Sourcefire VRT Rules Update

Date: 2011-02-10

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2.9.0.4.

The format of the file is:

sid - Message (rule group, priority)

New rules:
18458 <-> BOTNET-CNC Night Dragon initial beacon (botnet-cnc.rules, High)
18459 <-> BOTNET-CNC Night Dragon keepalive message (botnet-cnc.rules, High)

Updated rules:
15357 <-> WEB-CLIENT Adobe PDF JBIG2 remote code execution attempt (web-client.rules, High)