CVS: snort - jhewlett

Jeremy Hewlett <[email protected]> Thu, 9 Dec 2004 12:38:47 -0500
Newsgroups gmane.comp.security.ids.snort.cvs
Message-ID <[email protected]>
CVSROOT:	/usr/cvsroot-snort
Module name:	snort
Changes by:	[email protected]	2004/12/09 12:38:47

Modified files:
	.              : Tag: SNORT_2_3 ChangeLog 
	src            : Tag: SNORT_2_3 decode.c decode.h log.c parser.c 
	                 snort.c snort.h util.c util.h 
	src/detection-plugins: Tag: SNORT_2_3 sp_byte_jump.c sp_pcre.c 
	src/preprocessors: Tag: SNORT_2_3 snort_httpinspect.c 
	                   spp_arpspoof.c spp_stream4.c 

Log message:
* Updated error message when IIS Unicode map file is not found.
* Ignore RST|ACK midstream pickup case so we don't get an evasive TCP
alert.  Thanks for the report, Sekure.
* Fix "config logdir:" so that this works correctly when /var/log/snort
does not exist.
* Fixed bug when setting the doe_ptr on a successful pcre match.  It is
now set relative to base_ptr.
* Added from_beginning and multiplier options for byte_jump.
from_beginning skips bytes from the beginning of the content,
instead of from the location immediately following the number of
bytes to skip.  multiplier takes a numeric argument, and skips x
times that number of bytes.
* In "fast" output, now log only actual packet contents when UDP
data length is greater than actual data length. Thanks Brian
Caswell for spotting this.
* Arpspoof fixes from Jeff Nathan. Thanks Jeff.



-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now. 
http://productguide.itmanagersjournal.com/