Imprvoed Wide String Detection has been added to Snort #
"Brendan Bell \(brebell\) via Snort-users" <[email protected]> Mon, 7 Apr 2025 13:01:22 +0000
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <DM6PR11MB4737155444DD12E3D6AD7544B2AA2@DM6PR11MB4737.namprd11.prod.outlook.com> |
--===============6954584539982133023==
Content-Language: en-US
Content-Type: multipart/alternative;
boundary="_000_DM6PR11MB4737155444DD12E3D6AD7544B2AA2DM6PR11MB4737namp_"
--_000_DM6PR11MB4737155444DD12E3D6AD7544B2AA2DM6PR11MB4737namp_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable
Hello All,
The team has added new modifiers for the "content=94 option to simplify det=
ection against multi-byte character strings to Snort 3.6.2.0
You can find the full details here:
https://blog.snort.org/
Snort Blog<https://blog.snort.org/>
We are announcing the end of life for Talos rules in the following versions=
of Snort 2: Snort 2.9.8.3; Snort 2.9.13.0; Snort 2.9.8.3 Rules: This rule =
set is no longer available. Snort 2.9.13.0 Rules: We will no longer produce=
Talos rules for these versions of Snort on or around July 1, 2024. We enco=
urage our open-source users to upgrade to the latest version of Snort 3 ava=
ilable here: Snort ...
blog.snort.org
Brendan
--_000_DM6PR11MB4737155444DD12E3D6AD7544B2AA2DM6PR11MB4737namp_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable
<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
Hello All,<br>
<br>
The team has added new modifiers for the "content=94 option to simplif=
y detection against multi-byte character strings to Snort 3.6.2.0</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
You can find the full details here:</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
<a href=3D"https://blog.snort.org/" id=3D"LPlnk">https://blog.snort.org/</a=
></div>
<div class=3D"_Entity _EType_OWALinkPreview _EId_OWALinkPreview _EReadonly_=
1">
<div id=3D"LPBorder_GTaHR0cHM6Ly9ibG9nLnNub3J0Lm9yZy8." class=3D"LPBorder38=
4091" style=3D"width: 100%; margin-top: 16px; margin-bottom: 16px; position=
: relative; max-width: 800px; min-width: 424px;">
<table id=3D"LPContainer384091" role=3D"presentation" style=3D"padding: 12p=
x 36px 12px 12px; width: 100%; border-width: 1px; border-style: solid; bord=
er-color: rgb(200, 200, 200); border-radius: 2px;">
<tbody>
<tr valign=3D"top" style=3D"border-spacing: 0px;">
<td style=3D"width: 100%;">
<div id=3D"LPTitle384091" style=3D"font-size: 21px; font-weight: 300; margi=
n-right: 8px; font-family: wf_segoe-ui_light, "Segoe UI Light", &=
quot;Segoe WP Light", "Segoe UI", "Segoe WP", Taho=
ma, Arial, sans-serif; margin-bottom: 12px;">
<a target=3D"_blank" id=3D"LPUrlAnchor384091" href=3D"https://blog.snort.or=
g/" style=3D"text-decoration: none; color: var(--themePrimary);">Snort Blog=
</a></div>
<div id=3D"LPDescription384091" style=3D"font-size: 14px; max-height: 100px=
; color: rgb(102, 102, 102); font-family: wf_segoe-ui_normal, "Segoe U=
I", "Segoe WP", Tahoma, Arial, sans-serif; margin-bottom: 12=
px; margin-right: 8px; overflow: hidden;">
We are announcing the end of life for Talos rules in the following versions=
of Snort 2: Snort 2.9.8.3; Snort 2.9.13.0; Snort 2.9.8.3 Rules: This rule =
set is no longer available. Snort 2.9.13.0 Rules: We will no longer produce=
Talos rules for these versions
of Snort on or around July 1, 2024. We encourage our open-source users to =
upgrade to the latest version of Snort 3 available here: Snort ...</div>
<div id=3D"LPMetadata384091" style=3D"font-size: 14px; font-weight: 400; co=
lor: rgb(166, 166, 166); font-family: wf_segoe-ui_normal, "Segoe UI&qu=
ot;, "Segoe WP", Tahoma, Arial, sans-serif;">
blog.snort.org</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
Brendan</div>
<div class=3D"elementToProof" style=3D"font-family: Aptos, Aptos_EmbeddedFo=
nt, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; c=
olor: rgb(0, 0, 0);">
<br>
</div>
</body>
</html>
--_000_DM6PR11MB4737155444DD12E3D6AD7544B2AA2DM6PR11MB4737namp_--
--===============6954584539982133023==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users
To unsubscribe, send an email to:
[email protected]
Please visit http://blog.snort.org to stay current on all the latest Snort news!
Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
--===============6954584539982133023==--