CVS: snort - jhewlett

Jeremy Hewlett <[email protected]> Tue, 14 Dec 2004 14:47:23 -0500
Newsgroups gmane.comp.security.ids.snort.cvs
Message-ID <[email protected]>
CVSROOT:	/usr/cvsroot-snort
Module name:	snort
Changes by:	[email protected]	2004/12/14 14:47:23

Modified files:
	.              : ChangeLog 
	doc            : README.http_inspect 
	src            : decode.c decode.h log.c parser.c snort.c 
	                 snort.h util.c util.h 
	src/detection-plugins: sp_byte_jump.c sp_pcre.c 
	src/preprocessors: Makefile.am snort_httpinspect.c 
	                   spp_arpspoof.c spp_stream4.c 

Log message:
* Updated error message when IIS Unicode map file is not found.
* Ignore RST|ACK midstream pickup case so we don't get an evasive TCP
alert.  Thanks for the report, Sekure.
* Fix "config logdir:" so that this works correctly when /var/log/snort
does not exist.
* Fixed bug when setting the doe_ptr on a successful pcre match.  It is
now set relative to base_ptr.
* Added from_beginning and multiplier options for byte_jump.
from_beginning skips bytes from the beginning of the content,
instead of from the location immediately following the number of
bytes to skip.  multiplier takes a numeric argument, and skips x
times that number of bytes.
* In "fast" output, now log only actual packet contents when UDP
data length is greater than actual data length. Thanks Brian
Caswell for spotting this.
* Arpspoof fixes from Jeff Nathan. Thanks Jeff.
* Updated documentation on flow_depth and HTTP headers per
conversations with Joe Patterson. Thanks Joe!



-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now. 
http://productguide.itmanagersjournal.com/