Snort: by date

777 messages starting Jul 01 05 and ending Sep 30 05
Date index | Thread index | Author index


Friday, 01 July

making Snort listen to correct NIC David Naylor
RE: making Snort listen to correct NIC Joshua Berry

Saturday, 02 July

connecting snort at mysql deny
connecting snort and mysql deny

Sunday, 03 July

Re: connecting snort at mysql Kevin Johnson

Monday, 04 July

Optimizing Snort, MySQL & BASE installation Affan Basalamah
Re: Optimizing Snort, MySQL & BASE installation Gary Richardson
Re: Optimizing Snort, MySQL & BASE installation Kevin Johnson
Re: Optimizing Snort, MySQL & BASE installation Michael Stone
Re: Optimizing Snort, MySQL & BASE installation Michael Stone

Tuesday, 05 July

Bleeding-Edge Virus 2001268 false positive (SWEN.A) Rich Adamson
Re: Bleeding-Edge Virus 2001268 false positive (SWEN.A) Xavier Cabrera
Logs in Messages Xavier Cabrera

Wednesday, 06 July

windows 2k interface cmd in conf Turnquist,Wayne
RE: making Snort listen to correct NIC David Naylor
RE: making Snort listen to correct NIC Joshua Berry
Re: windows 2k interface cmd in conf Matt Kettler
RE: making Snort listen to correct NIC David Naylor
RE: making Snort listen to correct NIC Joe Pope

Thursday, 07 July

Need a help Ks, Mithun (GE Commercial Finance, non-GE)
Re: making Snort listen to correct NIC Kevin Reiter
RE: Need a help Ks, Mithun (GE Commercial Finance, non-GE)
RE: windows 2k interface cmd in conf Turnquist,Wayne
(snort_decoder): Short UDP packet, length field > payload length Flora.francesco
Re: windows 2k interface cmd in conf Kevin Reiter
RE: windows 2k interface cmd in conf Turnquist,Wayne
Snort Rules & Variables Pennell, Ronald B.
RE: Snort Rules & Variables Briggs, Bruce
Re: windows 2k interface cmd in conf Kevin Reiter
Re: Snort Rules & Variables Joel Esler
RE: making Snort listen to correct NIC David Naylor
RE: windows 2k interface cmd in conf Michael Steele

Friday, 08 July

RE: windows 2k interface cmd in conf Turnquist,Wayne
windows 2k single pc with multiple snort interface with portscan log ? Turnquist,Wayne
Re: windows 2k single pc with multiple snort interface with portscan log ? Rich Adamson
snort variable to specify 2 networks and exclude one IP inside the network - How? Simon Yip
RE: snort variable to specify 2 networks and exclude one IP inside the network - How? Srinivas Katta
RE: snort variable to specify 2 networks and exclude one IP inside the network - How? Srinivas Katta
Looking for Minimum System Requirments for BASE with SQL Bill Warren
MYSQL database maintenance for Snort Byron Pezan
RE: Looking for Minimum System Requirments for BASE with SQL Willy, Andrew
Re: MYSQL database maintenance for Snort Jeff Kell
Re: Looking for Minimum System Requirments for BASE with SQL Bill Warren
Re: Snort-users digest, Vol 1 #5189 - 7 msgs Nick Plante

Saturday, 09 July

waldogps - monitor multiple copies of barnyard running against multiple databases Richard Harman

Sunday, 10 July

RE: Need a help Charles Heselton

Monday, 11 July

sid-msg.map file & ACID Bahya NASSR EDDINE
RE: snort variable to specify 2 networks and exclude one IP inside the network - How? Paul Melson
RE: Logs in Messages Paul Melson
Re: sid-msg.map file & ACID Joel Esler
snortcenter2 and "no updates at this time" John Hally

Tuesday, 12 July

Possible Evasion in Snort Multi Pattern Algorithm bmc
PacSec/core05 Call For Papers Dragos Ruiu

Wednesday, 13 July

Snort config and setup Need you help - Please! Arthur Chilipweli
RE: Snort config and setup Need you help - Please! Patrick Harper
UNSUBSCRIBE Shaun Gray
Re: UNSUBSCRIBE Matt Kettler
Re: Snort config and setup Need you help - Please! Matt Kettler
Re: Snort config and setup Need you help - Please! Matt Kettler
RE: Snort config and setup Need you help - Please! Jeff Dell
Re: Snort-users digest, Vol 1 #5192 - 5 msgs Simon Yip
Can a win2k pcap 1 interface have multiple sniff apps.......... Turnquist,Wayne
RE: Snort config and setup Need you help - Please! Arthur Chilipweli
RE: Snort config and setup Need you help - Please! Arthur Chilipweli
Re: Re: Snort-users digest, Vol 1 #5192 - 5 msgs Paul Schmehl
Re: Can a win2k pcap 1 interface have multiple sniff apps.......... Rich Adamson
Re: Possible Evasion in Snort Multi Pattern Algorithm Zultan
Re: Re: Possible Evasion in Snort Multi Pattern Algorithm Joel Esler
Re: Re: Possible Evasion in Snort Multi Pattern Algorithm Jason

Thursday, 14 July

help:rh3+pptp+radius+mysql error? abanger wu
snort/acid/base not displaying portscan traffic Paule
preprocessor http_inspect_server destroying traffic snort guy
Re: (snort_decoder): Short UDP packet, length field > payload length Jason Brvenik
Re: (snort_decoder): Short UDP packet, length field > payload length Joel Esler
Re: snort/acid/base not displaying portscan traffic Joel Esler
syslog facility Chris Stankaitis
Re: syslog facility Rich Adamson
Re: syslog facility Joel Esler
Re: syslog facility Joel Esler
RE: (snort_decoder): Short UDP packet, length field > payload length Willy, Andrew
Variable to specify 2 networks and exclude 1 host - How? Simon Yip
RE: (snort_decoder): Short UDP packet, length field > payload leng M. Shirk
RE: (snort_decoder): Short UDP packet, length field > payload leng Willy, Andrew
RE: (snort_decoder): Short UDP packet, length field > payload leng M. Shirk
RE: Re: Snort-users digest, Vol 1 #5192 - 5 msgs Paul Melson
Re: Re: Snort-users digest, Vol 1 #5192 - 5 msgs Jason Brvenik
Re: Variable to specify 2 networks and exclude 1 host - How? Matt Kettler
Re: preprocessor http_inspect_server destroying traffic Will Metcalf

Friday, 15 July

ACID and sid-msg.map file Bahya NASSR EDDINE
Re: ACID and sid-msg.map file Guillaume Arcas
Re: ACID and sid-msg.map file Bahya NASSR EDDINE
Re: ACID and sid-msg.map file Guillaume Arcas
Re: ACID and sid-msg.map file Bahya NASSR EDDINE
Re: ACID and sid-msg.map file Paul Schmehl
Old unified log files Kolanovic, Tomislav/Human Resources
Re: Old unified log files Paul Schmehl
RE: Old unified log files Kolanovic, Tomislav/Human Resources

Sunday, 17 July

UNSUSCRIBE Teva AVRIL
(no subject) Angelita de Cássia Corrêa
snort_decoder Angelita de Cássia Corrêa
Re: snort_decoder Joel Esler
Re: snort_decoder Martin Roesch

Monday, 18 July

snort_decoder Angelita de Cássia Corrêa
gui Plantier, Spencer
RE: Old unified log files SRH-Lists
False positive Angelita de Cássia Corrêa
Re: False positive Joel Esler
Re: False positive Angelita de Cássia Corrêa
Re: False positive Angelita de Cássia Corrêa
RE: Old unified log files Kolanovic, Tomislav/Human Resources
Re: False positive Matt Kettler
RE: False positive Briggs, Bruce

Tuesday, 19 July

SYN Proxy Xavier Cabrera
Re: SYN Proxy Jason Brvenik
Re: SYN Proxy Matt Kettler
Re: SYN Proxy Will Metcalf
Re: SYN Proxy Xavier Cabrera
Re: Snort-users digest, Vol 1 #5201 - 5 msgs Nick Plante

Wednesday, 20 July

Re: SYN Proxy Matt Kettler
Re: SYN Proxy Daniel Cid
Re: SYN Proxy Xavier Cabrera

Thursday, 21 July

upgrade snort Bahya NASSR EDDINE
Movin' on up... Joel Esler
Snort on Multiple Interfaces Ron
Re: Undocumented SIDs Matt Kettler
RE: Undocumented SIDs Willy, Andrew
Re: Undocumented SIDs Nigel Houghton
Undocumented SIDs Willy, Andrew
P2P traffic? gary douglas
RE: Undocumented SIDs Willy, Andrew
spp_arpspoof Jason Warren
RE: Undocumented SIDs Willy, Andrew
Re: Undocumented SIDs Matt Kettler
Re: Undocumented SIDs M. Shirk

Friday, 22 July

Output unified lmarcilly
Re: Output unified Jason Brvenik
snort perf monitoring John Hally
Re: snort perf monitoring Matt Kettler
Re: Snort on Multiple Interfaces Ron
Re: Snort on Multiple Interfaces Joel Esler
Snort Lunch at DefCon Jennifer Steffens

Saturday, 23 July

Re: snort perf monitoring Andreas Östling

Monday, 25 July

RE: snort perf monitoring John Hally
Exploit VQserver admin alert - need 9090 access Richard Brown
OSSRC Web Site Live Jennifer Steffens

Tuesday, 26 July

OT-ish: libpcap apps on x86_64 Alex Butcher, ISC/ISYS
http_inspect ?'s John Hally
IPS snort sara
RE: IPS James Bruce
Re: IPS Matt Kettler
Re: IPS Will Metcalf
Re: [Snort-devel] OT-ish: libpcap apps on x86_64 Phil Wood
Snort v2.3.4 Ron Jenkins
Re: Snort v2.3.4 Frank Knobbe
Re: Snort v2.3.4 Frank Knobbe
RE: IPS Patrick Harper
RE: IPS Theodore Stout

Wednesday, 27 July

Re: [Snort-devel] OT-ish: libpcap apps on x86_64 Alex Butcher, ISC/ISYS
Alerts snort sara
RE: Alerts Jeff Dell
Re: Snort v2.3.4 Jennifer Steffens
ids-load-balancing-HOWTO Jeremy M. Guthrie

Thursday, 28 July

Re: ids-load-balancing-HOWTO Richard Bejtlich
http_inspect ? John Hally
Snort 2.4 Released! Jennifer Steffens
Re: Snort 2.4 Released! Sam Evans
RE: Snort 2.4 Released! Jeff Dell
Re: Snort 2.4 Released! Martin Roesch
2.4.0 snort/snort-mysql RPM conflict Earl Sammons
Re: 2.4.0 snort/snort-mysql RPM conflict Martin Roesch

Friday, 29 July

Re: 2.4.0 snort/snort-mysql RPM conflict Earl Sammons
2.4.0 RPM - inline conflics w/ snort Earl Sammons
IPS Group Test Edition 3 Bob Walder
snort init.d script wont start snort in suse Cor Koelewijn
Snort 2.4.0 problem John Hally
Re: Snort 2.4.0 problem Frank Knobbe
Re: Snort 2.4.0 problem Frank Knobbe

Saturday, 30 July

Snort IDMEF Plugin 2.0.0alpha2 released for Snort 2.4.0 Sandro Poppi
Re: snort init.d script wont start snort in suse Cor Koelewijn
Re: Snort-users digest, Vol 1 #5213 - 2 msgs Nick Plante

Sunday, 31 July

windows platform, looking for easy cisco ACL mang solution Turnquist,Wayne
Re: windows platform, looking for easy cisco ACL mang solution Jason Brvenik

Monday, 01 August

Maximum Number Of IPs Per Variable In snort.conf O'Sullivan, Mairtin
Net minus one address? Rich Adamson
Alert on new IP in use? Rich Adamson
RE: Alert on new IP in use? Williams Jon
Re: Net minus one address? Jason Brvenik
(no subject) Jason Benway
Re: not logging to database Jason Benway
Re: (no subject) Xavier Cabrera
RE: (no subject) M. Shirk
RE: (no subject) Jeff Dell
Re: (no subject) Jason Benway
Re: (no subject) Jason Benway
Re: (no subject) Jason Brvenik
Re: (no subject) Jason Benway
Re: (no subject) Jason Brvenik
RE: (no subject) Joshua Berry
Re: (no subject) Jason Benway
Re: (no subject) M. Shirk
Re: Alert on new IP in use? Matt Kettler
Re: Alert on new IP in use? Rich Adamson
Re: Alert on new IP in use? Daniel Cid
Re: Alert on new IP in use? Matt Kettler
Re: Alert on new IP in use? James Riden
Re: Maximum Number Of IPs Per Variable In snort.conf Matt Kettler

Tuesday, 02 August

Snort rules for Jolt tommy garsia
RE: Maximum Number Of IPs Per Variable In snort.conf O'Sullivan, Mairtin
alert_syslog does not contain alerts' priorities!! Bahya NASSR EDDINE
Snort/Sguil Meeting in San Francisco, CA Jennifer Steffens
Problems with MySQL & Snort Stevo
Re: Problems with MySQL & Snort Dirk Geschke
Re: Alert on new IP in use? Jeff Coppock
Re: Problems with MySQL & Snort Stevo
Silly Question Bill Parker

Wednesday, 03 August

reference tags: snort, bleeding sigs, database plugin,MySQL, BASE, somebody! Jeff Kell
Re: Alert on new IP in use? Jason Benway
Re: Alert on new IP in use? James Riden

Thursday, 04 August

Re: Alert on new IP in use? Donofrio, Lewis

Friday, 05 August

Doubt Ks, Mithun (GE Commercial Finance, non-GE)
RE: Doubt patrick harper
Re: Doubt Kevin Reiter
RE: Doubt Ks, Mithun (GE Commercial Finance, non-GE)
Re: Doubt Kevin Reiter
[ANNOUNCE] WinPcap 3.1 has been released Gianluca Varenni
Re: Doubt James Riden

Saturday, 06 August

Re: reference tags: snort, bleeding sigs, database plugin,MySQL, BASE, somebody! Kevin Johnson
RE: [ANNOUNCE] WinPcap 3.1 has been released - FAILS with SNORT - READ... Michael Steele
Re: [ANNOUNCE] WinPcap 3.1 has been released - FAILS with SNORT - READ... Ron

Sunday, 07 August

Detecting TCP Timestamp PAWS DoS from tracefile J.Smith
Re: [Snort-devel] Detecting TCP Timestamp PAWS DoS from tracefile J.Smith
Re: [Snort-devel] Detecting TCP Timestamp PAWS DoS from tracefile J.Smith
Re: [Snort-devel] Detecting TCP Timestamp PAWS DoS from tracefile J.Smith

Monday, 08 August

RE: Doubt Alex Butcher, ISC/ISYS
Remote syslogging with multiple interfaces Kevin Ponds

Tuesday, 09 August

what is snort sara
Re: Remote syslogging with multiple interfaces Kevin Ponds
BandWidth question Sabbiolina
Snort InLine Mode Ruiyuan Jiang
Re: Snort InLine Mode Will Metcalf
Re: BandWidth question Matt Kettler
RE: BandWidth question Bob Konigsberg
RE: Remote syslogging with multiple interfaces John Hally
Re: BandWidth question Chris Lyon
RE: BandWidth question Willy, Andrew
Re: Snort InLine Mode Donofrio, Lewis
BASE 1.1.4 released Kevin Johnson
Re: Alert on new IP in use? Jason Benway
RE: Remote syslogging with multiple interfaces Charles Heselton
Re: Snort-users digest, Vol 1 #5225 - 3 msgs Nick Plante
RE: Remote syslogging with multiple interfaces Joshua Berry
Re: Remote syslogging with multiple interfaces Matt Kettler

Wednesday, 10 August

Re: BandWidth question Alex Butcher, ISC/ISYS

Thursday, 11 August

Install guide help-- for Snort, Apache, SSL, PHP, and BASE install on Red hat WS 3 Tracey Jackson
I am looking for a guide for this --Snort, Apache, SSL, PHP, and BASE install on Red hat WS 3 Tracey Jackson
RE: Install guide help-- for Snort, Apache, SSL, PHP, and BASE install on Red hat WS 3 Patrick Harper
Re: I am looking for a guide for this --Snort, Apache, SSL, PHP, and BASE install on Red hat WS 3 Will Metcalf
RE: Install guide help-- for Snort, Apache, SSL, PHP, and BASE install on Red hat WS 3 Tracey Jackson
Appliances using free software Gutemberg A. Vieira
Snort + ISS Console Gutemberg A. Vieira
RE: Appliances using free software Bob Konigsberg
RE: Appliances using free software Eric Hines
Re: Appliances using free software Kevin Reiter
remote SQL logging error David Naylor
Quick Barnyard question... Jeff Kell
Re: Quick Barnyard question... Paul Schmehl
Re: Quick Barnyard question... Dirk Geschke
Re: Quick Barnyard question... Mihai Petre
Re: Snort + ISS Console SN ORT
RE: Appliances using free software Jeff Dell
Re: Quick Barnyard question... Paul Schmehl
RE: Appliances using free software Paul Schmehl
Re: Quick Barnyard question... Mihai Petre
Re: Quick Barnyard question... Paul Schmehl
RE: Appliances using free software Jeff Dell
Re: Quick Barnyard question... Jeff Kell
RE: Quick Barnyard question... Min Qiu
snort+mysql+problems pureone
RE: Appliances using free software Eric Hines
RE: Snort + ISS Console Eric Hines
RE: Appliances using free software Eric Hines
Re: Quick Barnyard question... Paul Schmehl

Friday, 12 August

Software from SourceFire is free? Gutemberg A. Vieira
Error in ACID??? Kunael
RE: Error in ACID??? Patrick Harper
Re: Software from SourceFire is free? Jason Brvenik
Re: Error in ACID??? Kevin Reiter
Re: Error in ACID??? Kevin Johnson

Saturday, 13 August

Re: Quick Barnyard question... Joel Esler

Sunday, 14 August

MS05-039 and Zotob worm Nigel Houghton

Monday, 15 August

Database ERROR:Database ERROR:Got error 134 from table handler Mohamed Eldesoky
RNA Config Ollie Walsh
Re: RNA Config Jason Brvenik
RE: Quick Barnyard question... Min Qiu
RE: Quick Barnyard question... Min Qiu
RE: Quick Barnyard question... Paul Schmehl
Snort & ACID Lean Cornelius
RE: Snort & ACID Willy, Andrew
RE: Snort & ACID M. Shirk
RE: Snort & ACID Lean Cornelius
Re: RNA Config Michael Schwartzkopff
question about snortsnarf Dodd, David J
Re: question about snortsnarf Matt Kettler
RE: question about snortsnarf Bob Konigsberg
Re: question about snortsnarf Joel Esler
Re: Quick Barnyard question... Joel Esler
snort for dummies ? Banshee
RE: snort for dummies ? Willy, Andrew
RE: question about snortsnarf Michael Steele
RE: snort for dummies ? Patrick Harper
New virus zotob signature Cesar Sanabria Pineda
Re: New virus zotob signature Banshee
Re: New virus zotob signature Jason Brvenik
Sourcefire VRT Update for Zotob Worm Nigel Houghton

Tuesday, 16 August

Re: Database ERROR:Database ERROR:Got error 134 from table handler Mohamed Eldesoky
frag3 configuration Hin
MYSQL 4.0 root login attempt David Naylor
Honeynet Security Console 2.5 Released Jeff Dell
Re: MYSQL 4.0 root login attempt Paul Schmehl
Re: New virus zotob signature Troy Solo
snort-mysql packages for RHEL3 Justin Heath
RE: snort-mysql packages for RHEL3 Min Qiu
RE: MYSQL 4.0 root login attempt David Naylor
Re: [Secureideas-base-user] Fwd: Database ERROR:Database ERROR:Got error 134 from table handler Kevin Johnson
RE: MYSQL 4.0 root login attempt Paul Schmehl

Wednesday, 17 August

Re: Database ERROR:Database ERROR:Got error 134 from table handler Mohamed Eldesoky
Var Home_Net and NIC talk prob Banshee
RE: Var Home_Net and NIC talk prob Willy, Andrew
Frag3 doc discrepancy Matthew K. Lee
RE: MYSQL 4.0 root login attempt David Naylor
Re: Frag3 doc discrepancy Eric Maheo
RE: Frag3 doc discrepancy Min Qiu

Thursday, 18 August

bare byte unicode encoding psitton
DOUBLE DECODING ATTACK hans
RE: question about snortsnarf M. Shirk
RE: MYSQL 4.0 root login attempt David Naylor
RE: DOUBLE DECODING ATTACK Briggs, Bruce
Re: Error in ACID??? Kunael
Can't compile snort inline on FC3 Martin Muench
unified format Igor Belikov

Friday, 19 August

help arun . seetha
Re: unified format Roland Turner (SourceForge)
Re[2]: unified format Igor Belikov
Re: Re[2]: unified format Roland Turner (SourceForge)
Re[4]: unified format Igor Belikov
Snort and gzip Encode Question dajackman
Bleeding Rules not detecting Brian Blake
Re: Snort and gzip Encode Question Joel Esler
RE: Bleeding Rules not detecting M. Shirk
RE: Bleeding Rules not detecting Brian Blake
Re: Bleeding Rules not detecting Eric Maheo
Re: Can't compile snort inline on FC3 Will Metcalf
RE: Bleeding Rules not detecting M. Shirk
Re: Re[4]: unified format Roland Turner (SourceForge)
Re: Snort and gzip Encode Question dajackman
Fwd: Re[4]: unified format Bamm Visscher
Selective pcaps on demand? Jeff Kell
Re: help Matt Kettler
juniper IPS Min Qiu
Re: juniper IPS Matt Kettler
Re: juniper IPS Chris Lyon
Re: help Kevin Reiter
Tapping into the ring buffer sekure
Re: Tapping into the ring buffer Harry Hoffman
RE: juniper IPS Bob Konigsberg
Snort w/ Base not recording hits. George Laiacona
Re: juniper IPS Bob Walder
Re: Snort w/ Base not recording hits. Kevin Johnson
Problem with barnyard 0.2.0 and snort 2.4.0 eric-list-snort-users

Saturday, 20 August

Re: Problem with barnyard 0.2.0 and snort 2.4.0 Paul Schmehl
Re: Problem with barnyard 0.2.0 and snort 2.4.0 eric-list-snort-users
Re: Problem with barnyard 0.2.0 and snort 2.4.0 Paul Schmehl
Re: Problem with barnyard 0.2.0 and snort 2.4.0 eric-list-snort-users
Re: Problem with barnyard 0.2.0 and snort 2.4.0 eric-list-snort-users
Re: Problem with barnyard 0.2.0 and snort 2.4.0 eric-list-snort-users
Re: Snort-users digest, Vol 1 #5242 - 7 msgs Nick Plante

Sunday, 21 August

Version 2.3.1 (Build 11) '''' By Martin Roesch & The Snort Team: http://www.snort.org/team.html (C) Copyright 1998-2004 Sourcefire Inc., et al. Received error message 16 deny
Re: Version 2.3.1 (Build 11) '''' By Martin Roesch & The Snort Team: http://www.snort.org/team.html (C) Copyright 1998-2004 Sourcefire Inc., et al. Received error message 16 Will Metcalf

Monday, 22 August

Re: Tapping into the ring buffer sekure
Re: Fwd: Re[4]: unified format Igor Belikov
TCP Portsweep Cody Holland
Snort 2.4.0 self-test mode Wolf, Brian
Stream4 min_ttl option Hin
Re: DOUBLE DECODING ATTACK hans
RE: Tapping into the ring buffer Joe Patterson
Anti SpyWare Sam Przyswa
Re: Anti SpyWare Will Metcalf

Tuesday, 23 August

Re: Tapping into the ring buffer Milani Paolo
mysql error No. 145 "mysql cannot open file xx.myi" Christopher
Re: Anti SpyWare Sam Przyswa
PIM - Multicasts Walt Rich
Re: PIM - Multicasts Eric Maheo
can't get snort (patched for snortsam) to trigger on a test rule Rob Ristroph
trouble with pmgraph Larry Wichman
Is snort an over kill just for apache? Pigeon

Wednesday, 24 August

Re: trouble with pmgraph Andreas Östling
Advantages of Snort IDS over eTrust IDS Giri Vardhan Valluru
Re: Advantages of Snort IDS over eTrust IDS M Raju
Alert with bug? Diego Cavalcante Fernandes
Re: Is snort an over kill just for apache? Matt Kettler
snort inline deny
Snort Sig 4135 IE JPEG heap overflow problem Jonathan Scheidell
Snort-Inline, IPTables and Performance Matt Linton
Re: snort inline Will Metcalf
Re: Snort Sig 4135 IE JPEG heap overflow problem Alex Kirk
Help newb understand how Snort is supposed to run. Chris W. Parker
RE: Help newb understand how Snort is supposed to run. Patrick Harper
RE: Help newb understand how Snort is supposed to run. Chris W. Parker
Almost there! Complaining about no MySQL support after recompiling with --with-mysql Chris W. Parker

Thursday, 25 August

RE: Help newb understand how Snort is supposed to run. Patrick Harper
Portscan Nils Fragoso
Re: Snort-Inline, IPTables and Performance Will Metcalf
RE: Almost there! Complaining about no MySQL support after recompiling with --with-mysql T Samp.
snort inline with mysql deny
Re: Help newb understand how Snort is supposed to run. John C. Silvia
Re: Snort-Inline, IPTables and Performance Matt Linton
RE: Snort-Inline, IPTables and Performance Briggs, Bruce
Re: Snort-Inline, IPTables and Performance Matt Linton
RE: Almost there! Complaining about no MySQL support after recompiling with --with-mysql Chris W. Parker
Re: BASE vs. ACID Quick Question Steve Brown
RE: Re: BASE vs. ACID Quick Question Briggs, Bruce
Re: BASE vs. ACID Quick Question John Creegan
IPtables QUEUE performance numbers from Ixia Brad Doctor
Re: Re: BASE vs. ACID Quick Question John Creegan
Re: IPtables QUEUE performance numbers from Ixia Brad Doctor
RE: Almost there! Complaining about no MySQL support after recompiling with --with-mysql Chris W. Parker

Friday, 26 August

Signature has generate alert without match with the packet Diego Cavalcante Fernandes
Re: Signature has generate alert without match with the packet Joel Esler
New to snort Dave Peters
RE: New to snort T Samp.
RE: New to snort Patrick Harper

Sunday, 28 August

Barnyard not Updating MySQL Someone.you dont.like
Re: Barnyard not Updating MySQL Someone.you dont.like

Monday, 29 August

Is SPADE already present in Snort 2.4 Vinay AR
Is SPADE already present in Snort 2.4 Vinay AR
FC4 and RHEL4 binaries? Eric Wood
RE: FC4 and RHEL4 binaries? Patrick Harper
how to further diagnose 'ICMP Destination Unreachable' problem? Chris W. Parker
snort deployment fname lname
RE: snort deployment Patrick Harper
Re: snort deployment MAEDA
Where is SPADE ? Vinay AR
Re: Snort-users digest, Vol 1 #5254 - 9 msgs (Automated reply) Sean Robinson
Re: Where is SPADE ? Peter Moody
Snort 2.4 and Spade Patch 2.3.2 Vinay AR

Tuesday, 30 August

BASE Graphs not working Lean Cornelius
Tagged packets Hin
Re: Tagged packets Dirk Geschke
RE: how to further diagnose 'ICMP Destination Unreachable' problem? Briggs, Bruce
trouble with pmgraph Larry Wichman
RE: how to further diagnose 'ICMP Destination Unreachable' problem? Chris W. Parker
Re: snort deployment David Klotz
Re: how to further diagnose 'ICMP Destination Unreachable' problem? Stephen Nesman
Re: snort deployment Will Metcalf
Re: snort deployment fname lname
Re: snort deployment Jason Brvenik
Re: BASE Graphs not working Kevin Johnson
RE: BASE Graphs not working Lean Cornelius

Wednesday, 31 August

Re: Snort 2.4 and Spade Patch 2.3.2 Alex Butcher, ISC/ISYS
Re: BASE Graphs not working Alex Butcher, ISC/ISYS
Re: how to further diagnose 'ICMP Destination Unreachable' problem? Alex Butcher, ISC/ISYS
sfPortscan IP list ? T Samp.
RE: sfPortscan IP list ? Lee Clemens
Re: Snort-users digest, Vol 1 #5257 - 7 msgs Nick Plante
RE: sfPortscan IP list ? T Samp.
Re: Re: Snort-users digest, Vol 1 #5257 - 7 msgs Richard Harman

Friday, 02 September

log to syslog but not to /var/log/snort/ directory Pablo Nebrera
(no subject) T.C.
Re: sfPortscan IP list ? Jason Brvenik
RE: (no subject) Paul Melson
RE: sfPortscan IP list ? T Samp.
RE: log to syslog but not to /var/log/snort/ directory Andre' M. DiMino
RE: (no subject) Patrick Harper
Re: Reload rules with out restarting snort completly Michael Boman
Reload rules with out restarting snort completly Pablo Nebrera
Interesting issue.. James Lay
Re: Reload rules with out restarting snort completly Frank Knobbe
Re: Reload rules with out restarting snort completly Andreas Östling
Re: Reload rules with out restarting snort completly Frank Knobbe

Saturday, 03 September

Re: Reload rules with out restarting snort completly Joel Esler

Monday, 05 September

RE: log to syslog but not to /var/log/snort/ directory Pablo Nebrera
not load snort rules when I use -D option Pablo Nebrera
checksum_mode Pablo Nebrera
decode_data_link option Pablo Nebrera
Re: not load snort rules when I use -D option T.C.
Re: not load snort rules when I use -D option Jason Brvenik
Re: not load snort rules when I use -D option Jason Brvenik
Re: checksum_mode Jason Brvenik
Re: decode_data_link option Jason Brvenik
Re: log to syslog but not to /var/log/snort/ directory Jason Brvenik
Re: checksum_mode Bamm Visscher
Correlation on Snort Events Kamal Ahmed

Tuesday, 06 September

Re: not load snort rules when I use -D option Pablo Nebrera
bad traffic in syn packet John Hally
Re: not load snort rules when I use -D option Jason Brvenik
Re: Correlation on Snort Events Jason Brvenik

Wednesday, 07 September

Re: log to syslog but not to /var/log/snort/ directory Pablo Nebrera
Second Snort instance killing performance Paul Melson
Re: [Snort-sigs] bad traffic in syn packet Frank Knobbe
snort died for no reason Wayne Ho
RE: snort died for no reason Patrick Harper
Re: snort died for no reason Andy Firman

Thursday, 08 September

Re: Second Snort instance killing performance Alex Butcher, ISC/ISYS
Re: Second Snort instance killing performance Jason Haar
Promiscuous mode Nils Fragoso
Re: Second Snort instance killing performance Szymon Miotk
RE: Second Snort instance killing performance Paul Melson
Snort and mysql.sock Luca Losio
Re: Snort and mysql.sock Dirk Geschke
RE: Second Snort instance killing performance Paul Melson
Re: Snort and mysql.sock Luca Losio
Re: Snort and mysql.sock Dirk Geschke
RE: Snort and mysql.sock Hartman, Shane
Map Bleeding snort signature name in ACID/BASE Wayne Ho
Re: Map Bleeding snort signature name in ACID/BASE Joel Esler
Upcoming Snort User Group Meetings Jennifer Steffens
RE: Upcoming Snort User Group Meetings Patrick Harper
Re: Upcoming Snort User Group Meetings Jennifer Steffens
Re: Snort and mysql.sock Evan J

Friday, 09 September

Re: Second Snort instance killing performance Alex Butcher, ISC/ISYS
RE: Second Snort instance killing performance Alex Butcher, ISC/ISYS
Problem with permissions when snort ran as user "snort" Sp0ng3 B0b
Re: Problem with permissions when snort ran as user "snort" Evan J
Re: Problem with permissions when snort ran as user "snort" Sp0ng3 B0b

Saturday, 10 September

Re: Snort-users digest, Vol 1 #5267 - 1 msg Nick Plante

Monday, 12 September

testing snorts snort sara
RE: testing snorts Kretzer, Jason R (Big Sandy)
Re: Second Snort instance killing performance snort sara
RE: testing snorts Eric Hines
Re: Second Snort instance killing performance Murali Raju
RE: Second Snort instance killing performance Paul Melson
Old Snort binaries for Windows securehell
Re: Old Snort binaries for Windows Rich Adamson
RE: Old Snort binaries for Windows Jeff Dell
(no subject) Larry Wichman
Remote Vulnerability in Snort - Fix and Workaround Available Jennifer Steffens
RE: Old Snort binaries for Windows Michael Steele
Snort SACK Option DoS clarifications Martin Roesch
nubie first attempt to start snort failed James Beistle
RE: nubie first attempt to start snort failed Jeff Dell

Tuesday, 13 September

snort rule firing order Kretzer, Jason R (Big Sandy)
RE: snort rule firing order Joshua Berry
Snort DoS Fallacies Ferguson, Justin (IARC)
Snort Report 1.3 dgullett
Nubie installing latest James Beistle
RE: Nubie installing latest Kretzer, Jason R (Big Sandy)
PPTP and Cisco IPSEC Ron Jenkins
RE: PPTP and Cisco IPSEC Paul Melson
Re: Snort DoS Fallacies Martin Roesch
Re: PPTP and Cisco IPSEC Murali Raju
RE: Snort DoS Fallacies Ferguson, Justin (IARC)
Re: Snort DoS Fallacies Martin Roesch
Re: Snort DoS Fallacies Martin Roesch
Re: Snort DoS Fallacies Martin Roesch
Re: Snort DoS Fallacies purplebag
Re: Snort DoS Fallacies Martin Roesch

Wednesday, 14 September

Snort logging to MySQL - but not to syslog Dahlmann, Stephan
Snort logging to MySQL but not to syslog Dahlmann, Stephan
RE: Snort logging to MySQL but not to syslog Bahya NASSR EDDINE
RE: Snort logging to MySQL but not to syslog Dahlmann, Stephan
Re: Image_Graph Quick Question Steve Brown
RE: Re: [Snort-users] Snort DoS Fallacies Ferguson, Justin (IARC)
FW: Re: [Snort-users] Snort DoS Fallacies Ferguson, Justin (IARC)
RE: Re: [Snort-users] Snort DoS Fallacies Ferguson, Justin (IARC)
Re: Re: [Snort-users] Snort DoS Fallacies Martin Roesch
Snort-devel] Re: Snort DoS Fallacies Ron Jenkins
Snort-devel] Re: Snort DoS Fallacies Ron Jenkins
New Snort 2.2 Rules Walt Rich
Re: New Snort 2.2 Rules Eric Hines
Re: New Snort 2.2 Rules Eric Hines
Re: New Snort 2.2 Rules (Walt Rich) Nigel Houghton
RE: New Snort 2.2 Rules Andre' M. DiMino
Re: New Snort 2.2 Rules Alex Kirk
Alerts generated by hosts on which snort is runnung Marcin Sura
RE: Alerts generated by hosts on which snort is runnung Briggs, Bruce
Re: Alerts generated by hosts on which snort is runnung Russ Starr
uricontent error Dario Alonso
Re: uricontent error Joel Esler
Re: uricontent error Russ Starr
Re: uricontent error Jason Haar

Thursday, 15 September

postscan Ron Jenkins
RE: postscan Paul Melson
maximum length for msg? Peggy Kam
Re: postscan Jeff Kell
Re: maximum length for msg? Alex Kirk
Re: postscan Michael Sierchio
RE: postscan Paul Melson
RE: Re: [Snort-users] Snort DoS Fallacies Ferguson, Justin (IARC)
RE: Re: [Snort-users] Snort DoS Fallacies Ferguson, Justin (IARC)
BASE Feature Suggestion to Display Rule Source McCash, John
RE: New Snort 2.2 Rules Andre' M. DiMino
Re: BASE Feature Suggestion to Display Rule Source Joel Esler
Double logging in alert_fast Zultan

Friday, 16 September

Re: maximum length for msg? Dirk Geschke
Re: BASE Feature Suggestion to Display Rule Source Alex Butcher, ISC/ISYS
Re: maximum length for msg? Alex Kirk
Re: maximum length for msg? Dirk Geschke
Re: maximum length for msg? Alex Kirk
A question about taps Brett, Gary
Re: A question about taps Ted Kaczmarek
Re: A question about taps Joel Esler
Re: A question about taps Richard Bejtlich
RE: A question about taps Brett, Gary
RE: Re: [Snort-users] Snort DoS Fallacies Ferguson, Justin (IARC)
Re: A question about taps Eric Hines
Re: A question about taps Eric Hines
RE: A question about taps Eric Hines
perfmon-graph sekure
Snort -u not creating logfiles with correct ownership Joe S
Re: perfmon-graph Andreas Östling
Re: Snort -u not creating logfiles with correct ownership Matt Kettler
Re: BASE Feature Suggestion to Display Rule Source Kevin Johnson
Snort 2.4.1 Available Jennifer Steffens
Re: Re: Image_Graph Quick Question Kevin Johnson

Saturday, 17 September

RE: Snort 2.4.1 Available Michael Steele
RE: Snort 2.4.1 Available Ron Jenkins
Re: Snort 2.4.1 Available Jason
Re: Snort 2.4.1 Available Jennifer Steffens
Geez Bill Parker
RE: Geez Ron Jenkins
Snort -T and -K in 2.4.1 Zultan
RE: Snort 2.4.1 Available Michael Steele

Sunday, 18 September

pmgraph v0.1 released Andreas Östling
RE: Snort 2.4.1 Available Rich Adamson
Re: [Snort-Users] Snort 2.4.1 Available Richard Bejtlich
RE: [Snort-Users] Snort 2.4.1 Available Ron Jenkins
RE: [Snort-Users] Snort 2.4.1 Available Michael Steele
Re: [Snort-Users] Snort 2.4.1 Available Richard Bejtlich
RE: [Snort-Users] Snort 2.4.1 Available Ron Jenkins
Re: [Snort-Users] Snort 2.4.1 Available Jason
RE: [Snort-Users] Snort 2.4.1 Available Ted Rohling
RE: [Snort-Users] Snort 2.4.1 Available Michael Steele
Re: [Snort-Users] Snort 2.4.1 Available Michael Stone
Re: [Snort-Users] Snort 2.4.1 Available Richard Bejtlich
Re: [Snort-Users] Snort 2.4.1 Available Theodore Stout
Re: [Snort-Users] Snort 2.4.1 Available Joe S
Re: [Snort-Users] Snort 2.4.1 Available Will Metcalf
Re: Double logging in alert_fast - Problem solved Zultan
Re: Snort 2.4.1 Available Martin Roesch
Re: [Snort-Users] Snort 2.4.1 Available Martin Roesch

Monday, 19 September

Re: [Snort-Users] Snort 2.4.1 Available Murali Raju
RE: [Snort-Users] Snort 2.4.1 Available Paul Melson
OBSD / PROMISCUOUS Sean Kiewiet
Re: Snort -T and -K in 2.4.1 Martin Roesch
Re: Snort -T and -K in 2.4.1 Martin Roesch
RE: OBSD / PROMISCUOUS Paul Melson
RE: OBSD / PROMISCUOUS Andre' M. DiMino
Re: Problem with barnyard 0.2.0 and snort 2.4.0 Jason Brvenik
mysql error 145 "mysql cannot open file xxx.myi" chrisnospam75-snortusers
please help me....!!!!!! fizza hafiz
Snort Signature Translations Almost Ready!! Matt Jonkman
Re: Snort 2.4 and Spade Patch 2.3.2 Jason Brvenik
attention....please...i really need your help.. fizza hafiz
Re: bad traffic in syn packet Brian Coyle
ACID/BASE vs PRELUDE ddodge
Re: Second Snort instance killing performance Marc Norton
Re: Re: BASE vs. ACID Quick Question Joel Esler
RE: Re: [Snort-users] Snort DoS Fallacies Steven Sturges
Wrong setup? tmp
Perfmonitor Passreality
Snort Report 1.3 David Gullett
how to configure snort with vlan fiorenzi
Snort not logging to syslog Dahlmann, Stephan
RE: Re: [Snort-users] Snort DoS Fallacies Steven Sturges
RE: Re: [Snort-users] Snort DoS Fallacies Steven Sturges
RE: Re: [Snort-users] Snort DoS Fallacies Steven Sturges
Re: ACID/BASE vs PRELUDE Joel Esler
Re: Snort not logging to syslog Joel Esler
(snort_decoder) WARNING: IP dgm len < IP Hdr len! Ron Jenkins
Re: ACID/BASE vs PRELUDE Gene R Gomez
Re: (snort_decoder) WARNING: IP dgm len < IP Hdr len! snort user
RE: ACID/BASE vs PRELUDE Ron Jenkins
Re: Problem with barnyard 0.2.0 and snort 2.4.0 Paul Schmehl
Re: attention....please...i really need your help.. Paul Schmehl
Re: please help me....!!!!!! Paul Schmehl
Suse 9.0 enterp - sensor setup issue. Donofrio, Lewis
oinkmaster - disabling rules without getting new updates Humes, David G.
Re: oinkmaster - disabling rules without getting new updates Joel Esler
perfstats.c sekure
Reminder - Upcoming Snort User Group Meetings Jennifer Talcott
Re: ACID/BASE vs PRELUDE Kris Karas
RE: oinkmaster - disabling rules without getting new updates Humes, David G.
Re: Re: ACID/BASE vs PRELUDE Gene R Gomez
ACID and Snort rules snort

Tuesday, 20 September

Re: oinkmaster - disabling rules without getting new updates Andreas Östling
Re: oinkmaster - disabling rules without getting new updates Alex Butcher, ISC/ISYS
No content match in modern snorts nard
Re: ACID/BASE vs PRELUDE Kris Karas
Dumb BASE question LW
RE: ACID and Snort rules Briggs, Bruce
Re: how to configure snort with vlan Russ Starr
Re: Dumb BASE question Paul Schmehl

Wednesday, 21 September

Rules not Triggering after Snort v2.4.1 Ron Jenkins
Duplicate classification Sean Kiewiet

Thursday, 22 September

Bug(?): mysql reserved name usage kliaaen
Re: Bug(?): mysql reserved name usage Wes Young

Friday, 23 September

Snort Beer Question Theodore Stout
RE: Re: [Snort-users] Bug(?): mysql reserved name usage Steven Sturges
installing snort Omar F. Altom
Re: Snort Beer Question Dominik Gehl
RE: installing snort Patrick Harper
Alternate to Snortcenter2? East, Bill
Re: Alternate to Snortcenter2? Wes Young
Re: Snort Beer Question Theodore Stout
RE: Alternate to Snortcenter2? East, Bill
Re: Alternate to Snortcenter2? Joel Esler
Re: Snort Beer Question Dominik Gehl
Re: Snort Beer Question Theodore Stout
Snort 2.4 port for FreeBSD Cody Holland
Re: Snort 2.4 port for FreeBSD Frank Knobbe
Re: Snort Beer Question Joe S
RE: Snort Beer Question Charles Heselton
Re: Snort 2.4 port for FreeBSD Scott Dexter

Saturday, 24 September

Problem! Install HenWen, now LetterStick wont launch si wood
Re: Problem! Install HenWen, now LetterStick wont launch eric-list-snort-users
Re: Problem! Install HenWen, now LetterStick wont launch Jason

Sunday, 25 September

Re: Problem! Install HenWen, now LetterStick wont launch Kevin Reiter
Duplicate SIDs recently? Jeff Kell
RE: Duplicate SIDs recently? Ron Jenkins
Re: Duplicate SIDs recently? Andreas Östling

Monday, 26 September

Re: Snort Beer Question The Frumious Robber of Zork
snort_inline problem afshin lamei
SMTP Content-Type overflow attempt SID 3461 Craig Mueller
Re: SMTP Content-Type overflow attempt SID 3461 Alex Kirk
PacSec05 Dragos Ruiu

Tuesday, 27 September

Get/wget sigs? SN ORT
Re: Get/wget sigs? Michael Sierchio
Re: Get/wget sigs? Russ Starr
RE: Get/wget sigs? SN ORT
RE: Get/wget sigs? Patrick Harper
Re: snort_inline problem Will Metcalf
RE: Get/wget sigs? SN ORT
SSH and telnet Login Attempt Rules Ron Jenkins
Re: SSH and telnet Login Attempt Rules Gene R Gomez
Re: SSH and telnet Login Attempt Rules Frank Knobbe
RE: SSH and telnet Login Attempt Rules Ron Jenkins
Re: SSH and telnet Login Attempt Rules Jason

Wednesday, 28 September

Lots of http_inspect alerts - configuration hints? Dahlmann, Stephan
Policy VNC server response Hin
Re: Policy VNC server response Joel Esler
Will Snort understand something like this? Hin
Re: Will Snort understand something like this? Joel Esler
Re: Will Snort understand something like this? Eric Maheo
Re: Will Snort understand something like this? Hin
RE: Lots of http_inspect alerts - configuration hints? Briggs, Bruce
Managing multiple sensors ? Alexandre Ahmim-Richard
learning snort James B Horwath
Re: learning snort Joel Esler
Any problems with Snort 2.3 config file in 2.4.1? Bill Warren
Tcpdump full conversation capture Court Graham
Re: Tcpdump full conversation capture Joel Esler
RE: Tcpdump full conversation capture Patrick Harper
Snort 2.4.2 Now Available Jennifer Steffens
RE: learning snort Andre' M. DiMino
Re: Alternate to Snortcenter2? Jason Alexander
Re: Snort-users digest, Vol 1 #5306 - 11 msgs (Auto-Reply) Sean Robinson

Thursday, 29 September

Re: Managing multiple sensors ? Alex Butcher, ISC/ISYS
How to test snort inline vikrant
Re: How to test snort inline Dino Dragovic
RE: learning snort Patrick Walsh
Snort 2.4.2 with ClamAV Bill Warren
Re: Snort 2.4.2 with ClamAV Will Metcalf

Friday, 30 September

Re: How to test snort inline vikrant
Bad escape sequence? sekure
Re: [Snort-sigs] Bad escape sequence? dajackman
Snort exit status sekure
Re: [Snort-sigs] Bad escape sequence? sekure
Snort performance concerns Larry Wichman
Re: Snort performance concerns Joel Esler
Re: Snort performance concerns sekure
Re: Snort performance concerns Larry Wichman
RE: Snort performance concerns Jeff Dell
RE: Snort performance concerns Jeff Dell
RE: Snort performance concerns Joshua Berry
Re: Re: [Snort-sigs] Bad escape sequence? Ali Eghtessadi
Re: Snort performance concerns Joel Esler
RE: Snort performance concerns Richard Bejtlich