Snort: by date

333 messages starting Oct 02 06 and ending Dec 29 06
Date index | Thread index | Author index


Monday, 02 October

PacSec 2006 announcement, EUSecWest 2007 Call For Papers (Mar 1-2, deadline Oct 20th) Dragos Ruiu

Tuesday, 03 October

Seattle Snort Users Group meets 10/17/2006 at 7:00 PM @ SSCC RAH304 James Affeld

Thursday, 05 October

I can not see it Greta.Ji
Snort-snmp stats Wes Young
(no subject) Sekuretty
Deploying snort on virtual servers carlopmart
Re: I can not see it Greta.Ji
Re: I can not see it Patrick S. Harper
Re: I can not see it Greta.Ji
Re: I can not see it Patrick S. Harper
Re: I can not see it Eric Hines
Re: I can not see it Greta.Ji
Re: (no subject) Martin Roesch
Snort rule setting Greta.Ji
Re: Snort rule setting Eric Hines

Friday, 06 October

Suse 10.0 Daniel Cordoba
Re: Suse 10.0 Justin Heath
Re: Suse 10.0 Joel Esler
Snort rules Mark Rohrbeck
Re: Suse 10.0 Justin Heath
Re: I can not see it Michael Scheidell
rule variables katsumi liquer
Re: rule variables Jason Brvenik
Re: (no subject) Randal T. Rioux

Sunday, 08 October

Re: (no subject) Martin Roesch

Monday, 09 October

Re: (no subject) Daniel Costello
IDS Policy Manager v2.0 Beta Released Jeff Dell

Tuesday, 10 October

Sentinix Linux Suresh Balabrahman
New IPS testing methodology Bob Walder
Re: [Sguil-users] Barnyard stop suddenly Bamm Visscher
Re: [Sguil-users] Barnyard stop suddenly Devin Kowatch
Re: (no subject) Jeff Nathan

Wednesday, 11 October

Question about !HOME_NET Nick Baronian
Re: Question about !HOME_NET M. Shirk
Re: Question about !HOME_NET Joel Esler
Re: Question about !HOME_NET Nick Baronian
Re: Question about !HOME_NET Nick Baronian
Re: Question about !HOME_NET Todd Wease
Mike Potamousis/Poughkeepsie/Contr/IBM is out of the office. Mike Potamousis
Re: Mike Potamousis/Poughkeepsie/Contr/IBM is out of theoffice. Patrick S. Harper

Thursday, 12 October

Re: Mike Potamousis/Poughkeepsie/Contr/IBM is out oftheoffice. M. Shirk
4d:41:43:44:41:44 - MACDAD Nick Baronian
Testing rpc decoder snort user

Friday, 13 October

DOUBLE DECODING ATTACK Julien VARLET
Re: DOUBLE DECODING ATTACK Joel Esler
Re: DOUBLE DECODING ATTACK Eric Hines
Dell Connect dajackman
Re: Testing rpc decoder Martin Roesch
Check network for system broadcasts... Akashdeep Bhardwaj
Re: Testing rpc decoder snort user
Re: Check network for system broadcasts... David Glosser
Re: Check network for system broadcasts... David Glosser

Sunday, 15 October

consult some questions about snort fan wu

Monday, 16 October

ruleset performance virendra rode //
Seattle Snort Users Group meets 10/17/2006 at 7:00 PM @ SSCC RAH304 James Affeld

Tuesday, 17 October

Re: 4d:41:43:44:41:44 - MACDAD Joel Esler

Wednesday, 18 October

Re-2: DOUBLE DECODING ATTACK Julien VARLET
Re: your mail Phil Wood
Re-2: your mail Julien VARLET
Re: your mail gary douglas
Re: your mail - gen id location Todd Wease
How to simulate and apply snort IDS source code in NS2?? *bahareh NTC*
Re: I can not see it Nick Oliver
simulate and apply snort IDS,,, *bahareh NTC*
Re: I can not see it Esteban Ribicic
Re: [Snort-devel] [Sguil-users] Barnyard stop suddenly Eric Lauzon
2.6.0.2 FTPTelnet Preprocessor Sandra Turner
Re: 2.6.0.2 FTPTelnet Preprocessor Justin Heath
Re: your mail - gen id location Nigel Houghton

Thursday, 19 October

Snort 2.6 and gen-msg.map Paul Melson
Re: Snort 2.6 and gen-msg.map Nigel Houghton
spp_portscan Bamm Visscher
Re: Snort 2.6 and gen-msg.map M. Shirk
Snort 2.6.0.2 (Build 85) - pfault Chris U

Friday, 20 October

Re: Snort 2.6.0.2 (Build 85) - pfault Chris U
Re: spp_portscan Justin Heath
Snort start error: [unknown rule type: dynamicpreprocessor] Aaron Giuoco
Re: Snort start error: [unknown rule type: dynamicpreprocessor] Justin Heath
Re: Snort start error: [unknown rule type: dynamicpreprocessor] Aaron Giuoco
Re: Snort 2.6.0.2 (Build 85) - pfault Joel Esler
Re: Snort start error: [unknown rule type: dynamicpreprocessor] Joel Esler
Re: Snort start error: [unknown rule type: dynamicpreprocessor] Aaron Giuoco
Dynamic Rules Bamm Visscher
Re: Snort start error: [unknown rule type: dynamicpreprocessor] Justin Heath
Re: Snort start error: [unknown rule type: dynamicpreprocessor] Aaron Giuoco
Re: Dynamic Rules Justin Heath

Saturday, 21 October

Re: Dynamic Rules Bamm Visscher

Tuesday, 24 October

Upgrade to 2.6.x Cody Holland
ANNOUNCE: WinPcap 4.0 beta2 has been released Gianluca Varenni
SOURCEfire Seeks a few good Snort-Heads Chris Kelley
Detecting Skype traffic (reliably) Andrew Hay
Re: Upgrade to 2.6.x Paul Melson
Re: Detecting Skype traffic (reliably) Michael Scheidell
Re: Upgrade to 2.6.x Michael Scheidell
Re: Detecting Skype traffic (reliably) Paul Halliday

Wednesday, 25 October

Re: Detecting Skype traffic (reliably) Humes, David G.
Need help in interpreting some Docs John Draper
Re: Need help in interpreting some Docs Justin Heath
Re: Detecting Skype traffic (reliably) Jason Haar
Re: Detecting Skype traffic (reliably) Nigel Houghton
Re: Detecting Skype traffic (reliably) baginski

Thursday, 26 October

Re: Detecting Skype traffic (reliably) Nicolas Saurbier
Newbie Questions Davis Lee
Re: Need help in interpreting some Docs John Draper
Re: Need help in interpreting some Docs Eric Hines
Re: I need help in interpreting some Docs John Draper
Re: Need help in interpreting some Docs John Draper

Friday, 27 October

Strange Problem Restarting Snort Beyerle, Christian
Re: Strange Problem Restarting Snort Joel Esler
Re: Newbie Questions Justin Heath
Re: Newbie Questions Adam Keeton
Upgrade Issues Cody Holland

Monday, 30 October

remote syslog Jesús Gálvez
Upgrade Issues Cody Holland
Re: remote syslog Justin Heath
Snort-2.6.0.2 on FC6 fail to log Nmap TCP portscans. Daniel
Snort 2.6.1 Beta 2 Question (snort_dynamicrule/) Eric Hines
tuning sigs priority with modifysid martin
Fwd: tuning sigs priority with modifysid martin
Re: Upgrade Issues Justin Heath
Re: Snort-2.6.0.2 on FC6 fail to log Nmap TCP portscans. Justin Heath
libdynamicexamplerule.so Eric Hines
Re: Snort 2.6.1 Beta 2 Question (snort_dynamicrule/) Justin Heath
Re: Snort 2.6.1 Beta 2 Question (snort_dynamicrule/) Justin Heath
Re: libdynamicexamplerule.so Eric Hines
Re: Snort 2.6.1 Beta 2 Question (snort_dynamicrule/) Eric Hines
Re: libdynamicexamplerule.so Nigel Houghton
Re: Snort-2.6.0.2 on FC6 fail to log Nmap TCP portscans. Daniel
Re: libdynamicexamplerule.so Eric Hines
Re: Snort 2.6.1 Beta 2 Question (snort_dynamicrule/) Justin Heath
Re: Snort 2.6.1 Beta 2 Question (snort_dynamicrule/) Justin Heath
Incorrect SID 108 Ian Masters

Tuesday, 31 October

Re: Incorrect SID 108 Todd Wease
Re: Fwd: tuning sigs priority with modifysid Brian
Re: tuning sigs priority with modifysid Stephen Nesman
Northern Virginia Snort Users Group Meeting - November 16th Mike Guiterman
Aanval Snort/Syslog Correlation; Halloween Special Administration
Re: Incorrect SID 108 Ian Masters
Re: Incorrect SID 108 Todd Wease
Re: Northern Virginia Snort Users Group Meeting - November 16th Richard Bejtlich

Wednesday, 01 November

November 3rd Chicago2600 Meeting Information Steven McGrath
Re: Incorrect SID 108 Brian
Snort as a PIDS! Zakai Kinan
Re: Snort as a PIDS! Eric Hines
Re: Snort as a PIDS! Joel Esler
libpcap v/s Phil Woods libpcap v/s pfring_3 Eric Hines

Thursday, 02 November

Availability of Snort v2.6.1 release candidate 1 Snort Releases
Aanval Series 2 v2.3 Just Released Administration
Re: Aanval Series 2 v2.3 Just Released Eric Hines
EUSecWest/London CFP extended to Nov. 7 Dragos Ruiu
Re: Aanval Series 2 v2.3 Just Released Eric Hines
Re: Aanval Series 2 v2.3 Just Released Administration
Re: Aanval Series 2 v2.3 Just Released Jeff Dell
Re: Aanval Series 2 v2.3 Just Released Eric Hines
Re: Aanval Series 2 v2.3 Just Released Timothy A . Holmes
Re: Aanval Series 2 v2.3 Just Released Eric Hines
Re: Aanval Series 2 v2.3 Just Released Administration
Re: Aanval Series 2 v2.3 Just Released Jeff Dell
Re: Aanval Series 2 v2.3 Just Released Alan Shimel
Re: Aanval Series 2 v2.3 Just Released Eric Hines
Re: Aanval Series 2 v2.3 Just Released Jeff Dell
Re: Aanval Series 2 v2.3 Just Released Randal T. Rioux

Friday, 03 November

Commercial offerings on the list - discussion info+lucretia.ca
Re: Aanval Series 2 v2.3 Just Released Michael Scheidell
Re: Aanval Series 2 v2.3 Just Released Martin Roesch
Re: Aanval Series 2 v2.3 Just Released Anthony J Placilla

Sunday, 05 November

Activating a sniffing nic Timothy A . Holmes
Re: Activating a sniffing nic Patrick S. Harper
Snort 2.6.0.2 + Snort-Clamav Marcin Stępnicki
Re: Activating a sniffing nic Eric Hines
Re: Snort 2.6.0.2 + Snort-Clamav Will Metcalf

Monday, 06 November

Re: Snort 2.6.0.2 + Snort-Clamav Victor Julien
Re: Activating a sniffing nic Timothy A . Holmes
Snort not catching anything Vintage Mud

Wednesday, 08 November

Is there any documentation showing how to write a snort plugin? John Draper
Re: Availability of Snort v2.6.1 release candidate 1 Jason Haar

Thursday, 09 November

SNORT GURUZ: Question regarding Setting up Snort on a multi-WAN network Sanjay Arora
Mike Potamousis/Poughkeepsie/Contr/IBM is out of the office. Mike Potamousis
Employment; Someone with passion for deep packet inspection mayberry
Re: Employment; Someone with passion for deep packet inspection M. Shirk

Monday, 13 November

inline snort at 400 mb ? James Affeld
Seattle Snort User Group meets Tuesday, Nov 14 7:00 PM @ SSCC room RAH304 topic Sguil James Affeld
Re: inline snort at 400 mb ? Roger Harris
Re: Is there any documentation showing how to write a snort plugin? Martin Roesch

Tuesday, 14 November

Extracting reports per IP address Landon Stewart | Superb Internet Corp.
Re: Extracting reports per IP address Dev Anand
Re: Extracting reports per IP address Kevin Johnson

Wednesday, 15 November

./configure options snort-2.6.0.2 Gentoo-Wally

Thursday, 16 November

snort2.6 BPF issue? John Hally
Re: snort2.6 BPF issue? Bamm Visscher
Re: snort2.6 BPF issue? John Hally
Re: snort2.6 BPF issue? John Hally
Re: snort2.6 BPF issue? Bamm Visscher
Re: snort2.6 BPF issue? John Hally
Availability of Snort v2.6.1 final Snort Releases
BASE 1.2.7 (karen) released Kevin Johnson
FPs for COMMUNITY MISC Q.931 Invalid Call Reference Length Buffer Overflow, Sig ID, 100000892 Russell Fulton

Friday, 17 November

Pass rules need SID in 2.6.1 James Lay
Re: Pass rules need SID in 2.6.1 Jeff Dell
2.6.1 and LOOOONG startup times plus more ignore_scanners info James Lay
Re: Pass rules need SID in 2.6.1 James Lay
Re: 2.6.1 and LOOOONG startup times plus more ignore_scanners info Justin Heath
Re: Pass rules need SID in 2.6.1 Justin Heath
Re: 2.6.1 and LOOOONG startup times plus more ignore_scanners info Nigel Houghton
Re: 2.6.1 and LOOOONG startup times plus moreignore_scanners info James Lay
Re: 2.6.1 and LOOOONG startup times plus moreignore_scanners info James Lay
Re: 2.6.1 and LOOOONG startup times plusmoreignore_scanners info John York
Re: Is there any documentation showing how to write a snort plugin? John Draper
help:store data to mysql fan wu

Sunday, 19 November

Re: Pass rules need SID in 2.6.1 Frank Knobbe

Monday, 20 November

Snort 2.6.1 uses all available processor forever Thomas Munn
Re: Snort 2.6.1 uses all available processor forever M. Shirk
Mike Potamousis/Poughkeepsie/Contr/IBM is out of the office. Mike Potamousis
Jerry Bedwell/CIN/Kendle bedwell . jerry

Tuesday, 21 November

Alert payloads not matching alert rules spagno_f
Snort 2.6.1 Stops Logging Colin Grady
Hawaii Snort Users Group Chris U
Re: Snort 2.6.1 Stops Logging Jason Haar
Re: Snort 2.6.1 Stops Logging Eric J. Feldhusen
Re: Snort 2.6.1 Stops Logging Colin Grady
Re: Snort 2.6.1 Stops Logging Martin Roesch

Wednesday, 22 November

Re: Snort 2.6.1 Stops Logging Jason Haar
Re: Alert payloads not matching alert rules Joel Esler
Re: Snort 2.6.1 Stops Logging Julio E. Gonzalez P.
Re: Snort 2.6.1 Stops Logging Eric Feldhusen
Bed rev found this morning James Lay
Re: Is there any documentation showing how to write a snort plugin? Martin Roesch
Re: Snort 2.6.1 Stops Logging Eric J. Feldhusen
Re: Alert payloads not matching alert rules spagno_f
Looooots of "Outstanding" and "Analyzed" packets - counter wrap ? Andreas Maus
Re: Snort 2.6.1 Stops Logging Eric J. Feldhusen
Re: Alert payloads not matching alert rules Joel Esler
Re: Alert payloads not matching alert rules Jason Haar
Re: Alert payloads not matching alert rules Marc Norton
newbie install question Jerry Hlinsky
Availability of Snort v2.6.1.1 Snort Releases
Re: Availability of Snort v2.6.1.1 Jason Haar

Thursday, 23 November

Re: Alert payloads not matching alert rules spagno_f
Re: Availability of Snort v2.6.1.1 Julio E. Gonzalez P.
Re: Availability of Snort v2.6.1.1 Justin Heath
Snort announcements Justin Heath
problem with snort 2.6.1.1 (stop working) Julio E. Gonzalez P.
Re: Looooots of "Outstanding" and "Analyzed" packets - counter wrap ? Andreas Maus
Re: Looooots of "Outstanding" and "Analyzed" packets - counter wrap ? Harry Hoffman
Re: problem with snort 2.6.1.1 (stop working) Justin Heath

Friday, 24 November

Re: Looooots of "Outstanding" and "Analyzed" packets - counter wrap ? Andreas Maus

Saturday, 25 November

Re: Is there any documentation showing how to write a snort plugin? Justin Heath
Re: problem with snort 2.6.1.1 (stop working) Jason Haar
Re: problem with snort 2.6.1.1 (stop working) Justin Heath

Sunday, 26 November

Re: Looooots of "Outstanding" and "Analyzed" packets - counter wrap ? Bamm Visscher

Monday, 27 November

Re: Looooots of "Outstanding" and "Analyzed" packets - counter wrap ? Andreas Maus
Re: Alert payloads not matching alert rules Joel Esler
Re: Alert payloads not matching alert rules Joel Esler
Re: Looooots of "Outstanding" and "Analyzed" packets - counter wrap ? Justin Heath
Re: Looooots of "Outstanding" and "Analyzed" packets - counter wrap ? Bamm Visscher
Re: Looooots of "Outstanding" and "Analyzed" packets - counter wrap ? Andreas Maus
Re: Alert payloads not matching alert rules Paul Melson

Tuesday, 28 November

Test Ron Jenkins
Snort v2.6.1 and v2.6.1.1 - Either shutdown or hangs after a short period of time Ron Jenkins
Re: Snort v2.6.1 and v2.6.1.1 - Either shutdown or hangs after a short period of time Joel Esler
Re: Snort v2.6.1 and v2.6.1.1 - Either shutdown or hangs after a short period of time Ron Jenkins

Wednesday, 29 November

HOW TO DECODE SNORT MESSAGES suresh
Re: HOW TO DECODE SNORT MESSAGES Eric Hines
Re: Snort v2.6.1 and v2.6.1.1 - Either shutdown or hangs after a short period of time Adam Keeton
Re: Is there any documentation showing how to write a snort plugin? Jason Brvenik
December 1st Chicago 2600 Meeting Reminder Steven McGrath
Re: December 1st Chicago 2600 Meeting Reminder Steven McGrath
Re: [Secureideas-base-user] BASE 1.2.7 (karen) released Humes, David G.
"Reset Cause" payload John Hally
snort 2.6.1.1 not sending to mysql Bryan Swann

Thursday, 30 November

delete signature based on SID martin
Has anyone got snort and acid running on RH with SELinux? Jacob, Raymond A Jr

Friday, 01 December

Re: Has anyone got snort and acid running on RH with SELinux? Dirk Geschke
Re: Has anyone got snort and acid running on RH with SELinux? Kevin Johnson
Re: Is there any documentation showing how to write a snort plugin? Richard Bejtlich
Re: Is there any documentation showing how to write a snort plugin? Jason

Saturday, 02 December

Re: delete signature based on SID Michael Scheidell
Re: Is there any documentation showing how to write a snort plugin? John Draper
Re: [RGSPAM] Re: Is there any documentation showing how to write a snort plugin? Martin Roesch

Sunday, 03 December

Re: [RGSPAM] Re: Is there any documentation showing how to write a snort plugin? Justin Heath
Re: [RGSPAM] Re: Is there any documentation showing how to write a snort plugin? John Draper
Re: [RGSPAM] Re: Is there any documentation showing how to write a snort plugin? Jason Brvenik
xjzhu () seu edu cn 朱晓炯

Monday, 04 December

tcp-penalties Rich

Thursday, 07 December

Northern Virginia Snort Users Group - Monday Dec. 11 Mike Guiterman
Changes to the Sourcefire VRT Rules Subscription Mike Guiterman
Multicore support for Snort Siddhartha Jain

Friday, 08 December

one way traffic? John Hally
Re: one way traffic? Bamm Visscher
Re: one way traffic? John Hally

Monday, 11 December

ANNOUNCE: WinPcap 4.0 beta3 has been released Gianluca Varenni
Snort 2.4 + Stream4 + HDLC Eric Hines
Re: Snort 2.4 + Stream4 + HDLC Will Metcalf
Possibly a bug in 2.6.1.x (CVS) with flowbits? Jason Haar

Wednesday, 13 December

CanSecWest 2007 (April 18-20) Call For Papers (Deadline Jan 7th) Dragos Ruiu

Sunday, 17 December

Which switches are recommneded Albert E. Whale
Re: Which switches are recommneded Michael Scheidell
Re: Which switches are recommneded CS Lee
Re: Which switches are recommneded Patrick S. Harper
Re: Which switches are recommneded Eric Hines
Re: Which switches are recommneded Jeff Coppock

Monday, 18 December

IDS Policy Manager v2.0 Released Jeff Dell
Snort v2.6.1.2 is available Mike Guiterman
Re: Which switches are recommneded Albert E. Whale
Re: Snort v2.6.1.2 is available info+lucretia.ca

Tuesday, 19 December

Freebsd + snort (error when Snort start) FRANCIS PROVENCHER
Re: Freebsd + snort (error when Snort start) Todd Wease
Rép. : Freebsd + snort (error when Snort start) FRANCIS PROVENCHER
Re: Rép. : Freebsd + snort (error when Snort start) Todd Wease
(no subject) FRANCIS PROVENCHER
Re: MySQL Error (subject changed) Nigel Houghton
Re: R?p. : Freebsd + snort (error when Snort start) Joel Esler
Re: MySQL Error (subject changed) Paul Schmehl

Wednesday, 20 December

Re: MySQL Error (subject changed) Nigel Houghton

Thursday, 21 December

Putting -o in config file? Hari Sekhon
Re: Putting -o in config file? Matthew Watchinski
Re: Putting -o in config file? Hari Sekhon
Segfault Andy Hester
Re: Segfault Martin Roesch
Re: Segfault Bryan Swann
Re: Segfault Martin Roesch

Friday, 22 December

Problems getting the JpGraph to appear Albert E. Whale

Monday, 25 December

snort data fname lname

Tuesday, 26 December

Reducing snort binary size malvika joshi
Re: Reducing snort binary size Michael W. Cocke
Re: Reducing snort binary size Will Metcalf
Re: Reducing snort binary size Frank Knobbe

Thursday, 28 December

SnortAV? John Hally
Re: SnortAV? purplebag
Re: SnortAV? jrhendri
Re: SnortAV? Jason
Re: SnortAV? Paul Schmehl

Friday, 29 December

Re: SnortAV? John Hally