[Snort-sigs] Sourcefire VRT Certified Rules Update

Sourcefire VRT research at ...435...
Fri Jul 28 17:59:05 EDT 2006


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Sourcefire VRT Certified Rules Update

Synopsis:
The Sourcefire VRT has added multiple rules to detect the use of
Spyware and potentially unwanted technology on a network.


Details:
As a result of continuing research in the field of Spyware and
potentially unwanted technology, the Sourcefire VRT has added multiple
rules to the Spyware and Backdoor rule sets.

Each rule is also accompanied by detailed documentation for each
Spyware, trojan and potentially unwanted software to assist in
determining the likelihood of infection and has relevant links to
information regarding their removal.

This rule pack also contains a module for the detection of the Japanese
peer-to-peer application "Winny".

This module is identified with gid 3 and sid 7019.

For instructions on how to use this module, refer to the Snort manual
section regarding "Shared Object Rules".

A complete list of new and modified rules is located at

http://www.snort.org/rules/docs/ruleset_changelogs/v26/changes-2006-07-28.html
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (Darwin)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFEyoipMpm0ve0NhMcRAt8hAJ46CAzBAeVoK0FRTGSH+dQQkd3qIQCgiQrA
so4IJjPR/lQivsVN2XaFYEw=
=5rOM
-----END PGP SIGNATURE-----




More information about the Snort-sigs mailing list