[Snort-devel] [Snort-users] Snort 2.9.8 Now Available

Joel Esler (jesler) jesler at ...3461...
Tue Dec 1 17:14:05 EST 2015

On Dec 1, 2015, at 3:25 PM, Michael Steele <michaels at ...2826...<mailto:michaels at ...2826...>> wrote:

This is usually the case when a new Snort release is pushed and Sourcefire does not sync the new Snort release with the current rules. The latest usually works, even if the versions do not match. I believe in most cases it’s just a filename rename that happens.

Not true.  They are completely built with the new version of Snort (which reflects in the Shared Object rules.  Windows cannot use these files, which is probably why you don’t notice a difference)

However, it brings up another question; Pulledpork extracts the Snort version from the Snort install; What happens when the Snort version fails to find a version of the rules that don’t match? Not a problem for windows because Windows requires a manual switch entry.

You can override the version in the pulledpork.conf

Sourcefire has been pretty good lately when making sure when a new Snort release happens, that the rules filename changes. I have no idea what happened here, but it does cause confusion when this happens…

Sourcefire can you please sync the rules filename with the new releases when pushed to the general public…

It usually happens within a day or so of the release.  I try to time them to come out at the same time, however, other circumstances sometimes conflict (release build times, etc)

Kindest regards,

WINSNORT.com<http://winsnort.com/> Management Team Member
****************** Established ~ 2001 *******************
*          Visit Us @ http://www.winsnort.com<http://www.winsnort.com/>           *
*      ~~ FREE WinIDS Snort installation guides ~~      *
*               ~~ FREE support forums ~~               *
* Snort: Open Source Network IDS - http://www.snort.org<http://www.snort.org/> *

From: Y M [mailto:snort at ...3347...]
Sent: Tuesday, December 1, 2015 12:09 PM
To: Dr. Stephen Gantz <stephen.gantz at ...3626...<mailto:stephen.gantz at ...3626...>>
Cc: Snort Releases <snortreleases at ...835...<mailto:snortreleases at ...835...>>; snort-users at lists.sourceforge.net<mailto:snort-users at lists.sourceforge.net>; snort-devel at lists.sourceforge.net<mailto:snort-devel at lists.sourceforge.net>
Subject: Re: [Snort-users] Snort 2.9.8 Now Available


I just threw in a quick test VM and Snort seems to start up fine with the rules (including so) tarball.


--== Initialization Complete ==--

   ,,_     -*> Snort! <*-
  o"  )~   Version GRE (Build 229)
   ''''    By Martin Roesch & The Snort Team: http://www.snort.org/contact#team
           Copyright (C) 2014-2015 Cisco and/or its affiliates. All rights reserved.
           Copyright (C) 1998-2013 Sourcefire, Inc., et al.
           Using libpcap version 1.5.3
           Using PCRE version: 8.31 2012-07-06
           Using ZLIB version: 1.2.8

           Rules Engine: SF_SNORT_DETECTION_ENGINE  Version 2.4  <Build 1>
           Rules Object: protocol-snmp  Version 1.0  <Build 1>
           Rules Object: protocol-other  Version 1.0  <Build 1>


           Preprocessor Object: SF_SIP  Version 1.1  <Build 1>
           Preprocessor Object: SF_MODBUS  Version 1.1  <Build 1>

Snort successfully validated the configuration!
Snort exiting



From: Dr. Stephen Gantz <stephen.gantz at ...3626...<mailto:stephen.gantz at ...3626...>>
Sent: Tuesday, December 1, 2015 1:36 AM
To: Snort Releases; snort-devel at lists.sourceforge.net<mailto:snort-devel at lists.sourceforge.net>; snort-users at lists.sourceforge.net<mailto:snort-users at lists.sourceforge.net>
Subject: Re: [Snort-users] Snort 2.9.8 Now Available

Any issue with running rules with this release pending a 2.9.8 ruleset?

Dr. Stephen D. Gantz
Professor of Information Assurance
The Graduate School
University of Maryland University College
stephen.gantz at ...3626...<mailto:stephen.gantz at ...3626...>
-------- Original message --------
From: Snort Releases <snortreleases at ...835...<mailto:snortreleases at ...835...>>
Date: 11/30/2015 2:30 PM (GMT-05:00)
To: snort-devel at lists.sourceforge.net<mailto:snort-devel at lists.sourceforge.net>, snort-users at lists.sourceforge.net<mailto:snort-users at lists.sourceforge.net>
Subject: [Snort-users] Snort 2.9.8 Now Available

Snort 2.9.8 is now available on snort.org<http://snort.org> at

http://www.snort.org/downloads in the Snort Stable Release section.

2015-11-17 - Snort

[*] New additions

 *  SMBv2/SMBv3 support for file inspection.

 *  Port override for metadata service in IPS rules.

 *  AppID Lua detector performance profiling.

 *  Perfmon dumps stats at fixed intervals from absolute time.

 *  New preprocessor alert (120:18) to detect SSH tunneling over HTTP

 *  New config option |disable_replace| to disable replace rule option.

 *  New Stream configuration |log_asymmetric_traffic| to control logging to syslog.

 *  New shell script in tools to create simple Lua detectors for AppID.

[*] Improvements

 *  sfip_t refactored to use struct in6_addr for all ip addresses.

 *  Post-detection callback for preprocessors.

 *  AppID support for multiple server/client detectors evaluating on same flow.

 *  AppID API for DNS packets.

 *  Memory optimizations throughout.

 *  Support sending UDP active responses.

 *  Fix perfmon tracking of pruned packets.

 *  Stability improvements for AppID.

 *  Stability improvements for Stream6 preprocessor.

 *  Added improved support to block malware in FTP preprocessor.

 *  Added support to differentiate between active and passive FTP connections.

 *  Improvements done in Stream6 preprocessor to avoid having duplicate packets

    in the DAQ retry queue.

 *  Resolved an issue where reputation config incorrectly displayed 'blacklist' in

    priority field even though 'whitelist' option was configured.

 *  Added support for multiple expected sessions created per packet

 *  Active response now supports MPLS

Please submit bugs, questions, and feedback to  bugs at ...835...<mailto:tobugs at ...835...>  or the

Snort-Users mailing list.

Happy Snorting!

The Snort Release Team

Go from Idea to Many App Stores Faster with Intel(R) XDK
Give your users amazing mobile app experiences with Intel(R) XDK.
Use one codebase in this all-in-one HTML5 development environment.
Design, debug & build mobile apps & 2D/3D high-impact games for multiple OSs.
Snort-devel mailing list
Snort-devel at lists.sourceforge.net<mailto:Snort-devel at lists.sourceforge.net>

Please visit http://blog.snort.org for the latest news about Snort!

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-devel/attachments/20151201/058f345a/attachment.html>

More information about the Snort-devel mailing list