CVS: snort - cazz
Brian Caswell <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.cvs |
|---|---|
| Message-ID | <[email protected]> |
CVSROOT: /cvsroot/snort Module name: snort Changes by: [email protected] 2004/02/27 14:36:20 Modified files: etc : sid sid-msg.map rules : backdoor.rules deleted.rules exploit.rules ftp.rules info.rules netbios.rules rpc.rules rservices.rules snmp.rules web-attacks.rules web-cgi.rules web-iis.rules web-misc.rules web-php.rules Log message: * 44 new rules, 52 updates. see snort-sigs mailing list in a few days for the full details. The cool rules are: (For ISS buffer overflow detection!) NETBIOS SMB Session Setup AndX request username overflow attempt NETBIOS SMB Data Service Session Setup AndX request username overflow attempt NETBIOS SMB Session Setup AndX request unicode username overflow attempt NETBIOS SMB Data Service Session Setup AndX request unicode username overflow attempt (For FW1 ISAKMP buffer overflow detection!) EXPLOIT ISAKMP first payload certificate request length overflow attempt EXPLOIT ISAKMP second payload certificate request length overflow attempt EXPLOIT ISAKMP third payload certificate request length overflow attempt EXPLOIT ISAKMP forth payload certificate request length overflow attempt EXPLOIT ISAKMP fifth payload certificate request length overflow attempt ------------------------------------------------------- SF.Net is sponsored by: Speed Start Your Linux Apps Now. Build and deploy apps & Web services for Linux with a free DVD software kit from IBM. Click Now! http://ads.osdn.com/?ad_id=1356&alloc_id=3438&op=click