Snort Blog: Snort 2.9.15.0 has been released!
"Joel Esler \(jesler\) via Snort-devel" <[email protected]> Thu, 10 Oct 2019 18:34:31 +0000
| Newsgroups | gmane.comp.security.ids.snort.devel |
|---|---|
| Message-ID | <00418890-B88C-4523-92B2-434ADC141C13__34174.3990707741$1570733500$gmane$org@cisco.com> |
--===============0985725936306543893== Content-Language: en-US Content-Type: multipart/alternative; boundary="_000_00418890B88C452392B2434ADC141C13ciscocom_" --_000_00418890B88C452392B2434ADC141C13ciscocom_ Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable https://blog.snort.org/2019/10/snort-29150-has-been-released.html Snort 2.9.15.0 has been released! Join as we welcome Snort 2.9.15.0 into the family! As always, available from our download site on Snort.org<https://snort.org/= downloads>, this feature contains the following release notes: 2019-10-10 - Snort 2.9.15 [*] New Additions * Added new debugs to print detection, file_processing and Preproc tim= e consumption info and verdict. * Added support to detect new Korean file formats .egg and .alg in the = file preprocessor. * Added support to detect new RAR file-type in the file preprocessor. [*] Improvements / Fix * Fix to generate ALERT if TEID value is zero in GTP v1 and v2 packets. * Fix to whitelist ftp data sessions when no file policy exists. * Fix RTF file magic to a more generic value to prevent evasions. * Added debug logs during HTTP reload * Added rule SID check during validation * Fix an issue where HTTP was processing non-HTTP traffic on port 443 * Added new debugs to print detection, file processing, and Prepro time= consumption info and verdicts Any notes or feedback for us on Snort 2.9.15.0? Please shoot us a note ove= r on the Snort-Users mailing list<https://snort.org/community>! Thanks! The Snort Development Team --_000_00418890B88C452392B2434ADC141C13ciscocom_ Content-Type: text/html; charset="us-ascii" Content-ID: <[email protected]> Content-Transfer-Encoding: quoted-printable <html> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"= > <base> </head> <body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; line-break:= after-white-space;" class=3D""> <base class=3D""> <div class=3D"Apple-Mail-URLShareUserContentTopClass"><br class=3D""> </div> <div class=3D"Apple-Mail-URLShareWrapperClass"> <blockquote type=3D"cite" style=3D"border-left-style: none; color: inherit;= padding: inherit; margin: inherit;" class=3D""> <div class=3D""> <div class=3D"original-url"><br class=3D""> <a href=3D"https://blog.snort.org/2019/10/snort-29150-has-been-released.htm= l" class=3D"">https://blog.snort.org/2019/10/snort-29150-has-been-released.= html</a><br class=3D""> <br class=3D""> </div> <div id=3D"article" role=3D"article" style=3D"text-rendering: optimizeLegib= ility; font-family: -apple-system-font; font-size: 1.2em; line-height: 1.5e= m; margin: 0px; padding: 0px;" class=3D"system exported"> <!-- This node will contain a number of div.page. --> <div class=3D"page" style=3D"word-wrap: break-word; max-width: 100%;"> <h1 class=3D"title" style=3D"font-size: 1.95552em; line-height: 1.2141em; m= argin-top: 0px; margin-bottom: 0.5em; max-width: 100%;"> Snort 2.9.15.0 has been released!</h1> Join as we welcome Snort 2.9.15.0 into the family! <br style=3D"max-width: = 100%;" class=3D""> <br style=3D"max-width: 100%;" class=3D""> As always, available from our <a href=3D"https://snort.org/downloads" targe= t=3D"_blank" style=3D"color: rgb(65, 110, 210); max-width: 100%;" class=3D"= "> download site on Snort.org</a>, this feature contains the following release= notes:<br style=3D"max-width: 100%;" class=3D""> <br style=3D"max-width: 100%;" class=3D""> 2019-10-10 - Snort 2.9.15<br style=3D"max-width: 100%;" class=3D""> <br style=3D"max-width: 100%;" class=3D""> [*] New Additions<br style=3D"max-width: 100%;" class=3D""> <br style=3D"max-width: 100%;" class=3D""> <ul style=3D"max-width: 100%;" class=3D""> <li style=3D"max-width: 100%;" class=3D""> Added new debugs to print d= etection, file_processing and Preproc time consumption info and verdict.</l= i><li style=3D"max-width: 100%;" class=3D"">Added support to detect new Kor= ean file formats .egg and .alg in the file preprocessor.</li><li style=3D"m= ax-width: 100%;" class=3D"">Added support to detect new RAR file-type in th= e file preprocessor.</li></ul> <br style=3D"max-width: 100%;" class=3D""> [*] Improvements / Fix<br style=3D"max-width: 100%;" class=3D""> <br style=3D"max-width: 100%;" class=3D""> <ul style=3D"max-width: 100%;" class=3D""> <li style=3D"max-width: 100%;" class=3D"">Fix to generate ALERT if TEID val= ue is zero in GTP v1 and v2 packets.</li><li style=3D"max-width: 100%;" cla= ss=3D"">Fix to whitelist ftp data sessions when no file policy exists.</li>= <li style=3D"max-width: 100%;" class=3D"">Fix RTF file magic to a more gene= ric value to prevent evasions.</li><li style=3D"max-width: 100%;" class=3D"= ">Added debug logs during HTTP reload</li><li style=3D"max-width: 100%;" cl= ass=3D"">Added rule SID check during validation</li><li style=3D"max-width:= 100%;" class=3D"">Fix an issue where HTTP was processing non-HTTP traffic = on port 443</li><li style=3D"max-width: 100%;" class=3D"">Added new debugs = to print detection, file processing, and Prepro time consumption info and v= erdicts</li></ul> <div style=3D"max-width: 100%;" class=3D"">Any notes or feedback for us on = Snort 2.9.15.0? Please shoot us a note over on the <a href=3D"https://snort.org/community" target=3D"_blank" style=3D"color: r= gb(65, 110, 210); max-width: 100%;" class=3D""> Snort-Users mailing list</a>!</div> <div style=3D"max-width: 100%;" class=3D""><br class=3D"webkit-block-placeh= older"> </div> <p style=3D"max-width: 100%;" class=3D"">Thanks!</p> <div style=3D"max-width: 100%;" class=3D""><br class=3D"webkit-block-placeh= older"> </div> <p style=3D"max-width: 100%;" class=3D"">The Snort Development Team</p> <br style=3D"max-width: 100%; display: none;" class=3D""> <div style=3D"max-width: 100%;" class=3D""><br class=3D"webkit-block-placeh= older"> </div> <div style=3D"max-width: 100%;" class=3D""><br class=3D"webkit-block-placeh= older"> </div> <div style=3D"max-width: 100%;" class=3D""><br class=3D"webkit-block-placeh= older"> </div> </div> </div> </div> </blockquote> </div> </body> </html> --_000_00418890B88C452392B2434ADC141C13ciscocom_-- --===============0985725936306543893== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Snort-devel mailing list [email protected] https://lists.snort.org/mailman/listinfo/snort-devel Please visit http://blog.snort.org for the latest news about Snort! --===============0985725936306543893==--