CVS: snort - cazz

Brian Caswell <[email protected]>
Newsgroups gmane.comp.security.ids.snort.cvs
Message-ID <[email protected]>
CVSROOT:	/cvsroot/snort
Module name:	snort
Changes by:	[email protected]	2004/02/27 14:36:20

Modified files:
	etc            : sid sid-msg.map 
	rules          : backdoor.rules deleted.rules exploit.rules 
	                 ftp.rules info.rules netbios.rules rpc.rules 
	                 rservices.rules snmp.rules web-attacks.rules 
	                 web-cgi.rules web-iis.rules web-misc.rules 
	                 web-php.rules 

Log message:
* 44 new rules, 52 updates.   see snort-sigs mailing list in a few days for the full details.

The cool rules are:
(For ISS buffer overflow detection!)
NETBIOS SMB Session Setup AndX request username overflow attempt
NETBIOS SMB Data Service Session Setup AndX request username overflow attempt
NETBIOS SMB Session Setup AndX request unicode username overflow attempt
NETBIOS SMB Data Service Session Setup AndX request unicode username overflow attempt

(For FW1 ISAKMP buffer overflow detection!)
EXPLOIT ISAKMP first payload certificate request length overflow attempt
EXPLOIT ISAKMP second payload certificate request length overflow attempt
EXPLOIT ISAKMP third payload certificate request length overflow attempt
EXPLOIT ISAKMP forth payload certificate request length overflow attempt
EXPLOIT ISAKMP fifth payload certificate request length overflow attempt



-------------------------------------------------------
SF.Net is sponsored by: Speed Start Your Linux Apps Now.
Build and deploy apps & Web services for Linux with
a free DVD software kit from IBM. Click Now!
http://ads.osdn.com/?ad_id=1356&alloc_id=3438&op=click
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.