Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Re: [Snort-users] Fixes and Mitigation Instructions Available for Snort Back Orifice Vulnerability

0 views
Skip to first unread message

Sam Evans

unread,
Oct 18, 2005, 5:56:00 PM10/18/05
to
------=_Part_28219_2690732.1129672490452
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

Jennifer,
I might be missing something, but when I click the
http://www.snort.org/dl/link all I see is the
2.4.2 version, not the 2.4.3.
Thanks,
Sam


On 10/18/05, Jennifer Steffens <jennifer...@sourcefire.com> wrote:
>
> Subject: Fix and Mitigation Available for Snort Vulnerability
>
> The Sourcefire Vulnerability Research Team (VRT) has learned of a
> vulnerability in Snort v2.4.0 and higher. Users are only vulnerable if
> the Back Orifice preprocessor is enabled. Snort v2.4.3 has been released
> to correct the issue and detailed instructions for mitigating the issue
> by disabling the Back Orifice preprocessor are below.
>
>
> Snort v2.4.3
>
> In addition to fixing the vulnerability, this version includes a
> mechanism to detect exploits against vulnerable sensors and, optionally
> for inline sensors, drop the offending traffic. These features enable a
> phased approach to upgrading while protecting unpatched sensors.
> Detection capabilities are part of the new preprocessor and therefore
> are available to all users regardless of subscription status.
>
> In addition to the source tarball, postgres, mysql and plain RPMs and a
> win32 installer are available at http://www.snort.org/dl. Please
> remember that updated rules are only included in major releases. For
> updated rules, visit http://www.snort.org/rules/.
>
>
> Mitigation Instructions:
>
> The Back Orifice preprocessor can be disabled by commenting out the line
> "preprocessor bo" in snort.conf. This can be done in any text editor
> using the following procedure:
>
> 1. Locate the line "preprocessor bo"
> 2. Comment out this line by preceding it with a hash (#). The new line
> will look like "#preprocessor bo"
> 3. Save the file
> 4. Restart snort
>
>
> Background:
>
> On Thursday, October 13th Sourcefire was contacted by USCERT with news
> of a vulnerability in Snort. We used the subsequent days to verify the
> vulnerability and to prepare mitigation strategies and the software
> updates necessary to fix the vulnerability for both Sourcefire customers
> and Snort users. While it cannot be said that no other problems will
> ever be found in the Snort code base, we can state that we will redouble
> our efforts to ensure the security of the system so many people have
> come to rely on for the detection of network-based threats. Sourcefire
> will also continue to work with the most sophisticated testing
> facilities in the industry to assure that every reasonable step is being
> taken to provide the most secure code base possible.
>
>
> Technical Details:
> The Back Orifice preprocessor contains a stack-based buffer overflow.
> This vulnerability could be leveraged by an attacker to execute code
> remotely on a Snort sensor where the Back Orifice preprocessor is
> enabled. However, there are a number of factors that make remote code
> execution difficult to achieve across different builds of Snort on
> different platforms, even on the same platform with different compiler
> versions, and it is more likely that an attacker could use the
> vulnerability as a denial of service attack.
>
>
> If you have any questions, please let us know at snort...@sourcefire.co=
m
>
> Thanks,
> Jennifer
>
>
> --
> Jennifer S. Steffens
> Director, Snort Product Management | Sourcefire, Inc.
> W: 410.423.1930 | C: 202.409.7707
> www.sourcefire.com <http://www.sourcefire.com> | www.snort.org<http://www=
.snort.org>
>
>
> -------------------------------------------------------
> This SF.Net email is sponsored by:
> Power Architecture Resource Center: Free content, downloads, discussions,
> and more. http://solutions.newsforge.com/ibmarch.tmpl
> _______________________________________________
> Snort-users mailing list
> Snort...@lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-users
>

------=_Part_28219_2690732.1129672490452
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

<div>Jennifer,</div>
<div>&nbsp;</div>
<div>I might be missing something, but when I click the <a href=3D"http://w=
ww.snort.org/dl/">http://www.snort.org/dl/</a>&nbsp;link all I see is the 2=
.4.2 version, not the 2.4.3.</div>
<div>&nbsp;</div>
<div>Thanks,</div>
<div>Sam</div>
<div><br><br>&nbsp;</div>
<div><span class=3D"gmail_quote">On 10/18/05, <b class=3D"gmail_sendername"=
>Jennifer Steffens</b> &lt;<a href=3D"mailto:jennifer.steffens@sourcefire.c=
om">jennifer...@sourcefire.com</a>&gt; wrote:</span>
<blockquote class=3D"gmail_quote" style=3D"PADDING-LEFT: 1ex; MARGIN: 0px 0=
px 0px 0.8ex; BORDER-LEFT: #ccc 1px solid">Subject: Fix and Mitigation Avai=
lable for Snort Vulnerability<br><br>The Sourcefire Vulnerability Research =
Team (VRT) has learned of a
<br>vulnerability in Snort v2.4.0 and higher. Users are only vulnerable if<=
br>the Back Orifice preprocessor is enabled. Snort v2.4.3 has been released=
<br>to correct the issue and detailed instructions for mitigating the issue
<br>by disabling the Back Orifice preprocessor are below.<br><br><br>Snort =
v2.4.3<br><br>In addition to fixing the vulnerability, this version include=
s a<br>mechanism to detect exploits against vulnerable sensors and, optiona=
lly
<br>for inline sensors, drop the offending traffic. These features enable a=
<br>phased approach to upgrading while protecting unpatched sensors.<br>Det=
ection capabilities are part of the new preprocessor and therefore<br>are a=
vailable to all users regardless of subscription status.
<br><br>In addition to the source tarball, postgres, mysql and plain RPMs a=
nd a<br>win32 installer are available at <a href=3D"http://www.snort.org/dl=
">http://www.snort.org/dl</a>. Please<br>remember that updated rules are on=
ly included in major releases. For
<br>updated rules, visit <a href=3D"http://www.snort.org/rules/">http://www=
.snort.org/rules/</a>.<br><br><br>Mitigation Instructions:<br><br>The Back =
Orifice preprocessor can be disabled by commenting out the line<br>&quot;pr=
eprocessor bo&quot; in=20
snort.conf. This can be done in any text editor<br>using the following proc=
edure:<br><br>1. Locate the line &quot;preprocessor bo&quot;<br>2. Comment =
out this line by preceding it with a hash (#). The new line<br>will look li=
ke &quot;#preprocessor bo&quot;
<br>3. Save the file<br>4. Restart snort<br><br><br>Background:<br><br>On T=
hursday, October 13th Sourcefire was contacted by USCERT with news<br>of a =
vulnerability in Snort. We used the subsequent days to verify the<br>vulner=
ability and to prepare mitigation strategies and the software
<br>updates necessary to fix the vulnerability for both Sourcefire customer=
s<br>and Snort users. While it cannot be said that no other problems will<b=
r>ever be found in the Snort code base, we can state that we will redouble
<br>our efforts to ensure the security of the system so many people have<br=
>come to rely on for the detection of network-based threats. Sourcefire<br>=
will also continue to work with the most sophisticated testing<br>facilitie=
s in the industry to assure that every reasonable step is being
<br>taken to provide the most secure code base possible.<br><br><br>Technic=
al Details:<br>The Back Orifice preprocessor contains a stack-based buffer =
overflow.<br>This vulnerability could be leveraged by an attacker to execut=
e code
<br>remotely on a Snort sensor where the Back Orifice preprocessor is<br>en=
abled.&nbsp;&nbsp;However, there are a number of factors that make remote c=
ode<br>execution difficult to achieve across different builds of Snort on<b=
r>different platforms, even on the same platform with different compiler
<br>versions, and it is more likely that an attacker could use the<br>vulne=
rability as a denial of service attack.<br><br><br>If you have any question=
s, please let us know at <a href=3D"mailto:snort...@sourcefire.com">snort=
-te...@sourcefire.com
</a><br><br>Thanks,<br>Jennifer<br><br><br>--<br>Jennifer S. Steffens<br>Di=
rector, Snort Product Management | Sourcefire, Inc.<br>W: 410.423.1930 | C:=
202.409.7707<br><a href=3D"http://www.sourcefire.com">www.sourcefire.com
</a> | <a href=3D"http://www.snort.org">www.snort.org</a><br><br><br>------=
-------------------------------------------------<br>This SF.Net email is s=
ponsored by:<br>Power Architecture Resource Center: Free content, downloads=
, discussions,
<br>and more. <a href=3D"http://solutions.newsforge.com/ibmarch.tmpl">http:=
//solutions.newsforge.com/ibmarch.tmpl</a><br>_____________________________=
__________________<br>Snort-users mailing list<br><a href=3D"mailto:Snort-u=
se...@lists.sourceforge.net">
Snort...@lists.sourceforge.net</a><br>Go to this URL to change user opti=
ons or unsubscribe:<br><a href=3D"https://lists.sourceforge.net/lists/listi=
nfo/snort-users">https://lists.sourceforge.net/lists/listinfo/snort-users
</a><br>Snort-users list archive:<br><a href=3D"http://www.geocrawler.com/r=
edir-sf.php3?list=3Dsnort-users">http://www.geocrawler.com/redir-sf.php3?li=
st=3Dsnort-users</a><br></blockquote></div><br>

------=_Part_28219_2690732.1129672490452--


-------------------------------------------------------
This SF.Net email is sponsored by:
Power Architecture Resource Center: Free content, downloads, discussions,
and more. http://solutions.newsforge.com/ibmarch.tmpl
_______________________________________________
Snort-users mailing list
Snort...@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Ron Jenkins

unread,
Oct 18, 2005, 6:37:18 PM10/18/05
to
I see it too.

-----Original Message-----
From: snort-us...@lists.sourceforge.net
[mailto:snort-us...@lists.sourceforge.net] On Behalf Of Jennifer
Steffens
Sent: Tuesday, October 18, 2005 5:31 PM
To: Sam Evans
Cc: snort-users @ lists. sourceforge. net
Subject: Re: [Snort-users] Fixes and Mitigation Instructions Available
for Snort Back Orifice Vulnerability

Sam,

Can you try refreshing the page? The 2.4.3 version is there for me. The=20
actual link is http://www.snort.org/dl/current/snort-2.4.3.tar.gz.

Thanks,
Jennifer

Sam Evans wrote:
> Jennifer,
> =20
> I might be missing something, but when I click the=20
> http://www.snort.org/dl/ link all I see is the 2.4.2 version, not the
2.4.3.
> =20
> Thanks,
> Sam
>=20
>=20
> =20
> On 10/18/05, *Jennifer Steffens* <jennifer...@sourcefire.com=20
> <mailto:jennifer...@sourcefire.com>> wrote:
>=20


> Subject: Fix and Mitigation Available for Snort Vulnerability

>=20


> The Sourcefire Vulnerability Research Team (VRT) has learned of a
> vulnerability in Snort v2.4.0 and higher. Users are only
vulnerable if
> the Back Orifice preprocessor is enabled. Snort v2.4.3 has been
released
> to correct the issue and detailed instructions for mitigating the
issue
> by disabling the Back Orifice preprocessor are below.

>=20
>=20
> Snort v2.4.3
>=20


> In addition to fixing the vulnerability, this version includes a
> mechanism to detect exploits against vulnerable sensors and,
optionally
> for inline sensors, drop the offending traffic. These features
enable a
> phased approach to upgrading while protecting unpatched sensors.
> Detection capabilities are part of the new preprocessor and
therefore
> are available to all users regardless of subscription status.

>=20


> In addition to the source tarball, postgres, mysql and plain RPMs
and a
> win32 installer are available at http://www.snort.org/dl. Please
> remember that updated rules are only included in major releases.
For
> updated rules, visit http://www.snort.org/rules/.

>=20
>=20
> Mitigation Instructions:
>=20


> The Back Orifice preprocessor can be disabled by commenting out
the line
> "preprocessor bo" in snort.conf. This can be done in any text
editor
> using the following procedure:

>=20


> 1. Locate the line "preprocessor bo"
> 2. Comment out this line by preceding it with a hash (#). The new
line
> will look like "#preprocessor bo"
> 3. Save the file
> 4. Restart snort

>=20
>=20
> Background:
>=20


> On Thursday, October 13th Sourcefire was contacted by USCERT with
news
> of a vulnerability in Snort. We used the subsequent days to verify
the
> vulnerability and to prepare mitigation strategies and the
software
> updates necessary to fix the vulnerability for both Sourcefire
customers
> and Snort users. While it cannot be said that no other problems
will
> ever be found in the Snort code base, we can state that we will
> redouble
> our efforts to ensure the security of the system so many people
have
> come to rely on for the detection of network-based threats.
Sourcefire
> will also continue to work with the most sophisticated testing
> facilities in the industry to assure that every reasonable step is
> being
> taken to provide the most secure code base possible.

>=20
>=20


> Technical Details:
> The Back Orifice preprocessor contains a stack-based buffer
overflow.
> This vulnerability could be leveraged by an attacker to execute
code
> remotely on a Snort sensor where the Back Orifice preprocessor is
> enabled. However, there are a number of factors that make remote
code
> execution difficult to achieve across different builds of Snort on
> different platforms, even on the same platform with different
compiler
> versions, and it is more likely that an attacker could use the
> vulnerability as a denial of service attack.

>=20
>=20


> If you have any questions, please let us know at

> snort...@sourcefire.com <mailto:snort...@sourcefire.com>
>=20
> Thanks,
> Jennifer
>=20
>=20


> --
> Jennifer S. Steffens
> Director, Snort Product Management | Sourcefire, Inc.
> W: 410.423.1930 | C: 202.409.7707
> www.sourcefire.com <http://www.sourcefire.com> | www.snort.org

> <http://www.snort.org>
>=20
>=20


> -------------------------------------------------------
> This SF.Net email is sponsored by:
> Power Architecture Resource Center: Free content, downloads,
> discussions,
> and more. http://solutions.newsforge.com/ibmarch.tmpl
> _______________________________________________
> Snort-users mailing list
> Snort...@lists.sourceforge.net

> <mailto:Snort...@lists.sourceforge.net>

>=20
>=20


-------------------------------------------------------
This SF.Net email is sponsored by:
Power Architecture Resource Center: Free content, downloads,
discussions,
and more. http://solutions.newsforge.com/ibmarch.tmpl
_______________________________________________
Snort-users mailing list
Snort...@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-users

Sam Evans

unread,
Oct 18, 2005, 8:32:57 PM10/18/05
to
------=_Part_30698_24809211.1129681883912

Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

Thanks, like I said, I think the problem was on my end (and it was).

On 10/18/05, Ron Jenkins <rjen...@dibr.net> wrote:
>
> I see it too.
>
> -----Original Message-----
> From: snort-us...@lists.sourceforge.net
> [mailto:snort-us...@lists.sourceforge.net] On Behalf Of Jennifer
> Steffens
> Sent: Tuesday, October 18, 2005 5:31 PM
> To: Sam Evans
> Cc: snort-users @ lists. sourceforge. net
> Subject: Re: [Snort-users] Fixes and Mitigation Instructions Available
> for Snort Back Orifice Vulnerability
>
> Sam,
>
> Can you try refreshing the page? The 2.4.3 version is there for me. The

> actual link is http://www.snort.org/dl/current/snort-2.4.3.tar.gz.
>
> Thanks,
> Jennifer
>
> Sam Evans wrote:
> > Jennifer,
> >

> > I might be missing something, but when I click the

> > http://www.snort.org/dl/ link all I see is the 2.4.2 version, not the
> 2.4.3.
> >

> > Thanks,
> > Sam
> >
> >
> >
> > On 10/18/05, *Jennifer Steffens* <jennifer...@sourcefire.com


> > <mailto:jennifer...@sourcefire.com>> wrote:
> >
> > Subject: Fix and Mitigation Available for Snort Vulnerability
> >

> > The Sourcefire Vulnerability Research Team (VRT) has learned of a
> > vulnerability in Snort v2.4.0 and higher. Users are only
> vulnerable if
> > the Back Orifice preprocessor is enabled. Snort v2.4.3 has been
> released
> > to correct the issue and detailed instructions for mitigating the
> issue
> > by disabling the Back Orifice preprocessor are below.
> >
> >

> > Snort v2.4.3


> >
> > In addition to fixing the vulnerability, this version includes a
> > mechanism to detect exploits against vulnerable sensors and,
> optionally
> > for inline sensors, drop the offending traffic. These features
> enable a
> > phased approach to upgrading while protecting unpatched sensors.
> > Detection capabilities are part of the new preprocessor and
> therefore
> > are available to all users regardless of subscription status.
> >

> > In addition to the source tarball, postgres, mysql and plain RPMs
> and a
> > win32 installer are available at http://www.snort.org/dl. Please
> > remember that updated rules are only included in major releases.
> For
> > updated rules, visit http://www.snort.org/rules/.
> >
> >

> > Mitigation Instructions:


> >
> > The Back Orifice preprocessor can be disabled by commenting out
> the line
> > "preprocessor bo" in snort.conf. This can be done in any text
> editor
> > using the following procedure:
> >

> > 1. Locate the line "preprocessor bo"
> > 2. Comment out this line by preceding it with a hash (#). The new
> line
> > will look like "#preprocessor bo"
> > 3. Save the file
> > 4. Restart snort
> >
> >

> > Background:


> >
> > On Thursday, October 13th Sourcefire was contacted by USCERT with
> news
> > of a vulnerability in Snort. We used the subsequent days to verify
> the
> > vulnerability and to prepare mitigation strategies and the
> software
> > updates necessary to fix the vulnerability for both Sourcefire
> customers
> > and Snort users. While it cannot be said that no other problems
> will
> > ever be found in the Snort code base, we can state that we will
> > redouble
> > our efforts to ensure the security of the system so many people
> have
> > come to rely on for the detection of network-based threats.
> Sourcefire
> > will also continue to work with the most sophisticated testing
> > facilities in the industry to assure that every reasonable step is
> > being
> > taken to provide the most secure code base possible.
> >
> >

> > Technical Details:
> > The Back Orifice preprocessor contains a stack-based buffer
> overflow.
> > This vulnerability could be leveraged by an attacker to execute
> code
> > remotely on a Snort sensor where the Back Orifice preprocessor is
> > enabled. However, there are a number of factors that make remote
> code
> > execution difficult to achieve across different builds of Snort on
> > different platforms, even on the same platform with different
> compiler
> > versions, and it is more likely that an attacker could use the
> > vulnerability as a denial of service attack.
> >
> >

> > If you have any questions, please let us know at
> > snort...@sourcefire.com <mailto:snort...@sourcefire.com>
> >

> > Thanks,
> > Jennifer


> >
> >
> > --
> > Jennifer S. Steffens
> > Director, Snort Product Management | Sourcefire, Inc.
> > W: 410.423.1930 | C: 202.409.7707
> > www.sourcefire.com <http://www.sourcefire.com> <
> http://www.sourcefire.com> | www.snort.org <http://www.snort.org>

> > <http://www.snort.org>


> >
> >
> > -------------------------------------------------------
> > This SF.Net email is sponsored by:
> > Power Architecture Resource Center: Free content, downloads,
> > discussions,
> > and more. http://solutions.newsforge.com/ibmarch.tmpl
> > _______________________________________________
> > Snort-users mailing list
> > Snort...@lists.sourceforge.net
> > <mailto:Snort...@lists.sourceforge.net>
> > Go to this URL to change user options or unsubscribe:
> > https://lists.sourceforge.net/lists/listinfo/snort-users
> > <https://lists.sourceforge.net/lists/listinfo/snort-users>
> > Snort-users list archive:
> > http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-users
> >
> >
>
>

> -------------------------------------------------------
> This SF.Net email is sponsored by:
> Power Architecture Resource Center: Free content, downloads,
> discussions,
> and more. http://solutions.newsforge.com/ibmarch.tmpl
> _______________________________________________
> Snort-users mailing list
> Snort...@lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-users
>

------=_Part_30698_24809211.1129681883912


Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

Thanks,&nbsp; like I said, I think the problem was on my end (and it was).<=
br>
<br>
<br><br><div><span class=3D"gmail_quote">On 10/18/05, <b class=3D"gmail_sen=
dername">Ron Jenkins</b> &lt;<a href=3D"mailto:rjen...@dibr.net">rjenkins@=
dibr.net</a>&gt; wrote:</span><blockquote class=3D"gmail_quote" style=3D"bo=
rder-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding=
-left: 1ex;">
I see it too.<br><br>-----Original Message-----<br>From: <a href=3D"mailto:=
snort-us...@lists.sourceforge.net">snort-us...@lists.sourceforg=
e.net</a><br>[mailto:<a href=3D"mailto:snort-us...@lists.sourceforge.=
net">
snort-us...@lists.sourceforge.net</a>] On Behalf Of Jennifer<br>Steff=
ens<br>Sent: Tuesday, October 18, 2005 5:31 PM<br>To: Sam Evans<br>Cc: snor=
t-users @ lists. sourceforge. net<br>Subject: Re: [Snort-users] Fixes and M=
itigation Instructions Available
<br>for Snort Back Orifice Vulnerability<br><br>Sam,<br><br>Can you try ref=
reshing the page? The 2.4.3 version is there for me. The<br>actual link is =
<a href=3D"http://www.snort.org/dl/current/snort-2.4.3.tar.gz">http://www.s=
nort.org/dl/current/snort-2.4.3.tar.gz
</a>.<br><br>Thanks,<br>Jennifer<br><br>Sam Evans wrote:<br>&gt; Jennifer,<=
br>&gt;<br>&gt; I might be missing something, but when I click the<br>&gt; =
<a href=3D"http://www.snort.org/dl/">http://www.snort.org/dl/</a> link all =
I see is the=20
2.4.2 version, not the<br>2.4.3.<br>&gt;<br>&gt; Thanks,<br>&gt; Sam<br>&gt=
;<br>&gt;<br>&gt;<br>&gt; On 10/18/05, *Jennifer Steffens* &lt;<a href=3D"m=
ailto:jennifer...@sourcefire.com">jennifer...@sourcefire.com</a=
>
<br>&gt; &lt;mailto:<a href=3D"mailto:jennifer...@sourcefire.com">jen=
nifer.s...@sourcefire.com</a>&gt;&gt; wrote:<br>&gt;<br>&gt;&nbsp;&nbsp=
;&nbsp;&nbsp; Subject: Fix and Mitigation Available for Snort Vulnerability=
<br>&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; The Sourcefire Vulnerability Resea=


rch Team (VRT) has learned of a

<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; vulnerability in Snort v2.4.0 and higher. =
Users are only<br>vulnerable if<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; the Back Or=
ifice preprocessor is enabled. Snort v2.4.3 has been<br>released<br>&gt;&nb=
sp;&nbsp;&nbsp;&nbsp; to correct the issue and detailed instructions for mi=
tigating the
<br>issue<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; by disabling the Back Orifice pre=
processor are below.<br>&gt;<br>&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; Snort =
v2.4.3<br>&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; In addition to fixing the vu=
lnerability, this version includes a<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; mechan=


ism to detect exploits against vulnerable sensors and,

<br>optionally<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; for inline sensors, drop the=
offending traffic. These features<br>enable a<br>&gt;&nbsp;&nbsp;&nbsp;&nb=
sp; phased approach to upgrading while protecting unpatched sensors.<br>&gt=
;&nbsp;&nbsp;&nbsp;&nbsp; Detection capabilities are part of the new prepro=
cessor and
<br>therefore<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; are available to all users re=
gardless of subscription status.<br>&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; In=
addition to the source tarball, postgres, mysql and plain RPMs<br>and a<br=
>&gt;&nbsp;&nbsp;&nbsp;&nbsp; win32 installer are available at=20
<a href=3D"http://www.snort.org/dl">http://www.snort.org/dl</a>. Please<br>=
&gt;&nbsp;&nbsp;&nbsp;&nbsp; remember that updated rules are only included =
in major releases.<br>For<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; updated rules, vi=

http://www.snort.org/rules/</a>.<br>&gt;<br>&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&=
nbsp; Mitigation Instructions:<br>&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; The =
Back Orifice preprocessor can be disabled by commenting out<br>the line<br>=
&gt;&nbsp;&nbsp;&nbsp;&nbsp; &quot;preprocessor bo&quot; in=20
snort.conf. This can be done in any text<br>editor<br>&gt;&nbsp;&nbsp;&nbsp=
;&nbsp; using the following procedure:<br>&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&nb=
sp; 1. Locate the line &quot;preprocessor bo&quot;<br>&gt;&nbsp;&nbsp;&nbsp=
;&nbsp; 2. Comment out this line by preceding it with a hash (#). The new
<br>line<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; will look like &quot;#preprocessor=
bo&quot;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; 3. Save the file<br>&gt;&nbsp;&nb=
sp;&nbsp;&nbsp; 4. Restart snort<br>&gt;<br>&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&=
nbsp; Background:<br>&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; On Thursday, Octo=


ber 13th Sourcefire was contacted by USCERT with

<br>news<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; of a vulnerability in Snort. We us=
ed the subsequent days to verify<br>the<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; vul=
nerability and to prepare mitigation strategies and the<br>software<br>&gt;=
&nbsp;&nbsp;&nbsp;&nbsp; updates necessary to fix the vulnerability for bot=
h Sourcefire
<br>customers<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; and Snort users. While it can=
not be said that no other problems<br>will<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; =
ever be found in the Snort code base, we can state that we will<br>&gt;&nbs=
p;&nbsp;&nbsp;&nbsp; redouble<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; our efforts t=


o ensure the security of the system so many people

<br>have<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; come to rely on for the detection =
of network-based threats.<br>Sourcefire<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; wil=
l also continue to work with the most sophisticated testing<br>&gt;&nbsp;&n=
bsp;&nbsp;&nbsp; facilities in the industry to assure that every reasonable=
step is
<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; being<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; take=
n to provide the most secure code base possible.<br>&gt;<br>&gt;<br>&gt;&nb=
sp;&nbsp;&nbsp;&nbsp; Technical Details:<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; Th=
e Back Orifice preprocessor contains a stack-based buffer<br>overflow.<br>&=
gt;&nbsp;&nbsp;&nbsp;&nbsp; This vulnerability could be leveraged by an att=
acker to execute
<br>code<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; remotely on a Snort sensor where t=
he Back Orifice preprocessor is<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; enabled.&nb=
sp;&nbsp;However, there are a number of factors that make remote<br>code<br=
>&gt;&nbsp;&nbsp;&nbsp;&nbsp; execution difficult to achieve across differe=
nt builds of Snort on
<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; different platforms, even on the same plat=
form with different<br>compiler<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; versions, a=
nd it is more likely that an attacker could use the<br>&gt;&nbsp;&nbsp;&nbs=
p;&nbsp; vulnerability as a denial of service attack.<br>
&gt;<br>&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; If you have any questions, ple=
ase let us know at<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; <a href=3D"mailto:snort-=
te...@sourcefire.com">snort...@sourcefire.com</a> &lt;mailto:<a href=3D"ma=
ilto:snort...@sourcefire.com">snort...@sourcefire.com
</a>&gt;<br>&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; Thanks,<br>&gt;&nbsp;&nbsp=
;&nbsp;&nbsp; Jennifer<br>&gt;<br>&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; --<b=
r>&gt;&nbsp;&nbsp;&nbsp;&nbsp; Jennifer S. Steffens<br>&gt;&nbsp;&nbsp;&nbs=
p;&nbsp; Director, Snort Product Management | Sourcefire, Inc.<br>&gt;&nbsp=
;&nbsp;&nbsp;&nbsp; W: 410.423.1930 | C:=20
202.409.7707<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; <a href=3D"http://www.sourcefi=
re.com">www.sourcefire.com</a> &lt;<a href=3D"http://www.sourcefire.com">ht=
tp://www.sourcefire.com</a>&gt; | <a href=3D"http://www.snort.org">www.snor=
t.org</a><br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;
<a href=3D"http://www.snort.org">http://www.snort.org</a>&gt;<br>&gt;<br>&g=
t;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; ----------------------------------------=
---------------<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; This SF.Net email is sponso=
red by:<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; Power Architecture Resource Center:=
Free content, downloads,
<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; discussions,<br>&gt;&nbsp;&nbsp;&nbsp;&nbs=
p; and more. <a href=3D"http://solutions.newsforge.com/ibmarch.tmpl">http:/=
/solutions.newsforge.com/ibmarch.tmpl</a><br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; _=
______________________________________________<br>&gt;&nbsp;&nbsp;&nbsp;&nb=
sp; Snort-users mailing list
<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; <a href=3D"mailto:Snort...@lists.source=
forge.net">Snort...@lists.sourceforge.net</a><br>&gt;&nbsp;&nbsp;&nbsp;&=
nbsp; &lt;mailto:<a href=3D"mailto:Snort...@lists.sourceforge.net">Snort=
-us...@lists.sourceforge.net</a>&gt;<br>
&gt;&nbsp;&nbsp;&nbsp;&nbsp; Go to this URL to change user options or unsub=
scribe:<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; <a href=3D"https://lists.sourceforg=
e.net/lists/listinfo/snort-users">https://lists.sourceforge.net/lists/listi=
nfo/snort-users</a><br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;<a href=3D"https://=
lists.sourceforge.net/lists/listinfo/snort-users">
https://lists.sourceforge.net/lists/listinfo/snort-users</a>&gt;<br>&gt;&nb=
sp;&nbsp;&nbsp;&nbsp; Snort-users list archive:<br>&gt;&nbsp;&nbsp;&nbsp;&n=
bsp; <a href=3D"http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-users"=
>http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-users
</a><br>&gt;<br>&gt;<br><br><br>-------------------------------------------=
------------<br>This SF.Net email is sponsored by:<br>Power Architecture Re=
source Center: Free content, downloads,<br>discussions,<br>and more. <a hre=
f=3D"http://solutions.newsforge.com/ibmarch.tmpl">
http://solutions.newsforge.com/ibmarch.tmpl</a><br>________________________=
_______________________<br>Snort-users mailing list<br><a href=3D"mailto:Sn=
ort-...@lists.sourceforge.net">Snort...@lists.sourceforge.net</a><br>
Go to this URL to change user options or unsubscribe:<br><a href=3D"https:/=
/lists.sourceforge.net/lists/listinfo/snort-users">https://lists.sourceforg=
e.net/lists/listinfo/snort-users</a><br>Snort-users list archive:<br><a hre=
f=3D"http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-users">
http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-users</a><br></blockqu=
ote></div><br>

------=_Part_30698_24809211.1129681883912--

0 new messages