Snort: by date

660 messages starting Jul 01 11 and ending Sep 30 11
Date index | Thread index | Author index


Friday, 01 July

Re: Snort rules maximum rules per file Hussein Bahaidarah
Re: Snort rules maximum rules per file Martin Holste
Re: Snort rules maximum rules per file Jason Wallace
[RE] Snort rules maximum rules per file 김무성

Saturday, 02 July

Re: Snort rules maximum rules per file Hussein Bahaidarah
OpenBSD 4.9 and Snort 2.9.0.5 - libsf_engine.so Missing Randal T. Rioux

Sunday, 03 July

Re: OpenBSD 4.9 and Snort 2.9.0.5 - libsf_engine.so Missing Randal T. Rioux

Monday, 04 July

Problem with http_inspect and Basic Authentication rule andreas
Re: Problem with http_inspect and Basic Authentication rule Joel Esler
Re: Problem with http_inspect and Basic Authentication rule andreas
Re: SnortSP: Writing an analyzer in Lua Tako Chanz

Tuesday, 05 July

Problem starting snort Er_Maqui
Re: Problem with http_inspect and Basic Authentication rule Russ Combs
Fwd: Problem starting snort Er_Maqui
What's the correct link for registered rules? Lay, James
Re: What's the correct link for registered rules? JJ Cummings
Re: What's the correct link for registered rules? Lay, James

Wednesday, 06 July

Re: False Negatives in Snort Dheeraj Gupta
Snort 2.9.1memory usage and rules Hatim Alghamdi
Sourcefire VRT Certified Snort Rules Update 2011-07-06 Research
PulledPork and missing sets Lay, James
Re: PulledPork and missing sets Lay, James
reject is identical to drop HN Nguyen
Installing snort Damien Hull

Thursday, 07 July

Re: reject is identical to drop Kevin Ross
Re: Problem starting snort Er_Maqui
Re: Installing snort Lay, James
Re: reject is identical to drop Russ Combs
Barnyard2 compile error (angry platypus) Lay, James
Re: Barnyard2 compile error (angry platypus) Lay, James
Re: Snort 2.9.1memory usage and rules Joel Esler
Re: False Negatives in Snort Joel Esler
disable Verifying Preprocessor Configurations Hussein Bahaidarah
Re: disable Verifying Preprocessor Configurations waldo kitty
Re: disable Verifying Preprocessor Configurations Hussein Bahaidarah
Re: disable Verifying Preprocessor Configurations Joel Esler
Re: disable Verifying Preprocessor Configurations Hussein Bahaidarah
Re: disable Verifying Preprocessor Configurations Russ Combs
Re: disable Verifying Preprocessor Configurations Will Metcalf
Re: disable Verifying Preprocessor Configurations Hussein Bahaidarah
Error running snort Damien Hull
Re: disable Verifying Preprocessor Configurations Hussein Bahaidarah
Re: disable Verifying Preprocessor Configurations Russ Combs
Sourcefire VRT Certified Snort Rules Update 2011-07-07 Research
Re: disable Verifying Preprocessor Configurations waldo kitty
Re: False Negatives in Snort Dheeraj Gupta
Re: reject is identical to drop HN Nguyen

Friday, 08 July

Re: disable Verifying Preprocessor Configurations Russ Combs
Re: False Negatives in Snort Joel Esler
Re: False Negatives in Snort Dheeraj Gupta
Re: [Snort-Users] Barnyard2 not starting beenph
Re: [Snort-Users] Barnyard2 not starting Michael Lubinski
Installing Snort Damien Hull
Re: Installing Snort Michael Lubinski
Re: Installing Snort Damien Hull
Re: Installing Snort Damien Hull
Re: Installing Snort Martin Holste
Re: Installing Snort Damien Hull
Re: Installing Snort Martin Holste
Re: Installing Snort Damien Hull
Re: Barnyard2 compile error (angry platypus) firnsy

Sunday, 10 July

Sguil 8 and Barnyard2 beta James Lay
Re: Sguil 8 and Barnyard2 beta firnsy
Re: Sguil 8 and Barnyard2 beta Bamm Visscher
Re: Sguil 8 and Barnyard2 beta James Lay

Monday, 11 July

problem in downloading from command line Negin Nickparsa
Re: problem in downloading from command line Joel Esler
Re: problem in downloading from command line Martin Holste
[HITB-Announce] REMINDER: HITB2011 - Malaysia Call for Papers Closes on the 15th Hafez Kamal

Tuesday, 12 July

Barnyard2 and timestamp extension Lay, James
Sourcefire VRT Certified Snort Rules Update 2011-07-12 Research
Re: Barnyard2 and timestamp extension Lay, James
Dynamic output plugins snort user
Re: Dynamic output plugins Joel Esler
Re: Dynamic output plugins Russ Combs

Wednesday, 13 July

Re: problem in downloading from command line Negin Nickparsa
Re: problem in downloading from command line Joel Esler
Re: problem in downloading from command line Negin Nickparsa
Trending Lay, James
Re: Trending JJC
Re: Trending Paul Halliday
Re: Trending James Lay

Thursday, 14 July

Sourcefire VRT Certified Snort Rules Update 2011-07-14 Research
Snort multithread Xiong Wu

Friday, 15 July

Re: problem in downloading from command line Jason Haar
Re: problem in downloading from command line Negin Nickparsa
Re: problem in downloading from command line Jason Haar
Snort inline extremely slow packet forwarding Hussein Bahaidarah
Re: [RE] Snort rules maximum rules per file Hussein Bahaidarah
Re: Snort inline extremely slow packet forwarding Hussein Bahaidarah
Re: Snort inline extremely slow packet forwarding Hussein Bahaidarah
Re: Snort inline extremely slow packet forwarding Hussein Bahaidarah
Re: Snort rules maximum rules per file Russ Combs
Re: Snort rules maximum rules per file Hussein Bahaidarah
Re: Snort inline extremely slow packet forwarding Hussein Bahaidarah
Re: Snort inline extremely slow packet forwarding Michael Altizer
Re: Snort inline extremely slow packet forwarding Hussein Bahaidarah
Re: Snort inline extremely slow packet forwarding Michael Altizer
Re: Snort inline extremely slow packet forwarding Hussein Bahaidarah
Re: Snort inline extremely slow packet forwarding Michael Altizer
Re: Snort inline extremely slow packet forwarding Hussein Bahaidarah

Saturday, 16 July

Re: problem in downloading from command line Negin Nickparsa
barnyard2 compile error on Solaris 10 David Lundy

Sunday, 17 July

Slackware 13.1 and Barnyard2 James Lay
Re: Slackware 13.1 and Barnyard2 James Lay

Monday, 18 July

Re: [Snort-Users] configuration to install snort Kevin Ross
Question Gibson, Nathan J. (HSC)
Re: Question Martin Holste
Re: Question Gibson, Nathan J. (HSC)
Re: Question Martin Holste

Tuesday, 19 July

How does Snorby classify alerts? Lay, James
Snort 2.9.1 RC Now Available Snort Releases
Snort 2.9.1 RC Now Available Snort Releases
Possible FP 19274 Lay, James
Re: Possible FP 19274 Weir, Jason
Re: Possible FP 19274 Castle, Shane
Sourcefire VRT Certified Snort Rules Update 2011-07-19 Research
Re: Possible FP 19274 rmkml
Quick Pulledpork modifysid question Lay, James
Re: Snort 2.9.1 RC Now Available rmkml
BASE Error when using Unified to MySQL? Michael Steele

Wednesday, 20 July

blacklist file for reputation processor 김무성
Re: BASE Error when using Unified to MySQL? Lay, James
sguil: Tcl support is not compiled into this build of barnyard2 Paul Marin
Re: sguil: Tcl support is not compiled into this build of barnyard2 Paul Halliday
Re: sguil: Tcl support is not compiled into this build of barnyard2 Paul Marin

Thursday, 21 July

Re: [Snort-Users] problem Kevin Ross
Re: Question Gibson, Nathan J. (HSC)
Re: Question Martin Holste
Re: blacklist file for reputation processor Alex Kirk
Re: blacklist file for reputation processor Will Metcalf
Re: blacklist file for reputation processor Steven Sturges
Re: [Snort-users] blacklist file for reputation processor Matthew Jonkman
Re: blacklist file for reputation processor Will Metcalf
Re: [Snort-users] blacklist file for reputation processor Joel Esler
Google's new feature: "Your Computer Appears To Be Infected" Jason Haar
Re: [Snort-users] blacklist file for reputation processor Pablo

Friday, 22 July

Barnyard2 startup issue Aycock, Jeff R.
Re: Barnyard2 startup issue James Lay
help with snort output to syslog - solaris David Lundy
Re: Question Gibson, Nathan J. (HSC)
Re: Barnyard2 startup issue Aycock, Jeff R.
Re: Barnyard2 startup issue Lay, James
Re: Barnyard2 startup issue beenph
Unified Logging - BASE - Portscans Michael Steele
Re: Question Martin Holste

Monday, 25 July

Re: [Snort-Users] [Snort]: can we use it to detect ARP cache poisoning Kevin Ross
Re: Question Gibson, Nathan J. (HSC)
Re: Question Martin Holste
Re: Question Will Metcalf
Re: Unified Logging - BASE - Portscans Lay, James
Syntax for ports Oliver Ruta
Re: Unified Logging - BASE - Portscans Michael Steele
Re: Unified Logging - BASE - Portscans Lay, James
Re: Unified Logging - BASE - Portscans Michael Steele
Re: Unified Logging - BASE - Portscans James Lay

Tuesday, 26 July

Re: [Snort-users] blacklist file for reputation processor 김무성
building a local IP reputation 김무성
Re: [Snort-users] blacklist file for reputation processor Matthew Jonkman
Re: Syntax for ports Lay, James
Reload Snort to use new ruleset RICHARD METZER
Re: Reload Snort to use new ruleset Gibson, Nathan J. (HSC)
Re: [Spam] Reload Snort to use new ruleset Lay, James
Re: Reload Snort to use new ruleset Castle, Shane
Re: Reload Snort to use new ruleset Marcos Rodriguez
Re: Reload Snort to use new ruleset Eoin Miller
Re: Reload Snort to use new ruleset Gregory Zill
Re: Reload Snort to use new ruleset Lay, James
Re: Reload Snort to use new ruleset Joel Esler
Re: Reload Snort to use new ruleset Lay, James
VRT Domain name lists snort user
Sourcefire VRT Certified Snort Rules Update 2011-07-26 Research
Re: VRT Domain name lists Joel Esler
Re: Unified Logging - BASE - Portscans James Lay
Re: Unified Logging - BASE - Portscans Michael Steele
Re: Unified Logging - BASE - Portscans Michael Steele

Wednesday, 27 July

Re: Unified Logging - BASE - Portscans Michael Steele
Barnyard2 not inputting portscans (was Unified Logging - BASE - Portscans) James Lay
Re: Barnyard2 not inputting portscans (was Unified Logging - BASE - Portscans) beenph
Re: Barnyard2 not inputting portscans (was Unified Logging - BASE - Portscans) James Lay
Re: Barnyard2 not inputting portscans (was Unified Logging - BASE - Portscans) beenph
SnortSam Block on all snort/barnyard2 alerts by default Robert Z
Re: Reload Snort to use new ruleset Agustin Roca
Snort Network Architecture. Pawan Lal
Re: Barnyard2 not inputting portscans (was Unified Logging - BASE - Portscans) James Lay
Re: Barnyard2 not inputting portscans (was Unified Logging - BASE - Portscans) beenph
SQueRT 0.9.0 Released Paul Halliday
Re: SQueRT 0.9.0 Released Lay, James
Re: VRT Domain name lists snort user
Re: VRT Domain name lists Joel Esler

Thursday, 28 July

Barnyard2 google groups announcement beenph
Re: Reload Snort to use new ruleset Paul Schmehl
Sourcefire VRT Certified Snort Rules Update 2011-07-28 Research

Friday, 29 July

Cookie jacking 19177 question Lay, James
flow-ip-file output documentation? Eoin Miller
Re: flow-ip-file output documentation? Joel Esler

Saturday, 30 July

Re: Cookie jacking 19177 question rmkml
Re: Unified Logging - BASE - Portscans Jason Brvenik
How the rules are organized for packets matching? Peter Peng

Sunday, 31 July

Re: VRT Domain name lists waldo kitty

Monday, 01 August

problem in downloading from command line Negin Nickparsa
BASE sensor name Lay, James
Re: BASE sensor name Joel Esler
Re: BASE sensor name Lay, James
Re: BASE sensor name Lay, James
Re: BASE sensor name beenph
Re: BASE sensor name Joel Esler
Re: BASE sensor name Lay, James

Tuesday, 02 August

Sourcefire VRT Certified Snort Rules Update 2011-08-02 Research
Snort.org issues Joel Esler
React option - without session reset Hussein Bahaidarah
Re: How the rules are organized for packets matching? Randal T. Rioux

Wednesday, 03 August

Is Sourcefire VRT rule released on snort.org web site same as SourceFile 3D 4500 rules? Zhuxian
Re: Is Sourcefire VRT rule released on snort.org web site same as SourceFile 3D 4500 rules? Alex Kirk
Accelerating Snort with NetFPGA N.v
BLACKLIST URI Request Rules Chris Granger
Re: BLACKLIST URI Request Rules Adam Gardner
Re: BLACKLIST URI Request Rules Joel Esler
Re: BLACKLIST URI Request Rules Chris Granger
support for OLSR protocol in Snort Vic O
same question about snort rules Zhuxian
Re: Is Sourcefire VRT rule released on snort.org web site same as SourceFile 3D 4500 rules? Zhuxian

Thursday, 04 August

Re: same question about snort rules Jason Wallace
Re: Is Sourcefire VRT rule released on snort.org web site same as SourceFile 3D 4500 rules? Jason Wallace
Quick pulledpork question Lay, James
Re: [Emerging-Sigs] FP on 2012886 but I don't see how Joel Esler
Re: Is Sourcefire VRT rule released on snort.org web site same as SourceFile 3D 4500 rules? Joel Esler
Re: Quick pulledpork question JJ Cummings
Re: Is Sourcefire VRT rule released on snort.org web site same as SourceFile 3D 4500 rules? JJ Cummings
Re: same question about snort rules Joel Esler
Re: same question about snort rules Will Metcalf
Re: same question about snort rules Joel Esler
Depth + HTTP_Method Chris Granger
Re: Quick pulledpork question Lay, James
Re: same question about snort rules rmkml
Re: same question about snort rules rmkml
Re: same question about snort rules Joel Esler

Saturday, 06 August

Possible issues with SSl Preprocessor? L0rd Ch0de1m0rt

Sunday, 07 August

Barnyard2 and dealing with mysql_error James Lay

Tuesday, 09 August

Re: Barnyard2 and dealing with mysql_error James Lay
Re: Barnyard2 and dealing with mysql_error Paul Schmehl
Re: Flowbits option in Snort rmkml
Re: Barnyard2 and dealing with mysql_error firnsy
Flowbits option in Snort Matthew Budge
Re: [Snort-users] Barnyard2 and dealing with mysql_error Dave Werden
Re: Barnyard2 and dealing with mysql_error James Lay
Error: Snort BASE install Redhat Rukender attri
Sourcefire VRT Certified Snort Rules Update 2011-08-09 Research
Re: support for OLSR protocol in Snort Matt Watchinski
Re: Barnyard2 and dealing with mysql_error James Lay
Re: Barnyard2 and dealing with mysql_error James Lay
SQueRT 0.9.2 Released Paul Halliday
Re: Barnyard2 and dealing with mysql_error beenph
Re: Barnyard2 and dealing with mysql_error Paul Schmehl

Wednesday, 10 August

Dynamic-preprocessor and util functions (for e.g. sfghash) snort user
Memory Issues W/ DCERPC2 Gibson, Nathan J. (HSC)
Re: Memory Issues W/ DCERPC2 Gibson, Nathan J. (HSC)
Duplicate/similar struct definitions between src/decoder.h and src/dynamic_plugins/sf_engine/sf_snort_packet.h? Joshua.Kinard

Thursday, 11 August

Re: Duplicate/similar struct definitions between src/decoder.h and src/dynamic_plugins/sf_engine/sf_snort_packet.h? Steven Sturges
Sourcefire VRT Certified Snort Rules Update 2011-08-11 Research
Re: Duplicate/similar struct definitions between src/decoder.h and src/dynamic_plugins/sf_engine/sf_snort_packet.h? Joshua.Kinard

Friday, 12 August

what means the deleted.rules Zhuxian
Re: what means the deleted.rules Jamie Riden
[PATCH]: Count discards in DecodeTCP (src/decode.c) Joshua.Kinard

Sunday, 14 August

BASE / SQL Server 2008 and 'create_base_tbls_mssql_extra.sql' ???? Michael Steele
Re: BASE / SQL Server 2008 and 'create_base_tbls_mssql_extra.sql' ???? Nigel Houghton
Re: BASE / SQL Server 2008 and 'create_base_tbls_mssql_extra.sql' ???? Michael Steele

Monday, 15 August

Ruxcon 2011 Final Call For Papers cfp
Sessionised data in preprocessors apple cake
Incorrect IP Flags Values in database output. kareem
Fwd: [Snort-users] Incorrect IP Flags Values in database output. Joel Esler
FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. waldo kitty
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. Russ Combs
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. Eoin Miller
Re: Incorrect IP Flags Values in database output. Russ Combs
Re: Incorrect IP Flags Values in database output. Joel Esler
Re: [PATCH]: Count discards in DecodeTCP (src/decode.c) Russ Combs
Re: [PATCH]: Count discards in DecodeTCP (src/decode.c) Joshua.Kinard
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus
Re: Incorrect IP Flags Values in database output. kareem
Re: Incorrect IP Flags Values in database output. kareem
Re: Incorrect IP Flags Values in database output. Joel Esler
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. Joel Esler
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus
Re: Incorrect IP Flags Values in database output. waldo kitty
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. waldo kitty
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. Joel Esler
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. waldo kitty
Re: Incorrect IP Flags Values in database output. beenph
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus

Tuesday, 16 August

Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. JJC
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. JJC
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. Russ Combs
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. Russ Combs
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus
Sourcefire SNMP MIB Mailing Lists
Re: Sourcefire SNMP MIB Joel Esler
Snort Inline - flow established does not appear to be working Ron Brash
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. Joel Esler
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. Joel Esler
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. Joel Esler
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus

Wednesday, 17 August

Re: some question about snort rules Zhuxian
Re: some question about snort rules Joel Esler
Re: some question about snort rules JJC
Re: Incorrect IP Flags Values in database output. kareem
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. waldo kitty
[Snort-Sigs] sid 17903 possible FP matan monitz
Re: [Snort-Sigs] sid 17903 possible FP Alex Kirk
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. Russ Combs
Re: Incorrect IP Flags Values in database output. beenph
What is the difference in using IPVAR and VAR ? Michael Steele

Thursday, 18 August

Re: What is the difference in using IPVAR and VAR ? Mike Lococo
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus
Re: What is the difference in using IPVAR and VAR ? Michael Steele
Re: What is the difference in using IPVAR and VAR ? Mike Lococo
Re: What is the difference in using IPVAR and VAR ? Michael Steele
Re: What is the difference in using IPVAR and VAR ? Mike Lococo

Friday, 19 August

winhe800 trjoan Crusty Saint
Re: winhe800 trjoan Joel Esler
Re: winhe800 trjoan Joel Esler

Saturday, 20 August

snort 2.9.0.5 config file problems Bill
Re: snort 2.9.0.5 config file problems Michael Steele
Re: snort 2.9.0.5 config file problems Michael Steele

Monday, 22 August

The HTML Snort Manual is back! Joel Esler
Re: The HTML Snort Manual is back! Ray Caparros
freebsd users: need help testing a patch Michael Scheidell
Re: freebsd users: need help testing a patch Michael Scheidell
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. Joel Esler
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. Joel Esler
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. Gibson, Nathan J. (HSC)
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. Joel Esler
Re: FATAL ERROR: /usr/local/etc/snort.conf(45) Unknown rule type: ipvar. alexus

Tuesday, 23 August

Re: [Snort-Sigs] The HTML Snort Manual is back! Juan Carlos
http_cookie containing the Set-Cookie/Cookie HTTP header element Eoin Miller
Re: http_cookie containing the Set-Cookie/Cookie HTTP header element Joel Esler
Re: http_cookie containing the Set-Cookie/Cookie HTTP header element Eoin Miller
Sourcefire VRT Certified Snort Rules Update 2011-08-23 Research
VRT Rule Update for 08/23/2011: A Special Note about this release. Joel Esler
Snort 2.9.1 Now Available Snort Releases
Snort 2.9.1 Now Available Snort Releases
snort web interface alexus
Re: snort web interface James Lay
Re: snort web interface Alex Wright
Re: snort web interface Jason Meller
Re: snort web interface Ray Caparros
Re: snort web interface Martin Holste
Re: snort web interface Dustin Webber
Re: snort web interface Alex Wright
Re: snort web interface Dustin Webber
Re: snort web interface Alex Wright
Re: snort web interface Dustin Webber
Re: snort web interface Dustin Webber
Re: snort web interface Alex Wright
Re: snort web interface Dustin Webber
Re: snort web interface Alex Wright
Re: snort web interface Jefferson, Shawn
Re: snort web interface Dustin Webber
Re: snort web interface Alex Wright
Re: snort web interface Dustin Webber
Re: snort web interface Jefferson, Shawn
Re: snort web interface Randal T. Rioux

Wednesday, 24 August

Re: Snort 2.9.1 Now Available vincent
Snort 2.9.0.x Performance hit in inline mode with NFQ Ville Vak
Re: snort web interface Paul Halliday
Re: Snort 2.9.1 Now Available vincent
Re: snort web interface Dustin Webber
Re: snort web interface Joel Esler
Re: snort web interface Joel Esler
Re: snort web interface Mike Lococo
Re: snort web interface Jason Wallace
Re: Snort 2.9.1 Now Available Ryan Jordan
Re: snort web interface Jason Meller
Possible FP 17379 Lay, James
Re: snort web interface alexus
Re: Possible FP 17379 Alex Kirk
Re: [Spam] Re: snort web interface Lay, James
Re: [Spam] Re: Possible FP 17379 Lay, James
Re: [Spam] Re: snort web interface Joel Esler
Re: snort web interface Paul Halliday
Re: snort web interface Lay, James
Re: [Snort-Sigs] VRT Rule Update for 08/23/2011: A Special Note about this release. Miguel Alvarez
Re: Snort 2.9.1 Now Available vincent
Re: [Snort-Sigs] VRT Rule Update for 08/23/2011: A Special Note about this release. Joel Esler
Re: VRT Rule Update for 08/23/2011: A Special Note about this release. Eoin Miller
Re: VRT Rule Update for 08/23/2011: A Special Note about this release. Joel Esler
Unknown SMTP configuration option 260 Johnny Venter
Re: Unknown SMTP configuration option 260 Nigel Houghton
Re: Unknown SMTP configuration option 260 Johnny Venter
Re: Unknown SMTP configuration option 260 Joel Esler
how to save the previous packet information for detection wei gao
Re: Unknown SMTP configuration option 260 Johnny Venter

Thursday, 25 August

Cross compile snort 2.9.1 for powerpc. narender
Cross compile snort 2.9.1 for powerpc. narender
snort sp for 10GE link ahmad reza noroozi
Error compiling daq-0.6.1 on Ubuntu 10.04 Edward Fjellskål
Re: snort sp for 10GE link Martin Holste
Re: Error compiling daq-0.6.1 on Ubuntu 10.04 Jason Wallace
Re: Error compiling daq-0.6.1 on Ubuntu 10.04 Edward Fjellskål
Re: snort web interface Paul Halliday
Re: Error compiling daq-0.6.1 on Ubuntu 10.04 Jason Wallace
Re: Error compiling daq-0.6.1 on Ubuntu 10.04 Jason Wallace
Re: Error compiling daq-0.6.1 on Ubuntu 10.04 Edward Fjellskål
Can you tag thresholded sessions? Paul Schmehl
Sourcefire VRT Certified Snort Rules Update 2011-08-25 Research
Re: Cross compile snort 2.9.1 for powerpc. narender

Friday, 26 August

VRT Rule Update for 08/25/2011: Modifications to the snort.conf file Joel Esler
Re: VRT Rule Update for 08/25/2011: Modifications to the snort.conf file Eoin Miller
Re: VRT Rule Update for 08/25/2011: Modifications to the snort.conf file Joel Esler
Re: VRT Rule Update for 08/25/2011: Modifications to the snort.conf file Greg Lane
Re: VRT Rule Update for 08/25/2011: Modifications to the snort.conf file Joel Esler
Re: snort web interface Richard Bejtlich
Barnyard2 to remote server Sherman Boyd

Saturday, 27 August

Re: Barnyard2 to remote server beenph
Re: snort web interface Agustin Roca
Re: Barnyard2 to remote server Sherman Boyd
Re: Barnyard2 to remote server Martin Holste
Re: Barnyard2 to remote server Sherman Boyd
Re: Barnyard2 to remote server Martin Holste

Sunday, 28 August

Snort - VPS web server (Debian) Johnny Venter
Re: Snort - VPS web server (Debian) Martin Holste
Redirect foo. Paul Halliday

Monday, 29 August

Snort - 2.9.0.5 daemon dying Dheeraj Gupta
Re: Redirect foo. James Lay
Re: Snort - VPS web server (Debian) johnny.venter
EnergySec and the OISF announce new SCADA Research! Matthew Jonkman
Re: Snort - VPS web server (Debian) Martin Holste
Re: [Snort-users] Snort 2.9.0.x Performance hit in inline mode with NFQ Russ Combs
Snort ->Barnyard2 James Kaufman
Re: Snort ->Barnyard2 beenph

Tuesday, 30 August

snort high availability ahmad reza noroozi
Re: Snort - VPS web server (Debian) Mike Lococo
Re: Snort - VPS web server (Debian) johnny.venter
Re: snort high availability Joel Esler
Re: Snort - VPS web server (Debian) Martin Holste
Re: Snort - VPS web server (Debian) Edward Fjellskål
Sourcefire VRT Certified Snort Rules Update 2011-08-30 Research

Thursday, 01 September

OT: Snorby site offline? Lay, James
Re: OT: Snorby site offline? Heine Lysemose
Re: OT: Snorby site offline? Lay, James
Create rule to alert on destination IP Address Mike Smith
Re: Create rule to alert on destination IP Address Joel Esler
Sourcefire VRT Certified Snort Rules Update 2011-09-01 Research
Re: OT: Snorby site offline? Dustin Webber

Monday, 05 September

wrong flow side on very old sid 1675 (always present on SEU 493) rmkml
wrong flow side on very old sid 1045 (always present on SEU 493) rmkml
Re: wrong flow side on very old sid 1045 (always present on SEU 493) Joe Gedeon

Tuesday, 06 September

Request change on snort v2.9.1 snort_httpinspect.h MAX_METHOD_LEN to 8 rmkml
new SIP preproc on snort v2.9.1 never firing? rmkml
Re: new SIP preproc on snort v2.9.1 never firing? Alex Kirk
Inline IPS Damien Hull
Re: Inline IPS Joel Esler
Re: Inline IPS Damien Hull
Re: Inline IPS Heine Lysemose

Wednesday, 07 September

Re: new SIP preproc on snort v2.9.1 never firing? rmkml
Confused about so_rules precompiled /snort version ? Will precompiled rules 2.9.0.5 work on snort 2.9.1 ? Morgan Cox
Snort Installation Error Rukender attri
Re: Inline IPS Morgan Cox
SMTP Rule vmpc vmpc
Re: Inline IPS Damien Hull
Re: Inline IPS Morgan Cox
Re: Inline IPS Heine Lysemose
Re: Inline IPS Morgan Cox
Re: Inline IPS Morgan Cox
Re: Inline IPS Heine Lysemose
Re: new SIP preproc on snort v2.9.1 never firing? Alex Kirk
Re: SMTP Rule Martin Holste
Re: new SIP preproc on snort v2.9.1 never firing? rmkml
Re: Inline IPS Joel Esler
Re: Snort Installation Error Joel Esler
Re: Confused about so_rules precompiled /snort version ? Will precompiled rules 2.9.0.5 work on snort 2.9.1 ? Joel Esler
Re: Inline IPS Russ Combs
Re: [Snort-Users] help reporting using unix socket (unsock) Joel Esler
Re: new SIP preproc on snort v2.9.1 never firing? Alex Kirk
Re: new SIP preproc on snort v2.9.1 never firing? rmkml
Re: Confused about so_rules precompiled /snort version ? Will precompiled rules 2.9.0.5 work on snort 2.9.1 ? Morgan Cox
Reputation clarification Lay, James
Sourcefire VRT Certified Snort Rules Update 2011-09-07 Research
Re: Reputation clarification Russ Combs
Re: Reputation clarification Lay, James
SID 1:20000 Kevin Ross
[PATCH]: Introduce 'SnortStrToNumRng' -- Parse a ranged numeric value Joshua.Kinard
[PATCH]: Kill dead code in src/util.c Joshua.Kinard

Thursday, 08 September

Installing snort 2.9.x on OpenIndiana/Solaris Express carlopmart
http_header rule vincent
Re: http_header rule Bad Horse
libdaq configure error in cross compiling elison.niven () gmail com

Friday, 09 September

Re: libdaq configure error in cross compiling Steven Sturges
Re: libdaq configure error in cross compiling elison.niven () gmail com
Re: libdaq configure error in cross compiling Steve Sturges

Saturday, 10 September

libdnet Randal T. Rioux

Sunday, 11 September

Dynamic Preprocessor Starter Kit on v. 2.9.1.0 compile error. enrico
Re: libdnet Martin Roesch
precompiled so_rules for arm elison.niven () gmail com

Monday, 12 September

Re: Request change on snort v2.9.1 snort_httpinspect.h MAX_METHOD_LEN to 8 Bhagya Bantwal
Google Groups was: libdnet Joel Esler
Re: Google Groups was: libdnet Randal T. Rioux
http ports defined twice in snort.conf - portvar and http_inspect Eoin Miller
Re: http ports defined twice in snort.conf - portvar and http_inspect waldo kitty
Re: http ports defined twice in snort.conf - portvar and http_inspect Joel Esler
Re: http ports defined twice in snort.conf - portvar and http_inspect Joel Esler

Tuesday, 13 September

Sourcefire VRT Certified Snort Rules Update 2011-09-13 Research
typo on old snort id 2437 rmkml
[PATCH]: Use uint8_t for protocol in some Stream5 functions Joshua.Kinard
Re: [PATCH][RESEND]: Use uint8_t for protocol in some Stream5functions Joshua.Kinard
Flowbits and threshold Dheeraj Gupta

Wednesday, 14 September

execute script on event x Tobias Dinse
Re: Flowbits and threshold Jason Wallace
Snort Rules changelog uri shalev
Re: Snort Rules changelog Alex Kirk
Re: Snort Rules changelog C Granger
Re: Snort Rules changelog Joel Esler
S5 and memcap default setting Eoin Miller
Re: Snort Rules changelog Chris Granger
Re: Flowbits and threshold Dheeraj Gupta
Re: S5 and memcap default setting Eoin Miller
Shared Object Rule 15451 vincent
snort not capturing Mario Remy Almeida
Re: Shared Object Rule 15451 Patrick Mullen
Re: execute script on event x Martin Holste
Re: snort not capturing Martin Holste
Re: snort not capturing Mario Remy Almeida
Re: snort not capturing Martin Holste
Re: snort not capturing Mario Remy Almeida

Thursday, 15 September

Re: snort not capturing Martin Holste
Re: snort not capturing Mario Remy Almeida
Re: snort not capturing Jason Wallace
Re: snort not capturing Mario Remy Almeida
Re: snort not capturing waldo kitty
Testing 2.9.1 and getting 'Unknown preprocessor: "sip"' Miguel Alvarez

Friday, 16 September

Snort Frontend Compare James Lay
Re: Snort Frontend Compare Dustin Webber
Sourcefire VRT Certified Snort Rules Update 2011-09-16 Research
Snort.org Blog: Snort 2.9.1 HTTP and SMTP logging features Joel Esler
Re: Snort.org Blog: Snort 2.9.1 HTTP and SMTP logging features Jason Haar

Saturday, 17 September

Re: Snort Frontend Compare James Lay
Re: Snort.org Blog: Snort 2.9.1 HTTP and SMTP logging features Joel Esler
Re: Snort.org Blog: Snort 2.9.1 HTTP and SMTP logging features Jason Haar
Re: Snort.org Blog: Snort 2.9.1 HTTP and SMTP logging features Richard Bejtlich

Sunday, 18 September

http_inspect message Mario Remy Almeida
Re: http_inspect message Martin Holste
Re: http_inspect message Mario Remy Almeida
Re: http_inspect message Martin Holste
Re: http_inspect message Mario Remy Almeida
Re: http_inspect message Martin Holste

Monday, 19 September

Re: [Snort-Users] Snort.org Blog: Snort 2.9.1 HTTP and SMTP logging features Bamm Visscher
FATAL ERROR: ByteExtract variable 'cve' in rule [3:16325] is used before it is defined. Administrator
Re: FATAL ERROR: ByteExtract variable 'cve' in rule [3:16325] is used before it is defined. Joel Esler
Re: [Snort-Users] Snort.org Blog: Snort 2.9.1 HTTP and SMTP logging features Jason Brvenik
Re: Active response not working in 2.9.0.4 ? Risto Vaarandi
Re: http_inspect message Jefferson, Shawn
Re: [Snort-Users] Snort.org Blog: Snort 2.9.1 HTTP and SMTP logging features Bamm Visscher
Re: Active response not working in 2.9.0.4 ? Russ Combs
Re: [Snort-Users] Snort.org Blog: Snort 2.9.1 HTTP and SMTP logging features Bamm Visscher

Tuesday, 20 September

Re: [Snort-Users] Snort.org Blog: Snort 2.9.1 HTTP and SMTP logging features Joel Esler
Re: Active response not working in 2.9.0.4 ? Risto Vaarandi
Possible FP 17390 Lay, James
Re: Possible FP 17390 Joel Esler
Re: Possible FP 17390 Joel Esler
Re: Dynamic Preprocessor Starter Kit on v. 2.9.1.0 compile error. Russ Combs
Sourcefire VRT Certified Snort Rules Update 2011-09-20 Research
Re: Possible FP 17390 Lay, James
Re: Possible FP 17390 Joel Esler
Re: Possible FP 17390 rmkml
Re: Possible FP 17390 Joel Esler
Re: Possible FP 17390 Lay, James
Re: Possible FP 17390 Joel Esler
snort developement ahmad reza noroozi

Wednesday, 21 September

Disable sid vs. Suppress Lay, James
Re: Disable sid vs. Suppress Alex Kirk
Re: Disable sid vs. Suppress Lay, James
Re: Disable sid vs. Suppress Jefferson, Shawn
RHEL: Snort Intrusion Detection System w/ Barnyard2 and PostgreSQL Support Randal T. Rioux
Re: Disable sid vs. Suppress Lay, James
Re: RHEL: Snort Intrusion Detection System w/ Barnyard2 and PostgreSQL Support Joel Esler
Sourcefire VRT Certified Snort Rules Update 2011-09-21 Research
Re: Disable sid vs. Suppress Dave Venman
Snort Daemon dying unexpectedly Dheeraj Gupta

Thursday, 22 September

Re: Active response not working in 2.9.0.4 ? Risto Vaarandi
[slightly OT] optical power level diagnostic ? Kungu Panda
Re: Snort Daemon dying unexpectedly Russ Combs
Re: Snort Daemon dying unexpectedly Lay, James
Re: Disable sid vs. Suppress Jefferson, Shawn
Re: Disable sid vs. Suppress Dave Venman
Re: Active response not working in 2.9.0.4 ? Russ Combs
Gentoo Linux Users: snort-2.9.1 and daq-0.6.1 added to Portage Jason Wallace
Fwd: Delivery Status Notification (Failure) Nabyl Benmlih
Re: Fwd: Delivery Status Notification (Failure) Jason Wallace
Sourcefire VRT Certified Snort Rules Update 2011-09-22 Research
Re: Gentoo Linux Users: snort-2.9.1 and daq-0.6.1 added to Portage NA
Re: Disable sid vs. Suppress Joel Esler
sid:19825 Apache Killer Yap Ji Wen

Friday, 23 September

Re: sid:19825 Apache Killer JJC

Sunday, 25 September

IPVAR qustion Qinwen Hu
Re: IPVAR qustion Joel Esler

Monday, 26 September

Unknown classtype Lay, James
Re: Unknown classtype Marcos Rodriguez
Re: Unknown classtype Lay, James
Re: Unknown classtype Joel Esler
Re: Unknown classtype rmkml
Re: Unknown classtype Lay, James
Re: how to call my own function on snort - Help Ryan Jordan

Tuesday, 27 September

how to call my own function on snort - Help ndritsos
Quickstart for Bro Cluster Martin Holste
[Snort-Sigs] 19213 thousands of FP matan monitz
Re: [Snort-Sigs] 19213 thousands of FP Alex Kirk
Re: [Snort-Sigs] 19213 thousands of FP JJC
Re: Unknown classtype Joel Esler
Re: how to call my own function on snort - Help Russ Combs
Re: Unknown classtype Lay, James
Problem with using 2 sensors Mike Boeckeler
Re: Problem with using 2 sensors JJC
Re: Problem with using 2 sensors beenph
Re: Problem with using 2 sensors Lay, James
Re: Problem with using 2 sensors Castle, Shane
Re: Problem with using 2 sensors Joel Esler
Re: Problem with using 2 sensors Lay, James
Re: Problem with using 2 sensors Joel Esler
Sourcefire VRT Certified Snort Rules Update 2011-09-27 Research
wrong pcre table on snort_manual.pdf in v2.9.1? rmkml
Re: wrong pcre table on snort_manual.pdf in v2.9.1? Joel Esler

Wednesday, 28 September

BASE - Graphing - PHP 5.3.6 Michael Steele
Segfault with Snort 2.9.1 Peter Bates
Re: Segfault with Snort 2.9.1 Lay, James
Re: Segfault with Snort 2.9.1 Peter Bates
SQL Injection Signature Ahmed Qaisi
Re: Segfault with Snort 2.9.1 Martin Holste
Re: SQL Injection Signature waldo kitty
Sourcefire VRT Certified Snort Rules Update 2011-09-28 Research
Re: Segfault with Snort 2.9.1 beenph

Thursday, 29 September

Re: SQL Injection Signature waldo kitty
Snort 2.9.1.0 on Gentoo; fatal startup error NA
how to disable an so_rule Lawrence R. Hughes, Sr.
Re: Snort 2.9.1.0 on Gentoo; fatal startup error Joel Esler
Re: how to disable an so_rule rmkml
Sourcefire VRT Certified Snort Rules Update 2011-09-29 Research
Re: Snort 2.9.1.0 on Gentoo; fatal startup error NA

Friday, 30 September

S5 prunes Peter Bates
Re: Snort 2.9.1.0 on Gentoo; fatal startup error Nigel Houghton
Re: S5 prunes Joel Esler
Installing only so_rules with pulledpork carlopmart
Re: [Spam] Re: S5 prunes Lay, James
Re: Snort 2.9.1.0 on Gentoo; fatal startup error NA
Re: how to disable an so_rule Kevin Ross
Re: how to disable an so_rule Lawrence R. Hughes, Sr.