Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-sigs] Sourcefire VRT Certified Rules Update |
|---|---|
| Date: | Fri, 27 Jan 2006 16:37:41 -0500 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
Sourcefire VRT Certified Rules Update
Synopsis: The Sourcefire VRT has added rules and improved detection capabilities as a result of ongoing research into vulnerabilities and in response to feedback regarding rule performance in certain situations.
Details: The Sourcefire VRT has made extensive changes to the rule set in order to improve detection and reduce false positive events.
The VRT have switched to a new build system for the VRT Certified Rules. This new system uses all the same code the VRT uses to build the Sourcefire product rule packs. The VRT have done a couple weeks worth of testing to make sure this system works as expected, but with all systems there are sometimes bugs. Please report any problems to bugs@snort.org or research@sourcefire.com
Additionally this new merge system has fixed an issue with rules not being moved into deleted.rules correctly. The changelog now shows that a number of rules have now been correctly moved to deleted.rules. These rules are no longer necessary for the operation of the system.
The VRT would also like to thank Jason Haar, Jeff Kell, and Russell Fulton for their help in tracking down several false positive conditions.
Please continue to submit false positive reports, these detailed reports with packet captures prove very useful in improving the quality of the Snort rule set.
New rules: See snort.org for a complete changelog http://www.snort.org/rules/docs/ruleset_changelogs/v24/changes-2006-01-27.html -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.0 (Darwin) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
iD8DBQFD2pKlMpm0ve0NhMcRAqglAJ4l/ldwQkHPMBv/MVuykgeQCJXCWgCgo21G qtLM5LMPQeWzkaz3OEfLQsU= =Zi9i -----END PGP SIGNATURE-----
------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Do you grep through log files for problems? Stop! Download the new AJAX search engine that makes searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! http://sel.as-us.falkag.net/sel?cmd=lnk&kid=103432&bid=230486&dat=121642 _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-sigs] Bleedingsnort.com Daily Update, bleeding |
|---|---|
| Next by Date: | [Snort-sigs] Bleedingsnort.com Daily Update, bleeding |
| Previous by Thread: | [Snort-sigs] Sourcefire VRT Certified Rules Update, Sourcefire VRT |
| Next by Thread: | [Snort-sigs] new rule for detect WEB-PHP AppServ main.php appserv_root param access, rmkml |
| Indexes: | [Date] [Thread] [Top] [All Lists] |