Snort Blog: Snort 2.9.15.0 has been released!

"Joel Esler \(jesler\) via Snort-devel" <[email protected]> Thu, 10 Oct 2019 18:34:31 +0000
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <00418890-B88C-4523-92B2-434ADC141C13__34174.3990707741$1570733500$gmane$org@cisco.com>
--===============0985725936306543893==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_00418890B88C452392B2434ADC141C13ciscocom_"

--_000_00418890B88C452392B2434ADC141C13ciscocom_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable



https://blog.snort.org/2019/10/snort-29150-has-been-released.html

Snort 2.9.15.0 has been released!
Join as we welcome Snort 2.9.15.0 into the family!

As always, available from our download site on Snort.org<https://snort.org/=
downloads>, this feature contains the following release notes:

2019-10-10 - Snort 2.9.15

[*] New Additions


  *    Added new debugs to print detection, file_processing and Preproc tim=
e consumption info and verdict.
  *   Added support to detect new Korean file formats .egg and .alg in the =
file preprocessor.
  *   Added support to detect new RAR file-type in the file preprocessor.

[*] Improvements / Fix


  *   Fix to generate ALERT if TEID value is zero in GTP v1 and v2 packets.
  *   Fix to whitelist ftp data sessions when no file policy exists.
  *   Fix RTF file magic to a more generic value to prevent evasions.
  *   Added debug logs during HTTP reload
  *   Added rule SID check during validation
  *   Fix an issue where HTTP was processing non-HTTP traffic on port 443
  *   Added new debugs to print detection, file processing, and Prepro time=
 consumption info and verdicts

Any notes or feedback for us on Snort 2.9.15.0?  Please shoot us a note ove=
r on the Snort-Users mailing list<https://snort.org/community>!


Thanks!


The Snort Development Team





--_000_00418890B88C452392B2434ADC141C13ciscocom_
Content-Type: text/html; charset="us-ascii"
Content-ID: <[email protected]>
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<base>
</head>
<body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; line-break:=
 after-white-space;" class=3D"">
<base class=3D"">
<div class=3D"Apple-Mail-URLShareUserContentTopClass"><br class=3D"">
</div>
<div class=3D"Apple-Mail-URLShareWrapperClass">
<blockquote type=3D"cite" style=3D"border-left-style: none; color: inherit;=
 padding: inherit; margin: inherit;" class=3D"">
<div class=3D"">
<div class=3D"original-url"><br class=3D"">
<a href=3D"https://blog.snort.org/2019/10/snort-29150-has-been-released.htm=
l" class=3D"">https://blog.snort.org/2019/10/snort-29150-has-been-released.=
html</a><br class=3D"">
<br class=3D"">
</div>
<div id=3D"article" role=3D"article" style=3D"text-rendering: optimizeLegib=
ility; font-family: -apple-system-font; font-size: 1.2em; line-height: 1.5e=
m; margin: 0px; padding: 0px;" class=3D"system exported">
<!-- This node will contain a number of div.page. -->
<div class=3D"page" style=3D"word-wrap: break-word; max-width: 100%;">
<h1 class=3D"title" style=3D"font-size: 1.95552em; line-height: 1.2141em; m=
argin-top: 0px; margin-bottom: 0.5em; max-width: 100%;">
Snort 2.9.15.0 has been released!</h1>
Join as we welcome Snort 2.9.15.0 into the family! <br style=3D"max-width: =
100%;" class=3D"">
<br style=3D"max-width: 100%;" class=3D"">
As always, available from our <a href=3D"https://snort.org/downloads" targe=
t=3D"_blank" style=3D"color: rgb(65, 110, 210); max-width: 100%;" class=3D"=
">
download site on Snort.org</a>, this feature contains the following release=
 notes:<br style=3D"max-width: 100%;" class=3D"">
<br style=3D"max-width: 100%;" class=3D"">
2019-10-10 - Snort 2.9.15<br style=3D"max-width: 100%;" class=3D"">
<br style=3D"max-width: 100%;" class=3D"">
[*] New Additions<br style=3D"max-width: 100%;" class=3D"">
<br style=3D"max-width: 100%;" class=3D"">
<ul style=3D"max-width: 100%;" class=3D"">
<li style=3D"max-width: 100%;" class=3D"">&nbsp;Added new debugs to print d=
etection, file_processing and Preproc time consumption info and verdict.</l=
i><li style=3D"max-width: 100%;" class=3D"">Added support to detect new Kor=
ean file formats .egg and .alg in the file preprocessor.</li><li style=3D"m=
ax-width: 100%;" class=3D"">Added support to detect new RAR file-type in th=
e file preprocessor.</li></ul>
<br style=3D"max-width: 100%;" class=3D"">
[*] Improvements / Fix<br style=3D"max-width: 100%;" class=3D"">
<br style=3D"max-width: 100%;" class=3D"">
<ul style=3D"max-width: 100%;" class=3D"">
<li style=3D"max-width: 100%;" class=3D"">Fix to generate ALERT if TEID val=
ue is zero in GTP v1 and v2 packets.</li><li style=3D"max-width: 100%;" cla=
ss=3D"">Fix to whitelist ftp data sessions when no file policy exists.</li>=
<li style=3D"max-width: 100%;" class=3D"">Fix RTF file magic to a more gene=
ric value to prevent evasions.</li><li style=3D"max-width: 100%;" class=3D"=
">Added debug logs during HTTP reload</li><li style=3D"max-width: 100%;" cl=
ass=3D"">Added rule SID check during validation</li><li style=3D"max-width:=
 100%;" class=3D"">Fix an issue where HTTP was processing non-HTTP traffic =
on port 443</li><li style=3D"max-width: 100%;" class=3D"">Added new debugs =
to print detection, file processing, and Prepro time consumption info and v=
erdicts</li></ul>
<div style=3D"max-width: 100%;" class=3D"">Any notes or feedback for us on =
Snort 2.9.15.0? &nbsp;Please shoot us a note over on the
<a href=3D"https://snort.org/community" target=3D"_blank" style=3D"color: r=
gb(65, 110, 210); max-width: 100%;" class=3D"">
Snort-Users mailing list</a>!</div>
<div style=3D"max-width: 100%;" class=3D""><br class=3D"webkit-block-placeh=
older">
</div>
<p style=3D"max-width: 100%;" class=3D"">Thanks!</p>
<div style=3D"max-width: 100%;" class=3D""><br class=3D"webkit-block-placeh=
older">
</div>
<p style=3D"max-width: 100%;" class=3D"">The Snort Development Team</p>
<br style=3D"max-width: 100%; display: none;" class=3D"">
<div style=3D"max-width: 100%;" class=3D""><br class=3D"webkit-block-placeh=
older">
</div>
<div style=3D"max-width: 100%;" class=3D""><br class=3D"webkit-block-placeh=
older">
</div>
<div style=3D"max-width: 100%;" class=3D""><br class=3D"webkit-block-placeh=
older">
</div>
</div>
</div>
</div>
</blockquote>
</div>
</body>
</html>

--_000_00418890B88C452392B2434ADC141C13ciscocom_--

--===============0985725936306543893==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-devel

Please visit http://blog.snort.org for the latest news about Snort!

--===============0985725936306543893==--