Snort mailing list archives

Snort 2.9.3 Now Available


From: Snort Releases <snortreleases () snort org>
Date: Wed, 18 Jul 2012 13:26:32 -0400

Snort 2.9.3 is now available on snort.org, at
http://www.snort.org/snort-downloads/ in the Latest Development
Release section.

2.9.0 RC & later packages are signed with a new PGP key
(that is signed with the previous key).

Snort 2.9.3 introduces the following new capabilities:

[*] New additions
  * Updates to flowbit rule option to allow for OR and AND
    of individual bits within a single rule, and allow flowbits
    to be used in multiple groups.  See README.flowbits and
    the Snort manual for details.

  * Dynamic output plugin architecture to provide an API that
    developers can write their own output mechanisms to log alert
    and packet data from Snort.  Some output plugins have been
    removed as a result of this to be maintained by their
    respective authors.

  * Update to dcerpc2 preprocessor for improved accuracy and
    handling of different OSs for SMB processing.  See README.dcerpc2
    and the Snort manual for details.

  * Updates to reputation preprocessor for handling of whitlelist
    and trustlists and zone information.  See README.reputation
    and the Snort manual for details.

  * Updates to the packet decoders to support pflog v4.

[*] Improvements
  * Updates to http_inspect client PAF handling and server flow_depth
    handling.

  * Logging updates to the smtp preprocessor.

  * Update to return error messages through the control socket.

  * Updates to the processing of email attachments for better
    handling of non-encoded attachments, and improved memory
    management for attachment processing.

  * Improvements in HTTP Inspect for better performance with gzip
    decompression.  Also improvements for handling simple responses,
    encoded query strings, transfer encoding and chunk encoding
    processing.

  * Fix logging of multiple unified2 alerts with reassembled packets.

  * Compiler warning cleanup across multiple platforms.

  * Added 116:458 and 116:459 to cover fragmentation issues.

  * Added detailed documentation of unified2 logging configuration and
    logging.

  * Removed --enable-decoder-preprocessor-rules configure option and
    hardened preprocessor and decoder rule event code.  To enable old
    behavior such that specific preprocessor and decoder rules don't
    have to be explicity added to snort.conf, add "config
    autogenerate_preprocessor_decoder_rules" to your snort.conf.

  * Fixed SMTP mempool allocation for significant memory savings.  Also
    tweaked memory required per stream5 session tracker.

  * Force exact versioning match of running dynamic engine and dynamic
    engine used to build SO rules.  This will cause Snort to generate
    an error and exit if .so rules are used from an older version.

  * User can now query reputation pp for routing table and management
    information.

Please see the Release Notes and ChangeLog for more details.

Please submit bugs, questions, and feedback to bugs () snort org.

Happy Snorting!
The Snort Release Team


------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-devel mailing list
Snort-devel () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-devel

Please visit http://blog.snort.org for the latest news about Snort!


Current thread: