1. Dynamic rules now have a Suricata optimized version. You’ll find these in a <name>.suricata.rules file in the suricata tarballs. Since suricata does IP matching much differently we don’t have to split into tcp/udp rules, and don’t need to check flags. These will be VERY efficient in Suricata.
2. We now have a snort-edge link to the current ruleset. This will help with some automated downloaders.
3. We had a few instances where depth/within were used when the other should have been. Still works, but Snort 2.9.0.3 now enforces this. We’re glad it does now, and cleaned up the rules that were violating style there.
2012081 – ET CURRENT_EVENTS Possible Bozvanovna Zeus Campaign Config File URL (current_events.rules)
2012082 – ET CURRENT_EVENTS Possible Bozvanovna Zeus Campaign Binary File URL (current_events.rules)
2012083 – ET CURRENT_EVENTS Possible Bozvanovna Zeus Campaign SSL Certificate (current_events.rules)
By Kevin Ross. Should be interesting, but high load. These are in but disabled by default.
I won’t comment on the changes here, most are just performance, depth/within changes, etc. Removing those that are just for updating to 2.9 http syntax for brevity.
2180 – GPL P2P BitTorrent announce request (p2p.rules)
3158 – GPL NETBIOS DCERPC CoGetInstanceFromFile little endian overflow attempt (netbios.rules)
2000332 – ET P2P ed2k request part (p2p.rules)
2000333 – ET P2P ed2k file request answer (p2p.rules)
2000334 – ET P2P BitTorrent peer sync (p2p.rules)
2000335 – ET P2P Overnet (Edonkey) Server Announce (p2p.rules)
2000340 – ET P2P Kaaza Media desktop p2pnetworking.exe Activity (p2p.rules)
2000357 – ET P2P BitTorrent Traffic (p2p.rules)
2001296 – ET P2P eDonkey File Status (p2p.rules)
2001297 – ET P2P eDonkey File Status Request (p2p.rules)
2001298 – ET P2P eDonkey Server Status Request (p2p.rules)
2001299 – ET P2P eDonkey Server Status (p2p.rules)
2001664 – ET P2P Gnutella Connect (p2p.rules)
2001809 – ET P2P Limewire P2P UDP Traffic (p2p.rules)
2002673 – ET P2P MS Foldershare Login Detected (p2p.rules)
2002681 – ET WEB_SPECIFIC_APPS Mambo Exploit (web_specific_apps.rules)
2002761 – ET P2P Gnutella TCP Ultrapeer Traffic (p2p.rules)
2002814 – ET P2P Direct Connect Traffic (client-server) (p2p.rules)
2002853 – ET DOS FreeBSD NFS RPC Kernel Panic (dos.rules)
2003323 – ET P2P Edonkey Client to Server Hello (p2p.rules)
2003331 – ET WEB_SPECIFIC_APPS PHP Generic membreManager.php remote file include (web_specific_apps.rules)
2003437 – ET P2P Ares over UDP (p2p.rules)
2003464 – ET ATTACK_RESPONSE Unusual FTP Server Banner (warFTPd) (attack_response.rules)
2003465 – ET ATTACK_RESPONSE Unusual FTP Server Banner (freeFTPd) (attack_response.rules)
2007801 – ET P2P Gnutella TCP Traffic (p2p.rules)
2008579 – ET SCAN Sipp SIP Stress Test Detected (scan.rules)
2008582 – ET P2P BitTorrent DHT find_node request (p2p.rules)
2008583 – ET P2P BitTorrent DHT nodes reply (p2p.rules)
2008584 – ET P2P BitTorrent DHT get_peers request (p2p.rules)
2008595 – ET P2P SoulSeek P2P Server Connection (p2p.rules)
2008611 – ET P2P SoulSeek P2P Login Response (p2p.rules)
2008641 – ET SCAN sipscan probe (scan.rules)
2009535 – ET POLICY Telnet to HP JetDirect Printer With No Password Set (policy.rules)
2009536 – ET POLICY External FTP Connection TO Local HP JetDirect Printer (policy.rules)
2009706 – ET POLICY Nessus Vulnerability Scanner Plugins Update (policy.rules)
2009966 – ET P2P KuGoo P2P Connection (p2p.rules)
2009967 – ET P2P eMule KAD Network Connection Request (p2p.rules)
2009968 – ET P2P eMule KAD Network Connection Request(2) (p2p.rules)
2009969 – ET P2P eMule KAD Network Firewalled Request (p2p.rules)
2009970 – ET P2P eMule Kademlia Hello Request (p2p.rules)
2009972 – ET P2P eMule KAD Network Server Status Request (p2p.rules)
2010139 – ET P2P Vuze BT Connection (p2p.rules)
2010140 – ET P2P Vuze BT UDP Connection (p2p.rules)
2010141 – ET P2P Vuze BT UDP Connection (2) (p2p.rules)
2010142 – ET P2P Vuze BT UDP Connection (3) (p2p.rules)
2010143 – ET P2P Vuze BT UDP Connection (4) (p2p.rules)
2010144 – ET P2P Vuze BT UDP Connection (5) (p2p.rules)
2800094 – ETPRO EXPLOIT Microsoft Windows Active Directory Crafted LDAP Request Buffer Overflow (exploit.rules)
2800095 – ETPRO EXPLOIT Microsoft Windows Active Directory Crafted LDAP Request Buffer Overflow (exploit.rules)
2800444 – ETPRO DOS IBM DB2 Database Server CONNECT Request Denial of Service (dos.rules)
2801174 – ETPRO WEB_CLIENT Microsoft Publisher pubconv.dll Size Value Memory Corruption (web_client.rules)
[///] Modified inactive rules: [///]
1699 – GPL P2P Fastrack kazaa/morpheus traffic (p2p.rules)
2000330 – ET P2P ed2k connection to server (p2p.rules)
2009973 – ET P2P eMule KAD Network Send Username (p2p.rules)
[---] Disabled and modified rules: [---]
2800929 – ETPRO SMTP Novell GroupWise Internet Agent Content-Type Buffer Overflow (smtp.rules)
[---] Disabled rules: [---]
2800936 – ETPRO FTP ProFTPD FTP Server TELNET_IAC Stack Buffer Overflow (ftp.rules)
[---] Removed rules: [---]
2008596 – ET SCAN Brute Force Exploit Detector HTTP Buffer Overflow Detection (scan.rules)
2801175 – ETPRO TROJAN Possible Worm.Win32.Qvod.a URL Request (trojan.rules)