<?xml version="1.0" encoding="UTF-8"?>
<rss version="0.91">
<channel>
<title>Snort.org - Snort saved my bacon!</title>
<link>http://www.snort.org/pub-bin/snortnews.cgi</link>
<language>en</language>
<description>News articles from Snort.org</description>
	<item>
		<title>Snort Community Rules Update</title>
		<link>http://www.snort.org/pub-bin/snortnews.cgi#169</link>
		<description>NOTE: This is the first Community rulepack which uses community-sid-msg.map, instead of the previous sid-msg.map. This change is being made in response to requests from numerous users of the Community rules, in order to make management of multiple rulesets simpler. If you have any questions about this new naming scheme, please e-mail research at sourcefire.com, and we will address them as best we can.&amp;lt;div&amp;gt;&amp;nbsp;&amp;lt;/div&amp;gt;&amp;lt;div&amp;gt;This message is to announce the availability of an update for the Sourcefire community rule set, which can be downloaded free of cost or registration from http://www.snort.org/pub-bin/downloads.cgi. &amp;lt;/div&amp;gt;&amp;lt;div&amp;gt;&amp;nbsp;&amp;lt;/div&amp;gt;&amp;lt;div&amp;gt;New rules in this release are identified as SIDs 100000196-100000198. These rules detect a directory traversal attack against the Qualcomm Worldmail server, ICMP messages with invalid codes, and scans performed by an NTP-based OS fingerprinting tool. &amp;lt;/div&amp;gt;&amp;lt;div&amp;gt;&amp;nbsp;&amp;lt;/div&amp;gt;&amp;lt;div&amp;gt;Sourcefire would like to thank rmkml for submitting these rules. As a reminder, anyone who wishes to submit rules may do so at http://www.snort.org/reg-bin/rulesubmit.cgi. &amp;lt;/div&amp;gt;&amp;lt;div&amp;gt;&amp;nbsp;&amp;lt;/div&amp;gt;&amp;lt;div&amp;gt;A list of new rules and their SIDs follows. &amp;lt;/div&amp;gt;&amp;lt;div&amp;gt;100000196  COMMUNITY IMAP Qualcomm WorldMail SELECT dot dot attempt &amp;lt;/div&amp;gt;&amp;lt;div&amp;gt;100000197  COMMUNITY ICMP undefined code &amp;lt;/div&amp;gt;&amp;lt;div&amp;gt;100000198  COMMUNITY MISC Ntp fingerprint detect&amp;lt;/div&amp;gt;&amp;lt;div&amp;gt;&amp;nbsp;&amp;lt;/div&amp;gt;&amp;lt;div&amp;gt;Alex Kirk &amp;lt;/div&amp;gt;&amp;lt;div&amp;gt;Community Rules Maintainer &amp;lt;/div&amp;gt;&amp;lt;div&amp;gt;Sourcefire, Inc.&amp;nbsp;&amp;lt;/div&amp;gt;</description>
		<author>Alex Kirk (Sourcefire)</author>
		<date>December 07, 2005 22:34:21</date>
	</item>
	<item>
		<title>New Security Website details Wireless Vulnerabilities</title>
		<link>http://www.snort.org/pub-bin/snortnews.cgi#168</link>
		<description>&amp;lt;p&amp;gt;Announced today, a new Security website has been launched focused on Wireless Vulernabilities.  &amp;lt;a href="http://www.wirelessVE.org"&amp;gt;http://www.wirelessVE.org &amp;lt;/a&amp;gt; is focused on access to Wireless networks and the vulnerabilities related to wireless networks.   &amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;One of the board members actually happens to be Andrew Lockhart, who, many of our readers may know, is the author of Snort-Wireless, an open source project adding wireless intrusion detection to Snort. &amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;Check it out!&amp;lt;/p&amp;gt;</description>
		<author>Joel Esler (Sourcefire)</author>
		<date>December 05, 2005 14:49:31</date>
	</item>
	<item>
		<title>Seasons Greetings from Sourcefire - 50% Annual Subscriptions Through December 31st!</title>
		<link>http://www.snort.org/pub-bin/snortnews.cgi#167</link>
		<description>&amp;lt;p&amp;gt;As a thank you for your continued support, Sourcefire would like to wish the Snort community a happy holiday season. We are pleased to extend a 50% discount for annual subscriptions to the Sourcefire VRT Certified Rules. &amp;lt;/p&amp;gt; &amp;lt;p&amp;gt;Promotion Details: Use the code &amp;quot;50ink&amp;quot; to receive 50% off an annual subscription to the Sourcefire VRT Certified Rules. This offer is not valid with any other promotion and is only available through December 31st, 2005. &amp;lt;/p&amp;gt;  &amp;lt;p&amp;gt;More information on Sourcefire subscriptions can be found &amp;lt;a href="http://www.snort.org/rules/why_subscribe.html" target="_blank"&amp;gt;here&amp;lt;/a&amp;gt;. &amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;&amp;lt;a target="_self" href="https://www.snort.org/reg-bin/subscribe.cgi"&amp;gt;Purchase now&amp;lt;/a&amp;gt; Questions? &amp;lt;a target="_self" href="mailto:snort-sub@sourcefire.com"&amp;gt;E-mail Us&amp;lt;/a&amp;gt;.&amp;lt;/p&amp;gt;</description>
		<author>Jennifer Talcott (Sourcefire)</author>
		<date>December 05, 2005 11:51:08</date>
	</item>
	<item>
		<title>mwcollect v3.0.1 Release</title>
		<link>http://www.snort.org/pub-bin/snortnews.cgi#166</link>
		<description>From Georg 'oxff' Wicherski, mwcollect Head Developer...&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt; The Honeynet Project is proud to announce the release of mwcollect v3.0.1 which contains some minor bug fixes, two new shellcode parsers and most importantly support for the Prelude IDS Aggregator.&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt; mwcollect is a UNIX daemon dedicated to collecting in-the-wild malware spreading using known exploits. Download it &amp;lt;a target="_blank" href="http://download.mwcollect.org/"&amp;gt;here&amp;lt;/a&amp;gt; as usual, see the included README file for installation instructions.&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt; There is no changelog for this update, review the Subversion Log available under &amp;lt;br /&amp;gt; &amp;lt;a target="_blank" href="http://www.mwcollect.org/log/mwcollect3/tags/mwcollect-3.0.1"&amp;gt;http://www.mwcollect.org/log/mwcollect3/tags/mwcollect-3.0.1&amp;lt;/a&amp;gt; for details.&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt; Big thanks to the &amp;lt;a target="_blank" href="http://www.mwcollect.org/"&amp;gt;mwcollect&amp;lt;/a&amp;gt; project.</description>
		<author>Jennifer Steffens (Sourcefire)</author>
		<date>December 04, 2005 19:58:17</date>
	</item>
	<item>
		<title>Final Reminder: Kansas City Snort User Group Meeting</title>
		<link>http://www.snort.org/pub-bin/snortnews.cgi#164</link>
		<description>I just wanted to give everyone a final reminder that our first meeting will be held Tuesday December 6th. Information is on our web site at &amp;lt;a href="http://www.kcsnort.org"&amp;gt;http://www.kcsnort.org&amp;lt;/a&amp;gt;.   Please &amp;lt;a href="http://www.snort.org/registrations/rsvp.html"&amp;gt; RSVP&amp;lt;/a&amp;gt; if you want to attend.   </description>
		<author>Russ Starr</author>
		<date>December 04, 2005 14:44:41</date>
	</item>
	<item>
		<title>Evading NIDS, revisited</title>
		<link>http://www.snort.org/pub-bin/snortnews.cgi#165</link>
		<description>An interesting article at SecurityFocus discusses a couple of IDS evasion techniques from years past and encourages veryone to use frag3properly...Read the full article &amp;lt;a target="_blank" href="http://www.securityfocus.com/infocus/1852"&amp;gt;here&amp;lt;/a&amp;gt;. &amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt; For more information, read the &amp;lt;a target="_blank" href="http://www.snort.org/reg/docs/target_based_frag.pdf"&amp;gt;Frag3 Development Paper&amp;lt;/a&amp;gt; by Judy Novak, Sourcefire VRT.&amp;lt;br /&amp;gt;</description>
		<author>Nigel Houghton (Sourcefire)</author>
		<date>December 04, 2005 14:43:40</date>
	</item>
	<item>
		<title>Case Study Shows Interesting Use of Snort</title>
		<link>http://www.snort.org/pub-bin/snortnews.cgi#163</link>
		<description>Snort was named in a recent TechRepublic Case study: &amp;quot;How much does unwanted Internet traffic really cost an organization?&amp;quot; Jonathan Yarden's details how he went about gathering this information, and shows how unwanted traffic affects his organization's bottom line. This is an interesting use for Snort but ultimately Yarden states &amp;quot;...like many other Internet problems, the best solution to dealing with junk Internet traffic is to do nothing at all.&amp;quot;&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt; Read the full case study &amp;lt;a href="http://techrepublic.com.com/5100-1009-5967393.html#" target="_blank"&amp;gt;here&amp;lt;/a&amp;gt;.</description>
		<author>Jennifer Steffens (Sourcefire)</author>
		<date>December 03, 2005 18:14:26</date>
	</item>
	<item>
		<title>Come meet the Snort team at LISA!</title>
		<link>http://www.snort.org/pub-bin/snortnews.cgi#161</link>
		<description>&amp;lt;p&amp;gt;Come meet members of the Snort team at the LISA (Large Installation Systems Administration) Conference Expo on December 7th and 8th in San Diego! We will be located in booth #38 in the conference&amp;rsquo;s .org pavilion. The Sguil project will be joining us in our booth as well, so come on out to San Diego for some sun and great Snort conversation!&amp;lt;/p&amp;gt; &amp;lt;p&amp;gt;The Snort team will also be hosting a Birds of a Feather session on December 6th from 7-8 pm in the Ascot room. Nigel Houghton from the Sourcefire VRT will be discussing all sorts of fun things you can do with Snort rules.&amp;lt;/p&amp;gt; &amp;lt;p&amp;gt;Register &amp;lt;a href="http://www.usenix.org/events/lisa05/registration/"&amp;gt;here&amp;lt;/a&amp;gt; for the conference!  For more information on the event, visit &amp;lt;a href="http://www.usenix.org/events/lisa05/"&amp;gt;http://www.usenix.org/events/lisa05/&amp;lt;/a&amp;gt;. &amp;lt;/p&amp;gt;</description>
		<author>Jennifer Talcott (Sourcefire)</author>
		<date>December 01, 2005 15:32:06</date>
	</item>
	<item>
		<title>Upcoming Gartner Open Source Summit</title>
		<link>http://www.snort.org/pub-bin/snortnews.cgi#160</link>
		<description>&amp;lt;p&amp;gt;Next week, Gartner will be hosting a new 2-day conference focusing on Open Source technology. The event will take place from December 7-9 at the JW Marriott Grande Lakes in Orlando, and will discuss the challenges that open source software introduces into modern mainstream IT organizations, offering suggestions on how to most effectively manage open source as an integral element of long term IT strategies.&amp;lt;/p&amp;gt; &amp;lt;p&amp;gt;&amp;lt;a href="https://www.gartner.com/EvReg/evRegister?EvCd=APN15"&amp;gt;Register now&amp;lt;/a&amp;gt; for this event.&amp;lt;/p&amp;gt; &amp;lt;p&amp;gt;Further information about this conference can be found &amp;lt;a href="http://www.gartner.com/2_events/conferences/os1_section.jsp"&amp;gt;here&amp;lt;/a&amp;gt;. &amp;lt;/p&amp;gt;</description>
		<author>Jennifer Talcott (Sourcefire)</author>
		<date>December 01, 2005 15:30:07</date>
	</item>
	<item>
		<title>Upcoming Irvine Underground Interview with Snort Lead Developer</title>
		<link>http://www.snort.org/pub-bin/snortnews.cgi#159</link>
		<description>&amp;lt;p&amp;gt;The Irvine Underground will be hosting a video conference interview with Snort lead developer, Marc Norton. All are welcome to attend. If you can not make it to the meeting but would like to have a question answered by Marc, please send your question to daman at irvineunderground.&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt; Details:&amp;lt;br /&amp;gt;  When:  December 9th 2005&amp;lt;br /&amp;gt;  Where: 14141 Jeffrey Road&amp;lt;br /&amp;gt;              Irvine, CA. 92620&amp;lt;/p&amp;gt;&amp;lt;p&amp;gt;For more details about the Irvine Underground, visit their &amp;lt;a target="_blank" href="http://www.irvineunderground.org/index.php"&amp;gt;web site&amp;lt;/a&amp;gt;. &amp;lt;/p&amp;gt;</description>
		<author>Jennifer Steffens (Sourcefire)</author>
		<date>November 29, 2005 15:20:44</date>
	</item>
</channel>
</rss>
