12 December, 2006

The 2.0.1 release of
psad is ready for
download. This is mostly a
bugfix release to correct some issue with respect to how psad modifies the @INC
directory list to import psad-specific perl modules. There is one feature addition
though - psad now adds a new keyword
psad_ip_len to the Snort rules language
to allow the length field in the IP header to be explicitly tested. This made it
possible to add a new signature for the Nachi worm to the
/etc/psad/signatures file. Here is the
ChangeLog:
- Added Nachi worm reconnaisannce icmp signature.
- Added the psad_ip_len signature keyword to allow the length field in the
IP header to be explicitly tested.
- Bugfix for inappropriately removing some directories in @INC when
splicing in psad perl module paths.
- Switched nf2csv installation path in install.pl to /usr/bin/.