cipherdyne.org

Michael Rash, Security Researcher



Software Release - psad-2.0.1

psad-2.0.1 release The 2.0.1 release of psad is ready for download. This is mostly a bugfix release to correct some issue with respect to how psad modifies the @INC directory list to import psad-specific perl modules. There is one feature addition though - psad now adds a new keyword psad_ip_len to the Snort rules language to allow the length field in the IP header to be explicitly tested. This made it possible to add a new signature for the Nachi worm to the /etc/psad/signatures file. Here is the ChangeLog:
  • Added Nachi worm reconnaisannce icmp signature.
  • Added the psad_ip_len signature keyword to allow the length field in the IP header to be explicitly tested.
  • Bugfix for inappropriately removing some directories in @INC when splicing in psad perl module paths.
  • Switched nf2csv installation path in install.pl to /usr/bin/.