Re: Snort Blog: Snort 2.9.15.0 has been released!

Dorian ROSSE via Snort-devel <[email protected]> Fri, 11 Oct 2019 10:12:54 +0000
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <AM0PR08MB4996E773240DB36D0DCCDE37DA970@AM0PR08MB4996.eurprd08.prod.outlook.com>
--===============6392725009028634078==
Content-Language: fr-FR
Content-Type: multipart/alternative;
	boundary="_000_AM0PR08MB4996E773240DB36D0DCCDE37DA970AM0PR08MB4996eurp_"

--_000_AM0PR08MB4996E773240DB36D0DCCDE37DA970AM0PR08MB4996eurp_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Does the egg info file in nghttp2 is a Korean egg?

(I have download by run python and go scripts!)

(the egg seems be in my android phone by watching malwarebyte works)

(malwarebyte doesn't hijack the egg)

Thank you in advance to answer my questions because I am again in wait for =
use snort 2 9 14 1 lol,

Regards.


Dorian rosse.

T=E9l=E9charger Outlook pour Android<https://aka.ms/ghei36>
________________________________
From: Snort-users <[email protected]> on behalf of Joel E=
sler (jesler) via Snort-users <[email protected]>
Sent: Thursday, October 10, 2019 8:34:31 PM
To: Snort <[email protected]>; Chang Liu via Snort-devel <snort-d=
[email protected]>; [email protected] <[email protected]=
rg>
Subject: [Snort-users] Snort Blog: Snort 2.9.15.0 has been released!



https://blog.snort.org/2019/10/snort-29150-has-been-released.html

Snort 2.9.15.0 has been released!
Join as we welcome Snort 2.9.15.0 into the family!

As always, available from our download site on Snort.org<https://snort.org/=
downloads>, this feature contains the following release notes:

2019-10-10 - Snort 2.9.15

[*] New Additions


  *    Added new debugs to print detection, file_processing and Preproc tim=
e consumption info and verdict.
  *   Added support to detect new Korean file formats .egg and .alg in the =
file preprocessor.
  *   Added support to detect new RAR file-type in the file preprocessor.

[*] Improvements / Fix


  *   Fix to generate ALERT if TEID value is zero in GTP v1 and v2 packets.
  *   Fix to whitelist ftp data sessions when no file policy exists.
  *   Fix RTF file magic to a more generic value to prevent evasions.
  *   Added debug logs during HTTP reload
  *   Added rule SID check during validation
  *   Fix an issue where HTTP was processing non-HTTP traffic on port 443
  *   Added new debugs to print detection, file processing, and Prepro time=
 consumption info and verdicts

Any notes or feedback for us on Snort 2.9.15.0?  Please shoot us a note ove=
r on the Snort-Users mailing list<https://snort.org/community>!


Thanks!


The Snort Development Team





--_000_AM0PR08MB4996E773240DB36D0DCCDE37DA970AM0PR08MB4996eurp_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<base>
</head>
<body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; line-break:=
 after-white-space;" class=3D"">
<div dir=3D"ltr" text-align=3D"left">
<div style=3D"color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);=
 text-align: left;" dir=3D"ltr">
Does the egg info file in nghttp2 is a Korean egg?&nbsp;</div>
<div style=3D"color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);=
 text-align: left;" dir=3D"ltr">
<br>
</div>
<div style=3D"color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);=
 text-align: left;" dir=3D"ltr">
(I have download by run python and go scripts!)&nbsp;</div>
<div style=3D"color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);=
 text-align: left;" dir=3D"ltr">
<br>
</div>
<div style=3D"color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);=
 text-align: left;" dir=3D"ltr">
(the egg seems be in my android phone by watching malwarebyte works)&nbsp;<=
/div>
<div style=3D"color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);=
 text-align: left;" dir=3D"ltr">
<br>
</div>
<div style=3D"color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);=
 text-align: left;" dir=3D"ltr">
(malwarebyte doesn't hijack the egg)&nbsp;</div>
<div style=3D"color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);=
 text-align: left;" dir=3D"ltr">
<br>
</div>
<div style=3D"color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);=
 text-align: left;" dir=3D"ltr">
Thank you in advance to answer my questions because I am again in wait for =
use snort 2 9 14 1 lol,&nbsp;</div>
<div style=3D"color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);=
 text-align: left;" dir=3D"ltr">
<br>
</div>
<div style=3D"color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);=
 text-align: left;" dir=3D"ltr">
Regards.&nbsp;</div>
<div style=3D"color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);=
 text-align: left;" dir=3D"ltr">
<br>
</div>
<div style=3D"color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);=
 text-align: left;" dir=3D"ltr">
<br>
</div>
<div style=3D"color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);=
 text-align: left;" dir=3D"ltr">
Dorian rosse.&nbsp;</div>
<div id=3D"ms-outlook-mobile-signature">
<div><br>
</div>
T=E9l=E9charger <a href=3D"https://aka.ms/ghei36">Outlook pour Android</a><=
/div>
</div>
<hr style=3D"display:inline-block;width:98%" tabindex=3D"-1">
<div id=3D"divRplyFwdMsg" dir=3D"ltr"><font face=3D"Calibri, sans-serif" st=
yle=3D"font-size:11pt" color=3D"#000000"><b>From:</b> Snort-users &lt;snort=
[email protected]&gt; on behalf of Joel Esler (jesler) via Sno=
rt-users &lt;[email protected]&gt;<br>
<b>Sent:</b> Thursday, October 10, 2019 8:34:31 PM<br>
<b>To:</b> Snort &lt;[email protected]&gt;; Chang Liu via Snort-d=
evel &lt;[email protected]&gt;; [email protected] &lt;sn=
[email protected]&gt;<br>
<b>Subject:</b> [Snort-users] Snort Blog: Snort 2.9.15.0 has been released!=
</font>
<div>&nbsp;</div>
</div>
<div><base class=3D"">
<div class=3D"Apple-Mail-URLShareUserContentTopClass"><br class=3D"">
</div>
<div class=3D"Apple-Mail-URLShareWrapperClass">
<blockquote type=3D"cite" style=3D"border-left-style: none; color: inherit;=
 padding: inherit; margin: inherit;" class=3D"">
<div class=3D"">
<div class=3D"original-url"><br class=3D"">
<a href=3D"https://blog.snort.org/2019/10/snort-29150-has-been-released.htm=
l" class=3D"">https://blog.snort.org/2019/10/snort-29150-has-been-released.=
html</a><br class=3D"">
<br class=3D"">
</div>
<div id=3D"article" role=3D"article" style=3D"text-rendering: optimizeLegib=
ility; font-family: -apple-system-font; font-size: 1.2em; line-height: 1.5e=
m; margin: 0px; padding: 0px;" class=3D"system exported">
<!-- This node will contain a number of div.page. -->
<div class=3D"page" style=3D"word-wrap: break-word; max-width: 100%;">
<h1 class=3D"title" style=3D"font-size: 1.95552em; line-height: 1.2141em; m=
argin-top: 0px; margin-bottom: 0.5em; max-width: 100%;">
Snort 2.9.15.0 has been released!</h1>
Join as we welcome Snort 2.9.15.0 into the family! <br style=3D"max-width: =
100%;" class=3D"">
<br style=3D"max-width: 100%;" class=3D"">
As always, available from our <a href=3D"https://snort.org/downloads" targe=
t=3D"_blank" style=3D"color: rgb(65, 110, 210); max-width: 100%;" class=3D"=
">
download site on Snort.org</a>, this feature contains the following release=
 notes:<br style=3D"max-width: 100%;" class=3D"">
<br style=3D"max-width: 100%;" class=3D"">
2019-10-10 - Snort 2.9.15<br style=3D"max-width: 100%;" class=3D"">
<br style=3D"max-width: 100%;" class=3D"">
[*] New Additions<br style=3D"max-width: 100%;" class=3D"">
<br style=3D"max-width: 100%;" class=3D"">
<ul style=3D"max-width: 100%;" class=3D"">
<li style=3D"max-width: 100%;" class=3D"">&nbsp;Added new debugs to print d=
etection, file_processing and Preproc time consumption info and verdict.</l=
i><li style=3D"max-width: 100%;" class=3D"">Added support to detect new Kor=
ean file formats .egg and .alg in the file preprocessor.</li><li style=3D"m=
ax-width: 100%;" class=3D"">Added support to detect new RAR file-type in th=
e file preprocessor.</li></ul>
<br style=3D"max-width: 100%;" class=3D"">
[*] Improvements / Fix<br style=3D"max-width: 100%;" class=3D"">
<br style=3D"max-width: 100%;" class=3D"">
<ul style=3D"max-width: 100%;" class=3D"">
<li style=3D"max-width: 100%;" class=3D"">Fix to generate ALERT if TEID val=
ue is zero in GTP v1 and v2 packets.</li><li style=3D"max-width: 100%;" cla=
ss=3D"">Fix to whitelist ftp data sessions when no file policy exists.</li>=
<li style=3D"max-width: 100%;" class=3D"">Fix RTF file magic to a more gene=
ric value to prevent evasions.</li><li style=3D"max-width: 100%;" class=3D"=
">Added debug logs during HTTP reload</li><li style=3D"max-width: 100%;" cl=
ass=3D"">Added rule SID check during validation</li><li style=3D"max-width:=
 100%;" class=3D"">Fix an issue where HTTP was processing non-HTTP traffic =
on port 443</li><li style=3D"max-width: 100%;" class=3D"">Added new debugs =
to print detection, file processing, and Prepro time consumption info and v=
erdicts</li></ul>
<div style=3D"max-width: 100%;" class=3D"">Any notes or feedback for us on =
Snort 2.9.15.0? &nbsp;Please shoot us a note over on the
<a href=3D"https://snort.org/community" target=3D"_blank" style=3D"color: r=
gb(65, 110, 210); max-width: 100%;" class=3D"">
Snort-Users mailing list</a>!</div>
<div style=3D"max-width: 100%;" class=3D""><br class=3D"webkit-block-placeh=
older">
</div>
<p style=3D"max-width: 100%;" class=3D"">Thanks!</p>
<div style=3D"max-width: 100%;" class=3D""><br class=3D"webkit-block-placeh=
older">
</div>
<p style=3D"max-width: 100%;" class=3D"">The Snort Development Team</p>
<br style=3D"max-width: 100%; display: none;" class=3D"">
<div style=3D"max-width: 100%;" class=3D""><br class=3D"webkit-block-placeh=
older">
</div>
<div style=3D"max-width: 100%;" class=3D""><br class=3D"webkit-block-placeh=
older">
</div>
<div style=3D"max-width: 100%;" class=3D""><br class=3D"webkit-block-placeh=
older">
</div>
</div>
</div>
</div>
</blockquote>
</div>
</div>
</body>
</html>

--_000_AM0PR08MB4996E773240DB36D0DCCDE37DA970AM0PR08MB4996eurp_--

--===============6392725009028634078==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-devel

Please visit http://blog.snort.org for the latest news about Snort!

--===============6392725009028634078==--