Snort mailing list archives

Snort 3.0 first subsystem alpha available


From: Martin Roesch <roesch () sourcefire com>
Date: Thu, 5 Apr 2007 17:30:25 -0400

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

The first alpha test for the Snort 3.0 code base is up and available  
in my user area on snort.org.  For you intrepid souls who would like  
to have a look and test it out, please feel free to download the code  
and get going.

http://www.snort.org/users/roesch/Site/Snort%203.0.html

You can download the code directly from

http://www.snort.org/users/roesch/code/snort-03.0.0.a1.4.tar.gz

Snort 3.0 is a new code base with a new architecture.  This first  
alpha release is intended to test out the new Data Source subsystem  
which includes the data acquisition mechanism, the decoder (and  
protocol printers) and the flow manager.  The first alpha also  
includes the new command interface for Snort which is a CLI backed by  
the Lua embeddable programming language.

*Please* read the README, it only takes a few minutes and it'll get  
you up and running quickly.

The code is nowhere near feature complete.  It doesn't have a  
detection engine yet, it doesn't have an output system, it doesn't do  
a whole lot but sniff packets and display them its various output  
modes.  All that other functionality will be following in other  
releases but for now what I'm really looking for people to do is  
start exercising the protocol decoders in real-world environments.   
There are a lot of new and rewritten decoders in this code base so in  
addition to the classic protocols like IPv4, Ethernet and TCP I'm  
particularly interested in getting people to attack the IPv6, MPLS,  
GRE and PPPoE decoders as well as the TCP and IP options decoders.   
If you cause the program to crash while it's sniffing packets I'd  
really like to know about it.

Please have a look and let me know what bugs you find, big and  
small.  Remember to look at the BUGS file for information on filing  
complete bug reports.  Please send bug reports directly to me as  
opposed to the bugs address at snort.org, I'm the point person on  
this alpha series for now.

I'll be putting up architectural diagrams and discussions as I move  
the code forward in my user area on snort.org, stay tuned.

Thanks and happy snorting!

        -Marty

- --
Martin Roesch - Founder/CTO, Sourcefire Inc. - +1-410-290-1616
Sourcefire - Security for the Real World - http://www.sourcefire.com
Snort: Open Source IDP - http://www.snort.org




-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (Darwin)

iD8DBQFGFWpxqj0FAQQ3KOARAgBQAJ9PAcOhINcxsNZZ18WtGo+NPXYQGQCfb0u0
GjkuRzXWEYNChxNHZrZVpNQ=
=w7w/
-----END PGP SIGNATURE-----

-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys-and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: