CVS: snort - jhewlett
Jeremy Hewlett <[email protected]> Wed, 3 Nov 2004 11:28:31 -0500
| Newsgroups | gmane.comp.security.ids.snort.cvs |
|---|---|
| Message-ID | <[email protected]> |
CVSROOT: /usr/cvsroot-snort Module name: snort Changes by: [email protected] 2004/11/03 11:28:31 Modified files: . : ChangeLog configure.in src : plugbase.c snort.h util.c src/detection-plugins: sp_rpc_check.c src/preprocessors: perf-base.c perf-base.h perf.c perf.h sfprocpidstats.c snort_httpinspect.c spp_frag2.c spp_perfmonitor.c spp_stream4.c stream.h src/preprocessors/HttpInspect/client: hi_client.c src/preprocessors/HttpInspect/session_inspection: hi_si.c src/sfutil : acsmx2.c Log message: * Fixes for compilation on 64-bit Solaris. Snort 2_3 branch compiles cleanly; not tested as much on HEAD. (jhewlett, mnorton). Should be a few more changes coming shortly. * Compilation fix for AIX. Thanks Markus Waldeck. * perfmonitor config line can now be configured with accumulate or reset. Thanks Barry Basselgia for pointing out the issue (mnorton). Thanks Scott Dexter and Andreas Ostling for doing some initial testing. * Don't include the version string length as part of the directory length. Caused some false positives if the oversize directory length was set to small numbers. Thanks Jeremy Hewlett for catching this one. * Fix false positives that were occurring on some events. Thanks to Vjay Larosa for the report. * Fix linux perfmonitoring stats for the 2.6 kernel. Thanks to everyone that reported this bug. * Add an enforce_state keyword to stream4 so we won't pick up midstream sessions. This works well for asynchronous links and also for just monitoring legitimate traffic. ------------------------------------------------------- This SF.Net email is sponsored by: Sybase ASE Linux Express Edition - download now for FREE LinuxWorld Reader's Choice Award Winner for best database on Linux. http://ads.osdn.com/?ad_id=5588&alloc_id=12065&op=click