Softpedia
 


LINUX CATEGORIES:



GLOBAL PAGES >>
NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
WEEK'S BEST
  • Linux Kernel 3.9.3 / 3....
  • LibreOffice 3.6.6 / 4.0.3
  • MPlayer 1.1.1
  • systemd 204
  • Arch Linux 2013.05.01
  • Blender 2.67
  • KDE Software Compilatio...
  • CrunchBang Linux Stable...
  • Elementary OS 0.1 / 0.2...
  • SystemRescueCd 3.6.0
  • 7-DAY TOP DOWNLOAD
    #
    Program
    Psiphon 3
    2,838 downloads
    LibreOffice 3.6.6 /
    4.0.3

    1,317 downloads
    Wine 1.4.1 / 1.5.30
    1,152 downloads
    BackTrack 5 R3
    1,048 downloads
    Red Hat Linux 9
    950 downloads
    Adobe Flash Player
    for Linux
    11.2.202.258

    935 downloads
    Linux Mint 14.1 / 15
    RC

    849 downloads
    Red Hat Enterprise
    Linux 6.4

    675 downloads
    VLC 2.0.6
    661 downloads
    Ubuntu 10.10
    632 downloads
    MOST POPULAR DISTROS
    #
    Distribution
    PCLinuxOS 2013.04
    User rating: 4.8/5
    Votes: 367
    OpenMandriva
    20130513

    User rating: 4.4/5
    Votes: 620
    Ubuntu 9.10
    User rating: 4.4/5
    Votes: 266
    Clonezilla LiveCD
    2.1.1-25 / 2.1.2-3

    User rating: 4.3/5
    Votes: 255
    BackTrack 5 R3
    User rating: 4.3/5
    Votes: 565
    Fedora 18
    User rating: 4.3/5
    Votes: 610
    openSUSE Linux 12.3
    / 13.1 Milestone 1

    User rating: 4.2/5
    Votes: 467
    Ubuntu 12.04.2 LTS
    User rating: 4.2/5
    Votes: 663
    Ubuntu 10.04.4 LTS
    User rating: 4.0/5
    Votes: 281
    Linux Mint 14.1 / 15
    RC

    User rating: 4.0/5
    Votes: 353
    Home > Linux > Security > Snort > Changelog

    Snort 2.9.4.6 - Changelog


    What's new in Snort 2.9.4.6:

    April 25th, 2013

    · Improved support for DAQ verdicts of whitelist and blacklist for 6in4 and 4in6 encapsulated traffic (similar to Teredo & GTP). See the Snort manual for configuration details.
    · Avoid changing the length of IP options in frag3 when receiving duplicate 0-offset fragments that have IP options.



    What's new in Snort 2.9.4.5:

    April 4th, 2013

    · Removed proxy information from normalized HTTP Uri to enable correct matching of patterns.
    · Update to log packets to unified2 across all alerts on stream reassembled packets.



    What's new in Snort 2.9.4.1:

    March 5th, 2013

    · Updated File processing for partial HTTP content and MIME attachments.
    · Addition of new config option max_attribute_services_per_host and improve memory usage within attribute table.
    · Handle excessive overlaps in frag3.
    · Stream API updates to return session key for a session.
    · Reduce false positives for TCP window slam events.
    · Updates to provide better encoding for TCP packets generated for respond and react.
    · Disable non-ethernet decoders by default for performance reasons. If needed, use --enable-non-ether-decoders with configure.



    What's new in Snort 2.9.4.0:

    December 4th, 2012

    New additions:
    · Consolidation of IPv6 -- now only a single build supports both IPv4 & IPv6, and removal of the IPv4 "only" code paths.
    · File API and improvements to file processing for HTTP downloads and email attachments via SMTP, POP, and IMAP to facilitate broader file support
    · Use of address space ID for tracking Frag & Stream connections when it is available with the DAQ
    · Logging of packet data that triggers PPM for post-analysis via Snort event
    · Decoding of IPv6 with PPPoE
    · Added an API call to add a service to a host in the attribute table. Remove the unused live attribute update code.

    Improvements:
    · Update to Stream5 PAF for handling gaps in the sequence numbers of packets being reassembled.
    · Selection of the Stream TCP policy based on the server rather than the destination of first packet seen by Snort
    · Allow disabling of global thresholds via a count of -1
    · Prevent blocking duplicate SYNs when using inline normalization
    · Add SSLv3 backwards compatibility support for SSLv2 ClientHello messages
    · Allow active responses to packets without data (eg, a TCP SYN)
    · Changed logic of option evaluations for shared library rules that use a custom evaluation function to match that of the builtin logic when the NOT_FLAG is used. The 'NOT' matching now happens within each of the individual rule option evaluation functions.
    · Updated SMTP preprocessor to better handle commands that have corresponding data on a subsequent line to reduce false positives. 3 commands fall into this category - X-EXPS, XEXCH50, and BDAT.
    · Improve support for encapsulated & tunneling protocols to block or fastpath a connection within the tunnel rather applying that to the whole tunnel.



    What's new in Snort 2.9.2.1:

    January 20th, 2012

    · Added new alerts for HTTP (undefined methods & HTTP 0.9 simple requests).
    · Updates to the Stream preprocessor in TCP session tracking to avoid re-queuing retransmitted data that was already flushed. Also various tweaks for PAF flushing.
    · Updates to the reputation preprocessor to handle shared memory switching.
    · Updates to the SCADA preprocessors in their handling of PAF flushing and Modbus request/response length checking. Also tweaks in alerts for reserved DNP3 functions.
    · Updates to flowbit groups to always use the group when some rules refer to a flow group while others do not refer to a group for the same flowbit.
    · Updates to GTP preprocessor to check invalid extension header length for GTPv1.
    · Updates to sfrt library, used in reputation preprocessor and target based configuration, when calculating memory allocated and support for IPv6.



    What's new in Snort 2.9.1.2:

    October 21st, 2011

    · Fixed an issue where Snort would sometimes stop processing traffic in a persistent HTTP 1.1 connection with a UTF-32 encoded response followed by a UTF-16 encoded response.



    What's new in Snort 2.8.6.1:

    September 12th, 2010

    · Snort 2.8.6.a fixes installer packages to include correct version of sensitive data preprocessor for linux and Windows
    · Eliminates false positives when using fast_pattern:only and having only one http content in the pattern matcher
    · Addresses false positives in FTP preprocessor with string format verification. 2.8.6.1 also addresses an issue with handling response codes to data transfer commands where the response code didn't contain a message




    WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

    SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM