[Snort-devel] RE: [Snort-users] Snort 1.8 released

Mayers, Philip J p.mayers at ...489...
Tue Jul 10 03:54:22 EDT 2001

Did Dragos get his fixes for the float/int arithmetic in the defragger in?


| Phil Mayers, Network Support     | 
| Centre for Computing Services    | 
| Imperial College                 | 

-----Original Message-----
From: Martin Roesch [mailto:roesch at ...402...]
Sent: 10 July 2001 04:52
To: snort-announce; snort-dev; snort-users; focus-ids; Bugtraq;
ids at ...508...; lwn at ...509...
Subject: [Snort-users] Snort 1.8 released

In a dress-rehearsal for the impending arrival of his baby later this
month, Martin Roesch has finally squeezed out Snort version 1.8.  

Snort 1.8 is available at:


Version 1.8 incorporates a number of changes and new features, including
some of the following:

New things:
* Stateful inspection and TCP stream reassembly module
* High performance IP defragmenter module
* High performance unified binary output module
* Tagging allows hosts that trip events to be tracked/logged
* Unique Rule IDs for every Snort rule and new printout code make
machine processing of Snort output much easier
* Enhanced cross-reference data with alerts
* Classifications and Priorities added to rules language
* ARP spoofing detection
* "IP" is now a supported protocol type in the Snort rules language
* Back Orifice detection plugin
* Telnet normalization plugin defeats telnet and ftp evasion techniques
* RPC normalization plugin defeats RPC fragmentation evasion techniques
* CSV format output plugin
* "uricontent" keyword allows HTTP traffic to be searched for data in
the URI field only
* 802.1Q decoder support
* linux_sll decoder support
* tcp window detection plugin
* same IP detection plugin
* -T switch to test Snort config before running
* -y switch to add year to timestamps
* -I switch to print interface name in Snort alerts
* -G switch for backawards compatability with old cross-reference lookup
* -L switch for naming the -b binary output file
* -k switch to tune checksum verification routines
* -z switch to run the rules engine in stateful mode (with stream4)

Additionally, there were a ton of fixes and development in the rest of
the code, and the spo_xml and spo_database routines have matured over
the past 6 months as well.

The full Changelog can be seen at http://www.snort.org/Changelog.htm for
the changes since 1.7 was released last January.

I'd like to thank Fyodor Yarochkin, Brian Caswell, Phil Wood, Jed
Pickel, Roman Danyliw, Dragos Ruiu, Jim Forster, Max Vision, the Silicon
Defense gang, Chris Cramer, Eugene Tsyrklevich, Chris Green, HD Moore,
DrSuse, Jeff Nathan and the whole gang on #snort for helping to make it

Happy Snorting!


Martin Roesch
roesch at ...402...
http://www.sourcefire.com - http://www.snort.org

Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:

More information about the Snort-devel mailing list