Sourcefire VRT Rules Update

Date: 2010-04-13

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version CURRENT.

The format of the file is:

sid - Message (rule group, priority)

New rules:
16538 <-> NETBIOS NT QUERY SECURITY DESC flowbit (netbios.rules, Low)

Updated rules:
16287 <-> SPECIFIC-THREATS SMB Negotiate Protocol response DoS attempt (specific-threats.rules, Medium)
16453 <-> SPECIFIC-THREATS SMB Negotiate Protocol response DoS attempt - empty SMB 1 (specific-threats.rules, Medium)
16454 <-> SPECIFIC-THREATS SMB Negotiate Protocol response DoS attempt - empty SMB 2 (specific-threats.rules, Medium)