Latest Post
Showing posts with label IPS/IDS. Show all posts
Showing posts with label IPS/IDS. Show all posts

UPDATE SNORT V-2.9.4.1 - network intrusion detection and prevention system

Written By Unknown on Thursday, 7 March 2013 | 07:06

Release Notes v-2.9.4.1: This release updates file processing for partial HTTP content and MIME attachments, adds the new configuration option max_attribute_services_per_host and improves memory usage within attribute tables, handles excessive overlaps in frag3, adds Stream API updates to return a session key for a session, reduces false positives for TCP window slam events, updates to provide better encoding for TCP packets generated for “respond and react”, and disables non-ethernet decoders by default (for performance reasons)
Snort is a network intrusion detection and prevention system. It is the most widely deployed technology of its kind in the world. It performs detection using a variety of methods including rules-based detection, anomaly detection, and heuristic analysis of network traffic. Its rules language is open source and available to the public as well.

Features

  • Protocol analysis and content searching/matching
  • Uses a flexible rules language to describe traffic that it should collect or pass
  • Detection engine that utilizes a modular plug-in architecture
  • Real-time alerting capability
  • Detects buffer overflows, stealth port scans, CGI attacks, SMB probes, OS fingerprinting attempts, and more
Download version :
windows : Snort_2_9_4_1_Installer.exe (2.7 MB)
Unix/Linux : snort-2.9.4.1.tar.gz (5.3 MB)
Find Other version |
Sources : http://www.snort.org

IPFire 2.13 - Core 66 released - An Open Source Firewall Distribution

Written By Unknown on Thursday, 21 February 2013 | 23:23


IPFire 2.13 is a new major version of IPFire, the Open Source Firewall distribution. The list of changes, enhancements, and fixes is endless.Following features which we’re the most excited about:

Base System

The most important components of the base system have been updated to include a brand new kernel based on the Linux 3.2 release. With that, IPFire now supports more hardware than ever before and many of the hardware problems from the past should be gone.
The most basic system libraries have been replaced as well, giving us great performance and fixing some general security issues. If you’d like to know more about this specifically, please read this post on our planet.

Quality of Service with CoDeL

In case you are struggling with a slow internet connection, CoDeL is your solution. This new algorithm shares the bandwidth fairly between all connections. It doesn’t need any configuration at all, but when tied together with our Quality of Service features, CoDeL gives you the most out of your connection.

ARM

We have finally declared the ARM versions of IPFire as stable. Since the very first testing release back in October 2011, a multitude of things have improved. As of today, IPFire runs on many different platforms, such as Marvell Kirkwood and Texas Instruments OMAP4-based systems, and of course, the Raspberry Pi computer.
The vast amount of people who have already been using IPFire ARM since we began to port it to the ARM architecture know that there was never really any big trouble to begin with. You can find more about this over here.

IPsec VPNs with strongswan 5

The IPsec implementation strongswan recently released a new version which cleaned up a significant amount of old code, some of which has been in use for over a decade. If you want to know the details, check out the IPFire planet post.

Wireless LAN

From our wishlist, we’ve implemented proper support for 5 GHz WLANs. Read this planet post to learn about the benefits.
Latest release: IPFire 2.13 - Core 66
Please click the button to download the IPFire ISO image for i586-compatible computers. This is the default image, you will most likely need to install IPFire. You may also pick your desired architecture from the tabs above and see a list of all image formats.
Download IPFire 2.13 - Core 66 (ISO-Image - i586 - 93.4M)
IPFire is a server distribution with intended to use as a firewall. It focuses on flexibility, and scales from small to middle sized business networks and home networks.

Along with this hardened, minimalist come lots of addons that can be installed with a simple click. That's what makes IPFire different from other firewall distributions: it is easy to configure for any task, and easy to administer once it's set up.

Features
  • stateful inspection firewall based on linux netfilter architecture
  • intrusion detection system with Guardian addon as extension (IPS system)
  • filter for invalid/non-standard packages
  • separate network segments for server (DMZ) and wireless with custom policies
  • DoS attack protection
  • application proxies for HTTP and FTP (with access control and content filtering) and DNS
  • incoming and outgoing packet filtering
  • Quality of Service and traffic shaping
Source-

Snort 2.9.4.0 has been released!

Written By Unknown on Tuesday, 4 December 2012 | 09:35

Snort® is an open source network intrusion prevention and detection system (IDS/IPS) developed by Sourcefire. Combining the benefits of signature, protocol, and anomaly-based inspection, Snort is the most widely deployed IDS/IPS technology worldwide. With millions of downloads and nearly 400,000 registered users, Snort has become the de facto standard for IPS.

Snort 2.9.4 is now available on snort.org, at http://www.snort.org/snort-downloads/ in the Latest Release section. 

************ Please note: 2.9.3.1 & later packages are signed with a new PGP key (that key is signed with the previous key). ************ 

Snort 2.9.4 includes changes for the following: 

[*] New additions 

* Consolidation of IPv6 -- now only a single build supports both IPv4 & IPv6, and removal of the IPv4 "only" code paths. 

* File API and improvements to file processing for HTTP downloads and email attachments via SMTP, POP, and IMAP to facilitate broader file support 

* Use of address space ID for tracking Frag & Stream connections when it is available with the DAQ 

* Logging of packet data that triggers PPM for post-analysis via Snort event 

* Decoding of IPv6 with PPPoE 

* Added an API call to add a service to a host in the attribute table. Remove the unused live attribute update code. 

[*] Improvements 

* Update to Stream5 PAF for handling gaps in the sequence numbers of packets being reassembled. 

* Selection of the Stream TCP policy based on the server rather than the destination of first packet seen by Snort 

* Allow disabling of global thresholds via a count of -1 

* Prevent blocking duplicate SYNs when using inline normalization 

* Add SSLv3 backwards compatibility support for SSLv2 ClientHello messages 

* Allow active responses to packets without data (eg, a TCP SYN) 

* Changed logic of option evaluations for shared library rules that use a custom evaluation function to match that of the builtin logic when the NOT_FLAG is used. The 'NOT' matching now happens within each of the individual rule option evaluation functions. 

* Updated SMTP preprocessor to better handle commands that have corresponding data on a subsequent line to reduce false positives. 3 commands fall into this category - X-EXPS, XEXCH50, and BDAT. 

* Improve support for encapsulated & tunneling protocols to block or fastpath a connection within the tunnel rather applying that to the whole tunnel. 

Please see the Release Notes and ChangeLog for more details. 


Source-
http://blog.snort.org/2012/12/snort-2940-has-been-released.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Snort+%28Snort%29


Snort Downloads

If you are using RHEL5, CentOS 5.5, or Fedora Core 11, please click here.

The Snort Engine is distributed both as source code and binaries for popular Linux distributions and Windows. It’s important to note that the The Snort Engine and Snort Rules are distributed separately.

Latest Release

We strongly recommend that you keep pace with the latest production release. Snort is evolving all the time and to stay current with latest detection capabilities you should always have both your Snort engine and ruleset up to date.

README

29 Nov, 2012
29 Nov, 2012

Source

MD5 SIG - 29 Nov, 2012
MD5 SIG - 29 Nov, 2012

Binaries

MD5 SIG - 29 Nov, 2012
MD5 SIG - 29 Nov, 2012
MD5 SIG - 29 Nov, 2012
MD5 SIG - 29 Nov, 2012
MD5 SIG - 29 Nov, 2012
MD5 SIG - 29 Nov, 2012
MD5 SIG - 29 Nov, 2012


Untangle - Linux-based network gateway with pluggable modules for network applications

Written By Unknown on Friday, 30 November 2012 | 11:37

Untangle is a Linux-based network gateway with pluggable modules for network applications like spam blocking, web filtering, anti-virus, anti-spyware, intrusion prevention, VPN, SSL VPN, firewall, and more. Visit http://untangle.com

Download untangle_932_x32.iso (430.6 MB)
Download other versions from here

Source-
http://www.untangle.com/
http://sourceforge.net/projects/untangle/

Screenshot-

OSSEC Version 2.7 Released

Written By Unknown on Wednesday, 21 November 2012 | 02:53

OSSEC is Free Software, a GPL-licensed, host-based intrusion detection system (HIDS) that operates on a client-server model. Its development is sponsored by Trend Micro, a software security outfit based in Tokyo, Japan.
OSSEC is cross-platform, with binary packages available for all Linux distributions, the BSDs, Windows, Solaris, Mac OS, VMWare ESX, AIX, and HP-UX.
OSSEC 2.7 is the latest, stable version available for download. As with any software update, it comes with its share of new features and bugfixes.
Some of the new features are:
  • Support for hybrid mode during installation
  • Client keys can now be generated in bulk from an input file
  • Support for hostname specification of server during installation
  • More granular rootcheck configuration control
  • GeoIP lookup support
The key enhancements in v2.7 are:
  1. Installation
    • Add hybrid mode – allows the same host to be both a server and an agent, useful for multi-tier OSSEC deployment.
    • Add  manage_agents -f option for bulk generation of client keys from an input file.
    • During Agent installation, allow the OSSEC server to be specified using hostname instead of IP.
  2. Syscheck
    • Add prelinking support – reduce confusion when a file change is the result of prelinking.
  3. Rootcheck
    • Add fine-grained configuration control – allows you to turn ON/OFF individual rootcheck tasks for more efficiency and flexibility. The default is all ON.
  4. Log monitoring/analysis
    • Add GeoIP lookup support – allows geographical city names to be associated with IP addresses in OSSEC alerts, for more intelligent correlation.
  5. Alert options and syslog output
    • Add syscheck MD5/SHA1 sum to alerts for easier integration with third-party file signature checking.
    • Support JSON and Splunk formats in syslog output.
  6. Rules and other notable changes/fixes
    • Windows 2000 logs support has been deprecated (but will probably still work fine). Vista and Windows Server 2008 logs are now officially supported.
    • Windows registry syscheck alert level has been reduced from 7 to 5 to reduce unnecessary noise from alerts which do not indicate a compromise.
    • Update decoders include: PIX, auditd, apache, pam, php.
    • Many updated rules, such as new checks for vulnerable web apps exploitation attempts.
    • Update rootcheck rules.
    • ossec-client.sh now allows for ‘reload’, in addition to ‘restart’
    • Many bug fixes…
  7. LICENSE text updated by adding exception clause for OpenSSL, while OSSEC is still under GPLv2
Download OSSEC 2.7 package from here.
Source -
http://www.ossec.net/?p=577

Snort 2.9.4 RC released - open source network intrusion prevention and detection system (IDS/IPS)

Written By Unknown on Thursday, 25 October 2012 | 23:50

Snort® is an open source network intrusion prevention and detection system (IDS/IPS) developed by Sourcefire. Combining the benefits of signature, protocol, and anomaly-based inspection, Snort is the most widely deployed IDS/IPS technology worldwide. With millions of downloads and nearly 400,000 registered users, Snort has become the de facto standard for IPS.


Snort 2.9.4 includes changes for the following:

[*] New additions

 * Consolidation of IPv6 -- now only a single build supports both IPv4 & IPv6, and removal of the IPv4 "only" code paths.

 * File API and improvements to file processing for HTTP downloads and email attachments via SMTP, POP, and IMAP to facilitate broader file support

 * Use of address space ID for tracking Frag & Stream connections when it is available with the DAQ

 * Logging of packet data that triggers PPM for post-analysis via Snort event

 * Decoding of IPv6 with PPPoE

[*] Improvements

 * Update to Stream5 PAF for handling gaps in the sequence numbers of packets being reassembled.

 * Selection of the Stream TCP policy based on the server rather than the destination of first packet seen by Snort

 * Allow disabling of global thresholds via a count of -1

 * Prevent blocking duplicate SYNs when using inline normalization

 * Add SSLv3 backwards compatibility support for SSLv2 ClientHello messages

 * Allow active responses to packets without data (eg, a TCP SYN)

 * Changed logic of option evaluations for shared library rules that use a custom evaluation function to match that of the builtin logic when the NOT_FLAG is used.  The 'NOT' matching now happens within each of the individual rule option evaluation functions.

Please see the Release Notes and ChangeLog for more details.


The purpose of this beta program is to allow people to get exposure to the technology and to use the code in real-world environments – and as an opportunity to solicit feedback on the design and user experience of the new Snort code as it evolves.

README

24 Oct, 2012

Source

MD5 SIG - 24 Oct, 2012
MD5 SIG - 24 Oct, 2012

Binaries

MD5 SIG - 24 Oct, 2012
MD5 SIG - 24 Oct, 2012
MD5 SIG - 24 Oct, 2012
MD5 SIG - 24 Oct, 2012
MD5 SIG - 24 Oct, 2012
MD5 SIG - 24 Oct, 2012
MD5 SIG - 24 Oct, 2012

Visit Website for more information -


OSSEC 2.7 Beta-1! released

Written By Unknown on Friday, 5 October 2012 | 23:00

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.

It runs on most operating systems, including Linux, MacOS, Solaris, HP-UX, AIX and Windows.


OSSEC Features

OSSEC is a full platform to monitor and control your systems. It mixes together all the aspects of HIDS (host-based intrusion detection), log monitoring and SIM/SIEM together in a simple, powerful and open source solution. It is also backed and fully supported by Trend Micro.


Key Benefits:-

Compliance Requirements


OSSEC helps customers meet specific compliance requirements such as PCI, HIPAA etc. It lets customers detect and alert on unauthorized file system modifications and malicious behavior embedded in the log files of COTS products as well as custom applications. For PCI, it covers the sections of file integrity monitoring (PCI 11.5, 10.5), log inspection and monitoring (section 10) and policy enforcement/checking.


Multi platform

OSSEC lets customers implement a comprehensive host based intrusion detection system with fine grained application/server specific policies across multiple platforms such as Linux, Solaris, AIX, HP-UX, BSD, Windows, Mac and Vmware ESX.

Real-time and Configurable Alerts

OSSEC lets customers configure incidents they want to be alerted on which lets them focus on raising the priority of critical incidents over the regular noise on any system. Integration with smtp, sms and syslog allows customers to be on top of alerts by sending these on to e-mail and handheld devices such as cell phones and pagers. Active response options to block an attack immediately is also available.

Integration with current infrastructure

OSSEC will integrate with current investments from customers such as SIM/SEM (Security Incident Management/Security Events Management) products for centralized reporting and correlation of events.

Centralized management

OSSEC provides a simplified centralized management server to manage policies across multiple operating systems. Additionally, it also lets customers define server specific overrides for finer grained policies.

Agent and agentless monitoring

OSSEC offers the flexibility of agent based and agentless monitoring of systems and networking components such as routers and firewalls. It lets customers who have restrictions on software being installed on systems (such as FDA approved systems or appliances) meet security and compliance needs.

Key Features
File Integrity checking

There is one thing in common to any attack to your networks and computers: they change your systems in some way. The goal of file integrity checking (or FIM – file integrity monitoring) is to detect these changes and alert you when they happen. It can be an attack, or a misuse by an employee or even a typo by an admin, any file, directory or registry change will be alerted to you.

Covers PCI DSS sections 11.5 and 10.5.5.

Log Monitoring

Your operating system wants to speak to you, but do you know how to listen? Every operating system, application, and device on your network generate logs (events) to let you know what is happening. OSSEC collects, analyzes and correlates these logs to let you know if something wrong is going on (attack, misuse, errors, etc). Do you want to know when an application is installed on your client box? Or when someone changes a rule in your firewall? By monitoring your logs, OSSEC will let you know of that.

Covers PCI DSS section 10 in a whole.


Rootkit detection

Criminals (also known as hackers) want to hide their actions, but using rootkit detection you can be notified when they (or trojans, viruses, etc) change your system in this way.

Active response

Take immediate and automatic responses when something happens. Why wait for hours when you can alert your admin and block an attack right way?

OSSEC 2.7 Beta-1 Available
New features and bug fixes:
  1. Installation
    • Add hybrid mode – allows the same host to be both a server and an agent, useful for multi-tier OSSEC deployment.
    • Add ‘ manage_agents -f’ option for bulk generation of client keys from an input file.
  2. Syscheck
    • Add prelinking support – reduce confusion when a file change is the result of prelinking. (Beta-1: We realize there is a performance penalty. Please report if you notice a performance impact.)
  3. Rootcheck
    • Add fine-grained configuration control – allows you to turn ON/OFF individual rootcheck tasks for more efficiency and flexibility. The default is all ON.
  4. Log monitoring/analysis
    • Add GeoIP lookup support – allows geographical city names to be associated with IP addresses in OSSEC alerts, for more intelligent correlation. (Beta-1: Fixed potential string buffer overflow issues)
    • Add multi-line log readers for Linux auditd, plus ModSec and Regex log readers.
  5. Alert options and syslog output
    • Add syscheck MD5/SHA1 sum to alerts for easier integration with third-party file signature checking.
    • Support JSON and Splunk formats in syslog output.
  6. Rules and other notable changes/fixes
    • Windows 2000 logs support has been deprecated (but will probably still work fine). Vista and Windows Server 2008 logs are now officially supported.
    • Windows registry syscheck alert level has been reduced from 7 to 5 to reduce unnecessary noise from alerts which do not indicate a compromise.
    • Update decoders include: PIX, auditd, apache, pam, php…
    • Many updated rules, such as new checks for vulnerable web apps exploitation attempts.
    • Update rootcheck rules
    • ossec-client.sh now allows for ‘reload’, in addition to ‘restart’
    • Many bug fixes…
  7. Windows Agent 2.7 Beta-1

How to test the BETA?


Download the beta-1 package from here.

Source -







 
Support : Creating Website | Johny Template | Mas Template
Copyright © 2011. Turorial Grapich Design and Blog Design - All Rights Reserved
Template Created by Creating Website Published by Mas Template
Proudly powered by Blogger