2"&gt;&lt;a href="http://www.snort.org/snort-downloads/"&gt;http://www.snort.org/snort-downloads/&lt;/a&gt;&lt;/span&gt;&lt;span class="s3"&gt; in the Latest Release section.&lt;/span&gt;&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;2.9.0 RC &amp;amp; later packages are signed with a new PGP key&amp;nbsp;(that is signed with the previous key).&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;Snort 2.9.2.3 includes changes for the following:&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;&amp;nbsp;* Update to GTP preprocessor to better handle GTPv1 data.&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;&amp;nbsp;* Update to DNP3 preprocessor to add stricter checking on&lt;/div&gt;&lt;div class="p1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;packets before processing by dnp3. &amp;nbsp;Improved checking&lt;/div&gt;&lt;div class="p1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;on reassembly buffer&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;&amp;nbsp;* Update to PCRE rule option processing to prevent issues&lt;/div&gt;&lt;div class="p1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;seen w/ libpcre-8.30 and certain rules.&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;&amp;nbsp;* Update to dcerpc2 to not abort reassembly if target-based&lt;/div&gt;&lt;div class="p1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;protocol is undefined.&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="p1"&gt;Please submit bugs, questions, and feedback to &lt;a href="mailto:bugs@snort.org"&gt;&lt;span class="s1"&gt;bugs@snort.org&lt;/span&gt;&lt;/a&gt;.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-6253272238312509883?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=V99rH3LUYDE:M_pVQAI7bC4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=V99rH3LUYDE:M_pVQAI7bC4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=V99rH3LUYDE:M_pVQAI7bC4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=V99rH3LUYDE:M_pVQAI7bC4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/V99rH3LUYDE" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/V99rH3LUYDE/snort-2923-has-been-released.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/05/snort-2923-has-been-released.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-8980496523967806953</guid><pubDate>Sat, 12 May 2012 02:19:00 +0000</pubDate><atom:updated>2012-05-11T22:19:55.227-04:00</atom:updated><title>VRT: PHP-CGI vulnerability - exploits in the wild and Snort coverage</title><description>&lt;a href="http://vrt-blog.snort.org/2012/05/php-cgi-vulnerability-exploits-in-wild.html"&gt;VRT: PHP-CGI vulnerability - exploits in the wild and Snort coverage&lt;/a&gt;: &lt;br /&gt;
&lt;br /&gt;
Just wanted to call our Snort.org blog subscribers out to this article by Alex Kirk over on our VRT Blog. &amp;nbsp;This article deals with the PHP-CGI vulnerability and which Snort rules you need to enable in order to protect your network from it.&lt;br /&gt;
&lt;br /&gt;
Take a look!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-8980496523967806953?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=Pu_8hU-spLo:_0wUF3uNTg8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=Pu_8hU-spLo:_0wUF3uNTg8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=Pu_8hU-spLo:_0wUF3uNTg8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=Pu_8hU-spLo:_0wUF3uNTg8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/Pu_8hU-spLo" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/Pu_8hU-spLo/vrt-php-cgi-vulnerability-exploits-in.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/05/vrt-php-cgi-vulnerability-exploits-in.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-794374516307538634</guid><pubDate>Thu, 10 May 2012 22:43:00 +0000</pubDate><atom:updated>2012-05-10T18:43:23.134-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.0</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">release</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.1</category><category domain="http://www.blogger.com/atom/ns#">updates</category><category domain="http://www.blogger.com/atom/ns#">2.9.1.2</category><title>VRT Rule Update for 05/10/2012</title><description>Join us as we welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2012-05-10.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced &lt;b&gt;819&lt;/b&gt; new rules and made modifications to &lt;b&gt;554&lt;/b&gt; additional rules.&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:&lt;br /&gt;
&lt;blockquote&gt;Synopsis:&lt;br /&gt;
This release adds and modifies rules in several categories.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
The Sourcefire VRT has added and modified multiple rules in the&lt;br /&gt;
backdoor, blacklist, botnet-cnc, dos, file-office, file-other,&lt;br /&gt;
indicator-compromise, misc and specific-threats rule sets to provide&lt;br /&gt;
coverage for emerging threats from these technologies.&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-794374516307538634?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=_VKXbs82TYU:AD8wAPYH_Vk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=_VKXbs82TYU:AD8wAPYH_Vk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=_VKXbs82TYU:AD8wAPYH_Vk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=_VKXbs82TYU:AD8wAPYH_Vk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/_VKXbs82TYU" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/_VKXbs82TYU/vrt-rule-update-for-05102012.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/05/vrt-rule-update-for-05102012.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-3330120884437448756</guid><pubDate>Thu, 10 May 2012 13:24:00 +0000</pubDate><atom:updated>2012-05-14T16:07:26.858-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">scholarship</category><category domain="http://www.blogger.com/atom/ns#">sourcefire</category><category domain="http://www.blogger.com/atom/ns#">snort</category><title>2012 Snort Scholarship is now open!</title><description>Annually, Sourcefire provides a &lt;a href="http://www.sourcefire.com/security-technologies/snort/snort-scholarship" target="_blank"&gt;Snort Scholarship&lt;/a&gt; to two individuals selected at random (by drawing) in the amount of $5000 US for higher education purposes. &amp;nbsp;The winners also receive a 10,000 credit to use toward any training courses or certification exam in the &lt;a href="http://www.sourcefire.com/services" target="_blank"&gt;Sourcefire Security Education Program&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
To be eligible, you must meet the &lt;a href="http://www.sourcefire.com/security-technologies/snort/snort-scholarship/rules" target="_blank"&gt;legal criteria found here on our website&lt;/a&gt;, &lt;a href="http://info.sourcefire.com/2012SnortScholarshipApplicationPage.html" target="_blank"&gt;sign up for the scholarship here&lt;/a&gt;, and following that, on or about May 31, 2012, two winners will be selected. &lt;br /&gt;
&lt;br /&gt;
For further information, please see the links above, also found &lt;a href="http://www.sourcefire.com/security-technologies/snort/snort-scholarship" target="_blank"&gt;linked here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-3330120884437448756?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=w9i0ra8C5_4:PhCCWmu-irE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=w9i0ra8C5_4:PhCCWmu-irE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=w9i0ra8C5_4:PhCCWmu-irE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=w9i0ra8C5_4:PhCCWmu-irE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/w9i0ra8C5_4" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/w9i0ra8C5_4/2012-snort-scholarship-is-now-open.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/05/2012-snort-scholarship-is-now-open.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-7325287937304442866</guid><pubDate>Wed, 09 May 2012 02:07:00 +0000</pubDate><atom:updated>2012-05-08T22:07:22.313-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">mstues</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.2</category><category domain="http://www.blogger.com/atom/ns#">updates</category><category domain="http://www.blogger.com/atom/ns#">2.9.1.2</category><title>VRT Rule Release for 05/08/2012, MS Tuesday</title><description>Sorry for the delay in getting the blog post up, we've been really busy today planning some great things for the future!  Join us as we welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2012-05-08.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 23 new rules and made modifications to 48 additional rules.&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:&lt;br /&gt;
&lt;blockquote&gt;Synopsis:&lt;br /&gt;
The Sourcefire VRT is aware of vulnerabilities affecting products from&lt;br /&gt;
Microsoft Corporation.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
Microsoft Security Advisory MS12-029:&lt;br /&gt;
The Microsoft RTF importer contains programming errors that may allow a&lt;br /&gt;
remote attacker to execute code on an affected system.&lt;br /&gt;
&lt;br /&gt;
A rule to detect attacks targeting this vulnerability is included in&lt;br /&gt;
this release and is identified with GID 3, SID 22089.&lt;br /&gt;
&lt;br /&gt;
Microsoft Security Advisory MS12-030:&lt;br /&gt;
Microsoft Excel contains programming errors that may allow a remote&lt;br /&gt;
attacker to execute code on a vulnerable system.&lt;br /&gt;
&lt;br /&gt;
Rules to detect attacks targeting these vulnerabilities are included in&lt;br /&gt;
this release and are identified with GID 1, SIDs 22076, 22077, 22078,&lt;br /&gt;
22081, 22091, 22092, 22093 and 22094.&lt;br /&gt;
&lt;br /&gt;
Microsoft Security Advisory MS12-031:&lt;br /&gt;
Microsoft Visio contains a programming error that may allow a remote&lt;br /&gt;
attacker to execute code on an affected system.&lt;br /&gt;
&lt;br /&gt;
A rule to detect attacks targeting this vulnerability is included in&lt;br /&gt;
this release and is identified with GID 1, SID 22075.&lt;br /&gt;
&lt;br /&gt;
Microsoft Security Advisory MS12-034:&lt;br /&gt;
Microsoft Office contains programming errors that may allow a remote&lt;br /&gt;
attacker to execute code on an affected system.&lt;br /&gt;
&lt;br /&gt;
Rules to detect attacks targeting these vulnerabilities are included in&lt;br /&gt;
this release and are identified with GID 1, SIDs 22085, 22086, 22087&lt;br /&gt;
and 22090.&lt;br /&gt;
&lt;br /&gt;
Microsoft Security Advisory MS12-035:&lt;br /&gt;
The Microsoft .NET Framework contains programming errors that may allow&lt;br /&gt;
a remote attacker to execute code on an affected system.&lt;br /&gt;
&lt;br /&gt;
Rules to detect attacks targeting these vulnerabilities are included in&lt;br /&gt;
this release and are identified with GID 1, SIDs 22079 and 22080.&lt;br /&gt;
&lt;br /&gt;
Additionally, the Sourcefire VRT has added and modified multiple rules&lt;br /&gt;
in the bad-traffic, botnet-cnc, file-identify, file-office, file-other,&lt;br /&gt;
server-mail and web-client rule sets to provide coverage for emerging&lt;br /&gt;
threats from these technologies.&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-7325287937304442866?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=BhNfrd0z4NI:oZ6F8ahl-3M:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=BhNfrd0z4NI:oZ6F8ahl-3M:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=BhNfrd0z4NI:oZ6F8ahl-3M:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=BhNfrd0z4NI:oZ6F8ahl-3M:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/BhNfrd0z4NI" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/BhNfrd0z4NI/vrt-rule-release-for-05082012-ms.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/05/vrt-rule-release-for-05082012-ms.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-8110271100664053505</guid><pubDate>Sat, 05 May 2012 02:02:00 +0000</pubDate><atom:updated>2012-05-04T22:02:38.992-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.2</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.1</category><category domain="http://www.blogger.com/atom/ns#">2.9.1.2</category><title>VRT Rule Update for 05/04/2012, #2 (Adobe 0day coverage)</title><description>In this release we introduced 9 new rules and made modifications to 1 additional rule.&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.&lt;br /&gt;
&lt;br /&gt;
This second release of the day provides coverage for CVE-2012-0779, which is discussed &lt;a href="http://www.adobe.com/support/security/bulletins/apsb12-09.html"&gt;here on Adobe's site&lt;/a&gt;.  Included in this update is more generic coverage for the attack vector surrounding this attack that is being seen in the wild.  The "INDICATOR-OBFUSCATION" rules below may very well catch a ton of additional exploit methods other than the Adobe attack referenced above.  &lt;br /&gt;
&lt;br /&gt;
Since the usual link on Snort.org isn't currently working, I'm posting the sid and rule msg's here:&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;&lt;br /&gt;
22066(1) "POLICY Microsoft Office Word ScriptBridge OCX controller attempt"&lt;br /&gt;
22067(1) "MISC Adobe Flash malformed error response"&lt;br /&gt;
22068(1) "SPECIFIC-THREATS Adobe Flash systemMemoryCall RTMP query"&lt;br /&gt;
22069(1) "SPECIFIC-THREATS Adobe Flash Player object confusion attempt"&lt;br /&gt;
22070(1) "SPECIFIC-THREATS Adobe Flash Player object confusion attempt"&lt;br /&gt;
22071(1) "INDICATOR-OBFUSCATION Microsoft Office Word JavaScript obfuscation - eval"&lt;br /&gt;
22072(1) "INDICATOR-OBFUSCATION Microsoft Office Word JavaScript obfuscation - fromCharCode"&lt;br /&gt;
22073(1) "INDICATOR-OBFUSCATION Microsoft Office Word JavaScript obfuscation - unescape"&lt;br /&gt;
22074(1) "INDICATOR-OBFUSCATION Microsoft Office Word JavaScript obfuscation - charCode"&lt;br /&gt;
&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:&lt;br /&gt;
&lt;blockquote&gt;Synopsis:&lt;br /&gt;
This release adds and modifies rules in several categories.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
The Sourcefire VRT has added and modified multiple rules in the indicator-obfuscation, misc and specific-threats rule sets to provide coverage for emerging threats from these technologies.&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-8110271100664053505?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=frUVCMNSIgs:VlEvUIHYtk4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=frUVCMNSIgs:VlEvUIHYtk4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=frUVCMNSIgs:VlEvUIHYtk4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=frUVCMNSIgs:VlEvUIHYtk4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/frUVCMNSIgs" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/frUVCMNSIgs/vrt-rule-update-for-05042012-2-adobe.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/05/vrt-rule-update-for-05042012-2-adobe.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-4380230194336379109</guid><pubDate>Fri, 04 May 2012 22:09:00 +0000</pubDate><atom:updated>2012-05-04T18:09:39.767-04:00</atom:updated><title>VRT Rules Update for 5/4/2012, PHP 0day, lots of malware</title><description>Join us as we welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2012-05-04.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 25 new rules and made modifications to 9 additional rules.&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.&lt;br /&gt;
&lt;br /&gt;
We'd also like to thank Eoin Miller for his contributions to this rule pack. &lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:&lt;br /&gt;
&lt;blockquote&gt;Synopsis:&lt;br /&gt;
This release adds and modifies rules in several categories.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
The Sourcefire VRT has added and modified multiple rules in the&lt;br /&gt;
backdoor, blacklist, botnet-cnc, exploit, file-identify, file-office,&lt;br /&gt;
file-other, specific-threats and web-php rule sets to provide coverage&lt;br /&gt;
for emerging threats from these technologies.&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-4380230194336379109?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=eWfKlgrTolY:-2a0-Abm6UY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=eWfKlgrTolY:-2a0-Abm6UY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=eWfKlgrTolY:-2a0-Abm6UY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=eWfKlgrTolY:-2a0-Abm6UY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/eWfKlgrTolY" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/eWfKlgrTolY/vrt-rules-update-for-542012-php-0day.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/05/vrt-rules-update-for-542012-php-0day.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-2937187088641420582</guid><pubDate>Wed, 02 May 2012 21:57:00 +0000</pubDate><atom:updated>2012-05-02T17:57:25.038-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.0</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.2</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.1</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>VRT Rule Update for 05/02/2012</title><description>Join us as we welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2012-05-02.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 100 new rules and made modifications to 163 additional rules.&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:&lt;br /&gt;
&lt;blockquote&gt;Synopsis:&lt;br /&gt;
This release adds and modifies rules in several categories.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
The Sourcefire VRT has added and modified multiple rules in the&lt;br /&gt;
backdoor, blacklist, botnet-cnc, chat, dns, dos, exploit,&lt;br /&gt;
file-identify, file-office, file-other, file-pdf, misc, mysql, netbios,&lt;br /&gt;
oracle, policy, server-mail, smtp, specific-threats, web-activex,&lt;br /&gt;
web-cgi, web-client and web-misc rule sets to provide coverage for&lt;br /&gt;
emerging threats from these technologies.&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-2937187088641420582?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=t0WiWZGFoQs:9f-wlILCxoM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=t0WiWZGFoQs:9f-wlILCxoM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=t0WiWZGFoQs:9f-wlILCxoM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=t0WiWZGFoQs:9f-wlILCxoM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/t0WiWZGFoQs" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/t0WiWZGFoQs/vrt-rule-update-for-05022012.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/05/vrt-rule-update-for-05022012.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-5826380918437424033</guid><pubDate>Thu, 26 Apr 2012 22:45:00 +0000</pubDate><atom:updated>2012-04-26T18:45:04.821-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.2</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>Registered user?  Time to upgrade to 2.9.2.2!</title><description>For those Registered Users for Snort (read: Not subscribers), letting you know it's been 30 days since the release of Snort 2.9.2.2 and now the rules are released to everyone for free.&lt;br /&gt;
&lt;br /&gt;
If you've been waiting to make the upgrade until this point, now is the time!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-5826380918437424033?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=iw6KNs1QWm8:t85pscv_8rg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=iw6KNs1QWm8:t85pscv_8rg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=iw6KNs1QWm8:t85pscv_8rg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=iw6KNs1QWm8:t85pscv_8rg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/iw6KNs1QWm8" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/iw6KNs1QWm8/registered-user-time-to-upgrade-to-2922.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/04/registered-user-time-to-upgrade-to-2922.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-8479617945026981141</guid><pubDate>Thu, 26 Apr 2012 21:14:00 +0000</pubDate><atom:updated>2012-04-26T17:14:20.851-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.0</category><category domain="http://www.blogger.com/atom/ns#">2.9.1.5</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.2</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.1</category><title>VRT Rule Update for 04/26/2012</title><description>Join us as we welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2012-04-26.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 3 new rules and made modifications to 24 additional rules.&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:&lt;br /&gt;
&lt;blockquote&gt;Synopsis:&lt;br /&gt;
This release adds and modifies rules in several categories.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
The Sourcefire VRT has added and modified multiple rules in the&lt;br /&gt;
backdoor, blacklist, dos, exploit, file-identify, file-office, misc,&lt;br /&gt;
specific-threats, telnet and web-misc rule sets to provide coverage for&lt;br /&gt;
emerging threats from these technologies.&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-8479617945026981141?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=-INKZ9osmn8:sqwEZ7Usi4I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=-INKZ9osmn8:sqwEZ7Usi4I:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=-INKZ9osmn8:sqwEZ7Usi4I:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=-INKZ9osmn8:sqwEZ7Usi4I:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/-INKZ9osmn8" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/-INKZ9osmn8/vrt-rule-update-for-04262012.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/04/vrt-rule-update-for-04262012.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-1520127785093491832</guid><pubDate>Wed, 25 Apr 2012 22:35:00 +0000</pubDate><atom:updated>2012-04-25T18:37:32.389-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.0</category><category domain="http://www.blogger.com/atom/ns#">2.9.1.5</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.2</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.1</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>VRT Rule Update for 4/25/2012</title><description>Join us as we welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2012-04-25.html"&gt;rule release&lt;/a&gt;&amp;nbsp;from the VRT. In this release we introduced 4 new rules and made modifications to 11 additional rules.&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:&lt;br /&gt;
&lt;blockquote&gt;Synopsis:&lt;br /&gt;
This release adds and modifies rules in several categories.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
The Sourcefire VRT has added and modified multiple rules in the&lt;br /&gt;
file-office and spyware-put rule sets to provide coverage for emerging&lt;br /&gt;
threats from these technologies.&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-1520127785093491832?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=A41IfpwLD4Q:2RRUZ519hfA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=A41IfpwLD4Q:2RRUZ519hfA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=A41IfpwLD4Q:2RRUZ519hfA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=A41IfpwLD4Q:2RRUZ519hfA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/A41IfpwLD4Q" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/A41IfpwLD4Q/vrt-rule-update-for-4252012.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/04/vrt-rule-update-for-4252012.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-6030730152123950732</guid><pubDate>Wed, 25 Apr 2012 19:50:00 +0000</pubDate><atom:updated>2012-04-25T18:35:31.142-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.0</category><category domain="http://www.blogger.com/atom/ns#">2.9.1.5</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.2</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.1</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>VRT Rule Update for 4/24/2012</title><description>Join us as we welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2012-04-24.html"&gt;rule release&lt;/a&gt;&amp;nbsp;from the VRT. In this release we introduced 44 new rules and made modifications to 658 additional rules.&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:&lt;br /&gt;
&lt;blockquote&gt;Synopsis:&lt;br /&gt;
This release adds and modifies rules in several categories.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
The Sourcefire VRT has added and modified multiple rules in the&lt;br /&gt;
blacklist, botnet-cnc, dos, exploit, file-identify, file-office,&lt;br /&gt;
file-pdf, indicator-compromise, misc, netbios, oracle, server-mail,&lt;br /&gt;
specific-threats, spyware-put, web-activex, web-client, web-iis and&lt;br /&gt;
web-php rule sets to provide coverage for emerging threats from these&lt;br /&gt;
technologies.&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-6030730152123950732?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=bNbJW0A-KNg:IamNYpZzMpo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=bNbJW0A-KNg:IamNYpZzMpo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=bNbJW0A-KNg:IamNYpZzMpo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=bNbJW0A-KNg:IamNYpZzMpo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/bNbJW0A-KNg" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/bNbJW0A-KNg/vrt-rule-update-for-4242012.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/04/vrt-rule-update-for-4242012.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-8847033281503086479</guid><pubDate>Tue, 17 Apr 2012 16:26:00 +0000</pubDate><atom:updated>2012-04-17T12:26:55.058-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.0</category><category domain="http://www.blogger.com/atom/ns#">2.9.1.5</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">release</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.2</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.1</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>VRT Rule Update for 04/17/2012</title><description>Join us as we welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2012-04-17.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 35 new rules and made modifications to &lt;b&gt;1152&lt;/b&gt;! additional rules.&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:&lt;br /&gt;
&lt;blockquote&gt;Synopsis:&lt;br /&gt;
This release adds and modifies rules in several categories.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
The Sourcefire VRT has added and modified multiple rules in the blacklist, botnet-cnc, dos, exploit, file-identify, file-office, file-other, file-pdf, imap, indicator-obfuscation, misc, netbios, oracle, policy-social, pua-toolbars, specific-threats, sql, web-activex, web-cgi, web-client and web-misc rule sets to provide coverage for emerging threats from these technologies.&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-8847033281503086479?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=J8xqCyM1_wg:CSB_Ffm7ihI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=J8xqCyM1_wg:CSB_Ffm7ihI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=J8xqCyM1_wg:CSB_Ffm7ihI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=J8xqCyM1_wg:CSB_Ffm7ihI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/J8xqCyM1_wg" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/J8xqCyM1_wg/vrt-rule-update-for-04172012.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/04/vrt-rule-update-for-04172012.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-6027128932991322938</guid><pubDate>Thu, 12 Apr 2012 20:01:00 +0000</pubDate><atom:updated>2012-04-12T16:01:04.185-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.0</category><category domain="http://www.blogger.com/atom/ns#">2.9.1.5</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.2</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.1</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>VRT Rule Update for 04/12/2012, Rule-Recategorization</title><description>Join us as we welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2012-04-12.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 47 new rules and made modifications to 581 additional rules.&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.&lt;br /&gt;
&lt;br /&gt;
In this rule release many rules were moved from their old categories to new categories as listed in &lt;a href="http://blog.snort.org/2012/04/vrt-rule-update-for-432012-rule.html"&gt;this blog post&lt;/a&gt;.  Rules are going to be continually moving throughout the next few months, so please pay attention to the blog to make sure you don't miss anything!&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:&lt;br /&gt;
&lt;blockquote&gt;Synopsis:&lt;br /&gt;
This release adds and modifies rules in several categories.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
The Sourcefire VRT has added and modified multiple rules in the&lt;br /&gt;
botnet-cnc, dns, dos, exploit, file-identify, file-office, file-pdf,&lt;br /&gt;
indicator-compromise, policy, policy-multimedia, pua-p2p, server-mail,&lt;br /&gt;
specific-threats, web-activex, web-client and web-misc rule sets to&lt;br /&gt;
provide coverage for emerging threats from these technologies.&lt;br /&gt;
&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-6027128932991322938?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=Xfuu-Xn6Oao:Q6FLYLC5pJ8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=Xfuu-Xn6Oao:Q6FLYLC5pJ8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=Xfuu-Xn6Oao:Q6FLYLC5pJ8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=Xfuu-Xn6Oao:Q6FLYLC5pJ8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/Xfuu-Xn6Oao" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/Xfuu-Xn6Oao/vrt-rule-update-for-04122012-rule.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/04/vrt-rule-update-for-04122012-rule.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-8610995347899181938</guid><pubDate>Wed, 11 Apr 2012 18:58:00 +0000</pubDate><atom:updated>2012-04-11T14:58:16.741-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.0</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">release</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.2</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.1</category><category domain="http://www.blogger.com/atom/ns#">updates</category><category domain="http://www.blogger.com/atom/ns#">2.9.1.2</category><title>VRT Rule Update for 04/11/2012, Samba Remote Root</title><description>Join us as we welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2012-04-11.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 5 new rules and made modifications to 11 additional rules.&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:&lt;br /&gt;
&lt;blockquote&gt;Synopsis:&lt;br /&gt;
This release adds and modifies rules in several categories and includes&lt;br /&gt;
detection for a Remote Code Execution (RCE) vulnerability in Samba.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
Samba Remote Code Execution (CVE-2012-1182):&lt;br /&gt;
The RPC code generator in certain versions of Samba does not correctly&lt;br /&gt;
validate an array length. This error may allow remote attackers to&lt;br /&gt;
execute code on an affected system.&lt;br /&gt;
&lt;br /&gt;
A rule to detect attacks targeting this vulnerability is included in&lt;br /&gt;
this release and is identified with GID 1, SID 21806.&lt;br /&gt;
&lt;br /&gt;
Additionally, the Sourcefire VRT has added and modified multiple rules&lt;br /&gt;
in the exploit, file-identify, file-office, indicator-compromise and&lt;br /&gt;
web-client rule sets to provide coverage for emerging threats from&lt;br /&gt;
these technologies.&lt;/blockquote&gt;&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-8610995347899181938?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=8EoEkXT5ez4:5SI41_Kr5as:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=8EoEkXT5ez4:5SI41_Kr5as:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=8EoEkXT5ez4:5SI41_Kr5as:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=8EoEkXT5ez4:5SI41_Kr5as:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/8EoEkXT5ez4" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/8EoEkXT5ez4/vrt-rule-update-for-04112012-samba.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/04/vrt-rule-update-for-04112012-samba.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-7562383856984666525</guid><pubDate>Tue, 10 Apr 2012 20:10:00 +0000</pubDate><atom:updated>2012-04-10T16:10:51.703-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">community</category><category domain="http://www.blogger.com/atom/ns#">guides</category><category domain="http://www.blogger.com/atom/ns#">docs</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.2</category><category domain="http://www.blogger.com/atom/ns#">snort.org</category><title>Snort 2.9.2.2 Install Guide for Debian 6.0.4 posted!</title><description>Thanks to Jason Weir, I just posted his Snort 2.9.2.2 Install Guide for Debian 6.0.4.&lt;br /&gt;
&lt;br /&gt;
You may find his updated guide at &lt;a href="http://www.snort.org/docs"&gt;http://www.snort.org/docs&lt;/a&gt;. &amp;nbsp;We'd like to thank Jason Weir and the rest of the Snort community with their constant support, guides, bug reports, false positive reports, and participation in the mailing lists.&lt;br /&gt;
&lt;br /&gt;
You all are fantastic!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-7562383856984666525?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=4qmRiA0H9ms:bFGkB6teTU4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=4qmRiA0H9ms:bFGkB6teTU4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=4qmRiA0H9ms:bFGkB6teTU4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=4qmRiA0H9ms:bFGkB6teTU4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/4qmRiA0H9ms" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/4qmRiA0H9ms/snort-2922-install-guide-for-debian-604.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>1</thr:total><feedburner:origLink>http://blog.snort.org/2012/04/snort-2922-install-guide-for-debian-604.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-6596837053556306287</guid><pubDate>Tue, 10 Apr 2012 17:46:00 +0000</pubDate><atom:updated>2012-04-10T13:46:50.278-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.0</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">mstues</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.2</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.1</category><category domain="http://www.blogger.com/atom/ns#">2.9.1.2</category><title>VRT Rule Update for 4/10/12, MS Tuesday</title><description>Join us as we welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2012-04-10.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 78 new rules and made modifications to 301 additional rules.

There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:
&lt;br /&gt;
&lt;blockquote&gt;
Synopsis:
The Sourcefire VRT is aware of vulnerabilities affecting products from
Microsoft Corporation.&amp;nbsp;&lt;/blockquote&gt;
&lt;blockquote&gt;
Details:&amp;nbsp;&lt;/blockquote&gt;
&lt;blockquote&gt;
Microsoft Security Bulletin MS12-023:
Microsoft Internet Explorer suffers from programming errors that may
allow a remote attacker to execute code on an affected system.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 21793 and 21796.&amp;nbsp;&lt;/blockquote&gt;
&lt;blockquote&gt;
Microsoft Security Bulletin MS12-024:
The Microsoft Windows Authenticode verification system contains a
programming error that may allow a remote attacker to include
executable code in an application while keeping the digital signature
intact.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 1, SID 21795. &amp;nbsp;&amp;nbsp;&lt;/blockquote&gt;
&lt;blockquote&gt;
Microsoft Security Bulletin MS12-025:
The Microsoft .NET Framework incorrectly validates some parameters used
in processing image data. This may allow a remote attacker to execute
code on an affected system.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 1, SID 21792.&amp;nbsp;&lt;/blockquote&gt;
&lt;blockquote&gt;
Microsoft Security Bulletin MS12-027:
The Microsoft Windows Common Controls ActiveX DLL (MSCOMCTL) contains
programming errors that may allow a remote attacker to execute code on
an affected system.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 21797 through 21801.&amp;nbsp;&lt;/blockquote&gt;
&lt;blockquote&gt;
Microsoft Security Bulletin MS12-028:
The Microsoft Office WPS converter contains a programming error that
may allow a remote attacker to execute code on an affected system.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 1, SID 21794.&amp;nbsp;&lt;/blockquote&gt;
&lt;blockquote&gt;
Additionally, the Sourcefire VRT has added and modified multiple rules
in the backdoor, botnet-cnc, dns, dos, exploit, file-identify,
file-office, file-other, file-pdf, netbios, policy, pop3, rpc, scada,
shellcode, smtp, specific-threats, sql, voip, web-activex and web-misc
rule sets to provide coverage for emerging threats from these
technologies.
&lt;/blockquote&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-6596837053556306287?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=c0Zrc10u9CU:adARtWETJD4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=c0Zrc10u9CU:adARtWETJD4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=c0Zrc10u9CU:adARtWETJD4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=c0Zrc10u9CU:adARtWETJD4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/c0Zrc10u9CU" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/c0Zrc10u9CU/vrt-rule-update-for-41012-ms-tuesday.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/04/vrt-rule-update-for-41012-ms-tuesday.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-288152166531305160</guid><pubDate>Thu, 05 Apr 2012 20:56:00 +0000</pubDate><atom:updated>2012-04-05T17:15:34.864-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.0</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.2</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.1</category><category domain="http://www.blogger.com/atom/ns#">updates</category><category domain="http://www.blogger.com/atom/ns#">2.9.1.2</category><title>VRT Rule Release for 3/5/2012</title><description>Join us as we welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2012-04-05.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 37 new rules and made modifications to 248 additional rules.&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;In VRT's rule release:
&lt;br /&gt;
&lt;blockquote&gt;
Synopsis:
This release adds and modifies rules in several categories.&amp;nbsp;&lt;/blockquote&gt;
&lt;blockquote&gt;
Details:
The Sourcefire VRT has added and modified multiple rules in the dos,
exploit, file-identify, file-office, file-other, file-pdf, misc,
multimedia, netbios, policy, policy-other, shellcode, smtp,
specific-threats, sql, web-activex and web-misc rule sets to provide
coverage for emerging threats from these technologies.&lt;/blockquote&gt;
&lt;b&gt;REMINDER: READ &lt;a href="http://blog.snort.org/2012/04/vrt-rule-update-for-432012-rule.html" target="_blank"&gt;THIS BLOG POST&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-288152166531305160?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=gIJ8NVhNXJw:wq_MdxyLp6c:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=gIJ8NVhNXJw:wq_MdxyLp6c:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=gIJ8NVhNXJw:wq_MdxyLp6c:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=gIJ8NVhNXJw:wq_MdxyLp6c:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/gIJ8NVhNXJw" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/gIJ8NVhNXJw/vrt-rule-release-for-352012.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/04/vrt-rule-release-for-352012.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-6611220529768687175</guid><pubDate>Tue, 03 Apr 2012 21:33:00 +0000</pubDate><atom:updated>2012-04-03T17:33:50.175-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.0</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">release</category><category domain="http://www.blogger.com/atom/ns#">downloads</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.2</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.1</category><category domain="http://www.blogger.com/atom/ns#">2.9.1.2</category><title>VRT Rule Update for 4/3/2012, Rule-Recategorization</title><description>Join us as we welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2012-04-03.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 30 new rules and made modifications to 169 additional rules.&lt;br /&gt;
&lt;br /&gt;
The following changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release, these can be added to the bottom of the &lt;code&gt;snort.conf&lt;/code&gt; where the rule declarations are made:&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt; include $RULE_PATH/file-office.rules&lt;br /&gt;
 include $RULE_PATH/file-other.rules&lt;br /&gt;
 include $RULE_PATH/file-pdf.rules&lt;br /&gt;
 include $RULE_PATH/indicator-compromise.rules&lt;br /&gt;
 include $RULE_PATH/indicator-obfuscation.rules&lt;br /&gt;
 include $RULE_PATH/policy-multimedia.rules&lt;br /&gt;
 include $RULE_PATH/policy-other.rules&lt;br /&gt;
 include $RULE_PATH/policy-social.rules&lt;br /&gt;
 include $RULE_PATH/pua-p2p.rules&lt;br /&gt;
 include $RULE_PATH/pua-toolbars.rules&lt;br /&gt;
 include $RULE_PATH/server-mail.rules&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;In VRT's rule release:
&lt;br /&gt;
&lt;blockquote&gt;
Synopsis:
This release introduces eleven new rule categories and contains new and
modified rules in several categories.&amp;nbsp;&lt;/blockquote&gt;
&lt;blockquote&gt;
Details:
This release introduces eleven new rule categories:&amp;nbsp;&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;code&gt;File-Office&lt;br /&gt;
File-Other&lt;br /&gt;
File-PDF&lt;br /&gt;
Indicator-Compromise&lt;br /&gt;
Indicator-Obfuscation&lt;br /&gt;
Policy-Multimedia&lt;br /&gt;
Policy-Other&lt;br /&gt;
Policy-Social&lt;br /&gt;
PUA-P2P&lt;br /&gt;
PUA-Toolbars&lt;br /&gt;
Server-Mail&lt;/code&gt;&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;code&gt;&lt;/code&gt;

These categories have been populated with rules that were formerly in
policy.rules, leaving 36 rules in that category. &amp;nbsp;These will be moved in the near future&amp;nbsp;&lt;/blockquote&gt;
&lt;blockquote&gt;
This release contains new and modified rules in the backdoor,
botnet-cnc, dos, exploit, file-identify, file-office, file-other,
file-pdf, indicator-compromise, indicator-obfuscation, mysql,
policy-multimedia, policy-other, policy-social, pua-p2p, pua-toolbars,
server-mail, specific-threats, spyware-put, voip, web-client and
web-php rule sets to provide coverage for emerging threats from these
technologies.&lt;/blockquote&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-6611220529768687175?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=WfgHydr2mIs:rEDgPiY9690:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=WfgHydr2mIs:rEDgPiY9690:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=WfgHydr2mIs:rEDgPiY9690:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=WfgHydr2mIs:rEDgPiY9690:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/WfgHydr2mIs" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/WfgHydr2mIs/vrt-rule-update-for-432012-rule.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>2</thr:total><feedburner:origLink>http://blog.snort.org/2012/04/vrt-rule-update-for-432012-rule.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-3463723731493183099</guid><pubDate>Thu, 29 Mar 2012 20:22:00 +0000</pubDate><atom:updated>2012-03-29T16:22:50.642-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.0</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.2</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.1</category><category domain="http://www.blogger.com/atom/ns#">updates</category><category domain="http://www.blogger.com/atom/ns#">2.9.1.2</category><title>VRT Rule Update for 3/29/2012</title><description>Join us as we welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2012-03-29.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 11 new rules and made modifications to 8 additional rules.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:
&lt;br /&gt;
&lt;blockquote&gt;
Synopsis:
This release adds and modifies rules in several categories.&amp;nbsp;&lt;/blockquote&gt;
&lt;blockquote&gt;

Details:
The Sourcefire VRT has added and modified multiple rules in the
exploit, file-identify and web-client rule sets to provide coverage for
emerging threats from these technologies.
&lt;/blockquote&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-3463723731493183099?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=sqqKauPiTI8:_SSc6q7Z74U:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=sqqKauPiTI8:_SSc6q7Z74U:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=sqqKauPiTI8:_SSc6q7Z74U:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=sqqKauPiTI8:_SSc6q7Z74U:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/sqqKauPiTI8" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/sqqKauPiTI8/vrt-rule-update-for-3292012.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/03/vrt-rule-update-for-3292012.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-4827447926200585424</guid><pubDate>Tue, 27 Mar 2012 21:43:00 +0000</pubDate><atom:updated>2012-03-27T17:43:29.501-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">release</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.2</category><category domain="http://www.blogger.com/atom/ns#">snort.org</category><title>Snort 2.9.2.2 has been released!</title><description>&lt;br /&gt;
&lt;div class="p1"&gt;
Snort 2.9.2.2 is now available on &lt;a href="http://snort.org/"&gt;&lt;span class="s1"&gt;snort.org&lt;/span&gt;&lt;/a&gt;, at&amp;nbsp;&lt;span class="s2"&gt;&lt;a href="http://www.snort.org/snort-downloads/"&gt;http://www.snort.org/snort-downloads/&lt;/a&gt;&lt;/span&gt;&lt;span class="s3"&gt; in the Latest Release section.&lt;/span&gt;&lt;/div&gt;
&lt;div class="p3"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="p1"&gt;
2.9.0 RC &amp;amp; later packages are signed with a new PGP key&amp;nbsp;(that is signed with the previous key).&lt;/div&gt;
&lt;div class="p3"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="p1"&gt;
Snort 2.9.2.2 includes changes for the following:&lt;/div&gt;
&lt;div class="p3"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="p1"&gt;
* Updates to HTTP Inspect to handle normalization with large&amp;nbsp;number of directories, eliminate false positives when chunks&amp;nbsp;span multiple packets, and remove the upper limit on the&amp;nbsp;gzip memcap.&lt;/div&gt;
&lt;div class="p3"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="p1"&gt;
* Update stream handling for TCP session cleanup with RSTs and&amp;nbsp;other TCP state tracking.&lt;/div&gt;
&lt;div class="p3"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="p1"&gt;
* Update for active responses to fragmented IPv6 traffic and to&amp;nbsp;the react page configuration.&lt;/div&gt;
&lt;div class="p3"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="p1"&gt;
* Updates to SIP preprocessor to limit false positives.&lt;/div&gt;
&lt;div class="p3"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="p1"&gt;
* Update for correct logging in unified2 when interface is passive.&lt;/div&gt;
&lt;div class="p3"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="p1"&gt;
* Add stats for SMTP preprocessor at termination.&lt;/div&gt;
&lt;div class="p3"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="p1"&gt;
* State tracking improvements to SMB processing in the dcerpc2&amp;nbsp;preprocessor when missing packets on a session.&lt;/div&gt;
&lt;div class="p3"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="p1"&gt;
Please see the Release Notes and ChangeLog for more details.&lt;/div&gt;
&lt;div class="p3"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="p1"&gt;
Please submit bugs, questions, and feedback to &lt;a href="mailto:bugs@snort.org"&gt;&lt;span class="s1"&gt;bugs@snort.org&lt;/span&gt;&lt;/a&gt;.&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-4827447926200585424?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=PWTOY3XFipQ:uaaAQJl08AE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=PWTOY3XFipQ:uaaAQJl08AE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=PWTOY3XFipQ:uaaAQJl08AE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=PWTOY3XFipQ:uaaAQJl08AE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/PWTOY3XFipQ" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/PWTOY3XFipQ/snort-2922-has-been-released.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/03/snort-2922-has-been-released.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-8036254446821689635</guid><pubDate>Tue, 27 Mar 2012 21:42:00 +0000</pubDate><atom:updated>2012-03-27T17:42:20.763-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.0</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.2</category><category domain="http://www.blogger.com/atom/ns#">2.9.2.1</category><category domain="http://www.blogger.com/atom/ns#">updates</category><category domain="http://www.blogger.com/atom/ns#">2.9.1.2</category><title>VRT Rule Update for 03/27/2012</title><description>Join us as we welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2012-03-27.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 26 new rules and made modifications to 297 additional rules.&lt;br /&gt;
&lt;br /&gt;
This rule release provides support for Snort 2.9.2.2 which has just been released.&lt;br /&gt;
&lt;br /&gt;
There was one change made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release, just a modification to this line:&lt;br /&gt;
&lt;code&gt;preprocessor ftp_telnet: global inspection_type stateful encrypted_traffic no&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;In VRT's rule release:
&lt;br /&gt;
&lt;blockquote&gt;
Synopsis:
This release adds and modifies rules in several categories.&amp;nbsp;&lt;/blockquote&gt;
&lt;blockquote&gt;
Details:
The Sourcefire VRT has added and modified multiple rules in the
backdoor, blacklist, botnet-cnc, exploit, file-identify, misc,
multimedia, netbios, phishing-spam, specific-threats, spyware-put, sql
and web-misc rule sets to provide coverage for emerging threats from
these technologies.
&lt;/blockquote&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2620048000216434889-8036254446821689635?l=blog.snort.org' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=0md-J4hg6NQ:o_wiGZS1ySk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=0md-J4hg6NQ:o_wiGZS1ySk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=0md-J4hg6NQ:o_wiGZS1ySk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=0md-J4hg6NQ:o_wiGZS1ySk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/0md-J4hg6NQ" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/0md-J4hg6NQ/vrt-rule-update-for-03272012.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2012/03/vrt-rule-update-for-03272012.html</feedburner:origLink></item></channel></rss>

