Snort Blog: Snort 2.9.14.1 has been released!

"Joel Esler \(jesler\) via Snort-devel" <[email protected]> Fri, 2 Aug 2019 19:24:25 +0000
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <[email protected]>
--===============0313639122973001744==
Content-Language: en-US
Content-Type: multipart/signed;
	boundary="Apple-Mail=_F5270A15-E128-4013-A051-060B3339E2D7";
	protocol="application/pkcs7-signature";
	micalg=sha-256

--Apple-Mail=_F5270A15-E128-4013-A051-060B3339E2D7
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_58170A90-0AC3-4929-B7D0-44B098D1187E"


--Apple-Mail=_58170A90-0AC3-4929-B7D0-44B098D1187E
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii


>=20
> https://blog.snort.org/2019/08/snort-29141-has-been-released.html =
<https://blog.snort.org/2019/08/snort-29141-has-been-released.html>
>=20
> Snort 2.9.14.1 has been released!
>=20
> Snort Community!
>=20
> We know it's a Friday, so we don't expect everyone to run right out =
and update, but in trying to get everything done before Black hat / =
Defcon, we wanted to make sure that 2.9.14.1 was shipped before we all =
got on planes to head out to "Hacker Summer Camp".
>=20
> We've just pushed 2.9.14.1 live on the website (snort.org/downloads =
<https://snort.org/downloads>).  Please head on over and check it out at =
your earliest convenience.
>=20
> Release notes are essentially the same as 2.9.14.0, with one minor =
fix, so I'll repost those:
>=20
> [*] New Additions
>=20
>  * Added support for wild card port numbers in host cache and =
overwriting port service AppId.
>=20
>  * Added support for new STLS client patterns to help better detect =
POP3S over SSL.
>=20
>  * Added support for detecting Mac based SMTP Microsoft Outlook client =
application.
>=20
>  * Added a new preprocessor alert 120:27 to alert if there is no =
proper end of header.
>=20
> [*] Improvements / Fix
>=20
>  * Improved appId detection for proxied traffic.
>=20
>  * Fix for enabling flow profiling mode without restarting snort =
detection engine.
>=20
>  * Fixed packet drop scenario.
>=20
>=20
> Thanks so much for bearing with us while we figured out the little bug =
with packet acquisition.=20
>=20
> As always, feedback can be directed to the Snort-users list =
<https://lists.snort.org/>.  Happy Snorting! =20

--
Joel Esler
Manager, Communities Division
Cisco Talos Intelligence Group
http://www.talosintelligence.com=

--Apple-Mail=_58170A90-0AC3-4929-B7D0-44B098D1187E
Content-Transfer-Encoding: 7bit
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv="Content-Type" content="text/html; charset=us-ascii"><base></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><base class=""><div class="Apple-Mail-URLShareUserContentTopClass"><br class=""></div><div class="Apple-Mail-URLShareWrapperClass"><blockquote type="cite" style="border-left-style: none; color: inherit; padding: inherit; margin: inherit;" class=""><div class=""><div class="original-url"><br class=""><a href="https://blog.snort.org/2019/08/snort-29141-has-been-released.html" class="">https://blog.snort.org/2019/08/snort-29141-has-been-released.html</a><br class=""><br class=""></div><div id="article" role="article" style="text-rendering: optimizeLegibility; font-family: -apple-system-font; font-s
 ize: 1.2em; line-height: 1.5em; margin: 0px; padding: 0px;" class="system exported">
        <!-- This node will contain a number of div.page. -->
    <div class="page" style="word-wrap: break-word; max-width: 100%;"><h1 class="title" style="font-size: 1.95552em; line-height: 1.2141em; margin-top: 0px; margin-bottom: 0.5em; max-width: 100%;">Snort 2.9.14.1 has been released!</h1>
Snort Community!<br style="max-width: 100%;" class="">
<br style="max-width: 100%;" class="">
We know it's a Friday, so we don't expect everyone to run right out and update, but in trying to get everything done before Black hat / Defcon, we wanted to make sure that 2.9.14.1 was shipped before we all got on planes to head out to "Hacker Summer Camp".<br style="max-width: 100%;" class="">
<br style="max-width: 100%;" class="">
We've just pushed 2.9.14.1 live on the website (<a href="https://snort.org/downloads" target="_blank" style="color: rgb(65, 110, 210); max-width: 100%;" class="">snort.org/downloads</a>). &nbsp;Please head on over and check it out at your earliest convenience.<br style="max-width: 100%;" class="">
<br style="max-width: 100%;" class="">
Release notes are essentially the same as 2.9.14.0, with one minor fix, so I'll repost those:<br style="max-width: 100%;" class="">
<br style="max-width: 100%;" class="">
<div class="scrollable" style="max-width: 100%; overflow-x: scroll; word-wrap: normal;"><pre style="white-space: pre-wrap; max-width: 100%; font-family: -apple-system-ui-monospaced, Menlo; font-size: 0.87em; line-height: 1.45em;" class="">[*] New Additions

 * Added support for wild card port numbers in host cache and overwriting port service AppId.

 * Added support for new STLS client patterns to help better detect POP3S over SSL.

 * Added support for detecting Mac based SMTP Microsoft Outlook client application.

 * Added a new preprocessor alert 120:27 to alert if there is no proper end of header.

[*] Improvements / Fix

 * Improved appId detection for proxied traffic.

 * Fix for enabling flow profiling mode without restarting snort detection engine.

 * Fixed packet drop scenario.</pre></div>
<br style="max-width: 100%;" class="">
<br style="max-width: 100%;" class="">
Thanks so much for bearing with us while we figured out the little bug with packet acquisition. <br style="max-width: 100%;" class="">
<br style="max-width: 100%;" class="">
As always, feedback can be directed to the <a href="https://lists.snort.org/" target="_blank" style="color: rgb(65, 110, 210); max-width: 100%;" class="">Snort-users list</a>. &nbsp;Happy Snorting! &nbsp;</div></div></div></blockquote><br class=""></div><div class="Apple-Mail-URLShareWrapperClass"><div class="Apple-Mail-URLShareWrapperClass">--</div><div class="Apple-Mail-URLShareWrapperClass">Joel Esler</div><div class="Apple-Mail-URLShareWrapperClass">Manager, Communities Division</div><div class="Apple-Mail-URLShareWrapperClass">Cisco Talos Intelligence Group</div><div class="Apple-Mail-URLShareWrapperClass"><a href="http://www.talosintelligence.com" class="">http://www.talosintelligence.com</a></div></div></body></html>
--Apple-Mail=_58170A90-0AC3-4929-B7D0-44B098D1187E--

--Apple-Mail=_F5270A15-E128-4013-A051-060B3339E2D7
Content-Disposition: attachment; filename="smime.p7s"
Content-Type: application/pkcs7-signature;
	name=smime.p7s
Content-Transfer-Encoding: base64

MIAGCSqGSIb3DQEHAqCAMIACAQExDzANBglghkgBZQMEAgEFADCABgkqhkiG9w0BBwEAAKCCCRYw
ggRuMIIDVqADAgECAgphEIBtAAAAAAAOMA0GCSqGSIb3DQEBBQUAMDUxFjAUBgNVBAoTDUNpc2Nv
IFN5c3RlbXMxGzAZBgNVBAMTEkNpc2NvIFJvb3QgQ0EgMjA0ODAeFw0xNDA0MDQyMDI0MThaFw0y
OTA1MTQyMDI1NDJaMCwxDjAMBgNVBAoTBUNpc2NvMRowGAYDVQQDExFDaXNjbyBFbXBsb3llZSBD
QTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMrffhZMUxX7I1bNxrllCgSV5d5MRWeM
DMcG4KsfbV83Knvn7aOtgH8RyPOC6+6fUNnJvz2hL7s8EQc177il2VFO2bD3U6CUgCwskmWtEG+h
hmtfQAqZpVBEGpBNz+ZM+0YGjUjjB9fhrWPX1egnABW/bgeyQ7tlBi999lldmxLFLH2960SwUuHC
/B7tnVn3HZOnqzGmQkI5J9OBYsZULCaM2z0U0KiOFeoopBv+vaw8nk3W1UyvjMv/S58FbA9xgTIk
Ye0Zq77qcbRojLvI9OSLP3dTon4VnnML41d0XoPS6JPGzDSRDAKXndcHk3VUtF+DLAIXqLCQZXfZ
UuTuIncCAwEAAaOCAYcwggGDMBAGCSsGAQQBgjcVAQQDAgEAMB0GA1UdDgQWBBSflTa0jl3VS8MK
wacpk0NRBv2JUTAZBgkrBgEEAYI3FAIEDB4KAFMAdQBiAEMAQTALBgNVHQ8EBAMCAYYwEgYDVR0T
AQH/BAgwBgEB/wIBADAfBgNVHSMEGDAWgBQn88gVHm6aAgkWrSugiWBf2nsvqjBDBgNVHR8EPDA6
MDigNqA0hjJodHRwOi8vd3d3LmNpc2NvLmNvbS9zZWN1cml0eS9wa2kvY3JsL2NyY2EyMDQ4LmNy
bDBQBggrBgEFBQcBAQREMEIwQAYIKwYBBQUHMAKGNGh0dHA6Ly93d3cuY2lzY28uY29tL3NlY3Vy
aXR5L3BraS9jZXJ0cy9jcmNhMjA0OC5jZXIwXAYDVR0gBFUwUzBRBgorBgEEAQkVARUAMEMwQQYI
KwYBBQUHAgEWNWh0dHA6Ly93d3cuY2lzY28uY29tL3NlY3VyaXR5L3BraS9wb2xpY2llcy9pbmRl
eC5odG1sMA0GCSqGSIb3DQEBBQUAA4IBAQA+Tr4jGkYCjV5r24oCNAtjm+UBPCZdjHCyJOtgXuyK
hGQuG1kVo2ca4Rbj/eBNfUSaIyjS7bb3oh/nRM3tbeqGIVQorGxhvPvIZVAEQIoqi/yfbhie9cU+
paKpHACucaYXu0kyS0pYE5NMNun3Lw3ogOs4XVR5yoVSpKTiVnfTDQchTpwkMgzivqXDcS1OiDfU
8C9WaEZHRWtdUIgl9zoppPGIQa1TflcxhirW4GeH2FOrgaN1d77bIcg6R7RpJ9Xu3/f01nGNunrR
cy993c2meJQoZcOJd15C6ugHwhAxeXY6QXYgkY8KQVCCGwkpshEgbwPrC+I/Itb6P7hGq7awMIIE
oDCCA4igAwIBAgIKAYYRaDD7OEqcKzANBgkqhkiG9w0BAQsFADAsMQ4wDAYDVQQKEwVDaXNjbzEa
MBgGA1UEAxMRQ2lzY28gRW1wbG95ZWUgQ0EwHhcNMTgxMTIxMDAwMDAwWhcNMjAxMTIwMDAxMDAw
WjCBlTEcMBoGA1UEAxMTSm9lbCBFc2xlciAoamVzbGVyKTEUMBIGA1UECxMLQ2lzY28gVXNlcnMx
EjAQBgNVBAsTCUVtcGxveWVlczETMBEGCgmSJomT8ixkARkTA2NvbTEVMBMGCgmSJomT8ixkARkT
BWNpc2NvMR8wHQYJKoZIhvcNAQkBDBBqZXNsZXJAY2lzY28uY29tMIIBIjANBgkqhkiG9w0BAQEF
AAOCAQ8AMIIBCgKCAQEAjY9Yo3zw0WCxtdtE4oQyXJqoSbeuJULMuLBbZbmalv2w7vNluXG9Qhsh
7zttHIU+z1j0XpG2BnYZMl4AgO23yOyghTAo5u8hBH9Riox9bw0hRkB/pAE89QeZ+1kNOGLuZfN8
B5sTFFmRTztX+TZtIkFONq7q9Wj+h0P5ikvyCgr3tjsbnJRNVSAynEfWGFxIxAGyEYIGMHeSz1ej
SenHps4yI8qTKsX9o3KLRz1nLucUDpm/TCLbQEI87Uv9Phd2v0FptbWUKik9agDjTW4/Q7PjBTPc
OpXem/8w8H9S7TKa248Opt2Nv24oqJZMVAUu6It9oQZWubO0bsYYp8yiDQIDAQABo4IBWDCCAVQw
DgYDVR0PAQH/BAQDAgTwMAwGA1UdEwEB/wQCMAAwegYIKwYBBQUHAQEEbjBsMDwGCCsGAQUFBzAC
hjBodHRwOi8vd3d3LmNpc2NvLmNvbS9zZWN1cml0eS9wa2kvY2VydHMvY2VjYS5jZXIwLAYIKwYB
BQUHMAGGIGh0dHA6Ly9wa2ljdnMuY2lzY28uY29tL3BraS9vY3NwMB8GA1UdIwQYMBaAFJ+VNrSO
XdVLwwrBpymTQ1EG/YlRMDoGA1UdHwQzMDEwL6AtoCuGKWh0dHA6Ly9jaXNjb2NlcnRzLmNpc2Nv
LmNvbS9maWxlL2NlY2EuY3JsMBsGA1UdEQQUMBKBEGplc2xlckBjaXNjby5jb20wHQYDVR0OBBYE
FDTmAUtoBuQRY6GKIvCllZGSohm5MB8GA1UdJQQYMBYGCisGAQQBgjcKAwwGCCsGAQUFBwMEMA0G
CSqGSIb3DQEBCwUAA4IBAQA3p6fJ3fQlcqszfVLrike+NXunUtbNejhKDOPMhVc3bsozBPggAZbo
m62BvhsvgVLj/+IS2qIEflQxhS2ToplJi8nXRpZ9Qtsu4mhCByy0Z0Xtaw0v2f78B1pskPxDdXZm
T47sc84h0iW+wuZ4yADZb2azb+2j7GNd/vdPLnVyDE209ksjrYyYNO7LifZqmSqIipBYOyG3JZ25
BMTQP7ttExfRKbrkRFSHapvISiFoBeakwGRSqiF7aTAnilXm0Kp1Aj6cQH0Ju3xgXSUpxQewDvZm
Q+AYG6sV6V0yy4fwa1UQAOVKH0dadXp1z9K5WcrqC8Wqz0ojBLT/Avhfy3sXMYICajCCAmYCAQEw
OjAsMQ4wDAYDVQQKEwVDaXNjbzEaMBgGA1UEAxMRQ2lzY28gRW1wbG95ZWUgQ0ECCgGGEWgw+zhK
nCswDQYJYIZIAWUDBAIBBQCgggEBMBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcN
AQkFMQ8XDTE5MDgwMjE5MjQyNFowLwYJKoZIhvcNAQkEMSIEIDkA7sUvUWKWmJf7dLIusDfc6SUs
AHD37UjvrYkKhdlkMEkGCSsGAQQBgjcQBDE8MDowLDEOMAwGA1UEChMFQ2lzY28xGjAYBgNVBAMT
EUNpc2NvIEVtcGxveWVlIENBAgoBhhFoMPs4SpwrMEsGCyqGSIb3DQEJEAILMTygOjAsMQ4wDAYD
VQQKEwVDaXNjbzEaMBgGA1UEAxMRQ2lzY28gRW1wbG95ZWUgQ0ECCgGGEWgw+zhKnCswDQYJKoZI
hvcNAQEBBQAEggEAR+jqbb55X9wT0pUxJpzmz7Y5XcdQoIyTUYOgalFHcrTjQjUjmKn8DU3X9uY5
8f/eo5YInO0FoNo2WvJcz4dhHtdhSaiDyD+UjQJ1oZc/o1x22i/jESDV9eah517w2EWZRnEOEDn2
SCfsoGsYn0afbMhbdk/V5ia0xsi9acffI1gPIBXMyvT4hOibDqGpz+vJSN91QKQZMj9wqrNXzWAP
vAgfbALA199o1NdcBsEq+x8f2FPqxzixxXPPSk/e6EELFCsEOpupw01Tb68wQMb8HYTvZ99PQ81N
UhcaHWgoODJX0GbqymLQoqivYK8H9KiVqLm74BYTH4nDHvplN4zgYgAAAAAAAA==

--Apple-Mail=_F5270A15-E128-4013-A051-060B3339E2D7--

--===============0313639122973001744==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-devel

Please visit http://blog.snort.org for the latest news about Snort!

--===============0313639122973001744==--