CVS log for snort/etc/gen-msg.map

(logo)

Help

(back) Up to [cvs] / snort / etc

Request diff between arbitrary revisions


Default branch: MAIN
Bookmark a link to: HEAD / (download)

Revision 1.53 / (view) - annotate - [select for diffs] , Wed May 6 22:28:06 2009 UTC (8 weeks, 2 days ago) by jjordan
Branch: MAIN
CVS Tags: SNORT_v2_8_5-BETA, SNORT_2_8_5, HEAD
Changes since 1.52: +12 -0 lines
Diff to previous 1.52
Updating open-source CVS for Snort 2.8.5 beta release.

Revision 1.52 / (view) - annotate - [select for diffs] , Mon Mar 9 17:03:21 2009 UTC (3 months, 3 weeks ago) by ssturges
Branch: MAIN
Changes since 1.51: +1 -0 lines
Diff to previous 1.51
* Add stream5 option to restrict the number of consecutive
  small TCP segments inserted for reassembly without seeing an ACK.
  Generate alert (gid:129,sid:12) when that limit is exceeded.
  Allow overriding of this configuration on a port basis via an
  ignore_ports option.

Revision 1.49.2.2 / (view) - annotate - [select for diffs] , Mon Mar 9 17:03:21 2009 UTC (3 months, 3 weeks ago) by ssturges
Branch: SNORT_2_8_4
CVS Tags: SNORT_v2_8_4_1, SNORT_v2_8_4
Changes since 1.49.2.1: +1 -0 lines
Diff to previous 1.49.2.1 to branch point 1.49 to next main 1.50
* Add stream5 option to restrict the number of consecutive
  small TCP segments inserted for reassembly without seeing an ACK.
  Generate alert (gid:129,sid:12) when that limit is exceeded.
  Allow overriding of this configuration on a port basis via an
  ignore_ports option.

Revision 1.49.2.1 / (view) - annotate - [select for diffs] , Mon Jan 26 21:49:53 2009 UTC (5 months ago) by twease
Branch: SNORT_2_8_4
CVS Tags: SNORT_v2_8_4-RC1
Changes since 1.49: +12 -11 lines
Diff to previous 1.49
Thought I was checking into 2_8_4 and HEAD but 2.8.4 was actually head.  Anyway, not going through the business again.  See HEAD checkins for comments

Revision 1.51 / (view) - annotate - [select for diffs] , Mon Jan 26 16:10:38 2009 UTC (5 months ago) by twease
Branch: MAIN
Changes since 1.50: +0 -0 lines
Diff to previous 1.50
Added dcerpc2 preprocessor documentation.

Revision 1.50 / (view) - annotate - [select for diffs] , Mon Jan 26 16:10:37 2009 UTC (5 months ago) by twease
Branch: MAIN
Changes since 1.49: +12 -11 lines
Diff to previous 1.49
Added dcerpc2 preprocessor documentation.

Revision 1.49 / (view) - annotate - [select for diffs] , Fri Oct 3 20:55:44 2008 UTC (8 months, 4 weeks ago) by twease
Branch: MAIN
CVS Tags: SNORT_v2_8_4-BETA
Branch point for: SNORT_2_8_4
Changes since 1.48: +43 -0 lines
Diff to previous 1.48
* Addition of dcerpc2 preprocessor. Addition of new rule options supported by preprocessor.

Revision 1.48 / (view) - annotate - [select for diffs] , Mon Sep 15 14:41:27 2008 UTC (9 months, 2 weeks ago) by twease
Branch: MAIN
Changes since 1.47: +2 -0 lines
Diff to previous 1.47
Update rule latency thresholding.

Revision 1.46.2.2 / (view) - annotate - [select for diffs] , Mon Sep 15 14:41:27 2008 UTC (9 months, 2 weeks ago) by twease
Branch: SNORT_2_8_3
CVS Tags: SNORT_v2_8_3_2, SNORT_v2_8_3_1
Changes since 1.46.2.1: +2 -0 lines
Diff to previous 1.46.2.1 to branch point 1.46 to next main 1.47
Update rule latency thresholding.

Revision 1.46.2.1 / (view) - annotate - [select for diffs] , Fri Jul 11 21:00:53 2008 UTC (11 months, 3 weeks ago) by twease
Branch: SNORT_2_8_3
CVS Tags: SNORT_v2_8_3-RC1, SNORT_v2_8_3
Changes since 1.46: +1 -1 lines
Diff to previous 1.46
Updates

Revision 1.47 / (view) - annotate - [select for diffs] , Fri Jul 11 21:00:23 2008 UTC (11 months, 3 weeks ago) by twease
Branch: MAIN
Changes since 1.46: +1 -1 lines
Diff to previous 1.46
Updates

Revision 1.46 / (view) - annotate - [select for diffs] , Mon Jun 16 18:17:44 2008 UTC (12 months, 2 weeks ago) by twease
Branch: MAIN
CVS Tags: SNORT_v2_8_3-BETA
Branch point for: SNORT_2_8_3
Changes since 1.45: +9 -9 lines
Diff to previous 1.45
* Fixed alert message for IP datagram being greater than captured length.

Revision 1.45 / (view) - annotate - [select for diffs] , Wed Jun 4 19:04:42 2008 UTC (12 months, 4 weeks ago) by twease
Branch: MAIN
Changes since 1.44: +7 -1 lines
Diff to previous 1.44
Add IPv6 decoder events.

Revision 1.44.4.1 / (view) - annotate - [select for diffs] , Wed Jun 4 19:03:09 2008 UTC (12 months, 4 weeks ago) by twease
Branch: SNORT_2_8_2
CVS Tags: SNORT_v2_8_2_2, SNORT_v2_8_2_1
Changes since 1.44: +7 -1 lines
Diff to previous 1.44 to next main 1.45
Add IPv6 decoder events.

Revision 1.44 / (view) - annotate - [select for diffs] , Wed Mar 12 20:15:45 2008 UTC (15 months, 3 weeks ago) by twease
Branch: MAIN
CVS Tags: SNORT_v2_8_2-RC, SNORT_v2_8_2-BETA, SNORT_v2_8_2
Branch point for: SNORT_2_8_2
Changes since 1.43: +5 -4 lines
Diff to previous 1.43
Update frag3 to remove enforcement of ttl_limit. Add preprocessor alert for min_ttl anomaly.
Fixed some typos.  Thanks to rmkml for pointing this out.

Revision 1.41.2.3 / (view) - annotate - [select for diffs] , Wed Mar 12 20:15:45 2008 UTC (15 months, 3 weeks ago) by twease
Branch: SNORT_2_8_1
CVS Tags: SNORT_v2_8_1
Changes since 1.41.2.2: +4 -3 lines
Diff to previous 1.41.2.2 to branch point 1.41 to next main 1.42
Update frag3 to remove enforcement of ttl_limit. Add preprocessor alert for min_ttl anomaly.
Fixed some typos.  Thanks to rmkml for pointing this out.

Revision 1.43 / (view) - annotate - [select for diffs] , Mon Jan 28 17:29:44 2008 UTC (17 months ago) by twease
Branch: MAIN
Changes since 1.42: +2 -1 lines
Diff to previous 1.42
Added IP in IP encapsulation support for both IPv4 and IPv6.
Update Stream5 to alert on data without TCP flags when non-linux policy.  Thanks to Chris Eagle, Naval Postgraduate School, for bringing this to our attention.

Revision 1.41.2.2 / (view) - annotate - [select for diffs] , Mon Jan 28 17:29:44 2008 UTC (17 months ago) by twease
Branch: SNORT_2_8_1
CVS Tags: SNORT_v2_8_1-RC, SNORT_v2_8_1-BETA
Changes since 1.41.2.1: +2 -1 lines
Diff to previous 1.41.2.1 to branch point 1.41
Added IP in IP encapsulation support for both IPv4 and IPv6.
Update Stream5 to alert on data without TCP flags when non-linux policy.  Thanks to Chris Eagle, Naval Postgraduate School, for bringing this to our attention.

Revision 1.42 / (view) - annotate - [select for diffs] , Mon Dec 10 19:15:34 2007 UTC (18 months, 3 weeks ago) by twease
Branch: MAIN
Changes since 1.41: +5 -1 lines
Diff to previous 1.41
Update to include GRE alerts

Revision 1.41.2.1 / (view) - annotate - [select for diffs] , Mon Dec 10 19:15:34 2007 UTC (18 months, 3 weeks ago) by twease
Branch: SNORT_2_8_1
Changes since 1.41: +5 -1 lines
Diff to previous 1.41
Update to include GRE alerts

Revision 1.41 / (view) - annotate - [select for diffs] , Mon Nov 12 23:02:12 2007 UTC (19 months, 3 weeks ago) by twease
Branch: MAIN
Branch point for: SNORT_2_8_1
Changes since 1.40: +4 -1 lines
Diff to previous 1.40
* Added overly long http header detection.

Revision 1.39.2.1 / (view) - annotate - [select for diffs] , Mon Aug 20 17:44:00 2007 UTC (22 months, 2 weeks ago) by ssturges
Branch: SNORT_2_8_0
CVS Tags: SNORT_v2_8_0_2, SNORT_v2_8_0_1, SNORT_v2_8_0-RC1, SNORT_v2_8_0-BETA, SNORT_v2_8_0
Changes since 1.39: +3 -6 lines
Diff to previous 1.39 to next main 1.40
* 2.8.0 beta prep.

Revision 1.40 / (view) - annotate - [select for diffs] , Mon Aug 20 17:43:59 2007 UTC (22 months, 2 weeks ago) by ssturges
Branch: MAIN
Changes since 1.39: +3 -6 lines
Diff to previous 1.39
* 2.8.0 beta prep.

Revision 1.39 / (view) - annotate - [select for diffs] , Thu May 10 15:05:25 2007 UTC (2 years, 1 month ago) by ssturges
Branch: MAIN
Branch point for: SNORT_2_8_0
Changes since 1.38: +1 -1 lines
Diff to previous 1.38
* Update gen-msg.map

Revision 1.36.2.3 / (view) - annotate - [select for diffs] , Thu May 10 15:05:25 2007 UTC (2 years, 1 month ago) by ssturges
Branch: SNORT_2_7_0
CVS Tags: SNORT_v2_7_0
Changes since 1.36.2.2: +1 -1 lines
Diff to previous 1.36.2.2 to branch point 1.36 to next main 1.37
* Update gen-msg.map

Revision 1.36.2.2 / (view) - annotate - [select for diffs] , Mon Apr 30 17:31:23 2007 UTC (2 years, 2 months ago) by ssturges
Branch: SNORT_2_7_0
Changes since 1.36.2.1: +3 -2 lines
Diff to previous 1.36.2.1 to branch point 1.36
* Handle TCP window scale option that is > 14.  Added decoder alert for
  this and adjust the scale per RFC 1323 in Stream5.

Revision 1.38 / (view) - annotate - [select for diffs] , Mon Apr 30 17:31:22 2007 UTC (2 years, 2 months ago) by ssturges
Branch: MAIN
Changes since 1.37: +3 -2 lines
Diff to previous 1.37
* Handle TCP window scale option that is > 14.  Added decoder alert for
  this and adjust the scale per RFC 1323 in Stream5.

Revision 1.36.2.1 / (view) - annotate - [select for diffs] , Wed Mar 28 15:07:51 2007 UTC (2 years, 3 months ago) by ssturges
Branch: SNORT_2_7_0
CVS Tags: SNORT_v2_7_0-BETA2
Changes since 1.36: +6 -0 lines
Diff to previous 1.36
* Added ability for Snort to track fragmented ICMPv6 to check for the
  remote BSD exploit (Bugtraq ID 22901, CVE-2007-1365).

Revision 1.37 / (view) - annotate - [select for diffs] , Wed Mar 28 15:07:50 2007 UTC (2 years, 3 months ago) by ssturges
Branch: MAIN
Changes since 1.36: +6 -0 lines
Diff to previous 1.36
* Added ability for Snort to track fragmented ICMPv6 to check for the
  remote BSD exploit (Bugtraq ID 22901, CVE-2007-1365).

Revision 1.28.2.8 / (view) - annotate - [select for diffs] , Thu Mar 15 18:46:21 2007 UTC (2 years, 3 months ago) by ssturges
Branch: SNORT_2_6_1
CVS Tags: SNORT_v2_6_1_5, SNORT_v2_6_1_4
Changes since 1.28.2.7: +7 -1 lines
Diff to previous 1.28.2.7 to branch point 1.28 to next main 1.29
* Added ability for Snort to track fragmented ICMPv6 to check for the
  remote BSD exploit (Bugtraq ID 22901, CVE-2007-1365).

Revision 1.36 / (view) - annotate - [select for diffs] , Wed Jan 17 13:58:20 2007 UTC (2 years, 5 months ago) by ssturges
Branch: MAIN
CVS Tags: SNORT_v2_7_0-BETA1
Branch point for: SNORT_2_7_0
Changes since 1.35: +2 -1 lines
Diff to previous 1.35
* Add Stream5 alert.

Revision 1.35 / (view) - annotate - [select for diffs] , Thu Nov 16 15:25:41 2006 UTC (2 years, 7 months ago) by amullican
Branch: MAIN
Changes since 1.34: +2 -1 lines
Diff to previous 1.34
Add DCE/RPC alert.

Revision 1.28.2.7 / (view) - annotate - [select for diffs] , Thu Nov 16 15:25:20 2006 UTC (2 years, 7 months ago) by amullican
Branch: SNORT_2_6_1
CVS Tags: SNORT_v2_6_1_3, SNORT_v2_6_1_2, SNORT_v2_6_1_1, SNORT_v2_6_1
Changes since 1.28.2.6: +2 -1 lines
Diff to previous 1.28.2.6 to branch point 1.28
Add DCE/RPC alert.

Revision 1.34 / (view) - annotate - [select for diffs] , Thu Oct 12 20:28:14 2006 UTC (2 years, 8 months ago) by ssturges
Branch: MAIN
Changes since 1.33: +2 -0 lines
Diff to previous 1.33
* Added additional TCP length checking and UDP length checking and new
  decode alerts for anomalous lengths.

Revision 1.28.2.6 / (view) - annotate - [select for diffs] , Thu Oct 12 20:28:13 2006 UTC (2 years, 8 months ago) by ssturges
Branch: SNORT_2_6_1
CVS Tags: SNORT_v2_6_1-RC1
Changes since 1.28.2.5: +2 -0 lines
Diff to previous 1.28.2.5 to branch point 1.28
* Added additional TCP length checking and UDP length checking and new
  decode alerts for anomalous lengths.

Revision 1.33 / (view) - annotate - [select for diffs] , Mon Oct 9 20:08:15 2006 UTC (2 years, 8 months ago) by ssturges
Branch: MAIN
Changes since 1.32: +1 -0 lines
Diff to previous 1.32
* Fix Stream4 to handle duplicate SYN packets by purging existing
  packets queued for reassembly after the seq of the SYN.  Also,
  properly handle retransmitted data that is overlapping the current
  packet and when trimmed overlapping the next packet.

Revision 1.28.2.5 / (view) - annotate - [select for diffs] , Mon Oct 9 20:08:14 2006 UTC (2 years, 8 months ago) by ssturges
Branch: SNORT_2_6_1
Changes since 1.28.2.4: +1 -0 lines
Diff to previous 1.28.2.4 to branch point 1.28
* Fix Stream4 to handle duplicate SYN packets by purging existing
  packets queued for reassembly after the seq of the SYN.  Also,
  properly handle retransmitted data that is overlapping the current
  packet and when trimmed overlapping the next packet.

Revision 1.32 / (view) - annotate - [select for diffs] , Mon Sep 18 13:36:23 2006 UTC (2 years, 9 months ago) by ssturges
Branch: MAIN
Changes since 1.31: +2 -0 lines
Diff to previous 1.31
* Added support to decode GRE encapsulated traffic.  Only IP as transport
  protocol is supported and only one layer of encapsulation will be
  decoded - packets with multiple GRE headers will be discarded.
* Added support for communcation with an Aruba Networks wireless
  mobility authentication/access control system.

Revision 1.28.2.4 / (view) - annotate - [select for diffs] , Mon Sep 18 13:36:21 2006 UTC (2 years, 9 months ago) by ssturges
Branch: SNORT_2_6_1
CVS Tags: SNORT_v2_6_1-BETA2
Changes since 1.28.2.3: +2 -0 lines
Diff to previous 1.28.2.3 to branch point 1.28
* Added support to decode GRE encapsulated traffic.  Only IP as transport
  protocol is supported and only one layer of encapsulation will be
  decoded - packets with multiple GRE headers will be discarded.
* Added support for communcation with an Aruba Networks wireless
  mobility authentication/access control system.

Revision 1.31 / (view) - annotate - [select for diffs] , Wed Sep 13 14:38:45 2006 UTC (2 years, 9 months ago) by ssturges
Branch: MAIN
Changes since 1.30: +6 -0 lines
Diff to previous 1.30
* Added code to print original datagram for all ICMP error types if
  alerted on.
* Fix to print original datagram on alert if original datagram was ICMP.
* Added additional decoder alerts for ICMP error types.
* Removed fragtracking of ICMP original datagram - it never made sense
  since only an ICMP response to the first frag is ever returned.
* Fixed issue where data and size pointers were not set correctly for
  ICMP error types.

Revision 1.28.2.3 / (view) - annotate - [select for diffs] , Wed Sep 13 14:38:44 2006 UTC (2 years, 9 months ago) by ssturges
Branch: SNORT_2_6_1
Changes since 1.28.2.2: +6 -0 lines
Diff to previous 1.28.2.2 to branch point 1.28
* Added code to print original datagram for all ICMP error types if
  alerted on.
* Fix to print original datagram on alert if original datagram was ICMP.
* Added additional decoder alerts for ICMP error types.
* Removed fragtracking of ICMP original datagram - it never made sense
  since only an ICMP response to the first frag is ever returned.
* Fixed issue where data and size pointers were not set correctly for
  ICMP error types.

Revision 1.30 / (view) - annotate - [select for diffs] , Fri Sep 1 14:52:10 2006 UTC (2 years, 10 months ago) by ssturges
Branch: MAIN
Changes since 1.29: +1 -1 lines
Diff to previous 1.29
* Cleanup some code, DNS Rdata client overflow is not microsoft
  specific (also vuln on some linux via UDP).

Revision 1.28.2.2 / (view) - annotate - [select for diffs] , Fri Sep 1 14:52:09 2006 UTC (2 years, 10 months ago) by ssturges
Branch: SNORT_2_6_1
Changes since 1.28.2.1: +1 -1 lines
Diff to previous 1.28.2.1 to branch point 1.28
* Cleanup some code, DNS Rdata client overflow is not microsoft
  specific (also vuln on some linux via UDP).

Revision 1.25.2.3 / (view) - annotate - [select for diffs] , Fri Sep 1 14:52:09 2006 UTC (2 years, 10 months ago) by ssturges
Branch: SNORT_2_6
CVS Tags: SNORT_v2_6_0_2
Changes since 1.25.2.2: +1 -2 lines
Diff to previous 1.25.2.2 to branch point 1.25 to next main 1.26
* Cleanup some code, DNS Rdata client overflow is not microsoft
  specific (also vuln on some linux via UDP).

Revision 1.28.2.1 / (view) - annotate - [select for diffs] , Wed Aug 30 14:18:51 2006 UTC (2 years, 10 months ago) by ssturges
Branch: SNORT_2_6_1
Changes since 1.28: +3 -0 lines
Diff to previous 1.28
* Add a dynamic preprocessor to decode and analyze DNS responses
  over TCP and UDP.  The TCP portion is stateful and requires
  stream is enabled.

Revision 1.29 / (view) - annotate - [select for diffs] , Wed Aug 30 14:18:50 2006 UTC (2 years, 10 months ago) by ssturges
Branch: MAIN
Changes since 1.28: +3 -0 lines
Diff to previous 1.28
* Add a dynamic preprocessor to decode and analyze DNS responses
  over TCP and UDP.  The TCP portion is stateful and requires
  stream is enabled.

Revision 1.25.2.2 / (view) - annotate - [select for diffs] , Tue Aug 29 16:59:39 2006 UTC (2 years, 10 months ago) by ssturges
Branch: SNORT_2_6
Changes since 1.25.2.1: +4 -0 lines
Diff to previous 1.25.2.1 to branch point 1.25
* Add a dynamic preprocessor to decode and analyze DNS responses
  over TCP and UDP.  The TCP portion is stateful and requires
  stream is enabled.

Revision 1.28 / (view) - annotate - [select for diffs] , Mon Aug 14 18:34:59 2006 UTC (2 years, 10 months ago) by ssturges
Branch: MAIN
CVS Tags: SNORT_v2_6_1-BETA
Branch point for: SNORT_2_6_1
Changes since 1.27: +7 -0 lines
Diff to previous 1.27
* New target-based Stream module.  Moved flow & flowbits to
  be part of Stream API.

Revision 1.27 / (view) - annotate - [select for diffs] , Mon Aug 14 16:04:16 2006 UTC (2 years, 10 months ago) by ssturges
Branch: MAIN
Changes since 1.26: +9 -0 lines
Diff to previous 1.26
* New target-based Stream module.  Moved flow & flowbits to
  be part of Stream API.

Revision 1.16.2.2.2.5 / (view) - annotate - [select for diffs] , Wed May 24 16:14:33 2006 UTC (3 years, 1 month ago) by ssturges
Branch: SNORT_2_4
CVS Tags: SNORT_v2_4_5
Changes since 1.16.2.2.2.4: +1 -0 lines
Diff to previous 1.16.2.2.2.4 to branch point 1.16.2.2 to next main 1.16.2.3
* Fix potential evasion in Stream4.

Revision 1.26 / (view) - annotate - [select for diffs] , Wed May 24 16:08:13 2006 UTC (3 years, 1 month ago) by ssturges
Branch: MAIN
Changes since 1.25: +1 -0 lines
Diff to previous 1.25
* Fix potential evasion in Stream4.

Revision 1.25.2.1 / (view) - annotate - [select for diffs] , Wed May 24 16:08:10 2006 UTC (3 years, 1 month ago) by ssturges
Branch: SNORT_2_6
CVS Tags: SNORT_v2_6_0_1, SNORT_v2_6_0
Changes since 1.25: +1 -0 lines
Diff to previous 1.25
* Fix potential evasion in Stream4.

Revision 1.25 / (view) - annotate - [select for diffs] , Thu Jan 19 16:51:56 2006 UTC (3 years, 5 months ago) by ssturges
Branch: MAIN
CVS Tags: SNORT_v2_6_0-RC2, SNORT_v2_6_0-RC1
Branch point for: SNORT_2_6
Changes since 1.24: +18 -2 lines
Diff to previous 1.24
* Added generator IDs for new preprocessors.

Revision 1.24 / (view) - annotate - [select for diffs] , Mon Oct 17 17:12:37 2005 UTC (3 years, 8 months ago) by mwatchinski
Branch: MAIN
Changes since 1.23: +2 -2 lines
Diff to previous 1.23
Update gen-msg.map

Revision 1.16.2.2.2.4 / (view) - annotate - [select for diffs] , Sun Oct 16 18:55:28 2005 UTC (3 years, 8 months ago) by ssturges
Branch: SNORT_2_4
CVS Tags: SNORT_v2_4_3
Changes since 1.16.2.2.2.3: +2 -1 lines
Diff to previous 1.16.2.2.2.3 to branch point 1.16.2.2
* Fix buffer overflow in Back Orifice preprocessor

Revision 1.23 / (view) - annotate - [select for diffs] , Sun Oct 16 18:55:25 2005 UTC (3 years, 8 months ago) by ssturges
Branch: MAIN
Changes since 1.22: +2 -1 lines
Diff to previous 1.22
* Fix buffer overflow in Back Orifice preprocessor

Revision 1.22 / (view) - annotate - [select for diffs] , Wed Sep 14 19:12:31 2005 UTC (3 years, 9 months ago) by amullican
Branch: MAIN
Changes since 1.21: +2 -1 lines
Diff to previous 1.21
Add new RPC alert for zero-length fragment.

Revision 1.16.2.2.2.3 / (view) - annotate - [select for diffs] , Wed Sep 14 19:09:09 2005 UTC (3 years, 9 months ago) by amullican
Branch: SNORT_2_4
CVS Tags: SNORT_v2_4_2, SNORT_v2_4_1
Changes since 1.16.2.2.2.2: +2 -1 lines
Diff to previous 1.16.2.2.2.2 to branch point 1.16.2.2
Add new alert to RPC on zero-length fragment.

Revision 1.16.2.2.2.2 / (view) - annotate - [select for diffs] , Fri Apr 22 22:11:53 2005 UTC (4 years, 2 months ago) by jhewlett
Branch: SNORT_2_4
CVS Tags: SNORT_v2_4_0
Changes since 1.16.2.2.2.1: +2 -1 lines
Diff to previous 1.16.2.2.2.1 to branch point 1.16.2.2
* Added xlink2state mini-preprocessor to catch MS Exchange buffer
X-Link2State data overflow (amullican).

Revision 1.21 / (view) - annotate - [select for diffs] , Fri Apr 22 22:11:25 2005 UTC (4 years, 2 months ago) by jhewlett
Branch: MAIN
Changes since 1.20: +2 -1 lines
Diff to previous 1.20
* Added xlink2state mini-preprocessor to catch MS Exchange buffer
X-Link2State data overflow (amullican).

Revision 1.16.2.3 / (view) - annotate - [select for diffs] , Fri Apr 22 19:03:55 2005 UTC (4 years, 2 months ago) by jhewlett
Branch: SNORT_2_3
CVS Tags: STABLE, SNORT_v2_3_3
Changes since 1.16.2.2: +2 -0 lines
Diff to previous 1.16.2.2 to branch point 1.16 to next main 1.17
* Added xlink2state mini-preprocessor to catch MS Exchange buffer
  X-Link2State data overflow (amullican).
* Bump to 2.3.3.

Revision 1.20 / (view) - annotate - [select for diffs] , Fri Mar 18 19:48:14 2005 UTC (4 years, 3 months ago) by jhewlett
Branch: MAIN
Changes since 1.19: +17 -10 lines
Diff to previous 1.19
* Updates/Fixes to Frag3 IP reassembler (thanks ssturges):
  1) Push first fragmented UDP packet through, but do not inspect
  other fragmented packets (until rebuilt).
  2) Printing of Configuration Info
  3) Code readability
* Removal of comment parsing code added for 2.3.1.
* Added support for detection of Lookback & Same src/dest attacks in
  the packet decoder. This obsoletes sids 527, 528. Thanks Marc
  Norton for the feature.
* Added FTP Bounce detection Plugin. Thanks Steve Sturges.
* Increased Flowbits hash table size. Thanks Marc Norton.
* Performance improvement in pattern matcher from Marc Norton.
* Eliminate duplicate alerts on Rebuilt Streams/IP reassembled packets.
* Patch from Andy Mullican and Steve Sturges.
* Added handling of midstream sessions in portscan preprocessors.
  Thanks Andy Mullican.
* Stream4 fixes - Handle PAWS, NULL TCP Flags in established session,
  limit overlaps in established session, update ACK when server sends
  RST. Performance changes for cleaning up session cache. Thanks
  Steve Sturges and Andy Mullican for the patches.
* Added uri_tab_delimiter option to HttpInspect. Patch from Andy
  Mullican.
* Updates to PerfMon to handle multiple CPUs properly. Thanks Steve Sturges.
* Fixed telnet decoder bug when ignoring Sub-negotiation end command.
  Thanks Steve Sturges.

Revision 1.16.2.2.2.1 / (view) - annotate - [select for diffs] , Wed Mar 16 21:52:16 2005 UTC (4 years, 3 months ago) by jhewlett
Branch: SNORT_2_4
Changes since 1.16.2.2: +17 -2 lines
Diff to previous 1.16.2.2
* Snort 2.4 CVS branch, build 1.
* Added support for detection of Lookback & Same src/dest attacks in
  the packet decoder. This obsoletes sids 527, 528. Thanks Marc
  Norton for the feature.
* Added global ignore ports feature. Thanks Andy Mullican for the feature. Usage:
* Provide ability for 3rd party code to take action when Snort
  indicates a packet should be dropped. Thanks Marc Norton.
* Added FTP Bounce detection Plugin. Thanks Steve Sturges for this feature.
* Performance improvement in pattern matcher from Marc Norton.
* Eliminate duplicate alerts on rebuilt streams/IP reassembled packets.
  Thanks Andy Mullican and Steve Sturges.
* Added better determination of direction for Back Orifice packets.
  Thanks Andy Mullican.
* Added handling of midstream sessions in portscan preprocessors.
  Thanks Andy Mullican.
* Stream4 fixes - Handle PAWS, NULL TCP Flags in established session,
  limit overlaps in established session, update ACK when server sends
  RST. Performance changes for cleaning up session cache. Thanks
  Steve Sturges and Andy Mullican for the patches.
* Added uri_tab_delimiter option to HttpInspect. Thanks Andy
  Mullican.
* Added categories (wire, ip defrag, tcp rebuilt, app layer) to
  PerfMon.  Also added atexitonly option to dump stats for entire life
  of snort. Thanks Steve Sturges.
* Fixed telnet decoder bug when ignoring Sub-negotiation end command.
  Thanks Steve Sturges.

Revision 1.19 / (view) - annotate - [select for diffs] , Wed Jan 26 19:12:05 2005 UTC (4 years, 5 months ago) by bmc
Branch: MAIN
Changes since 1.18: +9 -1 lines
Diff to previous 1.18
add frag3 alerts to gen-msg.map

Revision 1.16.2.2 / (view) - annotate - [select for diffs] , Tue Sep 28 15:06:50 2004 UTC (4 years, 9 months ago) by jhewlett
Branch: SNORT_2_3
CVS Tags: SNORT_v2_3_2, SNORT_v2_3_1, SNORT_v2_3_0-RC2, SNORT_v2_3_0-RC1, SNORT_v2_3_0
Branch point for: SNORT_2_4
Changes since 1.16.2.1: +2 -2 lines
Diff to previous 1.16.2.1 to branch point 1.16
* Change version 2.3->2.3.0
* verstuff now mods snort ver in snort.conf. /wave bmc
* Fixed 116:109 in gen-msg.map

Revision 1.18 / (view) - annotate - [select for diffs] , Tue Sep 28 15:06:21 2004 UTC (4 years, 9 months ago) by jhewlett
Branch: MAIN
Changes since 1.17: +2 -2 lines
Diff to previous 1.17
* Change version 2.3->2.3.0
* verstuff now mods snort ver in snort.conf. /wave bmc
* Fixed 116:109 in gen-msg.map

Revision 1.16.2.1 / (view) - annotate - [select for diffs] , Tue Sep 14 21:09:56 2004 UTC (4 years, 9 months ago) by bmc
Branch: SNORT_2_3
Changes since 1.16: +2 -2 lines
Diff to previous 1.16
* more better

Revision 1.13.4.1 / (view) - annotate - [select for diffs] , Tue Sep 14 21:09:08 2004 UTC (4 years, 9 months ago) by bmc
Branch: SNORT_2_2
Changes since 1.13: +2 -2 lines
Diff to previous 1.13 to next main 1.14
* more better

Revision 1.17 / (view) - annotate - [select for diffs] , Tue Sep 14 21:08:10 2004 UTC (4 years, 9 months ago) by bmc
Branch: MAIN
Changes since 1.16: +2 -2 lines
Diff to previous 1.16
* more better

Revision 1.16 / (view) - annotate - [select for diffs] , Mon Sep 13 17:44:49 2004 UTC (4 years, 9 months ago) by jhewlett
Branch: MAIN
Branch point for: SNORT_2_3
Changes since 1.15: +28 -0 lines
Diff to previous 1.15
* sync 2.3 code

Revision 1.15 / (view) - annotate - [select for diffs] , Thu Aug 12 18:43:24 2004 UTC (4 years, 10 months ago) by jhewlett
Branch: MAIN
Changes since 1.14: +1 -2 lines
Diff to previous 1.14
* sync fixes from stable into head.

Revision 1.14 / (view) - annotate - [select for diffs] , Wed Jun 30 17:45:30 2004 UTC (5 years ago) by bmc
Branch: MAIN
Changes since 1.13: +2 -1 lines
Diff to previous 1.13
* add the http inspect "WEBROOT DIRECTORY TRAVERSAL" alert

Revision 1.13 / (view) - annotate - [select for diffs] , Mon Oct 20 15:03:03 2003 UTC (5 years, 8 months ago) by chrisgreen
Branch: MAIN
CVS Tags: version-2-1-0, cmg, SNORT_v2_2_0-RC1, SNORT_v2_2_0, SNORT_v2_1_3-RC1, SNORT_v2_1_3, SNORT_v2_1_2, SNORT_v2_1_1-RC1, SNORT_v2_1_1, SNORT_v2_1_0, SNORT_2_1
Branch point for: SNORT_2_2
Changes since 1.12: +23 -1 lines
Diff to previous 1.12
* Major add/commit of 2.1 feature set...

  Will do a tag and then remove the "moved" files

Revision 1.12 / (view) - annotate - [select for diffs] , Thu Jun 5 14:26:46 2003 UTC (6 years, 1 month ago) by chrisgreen
Branch: MAIN
CVS Tags: version-2-0-6, version-2-0-5, version-2-0-2, version-2-0-1, SNORT_2_0
Changes since 1.11: +2 -2 lines
Diff to previous 1.11
* correcting gen-msg.map from ARB

Revision 1.11 / (view) - annotate - [select for diffs] , Mon Mar 31 13:12:53 2003 UTC (6 years, 3 months ago) by chrisgreen
Branch: MAIN
CVS Tags: version-2-0-0
Changes since 1.10: +3 -1 lines
Diff to previous 1.10
* misc andrewb fixes

Revision 1.10 / (view) - annotate - [select for diffs] , Fri Mar 28 14:23:11 2003 UTC (6 years, 3 months ago) by chrisgreen
Branch: MAIN
Changes since 1.9: +3 -3 lines
Diff to previous 1.9
* removed extra quotes from gen-msg.map

Revision 1.9 / (view) - annotate - [select for diffs] , Wed Mar 26 21:59:17 2003 UTC (6 years, 3 months ago) by chrisgreen
Branch: MAIN
Changes since 1.8: +14 -2 lines
Diff to previous 1.8
* rc1 -- dear god that took a long time.
  see snort-users for annouce
  changelog for details

Revision 1.8 / (view) - annotate - [select for diffs] , Mon Mar 17 18:39:42 2003 UTC (6 years, 3 months ago) by chrisgreen
Branch: MAIN
Changes since 1.7: +20 -14 lines
Diff to previous 1.7
* logic errors in spp_stream4, detect_scans
* DisableDetect in rpc_decode()
* new TCP options decoder -- anomaly detection added :^)

Revision 1.7 / (view) - annotate - [select for diffs] , Mon Mar 3 18:17:44 2003 UTC (6 years, 4 months ago) by chrisgreen
Branch: MAIN
CVS Tags: CMG
Changes since 1.6: +4 -0 lines
Diff to previous 1.6
* rpc fixes
* suspend mode fixes

Revision 1.3.2.1 / (view) - annotate - [select for diffs] , Mon Mar 3 18:04:37 2003 UTC (6 years, 4 months ago) by chrisgreen
Branch: SNORT_1_9
CVS Tags: version-1-9-1
Changes since 1.3: +5 -1 lines
Diff to previous 1.3 to next main 1.4
* rpc fixes
* snort 1.9.1

Revision 1.6 / (view) - annotate - [select for diffs] , Mon Feb 10 14:52:19 2003 UTC (6 years, 4 months ago) by andrewbaker
Branch: MAIN
Changes since 1.5: +1 -1 lines
Diff to previous 1.5
* fix id for "spp_frag2: Shifting to Suspend Mode"

Revision 1.5 / (view) - annotate - [select for diffs] , Thu Dec 5 16:22:00 2002 UTC (6 years, 6 months ago) by chrisgreen
Branch: MAIN
Changes since 1.4: +4 -4 lines
Diff to previous 1.4
* updating to placate Phil Wood :)

Revision 1.4 / (view) - annotate - [select for diffs] , Mon Nov 18 20:18:25 2002 UTC (6 years, 7 months ago) by chrisgreen
Branch: MAIN
Changes since 1.3: +6 -2 lines
Diff to previous 1.3
* Emergency mode/Suspend modes for stream4/frag2

Revision 1.3 / (view) - annotate - [select for diffs] , Wed Aug 14 03:17:58 2002 UTC (6 years, 10 months ago) by chrisgreen
Branch: MAIN
CVS Tags: version-1-9-0, beta-1_9_0-beta5
Branch point for: SNORT_1_9
Changes since 1.2: +3 -2 lines
Diff to previous 1.2
* preprocessor conversation: allowed_ip_protocols 1 6 17, alert_odd_protocols
* explicit parens for sp_session

Revision 1.2 / (view) - annotate - [select for diffs] , Thu May 30 20:01:15 2002 UTC (7 years, 1 month ago) by cazz
Branch: MAIN
CVS Tags: beta-1_9_0-beta6, beta-1_9_0-beta4, beta-1_9_0-beta2
Changes since 1.1: +46 -1 lines
Diff to previous 1.1
yes, lets keep it up to date.

BTW, if you add anything to generators.h and don't add it here, I will beat
you with a baseball bat.

Revision 1.1 / (view) - annotate - [select for diffs] , Thu May 30 18:30:26 2002 UTC (7 years, 1 month ago) by cazz
Branch: MAIN
* yeap, lets support this via snort now.

This form allows you to request diffs between any two revisions of a file. You may select a symbolic revision name using the selection box or you may type in a numeric name using the type-in text box.

Diffs between and
Type of Diff should be a

View only Branch:
Sort log by:

snort-team@sourcefire.com