Snort mailing list archives

Re: Snort - ACID - MySQL - My Head Ache


From: Erek Adams <erek () snort org>
Date: Sun, 23 Mar 2003 13:07:44 -0500 (EST)

On Sun, 23 Mar 2003 snort () xiata com wrote:

[...snip...]

<?xml version="1.0" encoding="UTF-16"?>
<DATABASE>
<EXE NAME="snort.exe" FILTER="GRABMI_FILTER_PRIVACY">
    <MATCHING_FILE NAME="LibnetNT.dll" SIZE="68161" CHECKSUM="0x4194F423"
MODULE_TYPE="WIN32" PE_CHECKSUM="0x1A1D9" LINKER_VERSION="0x10000"
LINK_DATE="02/03/2003 12:31:42" UPTO_LINK_DATE="02/03/2003 12:31:42"
/>
    <MATCHING_FILE NAME="snort.exe" SIZE="462848" CHECKSUM="0xBC282371"
MODULE_TYPE="WIN32" PE_CHECKSUM="0x0" LINKER_VERSION="0x0"
LINK_DATE="03/04/2003 16:36:08" UPTO_LINK_DATE="03/04/2003 16:36:08"
/>
</EXE>
<EXE NAME="kernel32.dll" FILTER="GRABMI_FILTER_THISFILEONLY">
    <MATCHING_FILE NAME="kernel32.dll" SIZE="930304" CHECKSUM="0xCBCCF8A9"
BIN_FILE_VERSION="5.1.2600.1106" BIN_PRODUCT_VERSION="5.1.2600.1106"
PRODUCT_VERSION="5.1.2600.1106" FILE_DESCRIPTION="Windows NT BASE API
Client DLL" COMPANY_NAME="Microsoft Corporation"
PRODUCT_NAME="Microsoftr Windowsr Operating System"
FILE_VERSION="5.1.2600.1106 (xpsp1.020828-1920)"
ORIGINAL_FILENAME="kernel32" INTERNAL_NAME="kernel32"
LEGAL_COPYRIGHT="c Microsoft Corporation. All rights reserved."
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x40004"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0xE7ED3"
LINKER_VERSION="0x50001" UPTO_BIN_FILE_VERSION="5.1.2600.1106"
UPTO_BIN_PRODUCT_VERSION="5.1.2600.1106" LINK_DATE="08/29/2002
10:40:40" UPTO_LINK_DATE="08/29/2002 10:40:40" VER_LANGUAGE="English
(United States) [0x409]" />
</EXE>
</DATABASE>

[...snip...]

Ok, pardon me for not following that XML garbage, but....  Other than
files and versions, I can't see any useful information in it.  Is there
_any_ sort of error message listed?  Is it Snort that dies, or is it
MySQL?  Anything in the EventLog, if XP has something like that.

Thanks to MS for hiding things from the users!  </sarcasm>

-----
Erek Adams

   "When things get weird, the weird turn pro."   H.S. Thompson


-------------------------------------------------------
This SF.net email is sponsored by:Crypto Challenge is now open! 
Get cracking and register here for some mind boggling fun and 
the chance of winning an Apple iPod:
http://ads.sourceforge.net/cgi-bin/redirect.pl?thaw0031en
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: