[Snort-sigs] Sourcefire VRT Certified Rules Update

Sourcefire VRT research at ...435...
Fri Jan 27 13:38:02 EST 2006

Hash: SHA1

Sourcefire VRT Certified Rules Update

The Sourcefire VRT has added rules and improved detection capabilities
as a result of ongoing research into vulnerabilities and in response to
feedback regarding rule performance in certain situations.

The Sourcefire VRT has made extensive changes to the rule set in order
to improve detection and reduce false positive events.

The VRT have switched to a new build system for the VRT Certified Rules.
This new system uses all the same code the VRT uses to build the Sourcefire
product rule packs. The VRT have done a couple weeks worth of testing to
make sure this system works as expected, but with all systems there are
sometimes bugs. Please report any problems to bugs at ...95... or
research at ...435...

Additionally this new merge system has fixed an issue with rules not
being moved into deleted.rules correctly.  The changelog now shows that a
number of rules have now been correctly moved to deleted.rules. These rules
are no longer necessary for the operation of the system.

The VRT would also like to thank Jason Haar, Jeff Kell, and Russell Fulton
for their help in tracking down several false positive conditions.

Please continue to submit false positive reports, these detailed reports
with packet captures prove very useful in improving the quality of the
rule set.

New rules:
See snort.org for a complete changelog
Version: GnuPG v1.4.0 (Darwin)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org


More information about the Snort-sigs mailing list