Home | About Us | FAQ | Signature Downloads | All Projects | Submit a Signature | Mailing Lists | Feeds | Open Job Board | Sponsors | Documentation

  • RSS Latest Docs

    • 2003394
    • SnortConfSamples
    • FastFluxDNSResponseDetection
    • 2007634
    • DilipPatel
    • TestTest123
    • 2003642
    • 2007588
    • 2007688
    • 2007706
  • RSS Latest Sigs

    • VIRUS/TROJAN_PRG
    • VIRUS/TROJAN_Win32.Pakes
    • current-sids.txt
    • CURRENT_EVENTS/CURRENT_WPAD
    • current-sids.txt
    • CURRENT_EVENTS/CURRENT_WPAD
    • current-sids.txt
    • WEB/WEB_Neosploit
    • current-sids.txt
    • VIRUS/TROJAN_Win32.Pakes
  • Recent Comments

    • gabrix on I’m Leaving Bleeding Threats!
    • Buck on Guard.zip Phish, Very targeted, Sig Available
    • Lance on Guard.zip Phish, Very targeted, Sig Available
    • akgunk on Guard.zip Phish, Very targeted, Sig Available
    • Bill475382635','199440348billy@msn.com','','20.134.10.131','2008-05-20 20:38:34','2008-05-20 20:38:34','','0','lynx','comment','0','0'),('0', '', '', '', '', '2008-05-21 20:38:34', '2008-05-21 20:38:34', '', 'spam', '', 'comment', '0','0' ) /* on How to Integrate/Use Bleeding Snort Rules
  • Recent Posts

    • Rule & Firewall Updates Re-enabled
    • I’m Leaving Bleeding Threats!
    • Encrypted Storm Sigs
    • Windows 98 Snort Signature
    • E-Jihad Tool Sigs
  • Archive for the 'Documentation' Category

    « Previous Entries

    New Ruleset: Compromised Hosts

    Friday, August 24th, 2007

    One last new ruleset to add this week. I promise no more for a bit.

    http://docs.bleedingthreats.net/bin/view/Main/CompromisedHost

    This is a compilation of several very reliable sources of hosts that are compromised. Not your everyday compromised spewing a little spam kind of hosts. These are significantly hostile.

    These are updated daily or better, so be sure you’re updating as well.

    If you have an intelligence source to add to the list please let me know.

    http://www.bleedingthreats.net/rules/bleeding-compromised.rules
    http://www.bleedingthreats.net/rules/bleeding-compromised-BLOCK.rules

    Matt

    Posted in Documentation, General, New Rules | 1 Comment »

    Storm Worm DNS and C&C Sigs; Updated Daily!

    Sunday, August 19th, 2007

    As we all know Storm has created an ongoing serious issue. To that end we’ve got a list of name servers in use by the Storm nets, and will be publishing storm signatures based on them. Updated daily at the least, likely more often as our information sources improve.

    This first list has over 800 servers that are confirmed hostile, and were active in the last 24 hours.

    http://www.bleedingthreats.net/rules/bleeding-storm.rules

    And a version prebuilt with a 30 day Snortsam block:

    http://www.bleedingthreats.net/rules/bleeding-storm-BLOCK.rules

    We’ll be collating Storm related links and data sources on the following page which is referenced in these sigs:

    http://doc.bleedingthreats.net/bin/view/Main/StormWorm

    If you have valuable links to contribute please feel free to throw them up on the page or send to me. Hopefully we can create a good list of material to help control this.

    Matt

    Posted in Documentation, General, New Rules | 3 Comments »

    STILL no word from Sourcefire about their License Changes

    Tuesday, July 17th, 2007

    Victor Julien (co-author of the inline portions of Snort) posted in his blog a while ago about the license changes to Snort that Sourcefire is trying to slip by. They have made a mass change to the Snort code, even that parts they do NOT hold the copyright about.

    Victor and myself have asked and blogged about the issue and after weeks have no response from Sourcefire. Victor doesn’t want the license on his code changed, and hasn’t been able to get a response from Sourcefire.

    I personally don’t have code in there, but I am concerned at the motivation of this change, as well as the lack of respect for the contributors rights. Victor has put up a new post which puts things very well:

    http://www.inliniac.net/blog/2007/07/16/snort-license-changes-revisited.html

    I echo that sentiment, and add my concerns here:

    What is the issue in GPLv3 that Sourcefire is concerned about?

    What are Sourcefire’s intentions for the future of Snort then?

    Why is CVS no longer accessible?

    Is it possible to get any response from Sourcefire about this? A lot of us rely on this code, and it’s not all owned by sourcefire. If we can’t trust Sourcefire to even communicate with us, then I think we need to start thinking about a new home for Snort.

    If you want the community’s trust, you have to communicate!

    Matt

    Posted in Documentation, General | 2 Comments »

    Sourcefire Changing the License on Snort…

    Saturday, June 30th, 2007

    Snort announced yet another license change. See below:

    http://www.snort.org/pub-bin/snortnews.cgi#664

    In essence they are rejecting the inherent condition of the GPL that future versions apply at the users discretion, even though their source code says it does apply.

    They are also taking the liberty of applying this to all contributed code, Snort_Inline for example:

    http://www.inliniac.net/blog/?p=90

    I can’t say it any better than Victor does in his blog in the link above. Sourcefire has of course written the majority of the snort code, but certainly not all. What is their concern with GPLv3, and what plans do they have for this code that would be in jeopardy from the license change?

    And why do they keep announcing these things on fridays? Expecting it to get missed on the way out the door? :)

    What are your thoughts? Anyone have an insight into the licensing issues that might be of concern to Sourcefire?

    Matt

    Posted in About Bleeding Edge Threats, Documentation, General, Other Projects, Vulnerabilities | No Comments »

    Managing Badware and Policy Violations with Aanval and Bleeding Edge Threats

    Friday, May 18th, 2007

    Great article by Russ McRee. Worth a read if you’re considering how to deploy, or what extra uses Snort can have on your network.

    http://holisticinfosec.org/toolsmith/docs/march2007.pdf

    Very well written Russ!

    Matt

    Posted in Documentation, General | No Comments »

    « Previous Entries
    • RSS Latest Docs

      • 2003394
      • SnortConfSamples
      • FastFluxDNSResponseDetection
      • 2007634
      • DilipPatel
      • TestTest123
      • 2003642
      • 2007588
      • 2007688
      • 2007706

    Entries (RSS) and Comments (RSS)
    Copyright © 2007 Bleeding Edge Threats.
    All trademarks and copyrights on this page are owned by their respective owners. Snort® is a registered trademark of Sourcefire, Inc.