Snort: by date

379 messages starting Jul 01 07 and ending Sep 29 07
Date index | Thread index | Author index


Sunday, 01 July

Error handling in Snort bahamin takhtaei

Monday, 02 July

multiple port variable fun ryan
Re: Mike Potamousis/Poughkeepsie/Contr/IBM is out of theoffice. Lee Brotherston

Tuesday, 03 July

Aanval 3.1.30161 Released (Snort / Syslog Correlation) Administration
Analysis Tools Michael Bann
Re: multiple port variable fun Ryan Hudson
PacSec 2007 Call For Papers (Nov. 29/30, deadline July 27) Dragos Ruiu

Wednesday, 04 July

Re: multiple port variable fun Jeffrey Denton

Thursday, 05 July

BASE Payload Search Humes, David G.
Re: BASE Payload Search Jeffrey Denton

Saturday, 07 July

IP Option lsrre Jeffrey Denton

Sunday, 08 July

More fun with IP Option lrsse Jeffrey Denton

Monday, 09 July

Re: More fun with IP Option lrsse Todd Wease
[Fwd: Re: [Snort-devel] IP Option Router Alert Wrong Value] Todd Wease

Wednesday, 11 July

Snort & Barnyard permission issues マシス・ザッカリー

Thursday, 12 July

Re: Snort & Barnyard permission issue Bamm Visscher
Snort rule to detect Windows PE Executable Downloads Humes, David G.
Re: Snort rule to detect Windows PE Executable Downloads Jeffrey Denton
telnet.rules FATAL ERROR jamal ayach
Re: Snort rule to detect Windows PE Executable Downloads Humes, David G.
Re: Snort rule to detect Windows PE ExecutableDownloads Paul Melson
Porn.rules dont work? FRANCIS PROVENCHER
Database Insertion Error Marc Appelbaum
Re: Database Insertion Error Dirk Geschke
Re: Snort rule to detect Windows PE ExecutableDownloads Matt Jonkman
Re: Snort rule to detect Windows PE Executable Downloads Humes, David G.
Re: [Snort-sigs] Snort rule to detect Windows PE Executable Downloads Matt Jonkman

Friday, 13 July

Re: [Snort-sigs] Snort rule to detect Windows PE Executable Downloads Humes, David G.
QUESTION: use Snort to benchmark silicon Chu Chen-Chau-ra9643
Re: [Snort-sigs] Snort rule to detect Windows PE Executable Downloads Will Metcalf
Re: QUESTION: use Snort to benchmark silicon Matthew Watchinski

Sunday, 15 July

Threshold-Local None snort-2.7 Jeffrey Denton
Snort 2.7.0 thresholding-local none Jeffrey Denton

Monday, 16 July

Re: Archiving events via BASE David Ryan
mysql database "gone away" David Ryan
Re: mysql database "gone away" Dirk Geschke
Re: mysql database "gone away" Jason Brvenik

Tuesday, 17 July

mysql error Atkins, Dwane P
Re: mysql error Atkins, Dwane P
Re: mysql error Atkins, Dwane P
Re: mysql database "gone away" cconn

Wednesday, 18 July

What's up with Snort's license? Martin Roesch
Fwd: What's up with Snort's license? Martin Roesch
ACSM-No Memory: queue_add! REJK295
Re: ACSM-No Memory: queue_add! Marc Norton
Re: What's up with Snort's license? Martin Roesch
Re: What's up with Snort's license? Loyal Moses
Fwd: What's up with Snort's license? Martin Roesch
Re: What's up with Snort's license? Matt Jonkman
Re: What's up with Snort's license? Ace Nimrod

Thursday, 19 July

Re: [Bleeding-sigs] RE: What's up with Snort's license? Alan Shimel
FOSS system console project - applicable to Snort? Greg Wallace
Re: What's up with Snort's license? (Answer rollup) Martin Roesch
Snort v2.7.0 Now Available Snort Releases
Re: What's up with Snort's license? (Answer rollup) Alan Shimel
Re: [Bleeding-sigs] RE: What's up with Snort's license? Matt Jonkman
Re: [Bleeding-sigs] RE: What's up with Snort'slicense? Alan Shimel
Re: What's up with Snort's license? Harry Hoffman
Re: What's up with Snort's license? Tom Le

Friday, 20 July

Re: [Bleeding-sigs] RE: What's up with Snort'slicense? Victor Julien
Re: [Bleeding-sigs] RE: What's up with Snort'slicense? Alan Shimel
Re: Snort v2.7.0 Now Available Colin Grady
CVS is back up Mike Guiterman
Re: Snort v2.7.0 Now Available Justin Heath
Re: Snort v2.7.0 Now Available Colin Grady
Re: CVS is back up Matt Kettler
Re: Snort v2.7.0 Now Available Justin Heath
Re: Snort v2.7.0 Now Available Colin Grady
Re: Snort v2.7.0 Now Available Todd Wease
Re: What's up with Snort's license? (Answer rollup) Matt Jonkman

Saturday, 21 July

Re: What's up with Snort's license? (Answer rollup) Paul Schmehl
Re: [Bleeding-sigs] Re: What's up with Snort's license? (Answer rollup) Matt Jonkman

Sunday, 22 July

IDMEF plugin for snort 2.6? Jochen Kaiser
Contibue to snort!! sabrina ykrelef
Re: IDMEF plugin for snort 2.6? Justin Heath

Monday, 23 July

Re: IDMEF plugin for snort 2.6? (infor) urko zurutuza
Snort v2.7.0 improve performance with lowmem search method on pcap file! rmkml
Re: Snort v2.7.0 improve performance with lowmem search method on pcap file! Colin Grady
Re: Snort v2.7.0 improve performance with lowmem search method on pcap file! Justin Heath
Re: Snort v2.7.0 improve performance with lowmem search method on pcap file! rmkml
Re: Snort v2.7.0 improve performance with lowmem search method on pcap file! Colin Grady
Fwd: Snort v2.7.0 improve performance with lowmem search method on pcap file! Justin Heath
Re: Snort v2.7.0 improve performance with lowmem search method on pcap file! rmkml
Re: Snort v2.7.0 improve performance with lowmem search method on pcap file! Marc Norton
Re: [Bleeding-sigs] RE: What's up with Snort's license? Martin Roesch

Tuesday, 24 July

little typo on snort 270 (and previous) pdf manual rmkml
Re: little typo on snort 270 (and previous) pdf manual Justin Heath
Contribue to snort!! sabrina ykrelef
Configuring Barnyard with Bleeding threat rules Christopher Rommel
Re: Configuring Barnyard with Bleeding threat rules Paul Melson
Re: multiple port variable fun Frank Knobbe
Re: Error handling in Snort Frank Knobbe
Re: Rules to block FT Frank Knobbe

Wednesday, 25 July

Re: Configuring Barnyard with Bleeding threat rules Paul Melson
Re: Error handling in Snort Justin Heath
Re: multiple port variable fun Justin Heath
Snort and nf_queue bahamin takhtaei

Thursday, 26 July

Re: Snort and nf_queue Will Metcalf

Friday, 27 July

This is a new one Atkins, Dwane P
Re: This is a new one Will Metcalf
Re: This is a new one Matt Jonkman
Re: Snort-users Digest, Vol 14, Issue 23 Terry Rose
Re: This is a new one Atkins, Dwane P
Re: This is a new one Will Metcalf
Re: This is a new one Atkins, Dwane P
Re: This is a new one Atkins, Dwane P
Re: This is a new one Will Metcalf

Monday, 30 July

EasyIDS 0.2 released h h
Re: This is a new one Atkins, Dwane P

Tuesday, 31 July

Re: This is a new one Atkins, Dwane P
Re: This is a new one Joel Esler
Re: This is a new one Atkins, Dwane P
Re: This is a new one Will Metcalf
Re: This is a new one Atkins, Dwane P
Re: This is a new one Atkins, Dwane P
YUM Atkins, Dwane P
Re: YUM M. Shirk
Re: YUM Atkins, Dwane P
Re: YUM Justin Heath
Re: YUM Matt Kettler
Re: YUM Atkins, Dwane P
P2P - is this handled well? Derrick
Really, really, penultimate, PacSec CFP deadline, Aug 10. Dragos Ruiu
Re: YUM M. Shirk

Wednesday, 01 August

Diagnosing snort 2.7.0 seg fault James Lay
Re: Diagnosing snort 2.7.0 seg fault M. Shirk
Re: Diagnosing snort 2.7.0 seg fault Matthew Watchinski
Re: YUM Justin Heath
Re: Diagnosing snort 2.7.0 seg fault Justin Heath
Re: Diagnosing snort 2.7.0 seg fault James Lay
Re: Diagnosing snort 2.7.0 seg fault Colin Grady
Re: YUM M. Shirk
Re: Diagnosing snort 2.7.0 seg fault Todd Wease
Re: P2P - is this handled well? Matt Jonkman

Thursday, 02 August

byte_test snort user
Re: byte_test Todd Wease
Re: byte_test Nigel Houghton
session monitoring question Eddie Corns
Re: session monitoring question Nigel Houghton
Re: session monitoring question Eddie Corns
Re: session monitoring question John Pritchard

Friday, 03 August

Looking for Archive help Bill Warren
Re: Looking for Archive help Paul Schmehl
Re: [Snort-devel] Evasion Due to Multiple Instances of SPAN Traffic Benjamin Small
VRT Rules Subscription ? John Hally
Re: VRT Rules Subscription ? David J. Bianco
Re: VRT Rules Subscription ? Mike Guiterman
Re: VRT Rules Subscription ? David J. Bianco

Monday, 06 August

Re: Snort-users Digest, Vol 15, Issue 4 Tom Webb
Snort 2.7.0.1 Now Available Snort Releases
Nashville Snort Users Group Meeting - August 22, 6:00 PM Mike Guiterman

Tuesday, 07 August

[$HOME_NET, !192.168.1.222, !192.168.1.223] ? (subnet except specific IPs) Yakov Lerner
Re: [$HOME_NET, !192.168.1.222, !192.168.1.223] ? (subnet except specific IPs) Matt Kettler
Re: [$HOME_NET, !192.168.1.222, !192.168.1.223] ? (subnet except specific IPs) Yakov Lerner
Re: [$HOME_NET, !192.168.1.222, !192.168.1.223] ? (subnet except specific IPs) James Lay
Re: [$HOME_NET, !192.168.1.222, !192.168.1.223] ? (subnet except specific IPs) Jason
Re: [$HOME_NET, !192.168.1.222, !192.168.1.223] ? (subnet except specific IPs) Yakov Lerner
Re: [$HOME_NET, !192.168.1.222, !192.168.1.223] ? (subnet except specific IPs) Jason
Re: [$HOME_NET, !192.168.1.222, !192.168.1.223] ? (subnet except specific IPs) Yakov Lerner
Re: [$HOME_NET, !192.168.1.222, !192.168.1.223] ? (subnet except specific IPs) Patrik Nordlén

Wednesday, 08 August

Little game about Snort ROPERT François
Search for PMGraph-Skript Beyerle, Christian
Re: Search for PMGraph-Skript Joel Esler
Re: Search for PMGraph-Skript Ryan Carter
Re: [$HOME_NET, !192.168.1.222, !192.168.1.223] ? (subnet except specific IPs) Matt Kettler
Re: Search for PMGraph-Skript Andreas Maus
Re: Search for PMGraph-Skript Ryan Carter
Re: Search for PMGraph-Skript Martin Roesch
new pcre P option missing on snort v2.7.0.[0-1] pdf manual rmkml
Re: [Snort-devel] new pcre P option missing on snort v2.7.0.[0-1] pdf manual Mike Guiterman
very litle typo on sf_snort_plugin_rc4.c snort v2.[6-7] rmkml
very litle typo on sf_snort_plugin_content.c snort v2.[6-7] rmkml

Thursday, 09 August

sid-msg.map snort user
Re: sid-msg.map Nigel Houghton
Re: sid-msg.map snort user
Re: sid-msg.map Nigel Houghton
Re: sid-msg.map Joel Esler
Re: sid-msg.map Adam Keeton
Re: Search for PMGraph-Skript Jason Brvenik

Friday, 10 August

Snort V2.7.x ClamAV patch John Jenkinson

Saturday, 11 August

What different between using "threshold" and "track" for rule and flow-portscan ?? Lerdpong Lerdpaisarnwong
Re: What different between using "threshold" and "track" for rule and flow-portscan ?? Paul Schmehl
Re: Snort V2.7.x ClamAV patch Will Metcalf
Windows support sudhakar govindavajhala

Sunday, 12 August

Re: Windows support Jason
Re: Windows support Michael Steele
How can change a rule action immediately? bahamin takhtaei

Monday, 13 August

Aanval 3.2 Released! (Snort and Syslog Correlation) Administration
config woes with 2.7.0.1 and frag3 Russell Fulton
Re: config woes with 2.7.0.1 and frag3 Justin Heath
Re: config woes with 2.7.0.1 and frag3 Russell Fulton
problems compiling 2.7.0.1 on Open BSD Russell Fulton

Tuesday, 14 August

HUP signal Yakov Lerner
'drop' vs 'reject' Yakov Lerner
problems with chats (icq, jabber, gadu gadu) Yakov Lerner
Fwd: 'drop' vs 'reject' Yakov Lerner
Re: config woes with 2.7.0.1 and frag3 Justin Heath
Re: problems compiling 2.7.0.1 on Open BSD Justin Heath
Re: HUP signal Justin Heath

Wednesday, 15 August

Richard Bejtlich to speak at August Chicago SUG Meeting. Wagner, Robert
Correction:Richard Bejtlich to speak at August Chicago SUG Meeting. Wagner, Robert

Thursday, 16 August

Snort problem maryam cheikhi
Re: Snort problem Jeff Dell
Installation - Snort/MySQL/Apache all on one box vs dedicated MySQL/Apache server Humes, David G.

Sunday, 19 August

Diagnosing MySQL server has gone away messages James Lay

Monday, 20 August

Problems daemonizing snort when using BPF filters Patrik Nordlén
Re: Diagnosing MySQL server has gone away messages Joel Esler
Re: Problems daemonizing snort when using BPF filters Joel Esler
Re: Diagnosing MySQL server has gone away messages Jason Haar
Barnyard for Windows? Michael Steele
barnyard with syslog and mysql logging fname lname
Re: Diagnosing MySQL server has gone away messages Joel Esler
Re: barnyard with syslog and mysql logging Bamm Visscher

Tuesday, 21 August

Re: Diagnosing MySQL server has gone away messages bleh
Re: Diagnosing MySQL server has gone away messages Dirk Geschke
Re: Diagnosing MySQL server has gone away messages Joel Esler
Re: Diagnosing MySQL server has gone away messages bleh
Re: Diagnosing MySQL server has gone away messages Jason
Re: Barnyard for Windows? M. Shirk
Re: barnyard with syslog and mysql logging fname lname
Re: barnyard with syslog and mysql logging Bamm Visscher
Re: Diagnosing MySQL server has gone away messages bleh
Re: Diagnosing MySQL server has gone away messages Matthew Watchinski
Re: Diagnosing MySQL server has gone away messages Michael Stone
Re: Diagnosing MySQL server has gone away messages Michael Stone
Listening to Wrong Interface (OS X) Quantum Scientific
Re: Diagnosing MySQL server has gone away messages Jason
Re: Diagnosing MySQL server has gone away messages Nerijus Krukauskas

Wednesday, 22 August

Re: Listening to Wrong Interface (OS X) Jason
[Semi-OT] What other applications contribute to Snort being a complete package? James Lay
Re: Diagnosing MySQL server has gone away messages bleh
Re: [Semi-OT] What other applications contribute to Snort being a complete package? Justin Heath
Re: Barnyard for Windows? Justin Heath
Re: [Semi-OT] What other applications contribute to Snort being a complete package? James Lay
Re: Barnyard for Windows? M. Shirk
Re: Barnyard for Windows? Justin Heath
Re: Listening to Wrong Interface (OS X) Quantum Scientific
Re: Listening to Wrong Interface (OS X) James Lay
Re: Listening to Wrong Interface (OS X) Jason
Re: Listening to Wrong Interface (OS X) Quantum Scientific
Re: Barnyard for Windows? Jason
Re: Listening to Wrong Interface (OS X) Quantum Scientific
Re: [RGSPAM] Re: Listening to Wrong Interface (OS X) Todd Wease
Snort 2.8 Beta Available on CVS Snort Releases
Re: [Semi-OT] What other applications contribute to Snort being a complete package? Joel Esler
Re: [RGSPAM] Re: Listening to Wrong Interface (OS X) Quantum Scientific
Re: Diagnosing MySQL server has gone away messages Jason

Thursday, 23 August

inline advice Dev Null
Re: Snort 2.8 Beta Available on CVS Marc Norton
IDS Policy Manager v2.1 Released Jeff Dell

Monday, 27 August

Snort keeps quitting john
Re: Snort keeps quitting john
mailing list suggestion john
Re: Snort keeps quitting john
Re: Snort keeps quitting john
Re: mailing list suggestion john
Stream5 and Asymmetric case snort user
ONLY TWO DAYS LEFT to register for August ChiSUG meeting. Wagner, Robert

Tuesday, 28 August

Correction ONLY TWO DAYS LEFT to register for August 29th ChiSUG meeting. Wagner, Robert
Recall: Correction ONLY TWO DAYS LEFT to register for August 29th ChiSUG meeting. Wagner, Robert
CORRECTION ONLY TWO DAYS LEFT to register for August 29th ChiSUG meeting. Wagner, Robert
Taking Down Wifi Quantum Scientific
Re: Taking Down Wifi Jason Brvenik
Sensor insertion options. Paul Halliday
Re: Taking Down Wifi Quantum Scientific
Re: Taking Down Wifi James Lay
Alert turns up as ftp_telnet Brian Lavender
Job Opportunity with Checkpoint as QA Lead Manager Matthew Hull
Re: Taking Down Wifi Quantum Scientific
Re: Taking Down Wifi James Lay

Wednesday, 29 August

snort rule lokesh sharma
Re: snort rule rmkml
Re: Taking Down Wifi Dev Null
Re: snort rule Joel Esler
Re: snort rule Nigel Houghton
Re: Taking Down Wifi Quantum Scientific
Re: Taking Down Wifi Martin Roesch
Re: snort rule Paul Schmehl
Re: snort rule Joel Esler
Re: snort rule Milo Velimirovic
CPU usage and bleeding-compromised.rules James Lay
Snort.org Registration has been fixed Mike Guiterman
Re: snort rule M. Shirk
http_inspect Tuning Eric
Snort 2.8 Beta Now Available Snort Releases
Re: CPU usage and bleeding-compromised.rules Matt Jonkman
Re: Snort 2.8 Beta Now Available Jeff Dell

Thursday, 30 August

Re: Snort keeps quitting john
webmin module john
Re: webmin module john
Re: webmin module Joel Esler
Re: Snort keeps quitting john
Re: Snort keeps quitting Joel Esler
Re: webmin module john
Re: Snort keeps quitting john
Re: webmin module Joel Esler
Webinar with Judy Novak Mike Guiterman
Re: snort rule pearl carlo

Friday, 31 August

Re: Snort 2.8 Beta Available on CVS Dirk Geschke
Re: webmin module john
snort 2.7.0.1 segfaults on amd64 Siim Põder
Re: Snort 2.8 Beta Available on CVS Justin Heath
Re: snort 2.7.0.1 segfaults on amd64 Justin Heath
Re: Snort 2.8 Beta Available on CVS Dirk Geschke
Re: Snort 2.8 Beta Available on CVS Justin Heath
Re: Snort 2.8 Beta Available on CVS Dirk Geschke
Re: Snort 2.8 Beta Available on CVS Kevin Johnson

Saturday, 01 September

Re: snort 2.7.0.1 segfaults on amd64 Info
need tutorial suri adin

Monday, 03 September

OT: VLANs and ngrep? Jason Haar

Tuesday, 04 September

Re: OT: VLANs and ngrep? Paul Melson
Re: OT: VLANs and ngrep? Jason Haar
rules to mysql John Hally

Wednesday, 05 September

sourcefire is falling... snort? Patrizio
Re: sourcefire is falling... snort? M. Shirk
Re: sourcefire is falling... snort? Will Metcalf
cofiguration snort suri adin
Re: cofiguration snort Joel Esler
portscan: Open Port fname lname

Thursday, 06 September

Re: portscan: Open Port fname lname
Re: sourcefire is falling... snort? Mike Guiterman
snort keeps dying!!! Zakai Kinan
Re: snort keeps dying!!! Joel Esler
Re: snort keeps dying!!! Zakai Kinan
Re: snort keeps dying!!! Joel Esler
Re: snort keeps dying!!! M. Shirk
Re: snort keeps dying!!! Zakai Kinan
Re: snort keeps dying!!! Todd Wease
Live Q&A on Stream Reassembly in Snort with Judy Novak - Tues Sept. 18 Mike Guiterman

Friday, 07 September

Snort 2.8 RC1 is now Available on CVS SnortReleases

Monday, 10 September

Re: snort keeps dying!!! Zakai Kinan

Wednesday, 12 September

Compile snort with inline option (libnet 1.0.x is obsolete) carlopmart
Re: Compile snort with inline option (libnet 1.0.x is obsolete) Tedi Heriyanto
Snort 2.8 RC1 Now Available Snort Releases
libc detects snort memory problems Russell Fulton
Re: libc detects snort memory problems Russell Fulton

Thursday, 13 September

Snort Alert Description in BASE chris mr
Re: Snort Alert Description in BASE David J. Bianco
Re: Snort Alert Description in BASE chris mr

Saturday, 15 September

catching some alerts, but NOT consistent Casiano, Jason (Sys Admin)

Sunday, 16 September

Re: Compile snort with inline option (libnet 1.0.x is obsolete) Juergen Leising
Re: catching some alerts, but NOT consistent Jason Brvenik
Re: catching some alerts, but NOT consistent Casiano, Jason (Sys Admin)
Re: catching some alerts, but NOT consistent Casiano, Jason (Sys Admin)

Monday, 17 September

Re: catching some alerts, but NOT consistent Jason Brvenik
Reminder - Live Q&A call with Judy Novak - Tuesday Mike Guiterman
Aanval Build 30222 Available & New Forum Administration

Tuesday, 18 September

Patrick Harper's Guide CoryC

Wednesday, 19 September

Snort 2.7.0.1 Preprocessor Drop Patches Joel Ebrahimi

Friday, 21 September

Snort error: Unterminated IP List and clamav problems carlopmart
Re: Snort error: Unterminated IP List and clamav problems carlopmart
Re: Snort error: Unterminated IP List and clamav problems Will Metcalf
Re: Snort error: Unterminated IP List and clamav problems (SOLVED) carlopmart

Saturday, 22 September

Blocking virus with snort inline 2.6.1.5 carlopmart
Re: Blocking virus with snort inline 2.6.1.5 Will Metcalf

Sunday, 23 September

Re: Blocking virus with snort inline 2.6.1.5 carlopmart
New Installation Rachid Abdelkhalak
Slackware Snort Installation Guide Jeffrey Denton
Re: New Installation Joel Esler

Monday, 24 September

Re: Blocking virus with snort inline 2.6.1.5 carlopmart
Re: Blocking virus with snort inline 2.6.1.5 Joel Esler
Re: Blocking virus with snort inline 2.6.1.5 Will Metcalf
Re: Blocking virus with snort inline 2.6.1.5 carlopmart
Re: Blocking virus with snort inline 2.6.1.5 (more info) carlopmart
Re: New Installation abdelmajid lakbabi

Wednesday, 26 September

www.snort.org offline? Michael Scheidell
Re: www.snort.org offline? Harry Hoffman
Re: www.snort.org offline? Joel Esler

Thursday, 27 September

Snort 2.8 Now Available Snort Releases
Snort 2.8 compile error James Lay
Re: Snort 2.8 compile error J. Jefferson Gray
Re: Snort 2.8 compile error M. Shirk
Re: Snort-users Digest, Vol 16, Issue 11 Terry Rose
Re: Snort-users Digest, Vol 16, Issue 11 M. Shirk
Re: Snort 2.8 compile error J. Jefferson Gray

Friday, 28 September

Re: Snort 2.8 compile error Adam Keeton
Re: Snort 2.8 compile error James Lay
Re: Snort 2.8 compile error Adam Keeton

Saturday, 29 September

Barnyard and Drop events Josep Román