Inline Normalization with Snort 2.9.0
Snort 2.9.0 can take a more active role in securing your network in inline deployments by normalizing packets and streams to minimize the chance that Snort incorrectly models end systems. To accomplish this, a new preprocessor was added. You must configure with this option to bu
Rule release for today, Tuesday November 9th, 2010
Microsoft Security Advisory MS10-087: Microsoft Office contains programming errors that may allow a remote attacker to execute code on an affected system. Microsoft Security Advisory MS10-088: Microsoft Office PowerPoint contains programming errors that may allow a remote attack
Rule Release for Today, Thursday October 28th, 2010
Adobe Shockwave Player vulnerability, see more here: http://www.snort.org/vrt/advisories/2010/10/28/vrt-rules-2010-10-28.html
Rule Release for Today, Tuesday October 26th, 2010
Vulnerabilities in Adobe Shockwave Director and Mozilla Firefox. More details here: http://www.snort.org/vrt/advisories/2010/10/26/vrt-rules-2010-10-26.html
Some Facts About Advanced Evasion Techniques
Chances are you've heard the recent "news" about Advanced Evasion Techniques (AETs) from Finnish IPS vendor Stonesoft. Originally announced in an October 4 press release, the good folks at Stonesoft reported the IDS/IPS evasion techniques mentioned in their release
Rule Release for Today, Tuesday October 12th, 2010
Big day for Microsoft patches today. Lots of rules to accompany it. Release notes here: http://www.snort.org/vrt/advisories/2010/10/12/vrt-rules-2010-10-12.html Read them here too: Microsoft Security Advisory MS10-070: The Microsoft .NET Framework discloses enough information
Rule Release for Today, Monday September 27th, 2010
We've added and modified multiple rules in the chat, dns, exploit, ftp, imap, misc, netbios, oracle, policy, pop3, rpc, specific-threats sql, tftp, web-activex, web-client and web-misc rule sets. Get it: http://www.snort.org/vrt/advisories/2010/09/27/vrt-rules-2010-09-27.htm
Rule Release for Today, Thursday September 23rd, 2010
Microsoft .NET Framework Information Disclosure (CVE-2010-3332): The Microsoft .NET Framework discloses enough information in error responses that an attacker is able to decrypt and modify encrypted data. The attacker is also able to forge cookies and obtain application files via
Rule Release for Today, Tuesday September 21st, 2010
Maintenance release this one. Quite a few modifications and additions. Check it out here http://www.snort.org/vrt/advisories/2010/09/21/vrt-rules-2010-09-21.html