The NetBSD Project

CVS log for pkgsrc/net/snort/Attic/Makefile.common

[BACK] Up to [cvs.NetBSD.org] / pkgsrc / net / snort

Request diff between arbitrary revisions


Default branch: MAIN


Revision 1.38, Sat Feb 17 21:45:18 2007 UTC (17 years, 2 months ago) by adrianp
Branch: MAIN
CVS Tags: pkgsrc-2013Q2-base, pkgsrc-2013Q2, pkgsrc-2012Q4-base, pkgsrc-2012Q4, pkgsrc-2011Q4-base, pkgsrc-2011Q4, pkgsrc-2011Q2-base, pkgsrc-2011Q2, pkgsrc-2009Q4-base, pkgsrc-2009Q4, pkgsrc-2008Q4-base, pkgsrc-2008Q4, pkgsrc-2008Q3-base, pkgsrc-2008Q3, pkgsrc-2008Q2-base, pkgsrc-2008Q2, pkgsrc-2008Q1-base, pkgsrc-2008Q1, pkgsrc-2007Q4-base, pkgsrc-2007Q4, pkgsrc-2007Q3-base, pkgsrc-2007Q3, pkgsrc-2007Q2-base, pkgsrc-2007Q2, pkgsrc-2007Q1-base, pkgsrc-2007Q1, cube-native-xorg-base, cube-native-xorg, HEAD
Changes since 1.37: +1 -1 lines
FILE REMOVED

Remove the now obsolete Makefile.common

Revision 1.37 / (download) - annotate - [select for diffs], Sun Jan 7 09:14:06 2007 UTC (17 years, 3 months ago) by rillig
Branch: MAIN
Changes since 1.36: +2 -2 lines
Diff to previous 1.36 (colored) to selected 1.12 (colored)

Mechanically replaced man/* with ${PKGMANDIR}/* in the definition of
INSTALLATION_DIRS, as well as all occurrences of ${PREFIX}/man with
${PREFIX}/${PKGMANDIR}.

Fixes PR 35265, although I did not use the patch provided therein.

Revision 1.36 / (download) - annotate - [select for diffs], Sun Jun 18 00:25:26 2006 UTC (17 years, 10 months ago) by rillig
Branch: MAIN
CVS Tags: pkgsrc-2006Q4-base, pkgsrc-2006Q4, pkgsrc-2006Q3-base, pkgsrc-2006Q3, pkgsrc-2006Q2-base, pkgsrc-2006Q2
Changes since 1.35: +2 -2 lines
Diff to previous 1.35 (colored) to selected 1.12 (colored)

Fixed a typo (SUBST_MESSAGE.cgi => SUBST_MESSAGE.paths) found by pkglint.

Revision 1.32.2.1 / (download) - annotate - [select for diffs], Tue Jun 6 23:46:35 2006 UTC (17 years, 10 months ago) by salo
Branch: pkgsrc-2006Q1
Changes since 1.32: +2 -2 lines
Diff to previous 1.32 (colored) next main 1.33 (colored) to selected 1.12 (colored)

Pullup ticket 1688 - requested by adrianp
security update for snort

Revisions pulled up:
- pkgsrc/net/snort/Makefile.common		1.35
- pkgsrc/net/snort/distinfo			1.35

   Module Name:		pkgsrc
   Committed By:	adrianp
   Date:		Tue Jun  6 18:51:52 UTC 2006

   Modified Files:
   	pkgsrc/net/snort: Makefile.common distinfo

   Log Message:
   Update to 2.4.5
   These releases have better performance, numerous new features and
   incorporate many bug fixes. Notable bug fixes and improvements include:

   * Tcp stream properly reassembled after failed sequence check,
     which may lead to possible detection evasion.
   * Added configurable stream flushpoints.
   * Improved rpc processing.
   * Improved portscan detection.
   * Improved http request processing and handling of possible
     evasion cases.
   * Improved performance monitoring.

Revision 1.35 / (download) - annotate - [select for diffs], Tue Jun 6 18:51:52 2006 UTC (17 years, 10 months ago) by adrianp
Branch: MAIN
Changes since 1.34: +2 -2 lines
Diff to previous 1.34 (colored) to selected 1.12 (colored)

Update to 2.4.5
These releases have better performance, numerous new features and
incorporate many bug fixes. Notable bug fixes and improvements include:

* Tcp stream properly reassembled after failed sequence check,
  which may lead to possible detection evasion.
* Added configurable stream flushpoints.
* Improved rpc processing.
* Improved portscan detection.
* Improved http request processing and handling of possible
  evasion cases.
* Improved performance monitoring.

Revision 1.34 / (download) - annotate - [select for diffs], Sun Apr 23 00:12:41 2006 UTC (17 years, 11 months ago) by jlam
Branch: MAIN
Changes since 1.33: +2 -2 lines
Diff to previous 1.33 (colored) to selected 1.12 (colored)

Modify packages that set PKG_USERS and PKG_GROUPS to follow the new
syntax as specified in pkgsrc/mk/install/bsd.pkginstall.mk:1.47.

Revision 1.33 / (download) - annotate - [select for diffs], Tue Apr 18 22:39:32 2006 UTC (18 years ago) by adrianp
Branch: MAIN
Changes since 1.32: +3 -3 lines
Diff to previous 1.32 (colored) to selected 1.12 (colored)

Add debug option
Suggested by Jason Miller in private email

Revision 1.29.2.1 / (download) - annotate - [select for diffs], Sat Mar 11 03:35:57 2006 UTC (18 years, 1 month ago) by snj
Branch: pkgsrc-2005Q4
Changes since 1.29: +3 -3 lines
Diff to previous 1.29 (colored) next main 1.30 (colored) to selected 1.12 (colored)

Pullup ticket 1212 - requested by Adrian Portelli
security update for snort

Revisions pulled up:
- pkgsrc/net/snort/distinfo		1.33, 1.34
- pkgsrc/net/snort/patches/patch-aa	1.13
- pkgsrc/net/snort/Makefile.common	1.32

   Module Name:    pkgsrc
   Committed By:   joerg
   Date:           Thu Feb 16 20:45:52 UTC 2006

   Modified Files:
           pkgsrc/net/snort: distinfo
           pkgsrc/net/snort/patches: patch-aa

   Log Message:
   Fix errno.
---
   Module Name:    pkgsrc
   Committed By:   adrianp
   Date:           Thu Mar  9 09:37:44 UTC 2006

   Modified Files:
           pkgsrc/net/snort: Makefile.common distinfo

   Log Message:
   Update to 2.4.4
   This includes the fix for:
           http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0839
   > +2006-02-20 Steven Sturges <ssturges@sourcefire.com>
   > +    * src/preprocessors/spp_frag3.c:
   > +    * configure.in:
   > +      Fix ip options handling.  Thanks to Vyacheslav Burdjanadze for
   > +      finding the issue.
   > +
   > +2006-01-09 Steven Sturges <ssturges@sourcefire.com>
   > +    * src/sfutil/mwm.c:
   > +      Fixed bug with multiple recurring patterns in Wu-Manbher
   > +      implementation.
   > +      Thanks to Evan Stawnyczy for pointing it out an Marc Norton for
   > +      the fix.
   > +    * src/parser/IpAddrSet.c:
   > +      Fixed problem with parsing conf file and rules when DNS is not
   > +      working.
   > +      Thanks Martin Olsson for mentioning this and testing the fix.
   > +    * src/preprocessors/spp_perfmonitor.c:
   > +    * src/preprocessors/perf-base.c:
   > +      Handle wrapping on 64-bit platforms
   > +
   > +2005-11-17 Andrew Mullican <amullican@sourcefire.com>
   > +    * src/sfutil/sfxhash.c:
   > +    * src/preprocessors/portscan.c:
   > +      Add tracker without using bogus data, to avoid internal buffer
   > +      overrun.
   > +      Thanks Sandro Poppi for the find.
   > +
   > +2005-11-11 Steven Sturges <ssturges@sourcefire.com>
   > +    * src/snort.c:
   > +      Allow value of 0 to be used with -G flag
   > +    * src/preprocessors/spp_bo.c:
   > +      Code Cleanup
   > +    * src/preprocessors/spp_frag3.c:
   > +      Fix memory leak and mishandling of IP Options.  Thanks Yin
   > +      Zhaohui for the find.

Revision 1.32 / (download) - annotate - [select for diffs], Thu Mar 9 09:37:44 2006 UTC (18 years, 1 month ago) by adrianp
Branch: MAIN
CVS Tags: pkgsrc-2006Q1-base
Branch point for: pkgsrc-2006Q1
Changes since 1.31: +3 -3 lines
Diff to previous 1.31 (colored) to selected 1.12 (colored)

Update to 2.4.4
This includes the fix for:
	http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0839
> +2006-02-20 Steven Sturges <ssturges@sourcefire.com>
> +    * src/preprocessors/spp_frag3.c:
> +    * configure.in:
> +      Fix ip options handling.  Thanks to Vyacheslav Burdjanadze for
> +      finding the issue.
> +
> +2006-01-09 Steven Sturges <ssturges@sourcefire.com>
> +    * src/sfutil/mwm.c:
> +      Fixed bug with multiple recurring patterns in Wu-Manbher implementation.
> +      Thanks to Evan Stawnyczy for pointing it out an Marc Norton for the
> +      fix.
> +    * src/parser/IpAddrSet.c:
> +      Fixed problem with parsing conf file and rules when DNS is not working.
> +      Thanks Martin Olsson for mentioning this and testing the fix.
> +    * src/preprocessors/spp_perfmonitor.c:
> +    * src/preprocessors/perf-base.c:
> +      Handle wrapping on 64-bit platforms
> +
> +2005-11-17 Andrew Mullican <amullican@sourcefire.com>
> +    * src/sfutil/sfxhash.c:
> +    * src/preprocessors/portscan.c:
> +      Add tracker without using bogus data, to avoid internal buffer overrun.
> +      Thanks Sandro Poppi for the find.
> +
> +2005-11-11 Steven Sturges <ssturges@sourcefire.com>
> +    * src/snort.c:
> +      Allow value of 0 to be used with -G flag
> +    * src/preprocessors/spp_bo.c:
> +      Code Cleanup
> +    * src/preprocessors/spp_frag3.c:
> +      Fix memory leak and mishandling of IP Options.  Thanks Yin
> +      Zhaohui for the find.

Revision 1.31 / (download) - annotate - [select for diffs], Tue Jan 3 17:34:40 2006 UTC (18 years, 3 months ago) by adrianp
Branch: MAIN
Changes since 1.30: +6 -1 lines
Diff to previous 1.30 (colored) to selected 1.12 (colored)

Include database schemas in the install
Bump snort{-mysql,-pgsql} to nb1

Revision 1.30 / (download) - annotate - [select for diffs], Thu Dec 29 06:22:03 2005 UTC (18 years, 3 months ago) by jlam
Branch: MAIN
Changes since 1.29: +1 -2 lines
Diff to previous 1.29 (colored) to selected 1.12 (colored)

Remove USE_PKGINSTALL from pkgsrc now that mk/install/pkginstall.mk
automatically detects whether we want the pkginstall machinery to be
used by the package Makefile.

Revision 1.29 / (download) - annotate - [select for diffs], Mon Dec 5 23:55:15 2005 UTC (18 years, 4 months ago) by rillig
Branch: MAIN
CVS Tags: pkgsrc-2005Q4-base
Branch point for: pkgsrc-2005Q4
Changes since 1.28: +2 -2 lines
Diff to previous 1.28 (colored) to selected 1.12 (colored)

Ran "pkglint --autofix", which corrected some of the quoting issues in
CONFIGURE_ARGS.

Revision 1.28 / (download) - annotate - [select for diffs], Mon Dec 5 20:50:49 2005 UTC (18 years, 4 months ago) by rillig
Branch: MAIN
Changes since 1.27: +3 -3 lines
Diff to previous 1.27 (colored) to selected 1.12 (colored)

Fixed pkglint warnings. The warnings are mostly quoting issues, for
example MAKE_ENV+=FOO=${BAR} is changed to MAKE_ENV+=FOO=${BAR:Q}. Some
other changes are outlined in

    http://mail-index.netbsd.org/tech-pkg/2005/12/02/0034.html

Revision 1.25.2.1 / (download) - annotate - [select for diffs], Mon Oct 24 00:05:11 2005 UTC (18 years, 5 months ago) by seb
Branch: pkgsrc-2005Q3
Changes since 1.25: +2 -2 lines
Diff to previous 1.25 (colored) next main 1.26 (colored) to selected 1.12 (colored)

Pullup ticket 848 - requested by Adrian Portelli
sync net/snort with HEAD, including a security update

Revisions pulled up:
- pkgsrc/net/snort/Makefile.common                            1.26, 1.27
- pkgsrc/net/snort/distinfo                                   1.31, 1.32

   Module Name:	pkgsrc
   Committed By:	adrianp
   Date:		Tue Oct 11 20:53:22 UTC 2005

   Modified Files:
   	pkgsrc/net/snort: Makefile.common distinfo

   Log Message:
   Update to 2.4.2
   - don't try to actually open the log file when in test mode
   - Fixes to address schema being a keyword in MySQL 5.0
---
   Module Name:	pkgsrc
   Committed By:	adrianp
   Date:		Tue Oct 18 15:15:04 UTC 2005

   Modified Files:
   	pkgsrc/net/snort: Makefile.common distinfo

   Log Message:
   Update to snort 2.4.3
   - Fixed potential buffer overflow in BackOrifice preprocessor and
     added an alert on attempt to overflow buffer in snort.  Thanks
     Andy Mullican for the fix.

Revision 1.27 / (download) - annotate - [select for diffs], Tue Oct 18 15:15:04 2005 UTC (18 years, 6 months ago) by adrianp
Branch: MAIN
Changes since 1.26: +2 -2 lines
Diff to previous 1.26 (colored) to selected 1.12 (colored)

Update to snort 2.4.3
- Fixed potential buffer overflow in BackOrifice preprocessor and
  added an alert on attempt to overflow buffer in snort.  Thanks
  Andy Mullican for the fix.

Revision 1.26 / (download) - annotate - [select for diffs], Tue Oct 11 20:53:22 2005 UTC (18 years, 6 months ago) by adrianp
Branch: MAIN
Changes since 1.25: +2 -2 lines
Diff to previous 1.25 (colored) to selected 1.12 (colored)

Update to 2.4.2
- don't try to actually open the log file when in test mode
- Fixes to address schema being a keyword in MySQL 5.0

Revision 1.25 / (download) - annotate - [select for diffs], Tue Sep 20 18:01:26 2005 UTC (18 years, 7 months ago) by adrianp
Branch: MAIN
CVS Tags: pkgsrc-2005Q3-base
Branch point for: pkgsrc-2005Q3
Changes since 1.24: +2 -3 lines
Diff to previous 1.24 (colored) to selected 1.12 (colored)

Update snort to 2.4.1
From the ChangeLog:
> 2005-09-16 - Snort 2.4.1 Released
> [*] New additions
>     * Added a -K command line option to manually select the logging mode using
>       a single switch.  The -b and -N switches will be deprecated in version
>       2.7.  Pcap logging is now the default for Snort at startup, use "-K ascii"
>       to revert to old behavior.
>
> [*] Improvements
>     * Win32 version now supports winpcap 3.1 and MySQL client 4.13.
>     * Added event on zero-length RPC fragments.
>     * Fixed TCP SACK processing for text based outputs that could result in a
>       DoS.
>     * General improvements to frag3 including Teardrop detection fix.
>     * Fixed a bug in the PPPoE decoder.
>     * Added patch for time stats from Bill Parker.  Enable with configure
>       --enable-timestats.
>     * Fixed IDS mode bailing at startup if logdir is specified in snort.conf
>       and /var/log/snort doesn't exist.
>     * Added decoder for IPEnc for OpenBSD.  Thanks Jason Ish for the patch
>       (long time ago) and Chris Kuethe for reraising the issue.
>     * Allow snort to use usernames (-u) and groupnames (-g) that include
>       numbers.  Thanks to Shaick for the patch.
>     * Fixed broken -T option.
>     * Change ip_proto to ip for portscan configuration.  Thanks David Bianco
>       for pointing this out.
>     * Fix for prelude initialization.  Thanks Yoann Vandoorselaere for the
>       update.
>     * For content matches, when subsequent rule options fail, start searching
>       again in correct location.
>     * Updated Win32 to handle pflog patch.
>     * Added support for new OpenBSD pflog format.  Older pflog format,
>       OpenBSD 3.3 and earlier is still supported.  Thanks Breno Leitao
>       and Christian Reis for the patch.
>     * Added statistics counter for ETH_LOOPBACK packets.  Thanks rmkml
>       for the patch.

Revision 1.24 / (download) - annotate - [select for diffs], Wed Sep 14 12:46:52 2005 UTC (18 years, 7 months ago) by adrianp
Branch: MAIN
Changes since 1.23: +2 -1 lines
Diff to previous 1.23 (colored) to selected 1.12 (colored)

Add patch from snort CVS to address a security issue:
	http://secunia.com/advisories/16786/
Whitespace police on MESSAGE
Bump to nb1

Revision 1.23 / (download) - annotate - [select for diffs], Tue Aug 23 11:48:50 2005 UTC (18 years, 7 months ago) by rillig
Branch: MAIN
Changes since 1.22: +2 -2 lines
Diff to previous 1.22 (colored) to selected 1.12 (colored)

The real user name in PKG_USERS does not need to be escaped with double
backslashes anymore. A single backslash is enough. Changed the
definition in all affected packages. For those that are not caught, an
additional check is placed into bsd.pkginstall.mk.

Revision 1.22 / (download) - annotate - [select for diffs], Fri Aug 19 18:12:38 2005 UTC (18 years, 8 months ago) by jlam
Branch: MAIN
Changes since 1.21: +6 -6 lines
Diff to previous 1.21 (colored) to selected 1.12 (colored)

Merge CONF_FILES/SUPPORT_FILES and CONF_FILES_PERMS/SUPPORT_FILES_PERMS
as the INSTALL and DEINSTALL scripts no longer distinguish between
the two types of files.  Drop SUPPORT_FILES{,_PERMS} and modify the
packages in pkgsrc accordingly.

Revision 1.21 / (download) - annotate - [select for diffs], Sat Aug 13 19:56:47 2005 UTC (18 years, 8 months ago) by adrianp
Branch: MAIN
Changes since 1.20: +5 -12 lines
Diff to previous 1.20 (colored) to selected 1.12 (colored)

Update snort to 2.4.0
If you are using this package make note of the distribution change
mentioned below.  I have update the MESSAGE to inform users of this and
there is now also a net/snort-rules package with the community rules.

> [*] Distribution Change
>     * Rules are no longer distributed as part of the Snort releases, they are
>       available as a separate download from snort.org.  This was done for
>       three reasons:
>         1) To better manage the new rules licensing.
>         2) To reduce the size of the engine download.
>         3) To move the thousands of documentation files for the rules into
>            the rules tarballs.  If you've ever checked Snort out of CVS you'll
>            know why this is a Good Thing.
>
> [*] New additions
>     * Added new IP defragmentation preprocessor, Frag3. The frag3 preprocessor
>       is a target-based IP defragmentation module, and is intended as a
>       replacement for the frag2 module.  Check out the README.frag3 for full
>       info on this new preprocessor.
>
>     * Libprelude support has been added (enable with --enable-prelude).
>       Thanks Yoann Vandoorselaere!
>
>     * An "ftpbounce" rule detection plugin was added for easier detection of
>       FTP bounce attacks.
>
>     * Added a new Snort config option, "ignore_ports," to ignore packets
>       based on port number.  This is similar to bpf filters, but done within
>       snort.conf.
>
> [*] Improvements
>     * Snort startup messages printed in syslog now contain a PID before each
>       entry. Thanks Sekure for initially bringing this up.
>
>     * Stream4: Performance improvements.
>
>     * Stream4: Added 'max_session_limit' option which limits number of
>       concurrent sessions tracked.  Added favor_old/favor_new options that
>       affect order in which packets are put together for reassembly.
>
>     * Stream4: New configuration options to manage flushpoints for improved
>       anti-evasion.  The flush_behavior option selects flushpoint management
>       mode.  New flush_base, flush_range, and flush_seed manage randomized
>       flushing.  Check out the snort.conf file for full config data on the
>       new flush options.
>
>     * Added two more alerts for BackOrifice client and server packets. This
>       allows specific alerts to be suppressed.
>
>     * PerfMon preprocessor updated to include more detailed stats for rebuilt
>       packets (applayer, wire, fragmented & TCP). Also added 'atexitonly'
>       option that dumps stats at exit of snort, and command line -Z flag to
>       specify the file to which stats are logged.
>
>     * Added new Http Inspect config item, "tab_uri_delimiter," which if
>       specified, lets a tab character (0x09) act as the delimiter for a URI.
>
>     * Added a '-G' command line flag to snort that specifies the Snort
>       instance log identifier. It takes a single argument that can be either
>       hex (prefaced with 0x) or decimal. The unified log files will include
>       the instance ID when the -G flag is used.
>
>     * "Same SRC/DST" (sid 527) and "Loopback Traffic" (sid 528) are now
>       handled in the IP decoder. Those sids are now considered obsolete.
>
>     * Http_Inspect "flow_depth" option now accepts a -1 value which tells
>       Snort to ignore all server-side traffic.
>
>     * RPMs have been updated to be more portable, and also now include a
>       "--with inline" option for those wanting to build Inline RPMs. Thanks
>       Daniel Wittenberg and JP Vossen for your help!
>
>     * Many, many bug fixes have also gone into this release, please see the
>       ChangeLog for details.

Revision 1.20 / (download) - annotate - [select for diffs], Wed Apr 27 18:36:25 2005 UTC (18 years, 11 months ago) by adrianp
Branch: MAIN
CVS Tags: pkgsrc-2005Q2-base, pkgsrc-2005Q2
Changes since 1.19: +3 -3 lines
Diff to previous 1.19 (colored) to selected 1.12 (colored)

- Update snort to 2.3.3
- Fix /var => ${VARBASE}
- Changes Include:
> * Issues with suppressing sfPortscan Open Ports have been fixed.
>
> * Added a new mini-preprocessor to catch the X-Link2State
>   vulnerability.  This preprocessor can be configured to drop the
>   offending connection when in Inline-mode. Please read snort.conf or
>   the snort manual for more details.  This preprocessor is enabled by
>   default in snort.conf.

Revision 1.19 / (download) - annotate - [select for diffs], Mon Apr 11 21:46:59 2005 UTC (19 years ago) by tv
Branch: MAIN
Changes since 1.18: +1 -2 lines
Diff to previous 1.18 (colored) to selected 1.12 (colored)

Remove USE_BUILDLINK3 and NO_BUILDLINK; these are no longer used.

Revision 1.18 / (download) - annotate - [select for diffs], Fri Mar 25 18:28:28 2005 UTC (19 years ago) by adrianp
Branch: MAIN
Changes since 1.17: +3 -3 lines
Diff to previous 1.17 (colored) to selected 1.12 (colored)

- Update snort from 2.3.0 -> 2.3.2

2005-03-10 - Snort 2.3.2 Released

* Removed end-of-line parser fix in favor of completely reworking
  this at the next parser overhaul.

2005-03-09 - Snort 2.3.1 Released

* Fixed issue where the number of flowbits were too small. Thanks Marc
  Norton for the fix.

* Fixed parsing of comments at end of line in config file.  In
  snort.conf, anything that follows a # on a line is considered a
  comment. Thanks Steve Sturges for the fix.

* Fixed alignment issue causing sfPortscan to crash on Solaris/HPUX.
  Thanks Andy Mullican for the fix. Thanks Senthil Prabu.S and
  Jonathan Miner for working with us on this.

Revision 1.16.2.1 / (download) - annotate - [select for diffs], Fri Feb 4 08:02:37 2005 UTC (19 years, 2 months ago) by salo
Branch: pkgsrc-2004Q4
Changes since 1.16: +2 -3 lines
Diff to previous 1.16 (colored) next main 1.17 (colored) to selected 1.12 (colored)

Pullup ticket 267 - requested by Adrian Portelli
security fix for snort

Revisions pulled up:
- pkgsrc/net/snort/Makefile.common  1.17
- pkgsrc/net/snort/PLIST            1.18
- pkgsrc/net/snort/distinfo         1.24
- pkgsrc/net/snort-mysql/Makefile   1.12
- pkgsrc/net/snort-contrib/DESCR    removed
- pkgsrc/net/snort-contrib/Makefile removed
- pkgsrc/net/snort-contrib/PLIST    removed
- pkgsrc/net/snort-contrib/distinfo removed

   Module Name:		pkgsrc
   Committed By:	adrianp
   Date:		Fri Jan 28 23:02:41 UTC 2005

   Modified Files:
   	pkgsrc/net/snort: Makefile Makefile.common PLIST

   Log Message:
   Update to snort 2.3.0

   2005-01-25 - Snort 2.3.0 Final Released

   * Fixed issue with sfPortscan reporting incorrect IP datagram length.
     Thanks Jon Hart for the test case and finding the bug, and Marc Norton
     for resolving the issue.

   * Threshold/Suppression now prints properly when logging to syslog.
     Thanks Sekure for pointing out the problem. Thanks Steve Sturges for
     working on the fix.

   * Threshold memcap argument now correctly handles non-integer input.
     Thanks nnposter for the patch.

   * Fixed issue reported by Allan Jensen, where on MacOS X, ppp links were
     not decoded properly. Thanks Dan Roelker for the fix.

   * Snort manual and FAQ are updated for 2.3. Thanks Jen Harvey for your
     work on putting it all together.

   2004-12-15 - Snort 2.3.0 RC2 Released

   * Small performance improvement to arpspoof and also fixed a problem
     where the list of configured IP/MAC entries would contain only one
     entry and leaked memory (Jeff Nathan).

   * Fixed a problem affecting MacOS X where linking may fail with
     non-standard libraries when global symbols are encountered multiple
     times (Jeff Nathan).

   * Ignore RST|ACK midstream pickup case so we don't get an evasive TCP
     alerts.  Thanks for the report, Sekure. Thanks Dan Roelker for the fix.

   * Moved CheckLogDir() to after parsing snort.conf (for IDS mode) so the
     logdir config will work if the default or command-line logdir does not
     exist on the system. Thanks Dan Roelker.

   * Fixed bug when setting the doe_ptr on a successful pcre match.
     It is now set relative to base_ptr. Thanks Steve Sturges for the
     fix.

   * Added from_beginning and multiplier options for byte_jump.
     from_beginning skips bytes from the beginning of the content,
     instead of from the location immediately following the number
     of bytes to skip.  multiplier takes a numeric argument, and
     skips x times that number of bytes. Thanks again to Steve Sturges.

   * In "fast" output, now log only actual packet contents when UDP
     data length is greater than actual data length. Thanks Brian
     Caswell for spotting this, and Andrew Mullican for working on the fix.

   * Please check the ChangeLog for further details.

   2004-11-18 - Snort 2.3.0 RC1 Released

   * Added IPS functionality from Snort-Inline.  A big thanks to the
     Snort-Inline guys (Jed Haile, Rob McMillen, William Metcalf, and Victor
     Julien).  Also, Thanks Dan Roelker for doing the integrating of
     Snort-Inline into the official Snort project.

   * Added new portscan detector.  The design and implementation was headed
     up by Dan Roelker, and included Marc Norton and Jeremy Hewlett.

   * Numerous changes for better 64bit Snort support from Jeremy Hewlett and
     Marc Norton.  Additionally, an --enable-64bit-gcc option was added to
     configure.  However, there are still some memory alignment issues to
     work out before 64bit mode is fully functional, patches are welcomed.
     Thanks Chris Baker for doing 64bit testing.

   * Added not_established keyword to the flow detection option.  This allows
     snort to do dynamic firewall rulesets.  Experimental for now.

   * Added an enforce_state keyword to stream4 so we won't pick up midstream
     sessions.  This works well for asynchronous links and also for
     just monitoring legitimate traffic.

   * Relocated ./contrib files to http://www.snort.org/dl/contrib as many
     are not maintained by Sourcefire and are out of date. The rpm and
     schema files have been relocated in their respective 'rpm' and 'schemas'
     directories under the snort parent directory.

   * perfmonitor config line can now be configured with "accumulate" or
     "reset."  Thanks Marc Norton for the feature, and Barry Basselgia for
     pointing out the issue.  Thanks Scott Dexter and Andreas Ostling for
     doing some initial testing.

   * Fixed 64-bit bug in sfmemcap.c found and tested by Ryan Matteson
     and Clay McClure.  Thanks guys.

   * Fixed reference times to match log time for first packet, for an event
     generated by a reassembled packet.  Incremented event ID to give
     unique ID for each packet.  Also made unified logging compatible with
     Windows.  Thanks Andrew Mullican for the fix.

   * Fixed linux perfmonitoring stats for the 2.6 kernel.  Thanks to
     everyone that reported this bug.  Thanks Dan Roelker for the fix.

   * Get thresholding/suppression to work for alerts that do not
     contain an ip header (primarily decode alerts).  Thanks
     Brian Caswell.

   * Fix conditions where snort would log double web alerts that
     contained only content options (no uricontents).  Thanks to kawa for
     finding and reporting this bug.

   * Fix suppression/thresholding bug for non-rule alerts.  Thanks to
     Alex Butcher for reporting it to us.

   * Many other bug fixes, please check the ChangeLog for details.
---
   Module Name:		pkgsrc
   Committed By:	taca
   Date:		Sat Jan 29 03:27:58 UTC 2005

   Modified Files:
   	pkgsrc/net/snort: distinfo

   Log Message:
   Update distinfo for snort-2.3.0.
---
   Module Name:		pkgsrc
   Committed By:	adrianp
   Date:		Fri Jan 28 23:03:59 UTC 2005

   Modified Files:
   	pkgsrc/net/snort-mysql: Makefile

   Log Message:
   Sync and minor tidy up for snort 2.3.0 release.
---
   Module Name:		pkgsrc
   Committed By:	adrianp
   Date:		Fri Jan 28 22:51:27 UTC 2005

   Removed Files:
   	pkgsrc/net/snort-contrib: DESCR Makefile PLIST distinfo

   Log Message:
   As of snort 2.3.0 all contrib files are now available from:
   http://www.snort.org/dl/contrib/

Revision 1.17 / (download) - annotate - [select for diffs], Fri Jan 28 23:02:41 2005 UTC (19 years, 2 months ago) by adrianp
Branch: MAIN
CVS Tags: pkgsrc-2005Q1-base, pkgsrc-2005Q1
Changes since 1.16: +2 -3 lines
Diff to previous 1.16 (colored) to selected 1.12 (colored)

Update to snort 2.3.0

2005-01-25 - Snort 2.3.0 Final Released

* Fixed issue with sfPortscan reporting incorrect IP datagram length.
  Thanks Jon Hart for the test case and finding the bug, and Marc Norton
  for resolving the issue.

* Threshold/Suppression now prints properly when logging to syslog.
  Thanks Sekure for pointing out the problem. Thanks Steve Sturges for
  working on the fix.

* Threshold memcap argument now correctly handles non-integer input.
  Thanks nnposter for the patch.

* Fixed issue reported by Allan Jensen, where on MacOS X, ppp links were
  not decoded properly. Thanks Dan Roelker for the fix.

* Snort manual and FAQ are updated for 2.3. Thanks Jen Harvey for your
  work on putting it all together.

2004-12-15 - Snort 2.3.0 RC2 Released

* Small performance improvement to arpspoof and also fixed a problem
  where the list of configured IP/MAC entries would contain only one
  entry and leaked memory (Jeff Nathan).

* Fixed a problem affecting MacOS X where linking may fail with
  non-standard libraries when global symbols are encountered multiple
  times (Jeff Nathan).

* Ignore RST|ACK midstream pickup case so we don't get an evasive TCP
  alerts.  Thanks for the report, Sekure. Thanks Dan Roelker for the fix.

* Moved CheckLogDir() to after parsing snort.conf (for IDS mode) so the
  logdir config will work if the default or command-line logdir does not
  exist on the system. Thanks Dan Roelker.

* Fixed bug when setting the doe_ptr on a successful pcre match.
  It is now set relative to base_ptr. Thanks Steve Sturges for the
  fix.

* Added from_beginning and multiplier options for byte_jump.
  from_beginning skips bytes from the beginning of the content,
  instead of from the location immediately following the number
  of bytes to skip.  multiplier takes a numeric argument, and
  skips x times that number of bytes. Thanks again to Steve Sturges.

* In "fast" output, now log only actual packet contents when UDP
  data length is greater than actual data length. Thanks Brian
  Caswell for spotting this, and Andrew Mullican for working on the fix.

* Please check the ChangeLog for further details.

2004-11-18 - Snort 2.3.0 RC1 Released

* Added IPS functionality from Snort-Inline.  A big thanks to the
  Snort-Inline guys (Jed Haile, Rob McMillen, William Metcalf, and Victor
  Julien).  Also, Thanks Dan Roelker for doing the integrating of
  Snort-Inline into the official Snort project.

* Added new portscan detector.  The design and implementation was headed
  up by Dan Roelker, and included Marc Norton and Jeremy Hewlett.

* Numerous changes for better 64bit Snort support from Jeremy Hewlett and
  Marc Norton.  Additionally, an --enable-64bit-gcc option was added to
  configure.  However, there are still some memory alignment issues to
  work out before 64bit mode is fully functional, patches are welcomed.
  Thanks Chris Baker for doing 64bit testing.

* Added not_established keyword to the flow detection option.  This allows
  snort to do dynamic firewall rulesets.  Experimental for now.

* Added an enforce_state keyword to stream4 so we won't pick up midstream
  sessions.  This works well for asynchronous links and also for
  just monitoring legitimate traffic.

* Relocated ./contrib files to http://www.snort.org/dl/contrib as many
  are not maintained by Sourcefire and are out of date. The rpm and
  schema files have been relocated in their respective 'rpm' and 'schemas'
  directories under the snort parent directory.

* perfmonitor config line can now be configured with "accumulate" or
  "reset."  Thanks Marc Norton for the feature, and Barry Basselgia for
  pointing out the issue.  Thanks Scott Dexter and Andreas Ostling for
  doing some initial testing.

* Fixed 64-bit bug in sfmemcap.c found and tested by Ryan Matteson
  and Clay McClure.  Thanks guys.

* Fixed reference times to match log time for first packet, for an event
  generated by a reassembled packet.  Incremented event ID to give
  unique ID for each packet.  Also made unified logging compatible with
  Windows.  Thanks Andrew Mullican for the fix.

* Fixed linux perfmonitoring stats for the 2.6 kernel.  Thanks to
  everyone that reported this bug.  Thanks Dan Roelker for the fix.

* Get thresholding/suppression to work for alerts that do not
  contain an ip header (primarily decode alerts).  Thanks
  Brian Caswell.

* Fix conditions where snort would log double web alerts that
  contained only content options (no uricontents).  Thanks to kawa for
  finding and reporting this bug.

* Fix suppression/thresholding bug for non-rule alerts.  Thanks to
  Alex Butcher for reporting it to us.

* Many other bug fixes, please check the ChangeLog for details.

Revision 1.16 / (download) - annotate - [select for diffs], Tue Sep 21 15:50:26 2004 UTC (19 years, 6 months ago) by adrianp
Branch: MAIN
CVS Tags: pkgsrc-2004Q4-base
Branch point for: pkgsrc-2004Q4
Changes since 1.15: +5 -3 lines
Diff to previous 1.15 (colored) to selected 1.12 (colored)

- Update snort to 2.2.0
- ok'ed snj@, wiz@
- Install database scripts which goes a part-way to addressing PR 18996

Updated database schema diagram from Chris Reid. Schema can be found in
./doc/snort_schema_v106.pdf
Added --include-pcre* configuration option to help cross compiling. Thanks
Erik de Castro Lopo.
Fixed thresholding/suppression issue with queuing multiple events per packet.
Thanks Andreas Ostling.
When a rebuilt stream causes an alert, log out the original packets instead of
the rebuilt packet. Thanks sekure@gmail.com for the report.
Turned off http_inspect alerts that were causing false positives in the preset
webserver profiles (Thanks Dan Roelker).
Turn off encoding alerts in HTTP parameter field. The parameter field is still
normalized, it just doesn't alert. This helps reduce alerts that are generated
from complex parameter queries (Thanks Dan Roelker).
Fixed memory leak in "fast" output. Thanks for your bug report
sekure@gmail.com.
Clear error code which under Windows was causing a subsequent false failure in
parsing threshold rules. (Thanks to Rich Adamson)

Further details can be found in Changelog and RELEASE.NOTES.

Revision 1.15 / (download) - annotate - [select for diffs], Thu Jul 1 17:10:22 2004 UTC (19 years, 9 months ago) by adrianp
Branch: MAIN
CVS Tags: pkgsrc-2004Q3-base, pkgsrc-2004Q3
Changes since 1.14: +10 -7 lines
Diff to previous 1.14 (colored) to selected 1.12 (colored)

- Upgrade snort to 2.1.3
- Grab maintainership of the package (with ok of previous owner)
- Use SUBST_* code

Ok'ed wiz@, snj@, salo@

From the changelog:

2004-05-06 Daniel Roelker <droelker@sourcefire.com>

    * src/detection-plugins/sp_pattern_match.c:
      Fixed rule read up error when parsing hexmode content options.
      Thanks for pointing it out Toni Maatta.  (Roelker)

    * src/preprocessors/spp_stream4.c:
       Fixed null pointer dereference when detect_scans were enabled and
       creating a new session that had funky flags.  Thanks to Chad
       Kreimendahl for reporting the bug and testing the fix.  (Roelker)

2004-04-20 Daniel Roelker <droelker@sourcefire.com>

    * src/event_queue.c:
    * src/event_queue.h:
    * src/sfutil/sfeventq.c:
    * src/sfutil/sfeventq.h:
      Added multi-event queueing in Snort.  Snort now supports logging
      multiple events per packet, and prioritizing those events using
      different methods.  Thanks to H.D. Moore for illustrating event
      obfuscations when snort only logged one event per packet. (Roelker)

    * src/snort.c:
    * src/decode.c:
    * src/detect.c:
    * src/fpcreate.c:
    * src/fpdetect.c:
    * src/preprocessors/spp_arpspoof.c:
    * src/preprocessors/spp_bo.c:
    * src/preprocessors/spp_frag2.c:
    * src/preprocessors/snort_httpinspect.c:
    * src/preprocessors/spp_rpc_decode.c:
    * src/preprocessors/spp_stream4.c:
      Updated event generators to use new event queueing sytem.  (Roelker)

    * src/output-plugins/spo_alert_fast.c:
      Added newline to 'cmg' alert output, so IP decode is easier to
      read.  (Roelker)

    * src/output-plugins/spo_database.c:
      Updated how current/utc times are calculated, as well as how they are
      formatted, thanks Marcus Janoski.  (Reid)

    * src/parser.c:
      Error on unterminated IP lists.  Added 'config event_queue' parameter.
      Configuration changes to 'config checksum_mode' for specifying
      which checksums to do.  (Norton)

    * src/plugbase.h:
      Fixes from Chris Reid for timestamp routines.  (Reid)

    * src/tag.c:
      Revert to old tag functionality.  Will add proposed tagging
      configurations in the future.  (Roelker)

Revision 1.14 / (download) - annotate - [select for diffs], Sat Apr 10 03:09:45 2004 UTC (20 years ago) by snj
Branch: MAIN
CVS Tags: pkgsrc-2004Q2-base, pkgsrc-2004Q2
Changes since 1.13: +5 -5 lines
Diff to previous 1.13 (colored) to selected 1.12 (colored)

Update to snort-2.1.2.  From Adrian Portelli in PR pkg/25029.

While here, convert to buildlink3.

Changes:
* Various portability fixes.
* Fixed conversation parsing faults so users can operate this
  preprocessor
* Detect non-rfc standard chunk encodings.  Detect abnormal HTTP
  requests with newlines, spaces, etc. before the request method.
* Fix negative stats output on snort exit or SIGUSR1.
* Removed escaping of '%' and '_' characters in MySQL
* Various documentation fixes/updates.
* Added Flowbits detection functionality.
* Added utility to parse out perfmon stats.
* Tagged Packets no longer have NULL msg name.
* Fixed http_inspect double alerting on pkts and rebuilt streams.
* http_inspect proxy_alert now supports normal proxy networks setups.
  http_inspect default server only valid if specified in config.
* Close Socket when Snort receives SIGHUP.
* Added GID, SID, and Rev to csv output.
* config chroot readded.
* Added additional error checking for custom rules.
* Flow now honors -q (quiet).
* Removed non_rfc_chars from default profiles.
* Added suppression negation.
* Better support for ODBC.  Better memory management. Improved escaping
  of SQL strings.
* Other miscellaneous bugfixes.

Revision 1.13 / (download) - annotate - [select for diffs], Wed Dec 31 14:11:42 2003 UTC (20 years, 3 months ago) by salo
Branch: MAIN
CVS Tags: pkgsrc-2004Q1-base, pkgsrc-2004Q1
Changes since 1.12: +23 -8 lines
Diff to previous 1.12 (colored)

Update to version 2.1.0.

Changes:

2.1.0:
======
- A new connection tracking module, Flow (replaces conversation)
- A new portscan detector based off of Flow, Flow-Portscan (replaces
  portscan2)
- A new http preprocessor, HttpInspect (replaces http_decode)
- Alert Thresholding and Suppression
- PCRE rule keyword (Perl Compat Regular Expressions)
- isdataat rule keyword (buffer length detection)
- A ton of new and updated rules.

2.0.6:
======
- 64-bit update for detection engine. (Thanks, Silio d'Angelo)
- Added better PPP decoding. (Thanks Jesper Peterson)
- Updated ip_proto optimization for high-speed detection engine.
- Fixed infinite loop problem that was introduced by the recursive pattern
  matching patch. Reported by Lawrence Reed, thanks for testing out the
  changes for us!
- Various changes to help respond (version 1) work a little better.
- spp_http_decode 64-bit patch from Dirk Mueller.
- Out-of-order ACK problem from Andrew Rucker. Also, updated stream4 to the
  most recent version from HEAD.
- Minor fixes to tagging related to 'src' and 'dst' directives
- When counting one byte patterns in 'ningroup' added a check for
  psLen==1 (wu-manber pattern matcher). Thanks Josh Sakofsky and Dennis
  McGuire for helping us test this.

2.0.5:
======
- Stream4 fixes from Andrew Rucker Jones.
- Allow memcap to be configured for threshold features.

2.0.4:
======
- Fixed a core dump introduced with 2.0.3 when dealing with negated patterns

2.0.3:
======
- doe_ptr handling in byte_test/byte_jump slightly modified to work
  better with the pcre patch
- content processing is now recursive to make distance/within processing
  better ( thanks to Shai Rubin for patch! )
- fixed a bug in the mwm.c pattern matcher that resulted in some alerts
  not firing in a particular configuration of rules

2.0.2:
======
- Added Thresholding and Suppression features (Marc Norton/Sourcefire)
- Fixed TCP RST processing bug found (Shai Rubin)
- Cleanup of spp_arpspoof (Jeff Nathan)
- Cleanup of win32 version including proper Event Log support (Chris Reid)
- Munged data fixes for stream4 (Chris Green)

Revision 1.12 / (download) - annotate - [selected], Tue Sep 23 15:43:50 2003 UTC (20 years, 6 months ago) by salo
Branch: MAIN
CVS Tags: pkgsrc-2003Q4-base, pkgsrc-2003Q4
Changes since 1.11: +11 -11 lines
Diff to previous 1.11 (colored)

Update to version 2.0.2.

Patch from Adrian Portelli via PR pkg/22900.

Changes:

- Added Thresholding and Suppression features (Marc Norton/Sourcefire)
- Fixed TCP RST processing bug found (Shai Rubin)
- Cleanup of spp_arpspoof (Jeff Nathan)
- Cleanup of win32 version including proper Event Log support (Chris Reid)
- Munged data fixes for stream4 (Chris Green)

Revision 1.11 / (download) - annotate - [select for diffs], Sat Jul 26 11:13:16 2003 UTC (20 years, 8 months ago) by salo
Branch: MAIN
Changes since 1.10: +6 -3 lines
Diff to previous 1.10 (colored) to selected 1.12 (colored)

Updated to version 2.0.1.

Changes:

- fix host endianess problem in udp decoder
- vlan decoding fixes from Michael Pomraning
- add tcp state checking to httpflow
- ignoring bad checksums throughout snort if checksumming is turned on
- config disable_ttcp_alerts is now also config disable_tcpopt_ttcp_alerts
- better initialization handling of low memory conditions pointing to the
- low memory search engine
- byte_jump / byte_test 2 byte cases handled and unified
- correctly assign port numbers on tcpoption events
- pass rule logic changed to "win" in specific multiple event cases
- named interface support for win32 from the winpcap folks
- spp_bo now also will work with log-only output plugins
- added window detection plugin documentation to manual
- lots of new rules and tons of rule documentation

Revision 1.10 / (download) - annotate - [select for diffs], Thu Jul 17 22:51:52 2003 UTC (20 years, 9 months ago) by grant
Branch: MAIN
Changes since 1.9: +2 -2 lines
Diff to previous 1.9 (colored) to selected 1.12 (colored)

s/netbsd.org/NetBSD.org/

Revision 1.6.2.3 / (download) - annotate - [select for diffs], Sun Apr 20 09:59:37 2003 UTC (21 years ago) by grant
Branch: netbsd-1-6-1
Changes since 1.6.2.2: +2 -1 lines
Diff to previous 1.6.2.2 (colored) to branchpoint 1.6 (colored) next main 1.7 (colored) to selected 1.12 (colored)

Pull up revision 1.9 (requested by salo in ticket #1258):

Bump PKGREVISION: honour PKG_SYSCONFDIR for real.  (i thought i fixed this
                  before but apparently i did not :/)

Revision 1.9 / (download) - annotate - [select for diffs], Wed Apr 16 15:51:22 2003 UTC (21 years ago) by salo
Branch: MAIN
Changes since 1.8: +2 -1 lines
Diff to previous 1.8 (colored) to selected 1.12 (colored)

Bump PKGREVISION: honour PKG_SYSCONFDIR for real.  (i thought i fixed this
                  before but apparently i did not :/)

Revision 1.6.2.2 / (download) - annotate - [select for diffs], Wed Apr 16 15:43:45 2003 UTC (21 years ago) by grant
Branch: netbsd-1-6-1
Changes since 1.6.2.1: +8 -12 lines
Diff to previous 1.6.2.1 (colored) to branchpoint 1.6 (colored) to selected 1.12 (colored)

Pull up revision 1.8 (requested by salo in ticket #1257):

Updated to version 2.0.0.
[security fix]

Revision 1.8 / (download) - annotate - [select for diffs], Wed Apr 16 06:37:19 2003 UTC (21 years ago) by salo
Branch: MAIN
Changes since 1.7: +8 -12 lines
Diff to previous 1.7 (colored) to selected 1.12 (colored)

Updated to version 2.0.0.

IMPORTANT: This version fixes remotely exploitable heap overflow in the stream4
           preprocessor module.

Advisory:  http://www.coresecurity.com/common/showdoc.php?idx=313&idxseccion=10

Changes:

2.0.0:
======
- Enhanced high-performance detection engine
- Stateful Pattern Matching
- New detection keywords: byte_test & byte_jump
- The Snort code base has undergone an external third party professional
  security audit funded by Sourcefire (http://www.sourcefire.com)
- Many new and updated rules
- snort.conf has been updated
- Enhancements to self preservation mechanisms in stream4 and frag2
- State tracking fixes in stream4
- New HTTP flow analyzer
- Enhanced protocol decoding (TCP options, 802.1q, etc)
- Enhanced protocol anomaly detection (IP, TCP, UDP, ICMP, RPC, HTTP, etc)
- Enhanced flexresp mode for real-time TCP session sniping
- Better chroot()'ing
- Tagging system updated
- Several million bugs addressed....
- Updated FAQ (thanks to Erek Adams and Dragos Ruiu) Snort 2.0 can be
  downloaded at http://www.snort.org/dl/snort-2.0.0.tar.gz. Binary
  versions of the codebase will be built over the next several days and
  made available at here.

2.0.rc4:
========
- byte_jump/byte_test don't force relative content options
- byte_jump/byte_test absolute offsets work
- Better FIN handling in Stream4

2.0.rc3:
========
- A low memory usage detection method (enabled via "config detection:
  search-method lowmem")
- Moved the default unix socket location to LOGDIR

2.0.rc2:
========
- syslog should work on win32 and unix
- major tagging updates
- new UDP decoding alerts
- snort.conf updates

2.0.rc1:
========
- Higher performance (due to a new pattern matcher and rebuilt detection
  engine)
- Better decoders
- Enhanced stream reassembly and defragmentation
- Tons of bug fixes
- Updated rules
- Updated snort.conf
- New detection keywords (byte_test, byte_jump, distance, within) &
  stateful pattern matching
- New HTTP flow analyzer
- Enhanced anomaly detection (HTTP, RPC, TCP, IP, etc)
- Better self preservation in stateful subsystems
- Xrefs fixed
- Flexresp works faster and more effectively
- Better chroot()'ing
- Fixed 802.1q decoding
- Better async state handling
- New alerting option: -A cmg!!

Revision 1.6.2.1 / (download) - annotate - [select for diffs], Fri Mar 7 07:46:24 2003 UTC (21 years, 1 month ago) by jmc
Branch: netbsd-1-6-1
Changes since 1.6: +45 -19 lines
Diff to previous 1.6 (colored) to selected 1.12 (colored)

Pullup rev 1.7 (from ticket 1192 requested by salo)
 Snort RPC preprocessing buffer overflow when decoding fragmented RPC
 records (http://www.kb.cert.org/vuls/id/916785).
 Versions affected <1.9.1.

Revision 1.7 / (download) - annotate - [select for diffs], Tue Mar 4 01:02:25 2003 UTC (21 years, 1 month ago) by salo
Branch: MAIN
Changes since 1.6: +45 -19 lines
Diff to previous 1.6 (colored) to selected 1.12 (colored)

Updated to version 1.9.1.

This version fixes the buffer overflow issue noted in:

  http://www.kb.cert.org/vuls/id/916785

Changes:

 - follow PKG_SYSCONFDIR
 - added rc.d script
 - create own user and group
 - added MESSAGE with post-install instructions
 - removed DEINSTALL
 - minor cleanups (this package was really half-baked..)

1.9.1:
======
 - src/preprocessors/spp_rpc_decode.c (PreprocRpcDecode):
	- alignment errors on non-x86 platforms
	- added new space delimited options
	  alert_fragments
	  no_alert_multiple_requests
	  no_alert_large_fragments
	  no_alert_incomplete
 - corrected buffer overflow in fragment normalization
 - src/snort.c
	- Win32 '-s' parameter wasn't configured to accept an optarg,
	  but code expected one, causing null-pointer violation.
 - Backport of 2.0 fixes for stream4 ( off by one errors on reassembly )

Revision 1.6 / (download) - annotate - [select for diffs], Sat Nov 9 13:44:43 2002 UTC (21 years, 5 months ago) by wiz
Branch: MAIN
CVS Tags: netbsd-1-6-1-base
Branch point for: netbsd-1-6-1
Changes since 1.5: +1 -2 lines
Diff to previous 1.5 (colored) to selected 1.12 (colored)

COMMENT should be set in Makefile, not any common Makefile parts.

Revision 1.5 / (download) - annotate - [select for diffs], Sun Oct 13 04:42:12 2002 UTC (21 years, 6 months ago) by hubertf
Branch: MAIN
Changes since 1.4: +13 -13 lines
Diff to previous 1.4 (colored) to selected 1.12 (colored)

Update snort to 1.9.0. Changes:
Lots of new rules, extended analyzing of packages etc.

Fixes PR 18637 by Adrian Portelli <adrianp@stindustries.net>

Revision 1.4 / (download) - annotate - [select for diffs], Thu Oct 10 12:28:24 2002 UTC (21 years, 6 months ago) by wiz
Branch: MAIN
Changes since 1.3: +3 -3 lines
Diff to previous 1.3 (colored) to selected 1.12 (colored)

Use BUILDLINK_PREFIX.libpcap.

Revision 1.3 / (download) - annotate - [select for diffs], Thu Oct 10 12:20:23 2002 UTC (21 years, 6 months ago) by wiz
Branch: MAIN
Changes since 1.2: +1 -3 lines
Diff to previous 1.2 (colored) to selected 1.12 (colored)

Remove libpcap buildlink.mk inclusion -- it's included in all the files that
include this file.

Revision 1.2 / (download) - annotate - [select for diffs], Mon Jul 15 14:41:26 2002 UTC (21 years, 9 months ago) by wiz
Branch: MAIN
CVS Tags: pkgviews-base, pkgviews, netbsd-1-6-RELEASE-base, netbsd-1-6
Changes since 1.1: +2 -2 lines
Diff to previous 1.1 (colored) to selected 1.12 (colored)

Update to 1.8.7, prompted by Mipam.
Changes:
The main purpose of this release is a stable target with many fragroute
and tcp connection oriented fixes.  This is also the last release of the
1.8.7 line and signals the start of the beta cycle for the 1.9 branch.

Revision 1.1 / (download) - annotate - [select for diffs], Mon Apr 15 08:31:16 2002 UTC (22 years ago) by rh
Branch: MAIN
CVS Tags: buildlink2-base, buildlink2
Diff to selected 1.12 (colored)

Remove SNORT_USE_PGSQL option.  This will be split out into a separate
package.  For that purpose, move most of Makefile into a new
Makefile.common.

This form allows you to request diff's between any two revisions of a file. You may select a symbolic revision name using the selection box or you may type in a numeric name using the type-in text box.




CVSweb <webmaster@jp.NetBSD.org>