CVS: snort - jhewlett
Jeremy Hewlett <[email protected]> Thu, 9 Dec 2004 12:38:47 -0500
| Newsgroups | gmane.comp.security.ids.snort.cvs |
|---|---|
| Message-ID | <[email protected]> |
CVSROOT: /usr/cvsroot-snort Module name: snort Changes by: [email protected] 2004/12/09 12:38:47 Modified files: . : Tag: SNORT_2_3 ChangeLog src : Tag: SNORT_2_3 decode.c decode.h log.c parser.c snort.c snort.h util.c util.h src/detection-plugins: Tag: SNORT_2_3 sp_byte_jump.c sp_pcre.c src/preprocessors: Tag: SNORT_2_3 snort_httpinspect.c spp_arpspoof.c spp_stream4.c Log message: * Updated error message when IIS Unicode map file is not found. * Ignore RST|ACK midstream pickup case so we don't get an evasive TCP alert. Thanks for the report, Sekure. * Fix "config logdir:" so that this works correctly when /var/log/snort does not exist. * Fixed bug when setting the doe_ptr on a successful pcre match. It is now set relative to base_ptr. * Added from_beginning and multiplier options for byte_jump. from_beginning skips bytes from the beginning of the content, instead of from the location immediately following the number of bytes to skip. multiplier takes a numeric argument, and skips x times that number of bytes. * In "fast" output, now log only actual packet contents when UDP data length is greater than actual data length. Thanks Brian Caswell for spotting this. * Arpspoof fixes from Jeff Nathan. Thanks Jeff. ------------------------------------------------------- SF email is sponsored by - The IT Product Guide Read honest & candid reviews on hundreds of IT Products from real users. Discover which products truly live up to the hype. Start reading now. http://productguide.itmanagersjournal.com/