8dd2d2ad1d
IMPORTANT: This version fixes remotely exploitable heap overflow in the stream4 preprocessor module. Advisory: http://www.coresecurity.com/common/showdoc.php?idx=313&idxseccion=10 Changes: 2.0.0: ====== - Enhanced high-performance detection engine - Stateful Pattern Matching - New detection keywords: byte_test & byte_jump - The Snort code base has undergone an external third party professional security audit funded by Sourcefire (http://www.sourcefire.com) - Many new and updated rules - snort.conf has been updated - Enhancements to self preservation mechanisms in stream4 and frag2 - State tracking fixes in stream4 - New HTTP flow analyzer - Enhanced protocol decoding (TCP options, 802.1q, etc) - Enhanced protocol anomaly detection (IP, TCP, UDP, ICMP, RPC, HTTP, etc) - Enhanced flexresp mode for real-time TCP session sniping - Better chroot()'ing - Tagging system updated - Several million bugs addressed.... - Updated FAQ (thanks to Erek Adams and Dragos Ruiu) Snort 2.0 can be downloaded at http://www.snort.org/dl/snort-2.0.0.tar.gz. Binary versions of the codebase will be built over the next several days and made available at here. 2.0.rc4: ======== - byte_jump/byte_test don't force relative content options - byte_jump/byte_test absolute offsets work - Better FIN handling in Stream4 2.0.rc3: ======== - A low memory usage detection method (enabled via "config detection: search-method lowmem") - Moved the default unix socket location to LOGDIR 2.0.rc2: ======== - syslog should work on win32 and unix - major tagging updates - new UDP decoding alerts - snort.conf updates 2.0.rc1: ======== - Higher performance (due to a new pattern matcher and rebuilt detection engine) - Better decoders - Enhanced stream reassembly and defragmentation - Tons of bug fixes - Updated rules - Updated snort.conf - New detection keywords (byte_test, byte_jump, distance, within) & stateful pattern matching - New HTTP flow analyzer - Enhanced anomaly detection (HTTP, RPC, TCP, IP, etc) - Better self preservation in stateful subsystems - Xrefs fixed - Flexresp works faster and more effectively - Better chroot()'ing - Fixed 802.1q decoding - Better async state handling - New alerting option: -A cmg!!
78 lines
2.3 KiB
Text
78 lines
2.3 KiB
Text
@comment $NetBSD: PLIST,v 1.9 2003/04/16 06:37:19 salo Exp $
|
|
bin/snort
|
|
etc/rc.d/snort
|
|
man/man8/snort.8
|
|
share/doc/snort/AUTHORS
|
|
share/doc/snort/BUGS
|
|
share/doc/snort/CREDITS
|
|
share/doc/snort/FAQ
|
|
share/doc/snort/INSTALL
|
|
share/doc/snort/NEWS
|
|
share/doc/snort/README
|
|
share/doc/snort/README.FLEXRESP
|
|
share/doc/snort/README.PLUGINS
|
|
share/doc/snort/README.csv
|
|
share/doc/snort/README.database
|
|
share/doc/snort/RULES.todo
|
|
share/doc/snort/SnortUsersManual.pdf
|
|
share/doc/snort/TODO
|
|
share/doc/snort/USAGE
|
|
share/doc/snort/snortman.tex
|
|
share/examples/snort/classification.config
|
|
share/examples/snort/reference.config
|
|
share/examples/snort/snort.conf.default
|
|
share/snort/rules/attack-responses.rules
|
|
share/snort/rules/backdoor.rules
|
|
share/snort/rules/bad-traffic.rules
|
|
share/snort/rules/chat.rules
|
|
share/snort/rules/ddos.rules
|
|
share/snort/rules/deleted.rules
|
|
share/snort/rules/dns.rules
|
|
share/snort/rules/dos.rules
|
|
share/snort/rules/experimental.rules
|
|
share/snort/rules/exploit.rules
|
|
share/snort/rules/finger.rules
|
|
share/snort/rules/ftp.rules
|
|
share/snort/rules/gen-msg.map
|
|
share/snort/rules/icmp-info.rules
|
|
share/snort/rules/icmp.rules
|
|
share/snort/rules/imap.rules
|
|
share/snort/rules/info.rules
|
|
share/snort/rules/local.rules
|
|
share/snort/rules/misc.rules
|
|
share/snort/rules/multimedia.rules
|
|
share/snort/rules/mysql.rules
|
|
share/snort/rules/netbios.rules
|
|
share/snort/rules/nntp.rules
|
|
share/snort/rules/oracle.rules
|
|
share/snort/rules/other-ids.rules
|
|
share/snort/rules/p2p.rules
|
|
share/snort/rules/policy.rules
|
|
share/snort/rules/pop2.rules
|
|
share/snort/rules/pop3.rules
|
|
share/snort/rules/porn.rules
|
|
share/snort/rules/rpc.rules
|
|
share/snort/rules/rservices.rules
|
|
share/snort/rules/scan.rules
|
|
share/snort/rules/shellcode.rules
|
|
share/snort/rules/sid
|
|
share/snort/rules/sid-msg.map
|
|
share/snort/rules/smtp.rules
|
|
share/snort/rules/snmp.rules
|
|
share/snort/rules/sql.rules
|
|
share/snort/rules/telnet.rules
|
|
share/snort/rules/tftp.rules
|
|
share/snort/rules/virus.rules
|
|
share/snort/rules/web-attacks.rules
|
|
share/snort/rules/web-cgi.rules
|
|
share/snort/rules/web-client.rules
|
|
share/snort/rules/web-coldfusion.rules
|
|
share/snort/rules/web-frontpage.rules
|
|
share/snort/rules/web-iis.rules
|
|
share/snort/rules/web-misc.rules
|
|
share/snort/rules/web-php.rules
|
|
share/snort/rules/x11.rules
|
|
@dirrm share/snort/rules
|
|
@dirrm share/snort
|
|
@dirrm share/examples/snort
|
|
@dirrm share/doc/snort
|