<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-2620048000216434889</atom:id><lastBuildDate>Tue, 21 May 2013 16:22:17 +0000</lastBuildDate><category>2.9.3.0</category><category>2.9.2.2</category><category>sguil</category><category>rules</category><category>2.9.0.4</category><category>vrt</category><category>news</category><category>2.9.0.0</category><category>2.9.4.1</category><category>development</category><category>immunet</category><category>perl</category><category>2.8.6.1</category><category>eol</category><category>mstues</category><category>community</category><category>2.9.1.1</category><category>adobe</category><category>updates</category><category>squert</category><category>sourcefire</category><category>2.9.0.3</category><category>2.9.1.5</category><category>2.9.3.1</category><category>2.9.4.5</category><category>downloads</category><category>Response</category><category>2.9.2.1</category><category>webcast</category><category>ips</category><category>2.9.0.1</category><category>2.9.2.3</category><category>tuning</category><category>windows</category><category>guides</category><category>snorby</category><category>rant</category><category>snort</category><category>database</category><category>manual</category><category>pulledpork</category><category>daemonlogger</category><category>docs</category><category>unified</category><category>old</category><category>mysql</category><category>speaking</category><category>barnyard2</category><category>shared object</category><category>barnyard</category><category>scholarship</category><category>2.92.2.1</category><category>2.9.1.2</category><category>razorback</category><category>website</category><category>blog</category><category>daq</category><category>Javascript Normalization</category><category>beta</category><category>output</category><category>snort.org</category><category>scada</category><category>2.9.0.5</category><category>unified2</category><category>ossim</category><category>2.9.4.0</category><category>SnortUnified</category><category>3rdparty</category><category>2.29.2.1</category><category>configurations</category><category>clamav</category><category>release candidate</category><category>release</category><category>2.9.1.0</category><category>2.9.0.2</category><category>2.9.4.6</category><category>2.9.2.0</category><title>Snort.org Blog</title><description>The Official Blog of the World Leading Open-Source IDS/IPS Snort.</description><link>http://blog.snort.org/</link><managingEditor>noreply@blogger.com (Joel Esler)</managingEditor><generator>Blogger</generator><openSearch:totalResults>446</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/Snort" /><feedburner:info uri="snort" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>Snort</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-5107607656341594394</guid><pubDate>Tue, 21 May 2013 16:20:00 +0000</pubDate><atom:updated>2013-05-21T12:22:17.089-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.0</category><category domain="http://www.blogger.com/atom/ns#">2.9.3.1</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.5</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.6</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.1</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">release</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>Sourcefire VRT Certified Snort Rules Update for 05/21/2013</title><description>Just released:&lt;br /&gt;
Sourcefire VRT Certified Snort Rules Update for 05/21/2013&lt;br /&gt;
&lt;br /&gt;
We welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2013-05-21.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 57 new rules and made modifications to 68 additional rules.
&lt;br /&gt;
&lt;br /&gt;
Port 10000 was added to the snort.conf for http_inspect, stream5, and HTTP_PORTS.  The Example VRT snort.conf's have been updated: &lt;a href="http://www.snort.org/vrt/snort-conf-configurations"&gt;http://www.snort.org/vrt/snort-conf-configurations&lt;/a&gt;.
&lt;br /&gt;
&lt;br /&gt;
The VRT would like to thank the following individuals for their contributions:&lt;br /&gt;
&lt;br /&gt;
Avery Tarasov&lt;br /&gt;
26654&lt;br /&gt;
26657&lt;br /&gt;
26660&lt;br /&gt;
26696&lt;br /&gt;
26697&lt;br /&gt;
&lt;br /&gt;
James Lay&lt;br /&gt;
26655&lt;br /&gt;
26656&lt;br /&gt;
26658&lt;br /&gt;
26659&lt;br /&gt;
26698&lt;br /&gt;
&lt;br /&gt;
Paul Bottomley&lt;br /&gt;
26695&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:
&lt;br /&gt;
&lt;blockquote&gt;
The Sourcefire VRT has added and modified multiple rules in the
blacklist, browser-firefox, browser-ie, browser-plugins,
browser-webkit, exploit-kit, file-flash, file-identify, file-image,
file-multimedia, file-office, file-pdf, malware-backdoor, malware-cnc,
malware-other, os-windows, protocol-ftp, pua-adware and web-client rule
sets to provide coverage for emerging threats from these technologies.

&lt;/blockquote&gt;
&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=44tuR-AZNUs:Ma1NlDuZyp4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=44tuR-AZNUs:Ma1NlDuZyp4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=44tuR-AZNUs:Ma1NlDuZyp4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=44tuR-AZNUs:Ma1NlDuZyp4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/44tuR-AZNUs" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/44tuR-AZNUs/sourcefire-vrt-certified-snort-rules_21.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/05/sourcefire-vrt-certified-snort-rules_21.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-2150161925710546046</guid><pubDate>Thu, 16 May 2013 15:29:00 +0000</pubDate><atom:updated>2013-05-16T11:29:35.550-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.0</category><category domain="http://www.blogger.com/atom/ns#">2.9.3.1</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.5</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.6</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.1</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">release</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>Sourcefire VRT Certified Snort Rules Update for 05/16/2013</title><description>Just released:&lt;br /&gt;
Sourcefire VRT Certified Snort Rules Update for 05/16/2013&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2013-05-16.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 11 new rules and made modifications to 24 additional rules.
&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.
&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:
&lt;br /&gt;
&lt;blockquote&gt;
The Sourcefire VRT has added and modified multiple rules in the
app-detect, blacklist, browser-firefox, browser-ie, browser-plugins,
exploit-kit, file-flash, file-other, file-pdf, malware-other,
os-windows, server-mysql, server-oracle and server-webapp rule sets to
provide coverage for emerging threats from these technologies.
&lt;/blockquote&gt;
&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=uLEKCi4zLZg:yH2o9LlZaXA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=uLEKCi4zLZg:yH2o9LlZaXA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=uLEKCi4zLZg:yH2o9LlZaXA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=uLEKCi4zLZg:yH2o9LlZaXA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/uLEKCi4zLZg" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/uLEKCi4zLZg/sourcefire-vrt-certified-snort-rules_16.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/05/sourcefire-vrt-certified-snort-rules_16.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-5811119173727545285</guid><pubDate>Tue, 14 May 2013 19:12:00 +0000</pubDate><atom:updated>2013-05-14T15:12:42.559-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.0</category><category domain="http://www.blogger.com/atom/ns#">2.9.3.1</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.5</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.6</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.1</category><category domain="http://www.blogger.com/atom/ns#">mstues</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">release</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>Sourcefire VRT Certified Snort Rules Update for 05/14/2013, MSTuesday</title><description>Just released:&lt;br /&gt;
Sourcefire VRT Certified Snort Rules Update for 05/14/2013&lt;br /&gt;
&lt;br /&gt;
We welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2013-05-14.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 25 new rules and made modifications to 24 additional rules.
&lt;br /&gt;
&lt;br /&gt;
Port 8500 was added to the snort.conf for http_inspect, stream5, and HTTP_PORTS. &amp;nbsp;The Example VRT snort.conf's have been updated:&amp;nbsp;&lt;a href="http://www.snort.org/vrt/snort-conf-configurations/"&gt;http://www.snort.org/vrt/snort-conf-configurations/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
The VRT would like to thank the following contributors for their addition(s):&lt;br /&gt;
&lt;br /&gt;
Nathan Fowler&lt;br /&gt;
26618&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:
&lt;br /&gt;
&lt;blockquote&gt;
Microsoft Security Advisory MS13-037:&lt;br /&gt;
Internet Explorer suffers from programming errors that may lead to&lt;br /&gt;
information disclosure or remote code execution.&lt;br /&gt;
&lt;br /&gt;
Rules to detect attacks targeting these vulnerabilities are included in&lt;br /&gt;
this release and are identified with GID 1, SIDs 26624, 26625, 26629&lt;br /&gt;
through 26631, 26633 through 26638, 26641, and 26642.&lt;br /&gt;
&lt;br /&gt;
Microsoft Security Advisory MS13-038:&lt;br /&gt;
Internet Explorer suffers from a programming error that may lead to&lt;br /&gt;
remote code execution.&lt;br /&gt;
&lt;br /&gt;
Previously released rules will detect attacks targeting this&lt;br /&gt;
vulnerability and have been updated with the appropriate reference&lt;br /&gt;
information. They are included in this release and are identified with&lt;br /&gt;
GID 1, 26569, 26570, 26571, and 26572.&lt;br /&gt;
&lt;br /&gt;
Microsoft Security Advisory MS13-039:&lt;br /&gt;
A programming error exists in the Windows 2012 Server HTTP subsystem&lt;br /&gt;
that may allow a remote attacker to cause a permanent Denial of Service&lt;br /&gt;
(DoS) against an affected system.&lt;br /&gt;
&lt;br /&gt;
A rule to detect attacks targeting this vulnerability is included in&lt;br /&gt;
this release and is identified with GID 1, SID 26632.&lt;br /&gt;
&lt;br /&gt;
Microsoft Security Advisory MS13-040:&lt;br /&gt;
The .NET Framework suffers from a programming error that may allow an&lt;br /&gt;
attacker to bypass XML authentication.&lt;br /&gt;
&lt;br /&gt;
Rules to detect attacks targeting this vulnerability are included in&lt;br /&gt;
this release and are identified with GID 1, SIDs 26639 and 26640&lt;br /&gt;
&lt;br /&gt;
Microsoft Security Advisory MS13-044:&lt;br /&gt;
Microsoft Visio suffers from a programming error that may expose&lt;br /&gt;
affected systems to information disclosure.&lt;br /&gt;
&lt;br /&gt;
Rules to detect attacks targeting this vulnerability are included in&lt;br /&gt;
this release and are identified with GID 1, SIDs 26626 through 26628.&lt;br /&gt;
&lt;br /&gt;
Microsoft Security Advisory MS13-045:&lt;br /&gt;
Microsoft Windows Live Essentials contains programming errors that may&lt;br /&gt;
expose affected systems to information disclosure.&lt;br /&gt;
&lt;br /&gt;
Rules to detect attacks targeting this vulnerability are included in&lt;br /&gt;
this release and are identified with GID 1, SIDs 26622 and 26623&lt;br /&gt;
&lt;br /&gt;
Additionally, the Sourcefire VRT has added and modified multiple rules&lt;br /&gt;
in the browser-ie, browser-other, browser-plugins, exploit-kit,&lt;br /&gt;
file-office, file-other, indicator-obfuscation, malware-cnc,&lt;br /&gt;
policy-other and server-webapp rule sets to provide coverage for&lt;br /&gt;
emerging threats from these technologies.&lt;/blockquote&gt;
&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=XTiSnTfgFzc:AGP2Y62RFEw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=XTiSnTfgFzc:AGP2Y62RFEw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=XTiSnTfgFzc:AGP2Y62RFEw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=XTiSnTfgFzc:AGP2Y62RFEw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/XTiSnTfgFzc" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/XTiSnTfgFzc/sourcefire-vrt-certified-snort-rules_14.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/05/sourcefire-vrt-certified-snort-rules_14.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-8563419513208739274</guid><pubDate>Tue, 14 May 2013 16:48:00 +0000</pubDate><atom:updated>2013-05-14T12:48:41.250-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">release</category><category domain="http://www.blogger.com/atom/ns#">barnyard2</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>Barnyard v.2.1-13 has been released!</title><description>We are happy to announce the latest STABLE release v2.1-13 which was tagged a few hours ago (&lt;a href="https://github.com/firnsy/barnyard2/tags"&gt;https://github.com/firnsy/barnyard2/tags&lt;/a&gt;)&lt;br /&gt;
&lt;br /&gt;
This release is a bug fix release that also introduce a few new features and enhancements.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
UPGRADE REQUIREMENTS&lt;br /&gt;
&lt;br /&gt;
If you are upgrading to barnyard2 2-1.13 (build 327) or above from a previous version and using output database.&lt;br /&gt;
&lt;br /&gt;
You will need to delete every row in your sig_reference table. (DELETE FROM sig_reference;)&lt;br /&gt;
&lt;br /&gt;
The table will be re-populated at startup, and has no impact on historical data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;FEATURE REQUESTS&lt;/b&gt;&lt;br /&gt;
Phil Daws - add interface and hostname field to spo_alert_csv if specified.&lt;br /&gt;
Jorge Pinto - spo_syslog_full support for ASCII,BASE64 payload&lt;br /&gt;
Jason Brvenik - variables ... (a long time ago, sorry :P)&lt;br /&gt;
Martin Olsson - remove some useless verbosity unless &lt;code&gt;./configure --enable-debug&lt;/code&gt; is specified and proper flag are used (&lt;code&gt;spo_database&lt;/code&gt; and &lt;code&gt;sid-msg.mapv2&lt;/code&gt;)&lt;br /&gt;
All other barnyard2 users who help and contribute.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;BUG REPORTS&lt;/b&gt;&lt;br /&gt;
Martin Olsson - bug in sig_reference generation and good discussions. Rewrote the code &amp;amp; al&lt;br /&gt;
John Eure and others - autogen.sh could cause some issue on some system so [&lt;code&gt;autoreconf -fv --install&lt;/code&gt;] is not set to autoreconf -fvi&lt;br /&gt;
John Naggets - spo_database: could stop barnyard2 from processing new event if some packets with ip option where processed and option_len was null.&lt;br /&gt;
Fäbu Hufi - spo_syslog_full: in complete mode was printing wrong ip version information and ip header length.&lt;br /&gt;
Jeremy Hoel - identified issue with suppression range in 2-1.13-BETA (fixed in release)&lt;br /&gt;
Bill Green - identified is with signature insertion mainly preprocessor in 2-1.13-BETA (fixed in release) &lt;br /&gt;
All other barnyard2 users who help and contribute.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;NEW FEATURES&lt;/b&gt;
&lt;br /&gt;
1. Support for sid-msg.map version 2 format.&lt;br /&gt;
&lt;br /&gt;
A new sig-msg.map format can be generated by pulledpok (upcomming release, already in svn).&lt;br /&gt;
&lt;br /&gt;
Detection of sid-msg.map version is done by a simple header in the file that shouldn't be altered if you want it to be processed correctly.&lt;br /&gt;
&lt;br /&gt;
The sig-msg.map version 2 format extends the information already present in the sid-msg.map file created from rules.&lt;br /&gt;
&lt;br /&gt;
This new format version allow signature pre-population if users are using output database method with barnyard2 2-1.13 and above.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
sid-msg.map v1 format:&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;SID || MSG || REF 1 || REF N&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;sid := integer&lt;/code&gt;&lt;br /&gt;
&lt;code&gt;msg := string&lt;/code&gt;&lt;br /&gt;
&lt;code&gt;ref := string&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
sid-msg.map v2 format:&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;GID || SID || REV || CLASSIFICATION || PRIORITY || MSG || REF 1 || REF N&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;gid := integer&lt;/code&gt;&lt;br /&gt;
&lt;code&gt;sid := integer&lt;/code&gt;&lt;br /&gt;
&lt;code&gt;rev := integer&lt;/code&gt;&lt;br /&gt;
&lt;code&gt;classification := string (if NULL set to NOCLASS)&lt;/code&gt;&lt;br /&gt;
&lt;code&gt;priority := integer (if prio == 0, classification priority is used)&lt;/code&gt;&lt;br /&gt;
&lt;code&gt;msg := string&lt;/code&gt;&lt;br /&gt;
&lt;code&gt;ref := string&lt;code&gt;&lt;br /&gt;
&lt;br /&gt;
=====================&lt;br /&gt;
generator (GID, gen-msg.map) are defaulted to the following value&lt;br /&gt;
if their information is not overruled in sid-msg.map v2 file via processing of preprocessor.rules:&lt;br /&gt;
&lt;br /&gt;
revision 1&lt;br /&gt;
classification 0&lt;br /&gt;
priority 3 &lt;br /&gt;
&lt;br /&gt;
If generator message is present in the sid-msg.map v2 file, and gen-msg.map message are longer &lt;br /&gt;
(more comprehensive by string length), &lt;br /&gt;
gen-msg.map messages are used instead of sid-msg.map v2 file generator messages.&lt;br /&gt;
=====================&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
2. Signature/event logging suppression at spooler level.&lt;br /&gt;
&lt;br /&gt;
Read doc/README.sig_suppression&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3. Configuration file variables.&lt;br /&gt;
&lt;br /&gt;
You can now use [var VARNAME value] in the barnyard2 configuration file and every instance of $VARNAME will get replaced by value.&lt;br /&gt;
&lt;br /&gt;
Note that variable declaration order is important only you include a variable with in a variable.&lt;br /&gt;
 &lt;br /&gt;
 EX (is VALID): &lt;br /&gt;
 &lt;code&gt;var INTERFACE ethX&lt;/code&gt;&lt;br /&gt;
 &lt;code&gt;var PATH /var/log/IDS&lt;/code&gt;&lt;br /&gt;
 &lt;code&gt;var LOG $PATH/$INTERFACE/log&lt;/code&gt;&lt;br /&gt;
 &lt;code&gt;var ARCHIVE $PATH/$INTERFACE/archive&lt;/code&gt;&lt;br /&gt;
 &lt;br /&gt;
 EX (is INVALID): &lt;br /&gt;
 &lt;code&gt;var LOG $PATH/$INTERFACE/log&lt;/code&gt;&lt;br /&gt;
 &lt;code&gt;var ARCHIVE $PATH/$INTERFACE/archive&lt;/code&gt;&lt;br /&gt;
 &lt;code&gt;var INTERFACE ethX&lt;/code&gt;&lt;br /&gt;
 &lt;code&gt;var PATH /var/log/IDS&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4. New output database configuration keyword.&lt;br /&gt;
&lt;br /&gt;
Keywords connection_limit and reconnect_sleep_time where added in 2-1.10 but where "undocumented" and shouldn't be modified unless you encounter an issue.&lt;br /&gt;
&lt;br /&gt;
  &lt;code&gt;connection_limit &lt;integer&gt;: default 10&lt;/integer&gt;&lt;/code&gt;&lt;br /&gt;
The maximum number of time that barnyard2 will tolerate a transaction faillure and or database connection failure.&lt;br /&gt;
&lt;br /&gt;
  &lt;code&gt;reconnect_sleep_time &lt;integer&gt; : default 5&lt;/integer&gt;&lt;/code&gt;&lt;br /&gt;
The number of seconds to sleep betwen connection retry.&lt;br /&gt;
&lt;br /&gt;
  &lt;code&gt;disable_signature_reference_table&lt;/code&gt;&lt;br /&gt;
Tell the output plugin not to synchronize the sig_reference table in the schema.&lt;br /&gt;
&lt;br /&gt;
Note: This option will speedup the process, especialy if you use sid-msg.mapv2 file or have alot of signature already in databases. (Make sure that you do not need that information before enabling this)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
So we hope you enjoy the new release, as a side note the RELEASE.NOTES file has not been updated and will be removed in the next version. It's honestly the most laborious part of release time ;)&lt;br /&gt;
&lt;br /&gt;
Regards,&lt;br /&gt;
&lt;br /&gt;
The barnyard2 team. &lt;/code&gt;&lt;/code&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=7fueitxfhM0:j_vmhn99RfA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=7fueitxfhM0:j_vmhn99RfA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=7fueitxfhM0:j_vmhn99RfA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=7fueitxfhM0:j_vmhn99RfA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/7fueitxfhM0" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/7fueitxfhM0/barnyard-v21-13-has-been-released.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/05/barnyard-v21-13-has-been-released.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-3310711964269728741</guid><pubDate>Thu, 09 May 2013 17:42:00 +0000</pubDate><atom:updated>2013-05-09T13:42:34.251-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.0</category><category domain="http://www.blogger.com/atom/ns#">2.9.3.1</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.5</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.6</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.1</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">release</category><title>Sourcefire VRT Certified Snort Rules Update for 05/09/2013</title><description>Just released:&lt;br /&gt;
Sourcefire VRT Certified Snort Rules Update for 05/09/2013&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2013-05-09.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 34 new rules and made modifications to 61 additional rules.
&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.
&lt;br /&gt;
&lt;br /&gt;
The VRT would like to thank the following people for their listed rule(s):&lt;br /&gt;
&lt;br /&gt;
Avery Tarasov&lt;br /&gt;
26589&lt;br /&gt;
26612&lt;br /&gt;
26613&lt;br /&gt;
26614&lt;br /&gt;
&lt;br /&gt;
James Lay&lt;br /&gt;
26585&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:
&lt;br /&gt;
&lt;blockquote&gt;
The Sourcefire VRT has added and modified multiple rules in the
blacklist, browser-ie, browser-plugins, browser-webkit, dos,
exploit-kit, file-executable, file-office, file-other,
indicator-compromise, indicator-obfuscation, malware-backdoor,
malware-cnc, os-windows, protocol-ftp, protocol-services,
protocol-voip, server-mail, server-oracle, server-other and web-client
rule sets to provide coverage for emerging threats from these
technologies.

&lt;/blockquote&gt;
&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=BpCuTR-BTTw:95Jkp14ABuQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=BpCuTR-BTTw:95Jkp14ABuQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=BpCuTR-BTTw:95Jkp14ABuQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=BpCuTR-BTTw:95Jkp14ABuQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/BpCuTR-BTTw" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/BpCuTR-BTTw/sourcefire-vrt-certified-snort-rules_9.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/05/sourcefire-vrt-certified-snort-rules_9.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-3964654690519626308</guid><pubDate>Tue, 07 May 2013 16:40:00 +0000</pubDate><atom:updated>2013-05-07T12:40:47.698-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">blog</category><title>Reminder: Google Reader is ending it's life on July 1, here's an alternative</title><description>As may of you may know, Google Reader is EOL'ing it's product effective July 1.&lt;br /&gt;
&lt;br /&gt;
Since several thousand of you are subscribed to this blog via Google Reader, I thought I'd let you know about another option that we offer that many of you also take advantage of. &amp;nbsp;Subscribing via email.&lt;br /&gt;
&lt;br /&gt;
If you go to &lt;a href="http://blog.snort.org/"&gt;http://blog.snort.org&lt;/a&gt;, look over to the right in the sidebar, you'll see "&lt;a href="http://feedburner.google.com/fb/a/mailverify?uri=Snort&amp;amp;loc=en_US" target="_blank"&gt;Subscribe to the Snort.org blog via email&lt;/a&gt;". &amp;nbsp;This will allow you to keep your updates to the Snort.org blog, but instead of having to go to a third program to read the feed, it'll be delivered shortly after I click "Publish" directly to your inbox.&lt;br /&gt;
&lt;br /&gt;
There are hundreds of people that do this already to the Snort blog, so it seems that it works quite well. &amp;nbsp;Give it a shot!&lt;br /&gt;
&lt;br /&gt;
Google Reader's EOL announcement:&amp;nbsp;&lt;a href="http://googlereader.blogspot.com/2013/03/powering-down-google-reader.html"&gt;http://googlereader.blogspot.com/2013/03/powering-down-google-reader.html&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=Xslqu9lRhQA:ul0YrKELd40:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=Xslqu9lRhQA:ul0YrKELd40:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=Xslqu9lRhQA:ul0YrKELd40:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=Xslqu9lRhQA:ul0YrKELd40:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/Xslqu9lRhQA" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/Xslqu9lRhQA/reminder-google-reader-is-ending-its.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/05/reminder-google-reader-is-ending-its.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-6728481258393644145</guid><pubDate>Tue, 07 May 2013 16:28:00 +0000</pubDate><atom:updated>2013-05-07T12:35:22.541-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.0</category><category domain="http://www.blogger.com/atom/ns#">2.9.3.1</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.5</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.6</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.1</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">release</category><title>Sourcefire VRT Certified Snort Rules Update for 05/07/2013</title><description>Just released:&lt;br /&gt;
Sourcefire VRT Certified Snort Rules Update for 05/07/2013&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2013-05-07.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 11 new rules and made modifications to 5 additional rules.
&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.
&lt;br /&gt;
&lt;br /&gt;
The VRT would like to thank the following people for their listed rule(s):&lt;br /&gt;
&lt;br /&gt;
Avery Tarasov:&lt;br /&gt;
26580&lt;br /&gt;
26581&lt;br /&gt;
26582&lt;br /&gt;
26583&lt;br /&gt;
&lt;br /&gt;
Eddie Mitchell:&lt;br /&gt;
26578&lt;br /&gt;
26579&lt;br /&gt;
&lt;br /&gt;
Nathan Fowler:&lt;br /&gt;
26576&lt;br /&gt;
26577&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:
&lt;br /&gt;
&lt;blockquote&gt;
The Sourcefire VRT has added and modified multiple rules in the
blacklist, browser-plugins, dos, indicator-compromise and netbios rule
sets to provide coverage for emerging threats from these technologies.
&lt;/blockquote&gt;
&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=jBxP0DXAW6I:srkuNWWdego:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=jBxP0DXAW6I:srkuNWWdego:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=jBxP0DXAW6I:srkuNWWdego:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=jBxP0DXAW6I:srkuNWWdego:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/jBxP0DXAW6I" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/jBxP0DXAW6I/sourcefire-vrt-certified-snort-rules_7.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/05/sourcefire-vrt-certified-snort-rules_7.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-7217556433886037188</guid><pubDate>Sat, 04 May 2013 20:39:00 +0000</pubDate><atom:updated>2013-05-04T16:39:43.343-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.0</category><category domain="http://www.blogger.com/atom/ns#">2.9.3.1</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.5</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.6</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.1</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">release</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>Sourcefire VRT Certified Snort Rules Update for 05/04/2013, IE 0day</title><description>Just released:&lt;br /&gt;
Sourcefire VRT Certified Snort Rules Update for 05/04/2013, including coverage for the new IE 0day&lt;br /&gt;
&lt;br /&gt;
We welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2013-05-04.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 11 new rules and made modifications to 46 additional rules.
&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.
&lt;br /&gt;
&lt;br /&gt;
The VRT would like to thank the following people for their listed rule(s):&lt;br /&gt;
&lt;br /&gt;
Avery Tarasov&lt;br /&gt;
26562&lt;br /&gt;
26563&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:
&lt;br /&gt;
&lt;blockquote&gt;
The Sourcefire VRT has added and modified multiple rules in the
browser-ie, exploit-kit, file-multimedia, file-pdf,
indicator-obfuscation and server-webapp rule sets to provide coverage
for emerging threats from these technologies.
&lt;/blockquote&gt;
&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=HvsFVSvOCgs:Ytzp5xl0xQ8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=HvsFVSvOCgs:Ytzp5xl0xQ8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=HvsFVSvOCgs:Ytzp5xl0xQ8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=HvsFVSvOCgs:Ytzp5xl0xQ8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/HvsFVSvOCgs" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/HvsFVSvOCgs/sourcefire-vrt-certified-snort-rules_4.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/05/sourcefire-vrt-certified-snort-rules_4.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-862997135539360141</guid><pubDate>Thu, 02 May 2013 18:02:00 +0000</pubDate><atom:updated>2013-05-02T14:02:36.217-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.0</category><category domain="http://www.blogger.com/atom/ns#">2.9.3.1</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.5</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.6</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.1</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>Sourcefire VRT Certified Snort Rules Update for 05/02/2013</title><description>Just released:&lt;br /&gt;
Sourcefire VRT Certified Snort Rules Update for 05/02/2013&lt;br /&gt;
&lt;br /&gt;
We welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2013-05-02.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 36 new rules and made modifications to 41 additional rules.
&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.
&lt;br /&gt;
&lt;br /&gt;
The VRT would like to thank the following individuals for their contributions to the listed rules:&lt;br /&gt;
&lt;br /&gt;
Avery Tarasov:&lt;br /&gt;
26533&lt;br /&gt;
26560&lt;br /&gt;
26561&lt;br /&gt;
&lt;br /&gt;
James Lay:&lt;br /&gt;
26522&lt;br /&gt;
&lt;br /&gt;
Yaser Mansour:&lt;br /&gt;
26553&lt;br /&gt;
26554&lt;br /&gt;
26555&lt;br /&gt;
26556&lt;br /&gt;
&lt;br /&gt;
Eddie Mitchell:&lt;br /&gt;
26526&lt;br /&gt;
&lt;br /&gt;
Dell SecureWorks:&lt;br /&gt;
26558&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:
&lt;br /&gt;
&lt;blockquote&gt;
The Sourcefire VRT has added and modified multiple rules in the
blacklist, browser-ie, browser-other, browser-plugins, exploit-kit,
file-identify, file-other, indicator-compromise, indicator-obfuscation,
malware-cnc, malware-other, os-other, policy-other, protocol-ftp,
pua-adware, server-mail, server-oracle and server-webapp rule sets to
provide coverage for emerging threats from these technologies.

&lt;/blockquote&gt;
&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=Ccnfaix9DHo:uYT55b0rZus:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=Ccnfaix9DHo:uYT55b0rZus:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=Ccnfaix9DHo:uYT55b0rZus:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=Ccnfaix9DHo:uYT55b0rZus:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/Ccnfaix9DHo" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/Ccnfaix9DHo/sourcefire-vrt-certified-snort-rules.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/05/sourcefire-vrt-certified-snort-rules.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-1639619648667799465</guid><pubDate>Tue, 30 Apr 2013 15:25:00 +0000</pubDate><atom:updated>2013-04-30T11:25:54.653-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.0</category><category domain="http://www.blogger.com/atom/ns#">2.9.3.1</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.5</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.6</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.1</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">release</category><title>Sourcefire VRT Certified Snort Rules Update for 04/30/2013</title><description>Just released:&lt;br /&gt;
Sourcefire VRT Certified Snort Rules Update for 04/30/2013&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2013-04-30.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 12 new rules and made modifications to 84 additional rules.
&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:
&lt;br /&gt;
&lt;blockquote&gt;
The Sourcefire VRT has added and modified multiple rules in the
blacklist, browser-plugins, exploit-kit, file-identify, file-other,
file-pdf, malware-cnc and tftp rule sets to provide coverage for
emerging threats from these technologies.
&lt;/blockquote&gt;
&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=_h2AEdqmKgM:mM6V-9wfHLg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=_h2AEdqmKgM:mM6V-9wfHLg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=_h2AEdqmKgM:mM6V-9wfHLg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=_h2AEdqmKgM:mM6V-9wfHLg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/_h2AEdqmKgM" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/_h2AEdqmKgM/sourcefire-vrt-certified-snort-rules_30.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/04/sourcefire-vrt-certified-snort-rules_30.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-5982257030339146643</guid><pubDate>Mon, 29 Apr 2013 14:11:00 +0000</pubDate><atom:updated>2013-04-29T10:11:52.487-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.0</category><category domain="http://www.blogger.com/atom/ns#">2.9.3.1</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.5</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.6</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.1</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">release</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>Sourcefire VRT Certified Snort Rules Update for 04/25/2013</title><description>Sourcefire VRT Certified Snort Rules Update for 04/25/2013&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2013-04-25.html"&gt;rule release&lt;/a&gt; from the VRT. In this release we introduced 26 new rules and made modifications to 12 additional rules.
&lt;br /&gt;
&lt;br /&gt;
There were changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.&lt;br /&gt;
&lt;br /&gt;
The following ports were added to the HTTP_PORTS, stream5 "both" attribute, and http_inspect's "ports" attribute line:&lt;br /&gt;
&lt;br /&gt;
82&lt;br /&gt;
83&lt;br /&gt;
84&lt;br /&gt;
85&lt;br /&gt;
86&lt;br /&gt;
87&lt;br /&gt;
88&lt;br /&gt;
89&lt;br /&gt;
3057&lt;br /&gt;
6080&lt;br /&gt;
&lt;br /&gt;
The lines now look like this (for easy copy and paste):&lt;br /&gt;
&lt;br /&gt;
HTTP_PORTS:&lt;br /&gt;
&lt;code&gt;portvar HTTP_PORTS [80,81,82,83,84,85,86,87,88,89,311,383,591,593,631,901,1220,1414,1741,1830,2301,2381,2809,3037,3057,3128,3702,4343,4848,5250,6080,6988,7000,7001,7144,7145,7510,7777,7779,8000,8008,8014,8028,8080,8085,8088,8090,8118,8123,8180,8181,8222,8243,8280,8300,8800,8888,8899,9000,9060,9080,9090,9091,9443,9999,11371,34443,34444,41080,50002,55555]&amp;nbsp;&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Stream5:&lt;br /&gt;
&lt;code&gt;
ports both 80 81 82 83 84 85 86 87 88 89 110 311 383 443 465 563 591 593 631 636 901 989 992 993 994 995 1220 1414 1830 2301 2381 2809 3037 3057 3128 3702 4343 4848 5250 6080 6988 7907 7000 7001 7144 7145 7510 7802 7777 7779 \
        7801 7900 7901 7902 7903 7904 7905 7906 7908 7909 7910 7911 7912 7913 7914 7915 7916 \
        7917 7918 7919 7920 8000 8008 8014 8028 8080 8085 8088 8090 8118 8123 8180 8222 8243 8280 8300 8800 8888 8899 9000 9060 9080 9090 9091 9443 9999 11371 34443 34444 41080 50002 55555&amp;nbsp;&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
http_inspect:&lt;br /&gt;
&lt;code&gt;
ports { 80 81 82 83 84 85 86 87 88 89 311 383 591 593 631 901 1220 1414 1741 1830 2301 2381 2809 3037 3057 3128 3702 4343 4848 5250 6080 6988 7000 7001 7144 7145 7510 7777 7779 8000 8008 8014 8028 8080 8085 8088 8090 8118 8123 8180 8181 8222 8243 8280 8300 8800 8888 8899 9000 9060 9080 9090 9091 9443 9999 11371 34443 34444 41080 50002 55555 }&lt;/code&gt;&lt;br /&gt;
&lt;code&gt;&lt;br /&gt;&lt;/code&gt;
And as indicated here: &lt;a href="http://blog.snort.org/2013/04/master-snortconf-configurations-have.html"&gt;http://blog.snort.org/2013/04/master-snortconf-configurations-have.html&lt;/a&gt;, the snort.conf configurations that we distribute have been updated.
&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:
&lt;br /&gt;
&lt;blockquote&gt;
The Sourcefire VRT has added and modified multiple rules in the
browser-other, browser-plugins, exploit-kit, file-flash, file-identify,
file-multimedia, file-other, file-pdf, malware-cnc, scada and
server-webapp rule sets to provide coverage for emerging threats from
these technologies.
&lt;/blockquote&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=vh3a5Rf6FxQ:Emx-ts9lGLo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=vh3a5Rf6FxQ:Emx-ts9lGLo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=vh3a5Rf6FxQ:Emx-ts9lGLo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=vh3a5Rf6FxQ:Emx-ts9lGLo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/vh3a5Rf6FxQ" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/vh3a5Rf6FxQ/sourcefire-vrt-certified-snort-rules_29.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/04/sourcefire-vrt-certified-snort-rules_29.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-2714390737160579169</guid><pubDate>Wed, 24 Apr 2013 19:39:00 +0000</pubDate><atom:updated>2013-04-24T15:39:06.361-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">2.9.4.6</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">snort.org</category><category domain="http://www.blogger.com/atom/ns#">configurations</category><title>Master Snort.conf configurations have been updated!</title><description>I've went ahead and updated our master snort.conf examples from the VRT on the Snort.conf configuration page:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.snort.org/vrt/snort-conf-configurations/"&gt;http://www.snort.org/vrt/snort-conf-configurations/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
By the way -- In case you want to find that page in the future, just remember to Google "Snort.conf configurations" &amp;nbsp;It's the first result.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=GQtlQRK_6EQ:7g5U0xm17x8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=GQtlQRK_6EQ:7g5U0xm17x8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=GQtlQRK_6EQ:7g5U0xm17x8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=GQtlQRK_6EQ:7g5U0xm17x8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/GQtlQRK_6EQ" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/GQtlQRK_6EQ/master-snortconf-configurations-have.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/04/master-snortconf-configurations-have.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-7965958956320483059</guid><pubDate>Wed, 24 Apr 2013 16:24:00 +0000</pubDate><atom:updated>2013-04-24T12:24:24.649-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">eol</category><title>VRT End-of-Life dates have been updated</title><description>As always when a new version of Snort comes out, I update the EOL date versions found here:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.snort.org/vrt/rules/eol_policy"&gt;http://www.snort.org/vrt/rules/eol_policy&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
So, take a look there and see if you are affected, and if so, be sure and stay current and update Snort! &amp;nbsp;&lt;a href="http://www.snort.org/snort-downloads"&gt;http://www.snort.org/snort-downloads&lt;/a&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=PvSxzmm7pPE:UQozjNkfupc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=PvSxzmm7pPE:UQozjNkfupc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=PvSxzmm7pPE:UQozjNkfupc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=PvSxzmm7pPE:UQozjNkfupc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/PvSxzmm7pPE" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/PvSxzmm7pPE/vrt-end-of-life-dates-have-been-updated.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/04/vrt-end-of-life-dates-have-been-updated.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-7822736063462341352</guid><pubDate>Wed, 24 Apr 2013 16:13:00 +0000</pubDate><atom:updated>2013-04-24T12:13:00.665-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">2.9.4.6</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">release</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>Snort 2.9.4.6 has been released!</title><description>Snort 2.9.4.6 is now available on &lt;a href="http://www.snort.org/"&gt;snort.org&lt;/a&gt;, at&lt;br /&gt;
&lt;a href="http://www.snort.org/snort-downloads/"&gt;http://www.snort.org/snort-downloads/&lt;/a&gt; in the Latest Release section.&lt;br /&gt;
&lt;br /&gt;
Snort 2.9.4.6 includes changes for the following:&lt;br /&gt;
&lt;br /&gt;
[*] Improvements&lt;br /&gt;
&lt;br /&gt;
* Improved support for DAQ verdicts of whitelist and blacklist for 6in4&amp;nbsp;and 4in6 encapsulated traffic (similar to Teredo &amp;amp; GTP).  See the&amp;nbsp;Snort manual for configuration details.&lt;br /&gt;
&lt;br /&gt;
* Avoid changing the length of IP options in frag3 when receiving&amp;nbsp;duplicate 0-offset fragments that have IP options.&lt;br /&gt;
&lt;br /&gt;
See the Release Notes and ChangeLog for more details.&lt;br /&gt;
&lt;br /&gt;
Please submit bugs, questions, and feedback to &lt;a href="mailto:bugs@snort.org"&gt;bugs@snort.org&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Happy Snorting!&lt;br /&gt;
The Snort Release Team&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=RJ4yZ1VutvQ:jiw4YznDGmA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=RJ4yZ1VutvQ:jiw4YznDGmA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=RJ4yZ1VutvQ:jiw4YznDGmA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=RJ4yZ1VutvQ:jiw4YznDGmA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/RJ4yZ1VutvQ" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/RJ4yZ1VutvQ/snort-2946-has-been-released.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>1</thr:total><feedburner:origLink>http://blog.snort.org/2013/04/snort-2946-has-been-released.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-6136799706004673538</guid><pubDate>Tue, 23 Apr 2013 21:06:00 +0000</pubDate><atom:updated>2013-04-23T17:06:19.432-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.0</category><category domain="http://www.blogger.com/atom/ns#">2.9.3.1</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.5</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.6</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.1</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">release</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>Sourcefire VRT Certified Snort Rules Update for 04/23/2013</title><description>Just released:&lt;br /&gt;
Sourcefire VRT Certified Snort Rules Update for 04/23/2013&lt;br /&gt;
&lt;br /&gt;
We welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2013-04-23.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 21 new rules and made modifications to 18 additional rules.&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.
&lt;br /&gt;
&lt;br /&gt;
The VRT would like to thank rmkml for their contribution in the development of rule(s):&lt;br /&gt;
26468&lt;br /&gt;
26469&lt;br /&gt;
&lt;br /&gt;
The VRT would like to thank Avery Tarasov for their contribution in the development of rule(s):&lt;br /&gt;
26470&lt;br /&gt;
26480&lt;br /&gt;
26481&lt;br /&gt;
26482&lt;br /&gt;
&lt;br /&gt;
The VRT would like to thank James Lay for their contribution in the development of rule(s):&lt;br /&gt;
26467&lt;br /&gt;
26483&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:
&lt;br /&gt;
&lt;blockquote&gt;
The Sourcefire VRT has added and modified multiple rules in the
browser-plugins, dns, file-executable, file-multimedia, file-other,
indicator-compromise, malware-cnc, malware-other, os-other,
protocol-ftp, pua-p2p, server-oracle, server-other and telnet rule sets
to provide coverage for emerging threats from these technologies.
&lt;/blockquote&gt;
&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=h6RikT3mMIc:0DCrMob8FQI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=h6RikT3mMIc:0DCrMob8FQI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=h6RikT3mMIc:0DCrMob8FQI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=h6RikT3mMIc:0DCrMob8FQI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/h6RikT3mMIc" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/h6RikT3mMIc/sourcefire-vrt-certified-snort-rules_23.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/04/sourcefire-vrt-certified-snort-rules_23.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-5559063434874266122</guid><pubDate>Thu, 18 Apr 2013 20:27:00 +0000</pubDate><atom:updated>2013-04-18T16:27:13.011-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.0</category><category domain="http://www.blogger.com/atom/ns#">2.9.3.1</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.5</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.1</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">release</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>Sourcefire VRT Certified Snort Rules Update for 04/18/2013</title><description>Just released:
Sourcefire VRT Certified Snort Rules Update for 04/18/2013
&lt;br /&gt;
&lt;br /&gt;
We welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2013-04-18.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 36 new rules and made modifications to 237 additional rules.
&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.
&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:
&lt;br /&gt;
&lt;blockquote&gt;
The Sourcefire VRT has added and modified multiple rules in the
blacklist, browser-firefox, browser-ie, browser-plugins, dns,
exploit-kit, file-flash, file-identify, file-image, file-multimedia,
file-office, file-other, indicator-obfuscation, malware-cnc, os-linux,
os-other, os-windows, protocol-voip, pua-other, server-mail,
server-mssql and server-webapp rule sets to provide coverage for
emerging threats from these technologies.
&lt;/blockquote&gt;
&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=jJwWM9Ta9fI:lcweoaS8wrc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=jJwWM9Ta9fI:lcweoaS8wrc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=jJwWM9Ta9fI:lcweoaS8wrc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=jJwWM9Ta9fI:lcweoaS8wrc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/jJwWM9Ta9fI" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/jJwWM9Ta9fI/sourcefire-vrt-certified-snort-rules_18.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/04/sourcefire-vrt-certified-snort-rules_18.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-7658473355422062026</guid><pubDate>Thu, 18 Apr 2013 16:31:00 +0000</pubDate><atom:updated>2013-04-18T12:31:30.876-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">docs</category><title>Snort Startup Scripts for various OSes have been updated!</title><description>Many thanks to one of our very dedicated Snort Community members, William Parker. &amp;nbsp;In his guides (also posted on the documentation page of Snort.org) he has embedded some Snort Startup scripts.&lt;br /&gt;
&lt;br /&gt;
Because some people are having problems with copy and pasting out of the PDF documentation, so Mr. Parker put these startup scripts in their own files and sent them to me. &amp;nbsp;I created a special section on &lt;a href="http://www.snort.org/docs"&gt;Snort.org/docs&lt;/a&gt; just for startup scripts, and they are all there!&lt;br /&gt;
&lt;br /&gt;
Many thanks to Mr. Parker for updating his scripts based on user feedback, and the new ones are now up.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=WYfIH5uZ6Es:1T24bCv3ItU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=WYfIH5uZ6Es:1T24bCv3ItU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=WYfIH5uZ6Es:1T24bCv3ItU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=WYfIH5uZ6Es:1T24bCv3ItU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/WYfIH5uZ6Es" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/WYfIH5uZ6Es/snort-startup-scripts-for-various-oses.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/04/snort-startup-scripts-for-various-oses.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-4532851572212673627</guid><pubDate>Tue, 16 Apr 2013 15:08:00 +0000</pubDate><atom:updated>2013-04-17T08:54:56.324-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.0</category><category domain="http://www.blogger.com/atom/ns#">2.9.3.1</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.5</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.1</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">release</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>Sourcefire VRT Certified Snort Rules Update for 04/16/2013</title><description>Just released:&lt;br /&gt;
Sourcefire VRT Certified Snort Rules Update for 04/16/2013
&lt;br /&gt;
&lt;br /&gt;
We welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2013-04-16.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 37 new rules and made modifications to 315 additional rules.
&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.
&lt;br /&gt;
&lt;br /&gt;
The VRT would like to thank Avery Tarasov for their contribution in the development of rule(s):&lt;br /&gt;
26398&lt;br /&gt;
&lt;br /&gt;
The VRT would like to thank Yaser Mansour for their contribution in the development of rule(s):&lt;br /&gt;
26395&lt;br /&gt;
26396&lt;br /&gt;
26399&lt;br /&gt;
26400&lt;br /&gt;
26401&lt;br /&gt;
26402&lt;br /&gt;
26403&lt;br /&gt;
26404&lt;br /&gt;
26405&lt;br /&gt;
26406&lt;br /&gt;
26407&lt;br /&gt;
26408&lt;br /&gt;
26409&lt;br /&gt;
26411&lt;br /&gt;
26412&lt;br /&gt;
26413&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:
&lt;br /&gt;
&lt;blockquote&gt;
The Sourcefire VRT has added and modified multiple rules in the
app-detect, blacklist, browser-ie, browser-other, browser-plugins, dos,
exploit, exploit-kit, file-flash, file-identify, file-image,
file-multimedia, file-office, file-other, indicator-compromise,
indicator-obfuscation, malware-backdoor, malware-cnc, malware-other,
netbios, nntp, os-windows, policy-other, policy-social, protocol-ftp,
protocol-imap, protocol-voip, scada, server-iis, server-other and
web-misc rule sets to provide coverage for emerging threats from these
technologies.
&lt;/blockquote&gt;
&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=SmJmAhjk_xY:knInexV1CuE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=SmJmAhjk_xY:knInexV1CuE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=SmJmAhjk_xY:knInexV1CuE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=SmJmAhjk_xY:knInexV1CuE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/SmJmAhjk_xY" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/SmJmAhjk_xY/sourcefire-vrt-certified-snort-rules_16.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/04/sourcefire-vrt-certified-snort-rules_16.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-2998771505718292970</guid><pubDate>Mon, 15 Apr 2013 14:52:00 +0000</pubDate><atom:updated>2013-04-15T11:43:21.906-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">ossim</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.1</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">docs</category><category domain="http://www.blogger.com/atom/ns#">snort.org</category><title>Integrating Snort and AlienVault OSSIM</title><description>Just added to the Docs section on Snort.org, another wonderful document by William Parker, a document that will help you integrate Snort-2.9.4.x and AlienVault's OSSIM tool.&lt;br /&gt;
&lt;br /&gt;
I've listed it under the "Snort Deployment Guides" section on &lt;a href="http://www.snort.org/docs"&gt;http://www.snort.org/docs&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Thanks William!&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=L5cYgXT8NA0:8exTs5c8rVg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=L5cYgXT8NA0:8exTs5c8rVg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=L5cYgXT8NA0:8exTs5c8rVg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=L5cYgXT8NA0:8exTs5c8rVg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/L5cYgXT8NA0" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/L5cYgXT8NA0/integrating-snort-and-alienvault-ossim.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/04/integrating-snort-and-alienvault-ossim.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-2160157181367058797</guid><pubDate>Thu, 11 Apr 2013 22:29:00 +0000</pubDate><atom:updated>2013-04-11T18:29:58.888-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.0</category><category domain="http://www.blogger.com/atom/ns#">2.9.3.1</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.5</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.1</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>Sourcefire VRT Certified Snort Rules Update for 04/11/2013</title><description>Just released:
Sourcefire VRT Certified Snort Rules Update for 04/11/2013
&lt;br /&gt;
&lt;br /&gt;
We welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2013-04-11.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 16 new rules and made modifications to 820 additional rules.
&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.
&lt;br /&gt;
&lt;br /&gt;
The VRT would like to thank James Lay for his contributions in the creation of the following rules:&lt;br /&gt;
26380&lt;br /&gt;
26381&lt;br /&gt;
26382&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:
&lt;br /&gt;
&lt;blockquote&gt;
The Sourcefire VRT has added and modified multiple rules in the
app-detect, blacklist, browser-firefox, browser-ie, browser-other,
browser-plugins, browser-webkit, dns, dos, exploit-kit,
file-executable, file-identify, file-multimedia, file-office,
file-other, file-pdf, malware-backdoor, malware-cnc, malware-other,
netbios, os-windows, policy-other, protocol-ftp, protocol-pop,
protocol-voip, rpc, scada, server-apache, server-iis, server-mssql,
server-mysql, server-other, server-webapp and web-client rule sets to
provide coverage for emerging threats from these technologies.
&lt;/blockquote&gt;
&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=I5r7MJaAs6E:81sNwbO25Lw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=I5r7MJaAs6E:81sNwbO25Lw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=I5r7MJaAs6E:81sNwbO25Lw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=I5r7MJaAs6E:81sNwbO25Lw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/I5r7MJaAs6E" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/I5r7MJaAs6E/sourcefire-vrt-certified-snort-rules_11.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/04/sourcefire-vrt-certified-snort-rules_11.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-5006344398711460930</guid><pubDate>Wed, 10 Apr 2013 13:42:00 +0000</pubDate><atom:updated>2013-04-10T09:42:59.910-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">rules</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.0</category><category domain="http://www.blogger.com/atom/ns#">2.9.3.1</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.5</category><category domain="http://www.blogger.com/atom/ns#">vrt</category><category domain="http://www.blogger.com/atom/ns#">2.9.4.1</category><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">release</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>Sourcefire VRT Certified Snort Rules Update for 04/09/2013, MSTUES</title><description>Sourcefire VRT Certified Snort Rules Update for 04/09/2013
&lt;br /&gt;
&lt;br /&gt;
(Sorry for the late post, this was released yesterday!&lt;br /&gt;
&lt;br /&gt;
We welcome the introduction of the newest &lt;a href="http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2013-04-09.html"&gt;rule release for today&lt;/a&gt; from the VRT. In this release we introduced 45 new rules and made modifications to 26 additional rules.
&lt;br /&gt;
&lt;br /&gt;
There were no changes made to the&amp;nbsp;&lt;code&gt;snort.conf&lt;/code&gt;&amp;nbsp;in this release.
&lt;br /&gt;
&lt;br /&gt;
The VRT would like to thank Avery Tarasov for his contribution of rules:&lt;br /&gt;
26335&lt;br /&gt;
26370&lt;br /&gt;
26371&lt;br /&gt;
&lt;br /&gt;
In VRT's rule release:
&lt;br /&gt;
&lt;blockquote&gt;
Details:
Microsoft Security Bulletin MS13-029:&amp;nbsp;&lt;/blockquote&gt;
&lt;blockquote&gt;
Microsoft Remote Desktop Client contains programming errors that may
allow a remote attacker to execute code on a vulnerable system.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 26355 through 26365.&amp;nbsp;&lt;/blockquote&gt;
&lt;blockquote&gt;
Microsoft Security Bulletin MS13-032:
A vulnerability in Microsoft Active Directory could lead to a denial of
service.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SID 26354.&amp;nbsp;&lt;/blockquote&gt;
&lt;blockquote&gt;
Additionally, the Sourcefire VRT has added and modified multiple rules
in the bad-traffic, blacklist, browser-ie, browser-plugins,
dos, exploit-kit, file-other, indicator-compromise,
indicator-obfuscation, malware-cnc, malware-other, netbios, os-windows,
protocol-ftp and server-webapp rule sets to provide coverage for
emerging threats from these technologies.
&lt;/blockquote&gt;
&lt;br /&gt;
&lt;br /&gt;
In order to &lt;a href="http://www.snort.org/vrt/buy-a-subscription/"&gt;subscribe now&lt;/a&gt; to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at &lt;a href="http://www.snort.org/store"&gt;http://www.snort.org/store&lt;/a&gt;.  Make sure and stay up to date to catch the most emerging threats!&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=-mPBDaSl1Lk:Lsy3zgwu72g:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=-mPBDaSl1Lk:Lsy3zgwu72g:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=-mPBDaSl1Lk:Lsy3zgwu72g:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=-mPBDaSl1Lk:Lsy3zgwu72g:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/-mPBDaSl1Lk" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/-mPBDaSl1Lk/sourcefire-vrt-certified-snort-rules_10.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/04/sourcefire-vrt-certified-snort-rules_10.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-3820717907624410159</guid><pubDate>Wed, 10 Apr 2013 13:33:00 +0000</pubDate><atom:updated>2013-04-10T09:33:34.188-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">barnyard2</category><title>Barnyard2 2-1.13-BETA is now available!</title><description>&lt;span style="font-family: Helvetica;"&gt;We are happy to announce the Availability of Barnyard2 2-1.13-BETA&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;which can be downloaded from HERE:&amp;nbsp;&lt;/span&gt;&lt;a href="https://github.com/firnsy/barnyard2.git" style="font-family: Helvetica;"&gt;https://github.com/firnsy/barnyard2.git&lt;/a&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;This release is a bug fix release that also introduce a few new&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;features and enhancements&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;=====================&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;UPGRADING REQUIREMENT&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;=====================&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;----------------------&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;If you are upgrading to barnyard2 2-1.13 Build 325 or above from a&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;previous version &amp;nbsp;that is not 2-1.13 and using the output database.&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;***** We highly recommend ******&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;To delete every row in your sig_reference table. (DELETE FROM sig_reference;)&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;The table will be re-populated at &amp;nbsp;process startup, and has no impact&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;on historical data.&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;----------------------&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;=====================&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;UPGRADING REQUIREMENT&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;=====================&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;Feature request:&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;----------------&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;Phil Daws: &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Add interface and hostname field to spo_alert_csv if&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;specified.&lt;/span&gt;&lt;br /&gt;
&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;Jorge Pinto: &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;spo_syslog_full support for ASCII,BASE64 payload&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;Jason Brvenik: &amp;nbsp;variables .....(a long time ago, sorry :P)&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;Martin Olsson: &amp;nbsp;Remove some useless verbosity unless&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;./configure --enable-debug is specified and proper&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;flag are used (spo_database and sid-msg.mapv2)&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;*And all other barnyard2 users who help and contribute.&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;Bug report:&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;-----------&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;Martin Olsson: &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;- bug in sig_reference generation and good&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;discussions.&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;John Eure and others &amp;nbsp;&amp;nbsp;- autogen.sh could cause some issue on some system so&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;[autoreconf -fv --install] is&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;not set to autoreconf -fvi&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;John Naggets &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;- spo_database: could stop barnyard2 from&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;processing new event if some&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;packets with ip&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;option where processed and&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;option_len &amp;nbsp;was null.&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;Fäbu Hufi &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;- spo_syslog_full: in complete mode was&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;printing wrong ip version&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;information and ip header length.&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;*And all other barnyard2 users who help and contribute.&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;New feature:&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;------------&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;Support for sid-msg.map Version 2 format.&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;-------&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;A new sig-msg.map format can be generated by pulledpok (upcoming release,&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;already in svn). Detection of sid-msg.map version is done by a simple&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;header in the &amp;nbsp;file that shouldn't be altered if you want it to be&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;processed correctly.&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;sig-msg.map version 2 format extend the information already present in&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;the sid-msg.map file created from rules.&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;This new format version allow signature &amp;nbsp;pre-population if users are&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;using output database method with &amp;nbsp;barnyard2 2-1.13 and above.&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;______________________&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;sid-msg.map v1 format:&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;______________________&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;SID || MSG || REF 1 || REF N&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;sid := integer&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;msg := string&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;ref := string&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;______________________&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;sid-msg.map v2 format:&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;______________________&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;GID || SID || REV || CLASSIFICATION || PRIORITY || MSG || REF 1 || REF N&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;gid := integer&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;sid := integer&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;rev := integer&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;classification := string (if NULL set to NOCLASS)&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;priority := integer (if prio == 0, classification priority is used)&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;msg := string&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;ref := string&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;=====================&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;generator (GID, gen-msg.map) are defaulted to the following value&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;if their information is not overruled in sid-msg.map v2 file via&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;processing of preprocessor.rules:&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;revision 1&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;classification 0&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;priority 3&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;If generator message is present in the sid-msg.map v2 file, and&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;gen-msg.map message are longer&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;(more comprehensive by string length),&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;gen-msg.map messages are used instead of sid-msg.map v2 file&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;generator messages.&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;=====================&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;&amp;nbsp;-------&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;Signature/event logging suppression at spooler level&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;-------&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;Read doc/README.sig_suppression&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;configuration file Variables:&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;-------&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;Barnyard2 configuration Variables&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;&amp;nbsp;-------&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;You can now use [var VARNAME value] in the barnyard2 configuration&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;file and every&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;instance of $VARNAME will get replaced by value.&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;Note that variable declaration order is important only you include a&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;variable in a variable.&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Helvetica;"&gt;EX (is VALID):&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;&amp;nbsp;var INTERFACE ethX&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;&amp;nbsp;var PATH /var/log/IDS&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;&amp;nbsp;var LOG $PATH/$INTERFACE/log&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;&amp;nbsp;var ARCHIVE $PATH/$INTERFACE/archive&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;&amp;nbsp;EX (is INVALID):&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;&amp;nbsp;var LOG $PATH/$INTERFACE/log&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;&amp;nbsp;var ARCHIVE $PATH/$INTERFACE/archive&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;&amp;nbsp;var INTERFACE ethX&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;&amp;nbsp;var PATH /var/log/IDS&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;&amp;nbsp;-------&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;new output database configuration keyword&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;-------&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;Keywords connection_limit and reconnect_sleep_time where added in&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;2-1.10 but where "undocumented" and shouldn't be modified unless&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;you encounter connectivity issue.&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;connection_limit &amp;lt;integer&amp;gt;: default 10 &amp;nbsp;- The maximum number of time&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;that barnyard2 will&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;tolerate a transaction&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;failure and or database&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;connection failure.&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;reconnect_sleep_time &amp;lt;integer&amp;gt; : default 5 - The number of seconds to sleep&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;between connection retry.&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;disable_signature_reference_table - Tell the output plugin not to synchronize&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;the sig_reference table in the schema.&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;This option will speedup the process,&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;especially if you use sid-msg.mapv2&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;file or &amp;nbsp;have a lot of signature already&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;in databases. (Make sure that you&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;do not need that&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: Helvetica;"&gt;information before enabling this)&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;&amp;nbsp;-------&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;Enjoy and do not hesitate to send feedback/suggestion/feature request.&lt;/span&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;br style="font-family: Helvetica;" /&gt;&lt;span style="font-family: Helvetica;"&gt;The barnyard2 team.&lt;/span&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=-cFiJatxYpk:Rbs5__FTk6k:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=-cFiJatxYpk:Rbs5__FTk6k:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=-cFiJatxYpk:Rbs5__FTk6k:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=-cFiJatxYpk:Rbs5__FTk6k:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/-cFiJatxYpk" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/-cFiJatxYpk/barnyard2-2-113-beta-is-now-available.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/04/barnyard2-2-113-beta-is-now-available.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-6654645683536716085</guid><pubDate>Mon, 08 Apr 2013 21:11:00 +0000</pubDate><atom:updated>2013-04-08T17:11:29.961-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">scholarship</category><category domain="http://www.blogger.com/atom/ns#">snort</category><title>2013 Snort Scholarship is now open!</title><description>Annually, Sourcefire provides a &lt;a href="http://www.sourcefire.com/security-technologies/snort/snort-scholarship" target="_blank"&gt;Snort Scholarship&lt;/a&gt; to two individuals selected at random (by drawing) in the amount of $5000 US for higher education purposes. &lt;br /&gt;
&lt;br /&gt;
To be eligible, you must meet the &lt;a href="http://www.sourcefire.com/security-technologies/snort/snort-scholarship/rules" target="_blank"&gt;legal criteria found here on our website&lt;/a&gt;, &lt;a href="https://info.sourcefire.com/2013SnortScholarshipApplication.html" target="_blank"&gt;sign up for the scholarship here&lt;/a&gt;, and following that, on or about May 17, 2013, two winners will be selected. &lt;br /&gt;
&lt;br /&gt;
For further information, please see the links above, also found &lt;a href="http://www.sourcefire.com/security-technologies/snort/snort-scholarship" target="_blank"&gt;linked here&lt;/a&gt;.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=e7Ehw7qwoEs:ojKJROdcBbk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=e7Ehw7qwoEs:ojKJROdcBbk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=e7Ehw7qwoEs:ojKJROdcBbk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=e7Ehw7qwoEs:ojKJROdcBbk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/e7Ehw7qwoEs" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/e7Ehw7qwoEs/2013-snort-scholarship-is-now-open.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/04/2013-snort-scholarship-is-now-open.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-3547754908791419403</guid><pubDate>Fri, 05 Apr 2013 19:55:00 +0000</pubDate><atom:updated>2013-04-05T15:55:33.341-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">snort</category><category domain="http://www.blogger.com/atom/ns#">docs</category><category domain="http://www.blogger.com/atom/ns#">updates</category><title>Snort 2.9.4.5 install docs have been updated!</title><description>Thanks to William Parker, again, working tirelessly until his documentation is updated, I just posted all the 2.9.4.5 install docs that he makes, now available at the only official &lt;a href="http://www.snort.org/docs" target="_blank"&gt;Snort Documentation&lt;/a&gt; site.&lt;br /&gt;
&lt;br /&gt;
There are docs for the following Operating Systems:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;CentOs 6.x&lt;/li&gt;
&lt;li&gt;NetBSD 6.0&lt;/li&gt;
&lt;li&gt;NetBSD 5.1.x&lt;/li&gt;
&lt;li&gt;Fedora 17&lt;/li&gt;
&lt;li&gt;Fedora 18&lt;/li&gt;
&lt;li&gt;OpenSuSE 14&lt;/li&gt;
&lt;li&gt;OpenSuSe 12&lt;/li&gt;
&lt;li&gt;FreeBSD 8.2&lt;/li&gt;
&lt;li&gt;FreeBSD 9.0&lt;/li&gt;
&lt;li&gt;OpenBSD 5.1&lt;/li&gt;
&lt;/ul&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=LaMl2J8yKyw:Az6R7govDn0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=LaMl2J8yKyw:Az6R7govDn0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=LaMl2J8yKyw:Az6R7govDn0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=LaMl2J8yKyw:Az6R7govDn0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/LaMl2J8yKyw" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/LaMl2J8yKyw/snort-2945-install-docs-have-been.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/04/snort-2945-install-docs-have-been.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-2620048000216434889.post-1232120566458923812</guid><pubDate>Fri, 05 Apr 2013 17:58:00 +0000</pubDate><atom:updated>2013-04-05T13:58:14.717-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">snort</category><title>Did you know there was a Snort IRC channel?</title><description>Ran into someone today online that was not aware that Snort had an IRC channel. &lt;br /&gt;
&lt;br /&gt;
So, for those of you that use IRC and would like to participate with us, #snort on irc.freenode.net is where we can be found!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Snort?a=-mhTjUIxZLA:tcPG6X-9ucw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=-mhTjUIxZLA:tcPG6X-9ucw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Snort?a=-mhTjUIxZLA:tcPG6X-9ucw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Snort?i=-mhTjUIxZLA:tcPG6X-9ucw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Snort/~4/-mhTjUIxZLA" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/Snort/~3/-mhTjUIxZLA/did-you-know-there-was-snort-irc-channel.html</link><author>noreply@blogger.com (Joel Esler)</author><thr:total>0</thr:total><feedburner:origLink>http://blog.snort.org/2013/04/did-you-know-there-was-snort-irc-channel.html</feedburner:origLink></item></channel></rss>
