Sourcefire VRT Rules Update

Date: 2009-03-10

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2.7.

The format of the file is:

sid - Message (rule group, priority)

Updated rules:
13948 <-> DNS large number of NXDOMAIN replies - possible DNS cache poisoning (dns.rules, Medium)
13949 <-> DNS excessive outbound NXDOMAIN replies - possible spoof of domain run by local DNS servers (dns.rules, Medium)