<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/">
  <channel rdf:about="http://blog.gmane.org/gmane.comp.security.ids.snort.general">
    <title>gmane.comp.security.ids.snort.general</title>
    <link>http://blog.gmane.org/gmane.comp.security.ids.snort.general</link>
    <description/>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>1901-01-01T00:00+00:00</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36723"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36712"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36711"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36703"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36697"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36696"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36694"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36689"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36686"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36682"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36679"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36676"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36673"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36672"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36671"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36661"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36660"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36657"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36651"/>
        <rdf:li rdf:resource="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36648"/>
      </rdf:Seq>
    </items>
    <image rdf:resource="http://gmane.org/img/gmane-25t.png"/>
    <textinput rdf:resource=""/>
  </channel>
  <image rdf:about="http://gmane.org/img/gmane-25t.png">
    <title>Gmane</title>
    <url>http://gmane.org/img/gmane-25t.png</url>
    <link>http://gmane.org</link>
  </image>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36723">
    <title>Snort alarm sameip</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36723</link>
    <description>&lt;pre&gt;
Hi,

Can anyone hazard a guess why the sameip keyword is triggering an alarm on a DHCP request.
The source is 0.0.0.0 the destination is 255.255.255.255 
The rule is the default: bad-traffic rule

alert ip any any -&amp;gt; any any (msg:"BAD-TRAFFIC same SRC/DST"; sameip; reference:bugtraq,2666; reference:cve,1999-0016; reference:url,www.cert.org/advisories/CA-1997-28.html; classtype:bad-unknown; sid:527; rev:8;)

phil&amp;lt; at &amp;gt;Rangoon:~$ snort --version

   ,,_     -*&amp;gt; Snort! &amp;lt;*-
  o"  )~   Version 2.9.2 IPv6 GRE (Build 78) 
   ''''    By Martin Roesch &amp;amp; The Snort Team: http://www.snort.org/snort/snort-team
           Copyright (C) 1998-2011 Sourcefire, Inc., et al.
           Using libpcap version 1.1.1
           Using PCRE version: 8.12 2011-01-15
           Using ZLIB version: 1.2.3.4



I could add exceptions to filter this out but would i like to know why it's being triggered.

Thanks

Phil Edwards



------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

&lt;/pre&gt;</description>
    <dc:creator>Philip Edwards</dc:creator>
    <dc:date>2012-05-26T12:12:15</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36712">
    <title>Testing snort</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36712</link>
    <description>&lt;pre&gt;Hi All,

I want to test snort using large packets.
I started wireshark and started to capture traffic. I am planning to save .pcap file and load it into a system running snort.
My question is how can I load .pcap or wireshark file to that system?
Is there any tool?

Is there any other method to test it?


Regards,
Sandip Bankewar

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!&lt;/pre&gt;</description>
    <dc:creator>Sandip Bankewar</dc:creator>
    <dc:date>2012-05-24T10:04:08</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36711">
    <title>Daemonlogger native package now in OpenWRT trunk!</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36711</link>
    <description>&lt;pre&gt;My patch for building Daemonlogger as a native OpenWRT package has been 
accepted into the mainline distribution and committed to trunk. 
Pre-built binary packages are now available for all supported 
architectures in the nightly snapshots tree.

Unfortunately these packages only work on the latest trunk firmware 
builds at the moment, and the 3.2 kernel along with the extra software 
included in these builds does not leave enough free JFFS space or usable 
RAM to run daemonlogger effectively. I'm trying to convince the 
developers to include this in the next stable release of Backfire 
(10.03.2) based on the 2.6 kernel, but no luck yet.

For the time being you can still grab my binary package from my GitHub 
repository. This one *does* install and run cleanly on the current 
stable version of Backfire (10.03.1).

   - Announcement: http://goo.gl/Wy5G8
   - Downloads: https://github.com/vineyard/WRT-SPAN

Cheers,
Robert Vineyard

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

&lt;/pre&gt;</description>
    <dc:creator>Robert Vineyard</dc:creator>
    <dc:date>2012-05-23T23:14:17</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36703">
    <title>Snort and real-time alerting</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36703</link>
    <description>&lt;pre&gt;Dear, I have a Snort 2.9 with Base running OK, but I need a real time
alerting mechanism via email if possible.

How can I do that ??? Any extra module to use in that way ???

Special thanks

JeLo

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

&lt;/pre&gt;</description>
    <dc:creator>Jeronimo L. Cabral</dc:creator>
    <dc:date>2012-05-23T14:10:05</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36697">
    <title>subcribe</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36697</link>
    <description>&lt;pre&gt;------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!&lt;/pre&gt;</description>
    <dc:creator>Lawrence R. Hughes, Sr.</dc:creator>
    <dc:date>2012-05-22T14:24:36</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36696">
    <title>Snort Stream5 Support</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36696</link>
    <description>&lt;pre&gt;Very new to snort.

I seem to be having some issues with getting Stream5 support up and running.  Here is the rule:

[root&amp;lt; at &amp;gt;hostname]# cat /tmp/test.rule
log tcp any any -&amp;gt;  xx.xx.xx.xx/29 23
alert tcp any any -&amp;gt; xx.xx.xx.xx/29 22 (\
msg:"Potential SSH Brute Force";\
flow:to_server;\
flags:S;\
threshold:type threshold, track by_src, count 3, seconds 60;\
classtype:attempted-dos;\
sid:2001218;\
rev:4;\
resp:rst-all;\
)

Using the following options to startup:

snort -d -i eth0 -c /tmp/test.rule -l /tmp/log

Produces a nasty error:

Running in IDS mode

        --== Initializing Snort ==--
Initializing Output Plugins!
Initializing Preprocessors!
Initializing Plug-ins!
Parsing Rules file "/tmp/test.rule"
Tagged Packet Limit: 256
Log directory = /tmp/log

+++++++++++++++++++++++++++++++++++++++++++++++++++
Initializing rule chains...
ERROR: /tmp/test.rule(11): Stream5 must be enabled to use the 'to_server' option.
Fatal Error, Quitting..



Review of the snort.conf file, it appears I DO have Stream5 support enabled:

preprocessor stream5_global: track_tcp yes, \
   track_udp yes, \
   track_icmp no, \
   max_tcp 262144, \
   max_udp 131072, \
   max_active_responses 2, \
   min_response_seconds 5
preprocessor stream5_tcp: policy windows, detect_anomalies, require_3whs 180, \
   overlap_limit 10, small_segments 3 bytes 150, timeout 180, \
    ports client 21 22 23 25 42 53 79 109 110 111 113 119 135 136 137 139 143 \
        161 445 513 514 587 593 691 1433 1521 2100 3306 6070 6665 6666 6667 6668 6669 \
        7000 8181 32770 32771 32772 32773 32774 32775 32776 32777 32778 32779, \
    ports both 80 81 311 443 465 563 591 593 636 901 989 992 993 994 995 1220 1414 1830 2301 2381 2809 3128 3702 4343 5250 7907 7001 7145 7510 7802 7777 7779 \
        7801 7900 7901 7902 7903 7904 7905 7906 7908 7909 7910 7911 7912 7913 7914 7915 7916 \
        7917 7918 7919 7920 8000 8008 8014 8028 8080 8088 8118 8123 8180 8243 8280 8800 8888 8899 9080 9090 9091 9443 9999 11371 55555
preprocessor stream5_udp: timeout 180



Why am I getting the error?
This e-mail transmission contains information that is confidential and may be privileged. It is intended only for the addressee(s) named above. If you receive this e-mail in error, please do not read, copy or disseminate it in any manner. If you are not the intended recipient, any disclosure, copying, distribution or use of the contents of this information is prohibited. Please reply to the message immediately by informing the sender that the message was misdirected. After replying, please erase it from your computer system. Your assistance in correcting this error is appreciated.
------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!&lt;/pre&gt;</description>
    <dc:creator>Turnbough, Bradley E.</dc:creator>
    <dc:date>2012-05-22T14:22:10</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36694">
    <title>Logging URI too long</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36694</link>
    <description>&lt;pre&gt;Hi all,

I realized a behaviour in Snort that I want to share with all of you. Snort
is now logging URI and Hostname as Extra Data but, what if URI is too long?
I've seen alerts related with error 500 that uri is present but when alert
is 414 (URI too long) there's no extra data.

I've made a patch in BASE to show Extra Data Info and tried with u2spewfoo
as well but it seems that in this case it's not logged. That
post&amp;lt;http://blog.snort.org/2011/09/snort-291-http-and-smtp-logging.html&amp;gt;says:

"When a HTTP Request URI is greater than 2048 or when a HTTP hostname
(specified in the "Host" Request header) is greater than 256, Snort will
log the truncated the URI and/or hostname. A preprocessor alert with
GID:119 and SID:25 is generated when hostname exceeds 256 bytes."

Where is truncated? How can I get Extra Data of a "URI Too Long" alert? Is
it logged in that case?

Best regards
Un saludo
------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!&lt;/pre&gt;</description>
    <dc:creator>Nelo Belda</dc:creator>
    <dc:date>2012-05-22T11:55:27</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36689">
    <title>vendor list surfing</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36689</link>
    <description>&lt;pre&gt;&amp;lt; at &amp;gt; whoever called me from safemedia.com

I joined this list to get advice and assistance from people who use snort, NOT a commercial.

If you have a product that you feel will assist me I am willing to listen, but please contact me via email and off this list.

Jake Sallee
Godfather of Bandwidth
System Engineer
University of Mary Hardin-Baylor
900 College St.
Belton TX. 76513
Fone: 254-295-4658
Phax: 254-295-4221
HTTP://WWW.UMHB.EDU

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!&lt;/pre&gt;</description>
    <dc:creator>Sallee, Stephen (Jake</dc:creator>
    <dc:date>2012-05-21T21:51:50</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36686">
    <title>New snort install question</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36686</link>
    <description>&lt;pre&gt;Hello all!

I work for a small private university and we are looking into deploying snort for monitoring our internal network.

We have 50+ buildings on campus and the idea is to place a single snort box in each building and have it sniff the uplink traffic, then report back to our NAC system (Packetfence).  The goal was to be able to use some of our older desktops (Dell 960s) as kind of snort nodes with no keyboard, mouse or monitor.

We would prefer to be able to manage all of these distributed snort boxes from a single place or at least from a web GUI on each box.

#1. Am I way off base thinking about using snort this way?
#2. What kind of tools exist to manage multiple snort boxes?
#3. Am I missing something crucial that would make me look like an idiot when I go to set this up?

I have other questions but I will not spam the list with them all at once.  Please let me know your ideas and or suggestions.

Jake Sallee
Godfather of Bandwidth
System Engineer
University of Mary Hardin-Baylor
900 College St.
Belton TX. 76513
Fone: 254-295-4658
Phax: 254-295-4221
HTTP://WWW.UMHB.EDU

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!&lt;/pre&gt;</description>
    <dc:creator>Sallee, Stephen (Jake</dc:creator>
    <dc:date>2012-05-21T19:37:39</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36682">
    <title>barnyard2 database and java</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36682</link>
    <description>&lt;pre&gt;hi,

i build an analyzer for barnyard2 in java. my tool can currently read from the barnyard2 database get get all values but i have problems how to interpret data_paylod from the data table.
how can i read work with the data_payload values from the data table?
has anybody some example for that?
i need to analyze sip records only.

king regards
gregor binder

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

&lt;/pre&gt;</description>
    <dc:creator>Gregor Binder</dc:creator>
    <dc:date>2012-05-21T13:38:19</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36679">
    <title>please ! unsuscribe me !!! I have done several timesbut it doesn't work</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36679</link>
    <description>&lt;pre&gt;&lt;/pre&gt;</description>
    <dc:creator>Adriana Solé</dc:creator>
    <dc:date>2012-05-20T20:23:14</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36676">
    <title>snort inline mode</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36676</link>
    <description>&lt;pre&gt;Hello the snort users:
I want to get an ips who block attacks so i study a little bit snort and 
download it from the Ubuntu repository but wenn i set snort in inline 
mode, the only --daq-mode who works without fatal error is the dump mode 
with what i test a nmap scan and sea that snort allow it after pressing 
crtl+c...
So i compile the source with libnet, daq, and snort: the daq compile 
instructions don't work, i don't mind and used the daq from the 
repository. but i have the same problem with the --daq-mode who only 
work without fatal error with the dump mode who is not an really inline 
mode after the snort manual.

I have sea that the most actions from the snort rules are alert and i 
want to know how snort could work in inline mode with alert action 
instead of block.

extract from snort launching:
Rule application order: 
activation-&amp;gt;dynamic-&amp;gt;pass-&amp;gt;drop-&amp;gt;sdrop-&amp;gt;reject-&amp;gt;alert-&amp;gt;log

If you want to answers me i have 2 questions:
-How patch the daq to bring it work in another mode ?
-Can i get snort rules who have inline actions like block or does the 
inline mode work otherwise with alert ?

Thank's for your answers.

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

&lt;/pre&gt;</description>
    <dc:creator>eddie</dc:creator>
    <dc:date>2012-05-18T22:59:42</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36673">
    <title>daq &lt;type&gt; for inline mode</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36673</link>
    <description>&lt;pre&gt;Hello the Snort Users,
I take snort in the hand to let him work as an ips with the inline mode: i get the 2.9.2.0 version from the Ubuntu repository like libnet and daq and wenn i try to run snort in inline mode an fatal error appear to prevent me that snort can't find the daq with the nfq, ipq daq types. the ipwf type work but by stopping snort with crtl+c i get this traceback:
Can't acquire (-1) - ipfw_daq_acquire: can't select divert socket (Interrupted system call)
the dump daq type work without problems but isn't made for inline mode about the snort manual.
I think the best packets acquire type (--daq type) for Ubuntu is nfq but wenn trying with it i get this traceback:
ERROR: Can't find nfq DAQ!
Fatal Error, Quitting..
and i can't compile the daqs from source: the ./configure works but not the make.
If someone know how to patch this problem thank's to answers.------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!&lt;/pre&gt;</description>
    <dc:creator>Eddie BRUGGEMANN</dc:creator>
    <dc:date>2012-05-20T06:05:16</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36672">
    <title>Alert management</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36672</link>
    <description>&lt;pre&gt;Dear all,
 I wonder if someone can advise me some alert correlation software for
Snort alerts to give me better protection. I recently heard of ACARM-ng,
but I am not sure about using it and I don't know how it wort with Snort.
Thanks
------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!&lt;/pre&gt;</description>
    <dc:creator>hamid alaei</dc:creator>
    <dc:date>2012-05-19T12:28:19</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36671">
    <title>Getting alerts from Snort to a SQL Server 2008</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36671</link>
    <description>&lt;pre&gt;Has anyone found a solution of getting alerts from Snort to a Microsoft SQL
Server 2008, other than using the output database option? 

Mes-


------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

&lt;/pre&gt;</description>
    <dc:creator>Michael Steele</dc:creator>
    <dc:date>2012-05-18T21:35:07</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36661">
    <title>php, base issue</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36661</link>
    <description>&lt;pre&gt;Hello,
I have configured snort-2.9.2.2 on an opensuse 12.1 box, everything is
working great except for the portscan traffic stays at 0% after an NMAP
test and when I select source ports link or dest ports link I recieve an
error.Does anyone know how I can resolve this issue?


 Basic Analysis and Security Engine (BASE)

    - Today's alerts:
unique&amp;lt;http://10.2.7.170/base/base_stat_alerts.php?time_cnt=1&amp;amp;time%5B0%5D%5B0%5D=+&amp;amp;time%5B0%5D%5B1%5D=%3E%3D&amp;amp;time%5B0%5D%5B2%5D=05&amp;amp;time%5B0%5D%5B3%5D=18&amp;amp;time%5B0%5D%5B4%5D=2012&amp;amp;time%5B0%5D%5B5%5D=&amp;amp;time%5B0%5D%5B6%5D=&amp;amp;time%5B0%5D%5B7%5D=&amp;amp;time%5B0%5D%5B8%5D=+&amp;amp;time%5B0%5D%5B9%5D=+&amp;gt;
listing&amp;lt;http://10.2.7.170/base/base_qry_main.php?new=1&amp;amp;time%5B0%5D%5B0%5D=+&amp;amp;time%5B0%5D%5B1%5D=%3E%3D&amp;amp;time%5B0%5D%5B2%5D=05&amp;amp;time%5B0%5D%5B3%5D=18&amp;amp;time%5B0%5D%5B4%5D=2012&amp;amp;time%5B0%5D%5B5%5D=&amp;amp;time%5B0%5D%5B6%5D=&amp;amp;time%5B0%5D%5B7%5D=&amp;amp;time%5B0%5D%5B8%5D=+&amp;amp;time%5B0%5D%5B9%5D=+&amp;amp;submit=Query+DB&amp;amp;num_result_rows=-1&amp;amp;time_cnt=1&amp;gt;
Source
IP&amp;lt;http://10.2.7.170/base/base_stat_uaddr.php?addr_type=1&amp;amp;sort_order=occur_d&amp;amp;time_cnt=1&amp;amp;time%5B0%5D%5B0%5D=+&amp;amp;time%5B0%5D%5B1%5D=%3E%3D&amp;amp;time%5B0%5D%5B2%5D=05&amp;amp;time%5B0%5D%5B3%5D=18&amp;amp;time%5B0%5D%5B4%5D=2012&amp;amp;time%5B0%5D%5B5%5D=&amp;amp;time%5B0%5D%5B6%5D=&amp;amp;time%5B0%5D%5B7%5D=&amp;amp;time%5B0%5D%5B8%5D=+&amp;amp;time%5B0%5D%5B9%5D=+&amp;gt;
Destination
IP&amp;lt;http://10.2.7.170/base/base_stat_uaddr.php?addr_type=2&amp;amp;sort_order=occur_d&amp;amp;time_cnt=1&amp;amp;time%5B0%5D%5B0%5D=+&amp;amp;time%5B0%5D%5B1%5D=%3E%3D&amp;amp;time%5B0%5D%5B2%5D=05&amp;amp;time%5B0%5D%5B3%5D=18&amp;amp;time%5B0%5D%5B4%5D=2012&amp;amp;time%5B0%5D%5B5%5D=&amp;amp;time%5B0%5D%5B6%5D=&amp;amp;time%5B0%5D%5B7%5D=&amp;amp;time%5B0%5D%5B8%5D=+&amp;amp;time%5B0%5D%5B9%5D=+&amp;gt;
-
Last 24 Hours alerts:
unique&amp;lt;http://10.2.7.170/base/base_stat_alerts.php?time_cnt=1&amp;amp;time%5B0%5D%5B0%5D=+&amp;amp;time%5B0%5D%5B1%5D=%3E%3D&amp;amp;time%5B0%5D%5B2%5D=05&amp;amp;time%5B0%5D%5B3%5D=17&amp;amp;time%5B0%5D%5B4%5D=2012&amp;amp;time%5B0%5D%5B5%5D=16&amp;amp;time%5B0%5D%5B6%5D=&amp;amp;time%5B0%5D%5B7%5D=&amp;amp;time%5B0%5D%5B8%5D=+&amp;amp;time%5B0%5D%5B9%5D=+&amp;gt;
listing&amp;lt;http://10.2.7.170/base/base_qry_main.php?new=1&amp;amp;time%5B0%5D%5B0%5D=+&amp;amp;time%5B0%5D%5B1%5D=%3E%3D&amp;amp;time%5B0%5D%5B2%5D=05&amp;amp;time%5B0%5D%5B3%5D=17&amp;amp;time%5B0%5D%5B4%5D=2012&amp;amp;time%5B0%5D%5B5%5D=16&amp;amp;time%5B0%5D%5B6%5D=&amp;amp;time%5B0%5D%5B7%5D=&amp;amp;time%5B0%5D%5B8%5D=+&amp;amp;time%5B0%5D%5B9%5D=+&amp;amp;submit=Query+DB&amp;amp;num_result_rows=-1&amp;amp;time_cnt=1&amp;gt;
Source
IP&amp;lt;http://10.2.7.170/base/base_stat_uaddr.php?addr_type=1&amp;amp;sort_order=occur_d&amp;amp;time_cnt=1&amp;amp;time%5B0%5D%5B0%5D=+&amp;amp;time%5B0%5D%5B1%5D=%3E%3D&amp;amp;time%5B0%5D%5B2%5D=05&amp;amp;time%5B0%5D%5B3%5D=17&amp;amp;time%5B0%5D%5B4%5D=2012&amp;amp;time%5B0%5D%5B5%5D=16&amp;amp;time%5B0%5D%5B6%5D=&amp;amp;time%5B0%5D%5B7%5D=&amp;amp;time%5B0%5D%5B8%5D=+&amp;amp;time%5B0%5D%5B9%5D=+&amp;gt;
Destination
IP&amp;lt;http://10.2.7.170/base/base_stat_uaddr.php?addr_type=2&amp;amp;sort_order=occur_d&amp;amp;time_cnt=1&amp;amp;time%5B0%5D%5B0%5D=+&amp;amp;time%5B0%5D%5B1%5D=%3E%3D&amp;amp;time%5B0%5D%5B2%5D=05&amp;amp;time%5B0%5D%5B3%5D=17&amp;amp;time%5B0%5D%5B4%5D=2012&amp;amp;time%5B0%5D%5B5%5D=16&amp;amp;time%5B0%5D%5B6%5D=&amp;amp;time%5B0%5D%5B7%5D=&amp;amp;time%5B0%5D%5B8%5D=+&amp;amp;time%5B0%5D%5B9%5D=+&amp;gt;
-
Last 72 Hours alerts:
unique&amp;lt;http://10.2.7.170/base/base_stat_alerts.php?time_cnt=1&amp;amp;time%5B0%5D%5B0%5D=+&amp;amp;time%5B0%5D%5B1%5D=%3E%3D&amp;amp;time%5B0%5D%5B2%5D=05&amp;amp;time%5B0%5D%5B3%5D=15&amp;amp;time%5B0%5D%5B4%5D=2012&amp;amp;time%5B0%5D%5B5%5D=16&amp;amp;time%5B0%5D%5B6%5D=&amp;amp;time%5B0%5D%5B7%5D=&amp;amp;time%5B0%5D%5B8%5D=+&amp;amp;time%5B0%5D%5B9%5D=+&amp;gt;
listing&amp;lt;http://10.2.7.170/base/base_qry_main.php?new=1&amp;amp;time%5B0%5D%5B0%5D=+&amp;amp;time%5B0%5D%5B1%5D=%3E%3D&amp;amp;time%5B0%5D%5B2%5D=05&amp;amp;time%5B0%5D%5B3%5D=15&amp;amp;time%5B0%5D%5B4%5D=2012&amp;amp;time%5B0%5D%5B5%5D=16&amp;amp;time%5B0%5D%5B6%5D=&amp;amp;time%5B0%5D%5B7%5D=&amp;amp;time%5B0%5D%5B8%5D=+&amp;amp;time%5B0%5D%5B9%5D=+&amp;amp;submit=Query+DB&amp;amp;num_result_rows=-1&amp;amp;time_cnt=1&amp;gt;
Source
IP&amp;lt;http://10.2.7.170/base/base_stat_uaddr.php?addr_type=1&amp;amp;sort_order=occur_d&amp;amp;time_cnt=1&amp;amp;time%5B0%5D%5B0%5D=+&amp;amp;time%5B0%5D%5B1%5D=%3E%3D&amp;amp;time%5B0%5D%5B2%5D=05&amp;amp;time%5B0%5D%5B3%5D=15&amp;amp;time%5B0%5D%5B4%5D=2012&amp;amp;time%5B0%5D%5B5%5D=16&amp;amp;time%5B0%5D%5B6%5D=&amp;amp;time%5B0%5D%5B7%5D=&amp;amp;time%5B0%5D%5B8%5D=+&amp;amp;time%5B0%5D%5B9%5D=+&amp;gt;
Destination
IP&amp;lt;http://10.2.7.170/base/base_stat_uaddr.php?addr_type=2&amp;amp;sort_order=occur_d&amp;amp;time_cnt=1&amp;amp;time%5B0%5D%5B0%5D=+&amp;amp;time%5B0%5D%5B1%5D=%3E%3D&amp;amp;time%5B0%5D%5B2%5D=05&amp;amp;time%5B0%5D%5B3%5D=15&amp;amp;time%5B0%5D%5B4%5D=2012&amp;amp;time%5B0%5D%5B5%5D=16&amp;amp;time%5B0%5D%5B6%5D=&amp;amp;time%5B0%5D%5B7%5D=&amp;amp;time%5B0%5D%5B8%5D=+&amp;amp;time%5B0%5D%5B9%5D=+&amp;gt;
-
Most recent 15 Alerts: any
protocol&amp;lt;http://10.2.7.170/base/base_qry_main.php?new=1&amp;amp;caller=last_any&amp;amp;num_result_rows=-1&amp;amp;submit=Last%20Any&amp;gt;
TCP&amp;lt;http://10.2.7.170/base/base_qry_main.php?new=1&amp;amp;layer4=TCP&amp;amp;caller=last_tcp&amp;amp;num_result_rows=-1&amp;amp;submit=Last%20TCP&amp;gt;
UDP&amp;lt;http://10.2.7.170/base/base_qry_main.php?new=1&amp;amp;layer4=UDP&amp;amp;caller=last_udp&amp;amp;num_result_rows=-1&amp;amp;submit=Last%20UDP&amp;gt;
ICMP&amp;lt;http://10.2.7.170/base/base_qry_main.php?new=1&amp;amp;layer4=ICMP&amp;amp;caller=last_icmp&amp;amp;num_result_rows=-1&amp;amp;submit=Last%20ICMP&amp;gt;
-
Last Source Ports: any
protocol&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=last_ports&amp;amp;port_type=1&amp;amp;proto=-1&amp;amp;sort_order=last_d&amp;gt;
TCP&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=last_ports&amp;amp;port_type=1&amp;amp;proto=6&amp;amp;sort_order=last_d&amp;gt;
UDP&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=last_ports&amp;amp;port_type=1&amp;amp;proto=17&amp;amp;sort_order=last_d&amp;gt;
-
Last Destination Ports: any
protocol&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=last_ports&amp;amp;port_type=2&amp;amp;proto=-1&amp;amp;sort_order=last_d&amp;gt;
TCP&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=last_ports&amp;amp;port_type=2&amp;amp;proto=6&amp;amp;sort_order=last_d&amp;gt;
UDP&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=last_ports&amp;amp;port_type=2&amp;amp;proto=17&amp;amp;sort_order=last_d&amp;gt;
-
Most Frequent Source Ports: any
protocol&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=most_frequent&amp;amp;port_type=1&amp;amp;proto=-1&amp;amp;sort_order=occur_d&amp;gt;
TCP&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=most_frequent&amp;amp;port_type=1&amp;amp;proto=6&amp;amp;sort_order=occur_d&amp;gt;
UDP&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=most_frequent&amp;amp;port_type=1&amp;amp;proto=17&amp;amp;sort_order=occur_d&amp;gt;
-
Most Frequent Destination Ports: any
protocol&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=most_frequent&amp;amp;port_type=2&amp;amp;proto=-1&amp;amp;sort_order=occur_d&amp;gt;
TCP&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=most_frequent&amp;amp;port_type=2&amp;amp;proto=6&amp;amp;sort_order=occur_d&amp;gt;
UDP&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=most_frequent&amp;amp;port_type=2&amp;amp;proto=17&amp;amp;sort_order=occur_d&amp;gt;
-
Most frequent 15 Addresses:
Source&amp;lt;http://10.2.7.170/base/base_stat_uaddr.php?caller=most_frequent&amp;amp;addr_type=1&amp;amp;sort_order=occur_d&amp;gt;
Destination&amp;lt;http://10.2.7.170/base/base_stat_uaddr.php?caller=most_frequent&amp;amp;addr_type=2&amp;amp;sort_order=occur_d&amp;gt;
-
Most recent 15 Unique
Alerts&amp;lt;http://10.2.7.170/base/base_stat_alerts.php?caller=last_alerts&amp;amp;sort_order=last_d&amp;gt;
-
Most frequent 5 Unique
Alerts&amp;lt;http://10.2.7.170/base/base_stat_alerts.php?caller=most_frequent&amp;amp;sort_order=occur_d&amp;gt;
 *Queried on *: Fri May 18, 2012 16:34:43
*Database:* snort&amp;lt; at &amp;gt;localhost    (*Schema Version:* 107)
*Time Window:* [2012-05-18 11:05:19] - [2012-05-18 11:06:55]
 *Search &amp;lt;http://10.2.7.170/base/base_qry_main.php?new=1&amp;gt;*
*Graph Alert Data &amp;lt;http://10.2.7.170/base/base_graph_main.php&amp;gt;*
Graph Alert Detection Time &amp;lt;http://10.2.7.170/base/base_stat_time.php&amp;gt;

------------------------------
  *Sensors/Total:* 1 &amp;lt;http://10.2.7.170/base/base_stat_sensor.php&amp;gt; / 2
*Unique Alerts:* 1 &amp;lt;http://10.2.7.170/base/base_stat_alerts.php&amp;gt;
*Categories: *1&amp;lt;http://10.2.7.170/base/base_stat_class.php?sort_order=class_a&amp;gt;
*Total Number of Alerts:*
48&amp;lt;http://10.2.7.170/base/base_qry_main.php?&amp;amp;num_result_rows=-1&amp;amp;submit=Query+DB&amp;amp;current_view=-1&amp;gt;

   - Src IP addrs: 13&amp;lt;http://10.2.7.170/base/base_stat_uaddr.php?addr_type=1&amp;gt;
   - Dest. IP addrs: 1&amp;lt;http://10.2.7.170/base/base_stat_uaddr.php?addr_type=2&amp;gt;
   - Unique IP links 13 &amp;lt;http://10.2.7.170/base/base_stat_iplink.php&amp;gt;
   -

   Source Ports:
2&amp;lt;http://10.2.7.170/base/base_stat_ports.php?port_type=1&amp;amp;proto=-1&amp;gt;
   -
      - TCP ( 0&amp;lt;http://10.2.7.170/base/base_stat_ports.php?port_type=1&amp;amp;proto=6&amp;gt;)
 UDP
      ( 2 &amp;lt;http://10.2.7.170/base/base_stat_ports.php?port_type=1&amp;amp;proto=17&amp;gt;)
   - Dest Ports:
2&amp;lt;http://10.2.7.170/base/base_stat_ports.php?port_type=2&amp;amp;proto=-1&amp;gt;
   -
      - TCP ( 0&amp;lt;http://10.2.7.170/base/base_stat_ports.php?port_type=2&amp;amp;proto=6&amp;gt;)
 UDP
      ( 2 &amp;lt;http://10.2.7.170/base/base_stat_ports.php?port_type=2&amp;amp;proto=17&amp;gt;)

*Traffic Profile by Protocol*  TCP
(0%)&amp;lt;http://10.2.7.170/base/base_qry_main.php?new=1&amp;amp;layer4=TCP&amp;amp;num_result_rows=-1&amp;amp;sort_order=time_d&amp;amp;submit=Query+DB&amp;gt;
   UDP (100%)&amp;lt;http://10.2.7.170/base/base_qry_main.php?new=1&amp;amp;layer4=UDP&amp;amp;num_result_rows=-1&amp;amp;sort_order=time_d&amp;amp;submit=Query+DB&amp;gt;
     ICMP (0%)&amp;lt;http://10.2.7.170/base/base_qry_main.php?new=1&amp;amp;layer4=ICMP&amp;amp;num_result_rows=-1&amp;amp;sort_order=time_d&amp;amp;submit=Query+DB&amp;gt;

------------------------------
  Portscan Traffic
(0%)&amp;lt;http://10.2.7.170/base/base_qry_main.php?new=1&amp;amp;layer4=RawIP&amp;amp;num_result_rows=-1&amp;amp;sort_order=time_d&amp;amp;submit=Query+DB&amp;gt;


  Basic Analysis and Security Engine (BASE)
  Home &amp;lt;http://10.2.7.170/base/base_main.php&amp;gt;  |
Search&amp;lt;http://10.2.7.170/base/base_qry_main.php?new=1&amp;gt;

  [ Back &amp;lt;http://10.2.7.170/base/base_main.php?back=1&amp;amp;&amp;gt; ]

/srv/www/htdocs/base/includes/base_cache.inc.php:556: ERROR:
$number_sensors_array is NOT an array!


/srv/www/htdocs/base/includes/base_cache.inc.php:564: ERROR:
$number_sensors_array is either NULL or empty!

 *Queried on* : Fri May 18, 2012 16:36:23      Meta Criteria *   any *   IP
Criteria *   any *   Layer 4 Criteria *   none * Payload Criteria *   any *


*No Alerts were found.*

         &amp;lt;&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=&amp;amp;sort_order=&amp;amp;port_type=1&amp;amp;proto=1&amp;amp;sort_order=port_a&amp;gt;
 Port &amp;gt;&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=&amp;amp;sort_order=&amp;amp;port_type=1&amp;amp;proto=1&amp;amp;sort_order=port_d&amp;gt;
   &amp;lt;&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=&amp;amp;sort_order=&amp;amp;port_type=1&amp;amp;proto=1&amp;amp;sort_order=sensor_a&amp;gt;
 Sensor &amp;gt;&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=&amp;amp;sort_order=&amp;amp;port_type=1&amp;amp;proto=1&amp;amp;sort_order=sensor_d&amp;gt;
   &amp;lt;&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=&amp;amp;sort_order=&amp;amp;port_type=1&amp;amp;proto=1&amp;amp;sort_order=occur_a&amp;gt;
 Occurrences &amp;gt;&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=&amp;amp;sort_order=&amp;amp;port_type=1&amp;amp;proto=1&amp;amp;sort_order=occur_d&amp;gt;
   &amp;lt;&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=&amp;amp;sort_order=&amp;amp;port_type=1&amp;amp;proto=1&amp;amp;sort_order=alerts_a&amp;gt;
Unique Alerts &amp;gt;&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=&amp;amp;sort_order=&amp;amp;port_type=1&amp;amp;proto=1&amp;amp;sort_order=alerts_d&amp;gt;
   &amp;lt;&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=&amp;amp;sort_order=&amp;amp;port_type=1&amp;amp;proto=1&amp;amp;sort_order=sip_a&amp;gt;
 Src. Addr. &amp;gt;&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=&amp;amp;sort_order=&amp;amp;port_type=1&amp;amp;proto=1&amp;amp;sort_order=sip_d&amp;gt;
   &amp;lt;&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=&amp;amp;sort_order=&amp;amp;port_type=1&amp;amp;proto=1&amp;amp;sort_order=dip_a&amp;gt;
 Dest. Addr. &amp;gt;&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=&amp;amp;sort_order=&amp;amp;port_type=1&amp;amp;proto=1&amp;amp;sort_order=dip_d&amp;gt;
   &amp;lt;&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=&amp;amp;sort_order=&amp;amp;port_type=1&amp;amp;proto=1&amp;amp;sort_order=first_a&amp;gt;
 First &amp;gt;&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=&amp;amp;sort_order=&amp;amp;port_type=1&amp;amp;proto=1&amp;amp;sort_order=first_d&amp;gt;
   &amp;lt;&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=&amp;amp;sort_order=&amp;amp;port_type=1&amp;amp;proto=1&amp;amp;sort_order=last_a&amp;gt;
 Last &amp;gt;&amp;lt;http://10.2.7.170/base/base_stat_ports.php?caller=&amp;amp;sort_order=&amp;amp;port_type=1&amp;amp;proto=1&amp;amp;sort_order=last_d&amp;gt;
    ACTION
{ action }ADD to AG (by ID)ADD to AG (by Name)Create AG (by Name)Delete
alert(s)Email alert(s) (full)Email alert(s) (summary)Email alert(s)
(csv)Archive
alert(s) (copy)Archive alert(s) (move)
------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!&lt;/pre&gt;</description>
    <dc:creator>Dennis Circolone</dc:creator>
    <dc:date>2012-05-18T16:37:02</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36660">
    <title>Snort 2.9.3 Beta Now Available</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36660</link>
    <description>&lt;pre&gt;Snort 2.9.3 Beta is now available on snort.org, at
http://www.snort.org/snort-downloads/ in the Latest Development
Release section.

2.9.0 RC &amp;amp; later packages are signed with a new PGP key
(that is signed with the previous key).

Snort 2.9.3 introduces the following new capabilities:

[*] New additions
  * Updates to flowbit rule option to allow for OR and AND
    of individual bits within a single rule, and allow flowbits
    to be used in multiple groups.  See README.flowbits and
    the Snort manual for details.

  * Dynamic output plugin architecture to provide an API that
    developers can write their own output mechanisms to log alert
    and packet data from Snort.  Some output plugins have been
    removed as a result of this to be maintained by their
    respective authors.

  * Update to dcerpc2 preprocessor for improved accuracy and
    handling of different OSs for SMB processing.  See README.dcerpc2
    and the Snort manual for details.

  * Updates to reputation preprocessor for handling of whitlelist
    and trustlists and zone information.  See README.reputation
    and the Snort manual for details.

  * Updates to the packet decoders to support pflog v4.

[*] Improvements
  * Update to return error messages through the control socket.

  * Updates to the processing of email attachments for better
    handling of non-encoded attachments, and improved memory
    management for attachment processing.

  * Improvements in HTTP Inspect for better performance with gzip
    decompression.  Also improvements for handling simple responses,
    encoded query strings, transfer encoding and chunk encoding
    processing.

  * Fix logging of multiple unified2 alerts with reassembled packets.

  * Compiler warning cleanup across multiple platforms.

  * Added 116:458 and 116:459 to cover fragmentation issues.

Please see the Release Notes and ChangeLog for more details.

Please submit bugs, questions, and feedback to snort-beta&amp;lt; at &amp;gt;sourcefire.com.

Happy Snorting!
The Snort Release Team


------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

&lt;/pre&gt;</description>
    <dc:creator>Snort Releases</dc:creator>
    <dc:date>2012-05-18T13:56:01</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36657">
    <title>Snort 2.8-&gt;2.9 upgrade, DAQ and libpcap</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36657</link>
    <description>&lt;pre&gt;Hi,
I'm trying to upgrade from 2.8 to 2.9.2.3, and I'm getting this error

checking for dlsym in -ldl... yes
./configure: line 15188: daq-modules-config: command not found
checking for daq_load_modules in -ldaq_static... no

    ERROR! daq_static library not found, go get it from
    http://www.snort.org/.
make: *** [snort_configure] Error 1

and from what I read here:
http://vrt-blog.snort.org/2010/08/snort-29-essentials-daq.html
pcap &amp;gt; 1.0.0 is required. I am still running pcap 0.9.8

Can somebody confirm that I can't continue working with the old pcap 
version?

Thanks,
Maurizio Molina

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

&lt;/pre&gt;</description>
    <dc:creator>Maurizio Molina</dc:creator>
    <dc:date>2012-05-18T05:46:39</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36651">
    <title>Snort &amp; Pulled Pork questions</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36651</link>
    <description>&lt;pre&gt;Working on updating to the latest version of snort (2.9.2.3) and using
pulledpork (0.6.1).

 

For those of us that are not paying subscribers of the VRT rule set
updating to the latest issue within the first 30 days causes issues..

 

I updated from 2.9.2.2 to 2.9.2.3 yesterday, when pulled pork runs it
detects the snort version and attempts to download the correct rule set,
well for me there is no rule set and won't be for 30 days..

 

Now I can manually set the snort version to 2.9.2.2 in pulledpork.conf
as long as 2.9.2.2 rules are compatible with 2.9.2.3 (which Joel
indicated they are.  This time..).

 

What happens when a change is made that make the older rules not
compatible?

 

Are my choices to (1) not upgrade to the latest snort version for 30
days, until "free" rules are available, or (2) purchase a rule
subscription?

 

Thanks,

Jason

_____________________________________________________________________________________________

Please visit www.nhrs.org to subscribe to NHRS email announcements and updates.------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!&lt;/pre&gt;</description>
    <dc:creator>Weir, Jason</dc:creator>
    <dc:date>2012-05-17T13:20:49</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36648">
    <title>Perfmonitor Issue</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36648</link>
    <description>&lt;pre&gt;Hi all,

I have an issue using the perfmonitor preprocessor for snort inline  to
provide the "Max performance snort stats" with the following parameters:

 

  preprocessor perfmonitor: time 300 pktcnt 5000 events max console

 

Here are the options used to launch snort :

 

        -A none \

        --dynamic-engine-lib "${SNORT_ENG}" 

        --dynamic-preprocessor-lib-dir "${SNORT_DYNPPDIR}"

        --dynamic-detection-lib-dir "${SNORT_DYNRULDIR}" 

        --daq-dir "${DAQ_DIR}" 

        -i "${INTERFACE}" 

        -c "${SNORT_CONF}" 

        --perfmon-file "${LOG_DIR}/snort.stats" 

        -l "${LOG_DIR}" 

        -Q

 

Since I'm using the "max " and  "console" parameters, my console should
display the results, based on the following code:

if(iFlags &amp;amp; MAX_PERF_STATS)

{

      .

      .

  LogMessage("uSeconds/Pkt\n");

  LogMessage("----------------\n");

  LogMessage("Snort:
%.3f\n",sfBaseStats-&amp;gt;usecs_per_packet.usertime);

  LogMessage("Sniffing:
%.3f\n",sfBaseStats-&amp;gt;usecs_per_packet.systemtime);

  LogMessage("Combined:
%.3f\n\n",sfBaseStats-&amp;gt;usecs_per_packet.totaltime);

  .

  .

}

But it doesn't...

It doesn't print me the Snort Max Performance at all..

The usec_per_packet structure is filled when "GetuSecondsPerPacket"  is
called but it seems like we never enter in the "if" clause 

and when I try to debug with gdb, I can see that "iFlag" is always equal
to 0 for an unknown reason and since "MAX_PERF_STATS" is equal to 1, the
"if" test fail.

 

FYI, here are the options used to compile snort :

 

--enable-dynamicplugin --enable-perfprofiling --enable-linux-smp-stats
--enable-targetbased --enable-ipv6 --enable-ppm --enable-gre
--enable-static-daq=no --enable-64bit-gcc=no 

 

 

If someone has an idea about the origin of the problem here...

 

Regards,

 

Abdelmonaim Mokadem.   

 

 

 

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!&lt;/pre&gt;</description>
    <dc:creator>Abdelmonaim Mokadem</dc:creator>
    <dc:date>2012-05-16T18:10:58</dc:date>
  </item>
  <item rdf:about="http://comments.gmane.org/gmane.comp.security.ids.snort.general/36642">
    <title>False positive</title>
    <link>http://comments.gmane.org/gmane.comp.security.ids.snort.general/36642</link>
    <description>&lt;pre&gt;

Hi,

I have recently installed snort on ubuntu and am just attempting to tune out the noise.
For some reason the BAD-TRAFFIC (same source and destination) rule is firing on DHCP broadcasts.

The source is 0.0.0.0 port 67 and the destination is 255.255.255.255 port 68.

Since the source and destination are different can anyone clue me in?

Thanks

Phil Edwards
------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users&amp;lt; at &amp;gt;lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

&lt;/pre&gt;</description>
    <dc:creator>Philip Edwards</dc:creator>
    <dc:date>2012-05-16T11:08:34</dc:date>
  </item>
  <textinput rdf:about="http://search.gmane.org/?group=$group=gmane.comp.security.ids.snort.general">
    <title>Search Engine</title>
    <description>Search the mailing list at Gmane</description>
    <name>query</name>
    <link>http://search.gmane.org/?group=$group=gmane.comp.security.ids.snort.general</link>
  </textinput>
</rdf:RDF>

