|
Mailing List Archive For snort-users@snort.org Apr 2003 By Subject- (Off List) Two items that are hard to digest...
- [Snort-announce] Snort 2.0 rc1 available
- [Snort-devel] Snort 2.0 Released!
- [Snort-devel] Snort 2.0 Released! (Absent jusqu'au 29/07/2002)
- [Snort-sigs] Questions 101
- [Snort-sigs] Sendmail Signature
- [Snort-sigs] SMTP From Comment Overflow rule problems
- [Snort-users] "Saving State" in Snort
- [Snort-users] "Saving State" in Snort (Absent jusqu'au 29/07/2002)
- [Snort-users] $HOME_NET
- [Snort-users] (A little off topic but not really) Connection dropping.
- [Snort-users] (no subject)
- [Snort-users] (no subject) (how to unsubscribe)
- [Snort-users] (OT) You caught them, what next?
- [Snort-users] (snort_decoder): Truncated Tcp Options
- [Snort-users] (spp_conversation) Bad IP protocol
- [Snort-users] (spp_portscan2) lines in alert file
- [Snort-users] (spp_stream4) TTL LIMIT Exceeded
- [Snort-users] ./setup.sh
- [Snort-users] /etc/init.d/snort file, Snort 1.9.1
- [Snort-users] /var/log/snort/some.ip.addr.dir/ permissions pr oblem
- [Snort-users] /var/log/snort/some.ip.addr.dir/ permissions problem
- [Snort-users] 2.0.0rc3 Available!
- [Snort-users] [ANN] HenWen 2.0!
- [Snort-users] [Fwd: CORE-2003-0307: Snort TCP Stream Reassembly Integer Overflow Vulnerability]
- [Snort-users] [Fwd: Snort <=1.9.1 exploit]
- [Snort-users] [output] Log application data into the database
- [Snort-users] [Snort-users]SNORT, +MySQL, +Acid, Apache on wi nXp
- [Snort-users] [Snort-users]SNORT, +MySQL, +Acid, Apache on winXp
- [Snort-users] A Friday afternoon hoho
- [Snort-users] A little pass rule help
- [Snort-users] A little pass rule help (Absent jusqu'au 29/07/2002)
- [Snort-users] about idmef xml
- [Snort-users] ACID
- [Snort-users] Acid and PHP Redhat 8.0
- [Snort-users] ACID Concerns
- [Snort-users] ACID Email Alert Configuration
- [Snort-users] ACID inconsistencies?
- [Snort-users] ACID issue
- [Snort-users] ACID name resolution
- [Snort-users] Acid slowness
- [Snort-users] adding additional sensor to ACID
- [Snort-users] alert file
- [Snort-users] Alert file exceeds 2GB
- [Snort-users] alert file XRef URL's
- [Snort-users] Alert messages in packet dumps
- [Snort-users] Alert.ids log file not being created
- [Snort-users] Allow me to field a question
- [Snort-users] Anyone integrated HIDS-style alerts into Snort DB?
- [Snort-users] APPLET catching
- [Snort-users] Applied Watch for the Snort IDS is Now Availabl e for Free Download
- [Snort-users] Applied Watch for the Snort IDS is Now Available for Free Download
- [Snort-users] Applied Watch is now FREE for Non-Commercial Use after overwhelming Demand!
- [Snort-users] are the Snort Signature Database or arachNIDS downloadable?
- [Snort-users] ASN.1
- [Snort-users] aswer to snort
- [Snort-users] Attention Windows Users : Install Complete IDS Solution on Windows - New Updates!
- [Snort-users] Automated snort tuner
- [Snort-users] Automatic Update of the Rule-base using SnortCenter
- [Snort-users] Barnyard log directory
- [Snort-users] Barnyard Shell Script
- [Snort-users] Barnyard writing cleartext MySQL-password to /var/log/messages!!!
- [Snort-users] Benchmarking snort
- [Snort-users] Best OS
- [Snort-users] Book soon available
- [Snort-users] BPF filter
- [Snort-users] Broken config directive? or just me?
- [Snort-users] Bug Report
- [Snort-users] Byte_jump & byte_check
- [Snort-users] Byte_test and Byte_jump
- [Snort-users] calllogfuncs() decoded length does not compute!
- [Snort-users] can I remove asn1_decode preprocessor?
- [Snort-users] Can snort add a rule to iptables?
- [Snort-users] Can snort detect the SYN flood?
- [Snort-users] Can snort detect the SYN flood? (Absent jusqu'au 29/07/2002)
- [Snort-users] capturing arp
- [Snort-users] capturing arp (Absent jusqu'au 29/07/2002)
- [Snort-users] Capturing only specific data
- [Snort-users] catch the http-tunnel traffic with snort
- [Snort-users] Cert Advisory and now no SNMP traps.
- [Snort-users] Cert Advisory and now no SNMP traps. (Absent jusqu'au 29/07/2002)
- [Snort-users] certificate verify error
- [Snort-users] chroot problems with Red Hat Advanced server
- [Snort-users] classification.config
- [Snort-users] Clean DB && Barnyard Start
- [Snort-users] Configure Error in snort 2.0.0
- [Snort-users] Confiremation of BO needed!
- [Snort-users] connect failed
- [Snort-users] Creating a new rule
- [Snort-users] Crystal Reports from MySQL
- [Snort-users] Curious FTP access, possible information gathering?
- [Snort-users] curl error
- [Snort-users] Define sealth eth0
- [Snort-users] Demarc
- [Snort-users] detecting http-tunnel traffic
- [Snort-users] DF and MF
- [Snort-users] Difference between distance and within
- [Snort-users] Disabling two alert messages
- [Snort-users] Do 1.9 rules work with 2.0?
- [Snort-users] Does snort support cygwin?
- [Snort-users] DROP connections?
- [Snort-users] Dual Alerts ?
- [Snort-users] Editing rules within Webmin
- [Snort-users] Educational Incident Data Comparison Pilot (X-Post)
- [Snort-users] email address not specified
- [Snort-users] Email Alert for Windows - Testers Needed
- [Snort-users] Email alerts
- [Snort-users] Email for Michael Steele - Please redirect - Read Inside
- [Snort-users] empty logs..how come ??
- [Snort-users] emty logs
- [Snort-users] ERROR: Please activate spp_conversation before trying to activate spp_portscan2
- [Snort-users] false alarm or not ?
- [Snort-users] false alarm with snort 2.0, why?
- [Snort-users] False positives due to stream4 issue?
- [Snort-users] FATAL ERROR: /etc/snort/rpc.rules:19: Unknown Flow Option: 'to_sever'
- [Snort-users] Firewall vs IDS
- [Snort-users] Firewalls on IDS
- [Snort-users] Fixed My Problems with Snort 2.0.0 and MySQL Client with Redhat 9
- [Snort-users] Flex Resp Is Resetting The Wrong Port
- [Snort-users] flexresp problem
- [Snort-users] Frag Preprocessor Preventing Log Parsing
- [Snort-users] Frag2
- [Snort-users] Frag2 timeout parameter
- [Snort-users] FreeBSD-5 / Snort 2.0 Installation Document
- [Snort-users] Fuzzy Matching in Snort
- [Snort-users] generating an alert
- [Snort-users] getting error when using -s
- [Snort-users] Gigabit NIC Recommendations...
- [Snort-users] Gnutella
- [Snort-users] GUI interface
- [Snort-users] help
- [Snort-users] Help Needed: i want to make a firewall
- [Snort-users] Help w/ ODBC Setup
- [Snort-users] Help with a config file please?
- [Snort-users] Help with a config file please?]
- [Snort-users] Help with Hogwash on OpenBSD
- [Snort-users] help with regular expressions
- [Snort-users] Hi
- [Snort-users] Hi Im new to Snort and I keep getting wierd errors....please help !
- [Snort-users] historical records of Snort logs?
- [Snort-users] Hogwash x Redhat
- [Snort-users] home_net and ext_net question
- [Snort-users] HOME_NET and EXTERNAL_NET snort.conf
- [Snort-users] How can I stop checking for Truncated Tcp Options?
- [Snort-users] How can I stop checking for Truncated TcpOptions? (Absent jusqu'au 29/07/2002)
- [Snort-users] How to centralize traffic
- [Snort-users] how to get snort to ignore kazaa
- [Snort-users] How to handle BPDU packet in Snort?
- [Snort-users] How to handle BPDU packet in Snort? (Absent jusqu'au 29/07/2002)
- [Snort-users] How to set WINDOWS up for a Stealth Interface...
- [Snort-users] How to Use Throttle when using Swatch for duplicate email alerts
- [Snort-users] HTTP traffic not being scanned after upgrade from 1.9.1 to 2.0.0
- [Snort-users] ICMP PING NMAP to 149.1.1.1
- [Snort-users] ICMP rule not behaving as expected
- [Snort-users] IDS Placement ideas for inside and outside a fi rewall.
- [Snort-users] IDS Placement ideas for inside and outside a firewall.
- [Snort-users] idscenter
- [Snort-users] Ignore host
- [Snort-users] ignored 1 duplicate alert(s)
- [Snort-users] Inaccurate info !!
- [Snort-users] install snort on RH linux
- [Snort-users] Installations of Snort on linux
- [Snort-users] Installing Snort with PHP, MySQL, ACID,etc
- [Snort-users] Installing Snort2.0 w/ MySQL support
- [Snort-users] interpreting logs...
- [Snort-users] Invalid Iterface with snort 2.0.0...
- [Snort-users] Invalid Iterface...
- [Snort-users] iptables vs snort vs portsentry order
- [Snort-users] IPv6 and snort v2rc2
- [Snort-users] Is Oracle supported on Win2k?
- [Snort-users] is there a 2.0 build that is mysql compatible
- [Snort-users] Is there a program to test snort rules?
- [Snort-users] It worked!
- [Snort-users] Jose Ramon Hernandez Macias/Sistemas/Megacentro/Alestra is out of the office.
- [Snort-users] Kazaa P2P Rules
- [Snort-users] Larry Lopez/ahg/IRCorp is out of the office.
- [Snort-users] Log everything for billing purposes
- [Snort-users] log file
- [Snort-users] log the content
- [Snort-users] logsnorter
- [Snort-users] logsnorter and shorewall
- [Snort-users] Looking for opinions...
- [Snort-users] Making snort smarter...
- [Snort-users] Mike Sands/ITS/Element K is out of the office.
- [Snort-users] mrtg machine
- [Snort-users] multiple files off of stdin?
- [Snort-users] MY SQL, SNORT.
- [Snort-users] MySQL & ACID Issues
- [Snort-users] MySQL 4
- [Snort-users] Mysql question
- [Snort-users] MySql-Acid logging
- [Snort-users] Need Help Installing snort on OpenBSD
- [Snort-users] Need to MAKE/DEVELOP my own firewall
- [Snort-users] Net_SSLeay updated Makefile.PL for RH9
- [Snort-users] Netbios rules and keeping snort quiet about them ;)
- [Snort-users] Network placement / using a VLAN
- [Snort-users] new features of snort 2.0
- [Snort-users] New guy.
- [Snort-users] New Release of snort_inline!
- [Snort-users] New Rules Question
- [Snort-users] new snort.conf
- [Snort-users] New stream 4 messages in 2.0
- [Snort-users] New stream 4 messages in 2.0 (Absent jusqu'au 29/07/2002)
- [Snort-users] New stream 4 messages in 2.0 (test)
- [Snort-users] New to Snort
- [Snort-users] new user, great product, but ...
- [Snort-users] Newbie Question
- [Snort-users] Newbie question (FAQ 4.3 update requested)
- [Snort-users] newbie question on Stream4 preprocessing - missing last packet
- [Snort-users] Newbie questions are as newbie questions does
- [Snort-users] No longer seeing exploit traffic on version 2.0.0
- [Snort-users] No memory error
- [Snort-users] No output to ACID
- [Snort-users] No output to ACID]
- [Snort-users] no portscan traffic
- [Snort-users] Noob question about different parts of a rule
- [Snort-users] Not logging to MYSQL
- [Snort-users] ODBC+TDS woes
- [Snort-users] Off topic: ActiveScout?
- [Snort-users] old version of snort?
- [Snort-users] one other item
- [Snort-users] Only *nix alerts?
- [Snort-users] Only Smtp traffic
- [Snort-users] OpenPcap( ) error with snort 2.0
- [Snort-users] options for consideration
- [Snort-users] Oracle Compromise (Tftp + Netcat)
- [Snort-users] OT - Spam
- [Snort-users] OT - Spam)
- [Snort-users] OT- Can any one recommend a turnkey log parser for cisco.
- [Snort-users] OT- Can anyone recommend a log parser for cisco?
- [Snort-users] OT: Drinking game - Content filter replies?
- [Snort-users] OT: French Snort Users, Please Read.
- [Snort-users] OT: Help with Barnyard
- [Snort-users] OT: The Signature from Hell
- [Snort-users] P2P rule not working
- [Snort-users] pass rule
- [Snort-users] Pass rule not passing preprocessors
- [Snort-users] Pass rule not passing preprocessors (Absent jusqu'au 29/07/2002)
- [Snort-users] Passive or Active
- [Snort-users] Performance Bottleneck
- [Snort-users] PHP install
- [Snort-users] php is too old !?!?
- [Snort-users] plz help
- [Snort-users] porno rules
- [Snort-users] porno rules -- portscan2 &c
- [Snort-users] porno rules [OT]
- [Snort-users] Port for MYsql
- [Snort-users] Portscan False Positives From My IP Range
- [Snort-users] portscan preprocessor and scan rules
- [Snort-users] Portscan setup
- [Snort-users] portscan target filter ?
- [Snort-users] Portscan with ICMP?
- [Snort-users] portscan2 effectiveness.
- [Snort-users] Portscan2 ignorehosts
- [Snort-users] Possible error with the "-L" flag?
- [Snort-users] postgres schema error
- [Snort-users] ppd files for Time-Module
- [Snort-users] preprocessor definition in snort manual!?!?!?
- [Snort-users] Priority codes
- [Snort-users] Problem logging to postgres
- [Snort-users] Problem with Snort 2.0.0 and MySQL Client with Redhat 9
- [Snort-users] Problems with ACID
- [Snort-users] Problems with Snort 2.0rc4
- [Snort-users] Procedure to upgrade snort 1.9.1 to 2.0 on linux 8.0
- [Snort-users] Protocol/Service/Source Bytes/Dest bytes needed
- [Snort-users] PureSecure using Snort 2.x now...
- [Snort-users] Question
- [Snort-users] Question -- spp_stream4 STEALTH ACTIVITY (unknown) detection
- [Snort-users] Question about Snort/ACID/MySQL + Barnyard and how they play together
- [Snort-users] Question about Snort/ACID/MySQL and how they pl ay together
- [Snort-users] Question about Snort/ACID/MySQL and how they play together
- [Snort-users] Question about Snort/ACID/MySQL and portscans
- [Snort-users] Question on /var/log/snort directory
- [Snort-users] Question on database for Snort
- [Snort-users] Question regarding Openbsd 3.3 Bridge
- [Snort-users] Quick Question
- [Snort-users] Quick(noob) question on rules. Role of snort.co nf?
- [Snort-users] Quick(noob) question on rules. Role of snort.conf?
- [Snort-users] Realtime alerts
- [Snort-users] Recall: Question about Snort/ACID/MySQL and how they play togethe r
- [Snort-users] regex support problem
- [Snort-users] Relation between events and rules set.
- [Snort-users] RH8 + Snort 2.0.0 Segmentation Fault on startup
- [Snort-users] Role of snort.conf regarding rules? (noob)
- [Snort-users] RSA Conference 2003
- [Snort-users] rule chains
- [Snort-users] Rule help Please
- [Snort-users] Run as user?
- [Snort-users] Same source/dest
- [Snort-users] Sample Pass rules
- [Snort-users] Script to cleanup ACID/Snort Alerts in MySQL DB...
- [Snort-users] search method lowmem
- [Snort-users] Securing a Snort machine
- [Snort-users] segmantation fault
- [Snort-users] segmentation fault...
- [Snort-users] sending snort output to a database OFFLINE
- [Snort-users] Sensor Config Creation in SnortCenter
- [Snort-users] setting up a mirroring port at switch
- [Snort-users] Setting up snort to syslog diffrent priority's
- [Snort-users] SID 1042 and WebDAV
- [Snort-users] Sid 466
- [Snort-users] sidestep
- [Snort-users] Small n00b question
- [Snort-users] smb alerts
- [Snort-users] SMTP From Comment Overflow rule problems
- [Snort-users] Sniffer setup.
- [Snort-users] SNMP plugin removed from Snort
- [Snort-users] SNMP plugin removed from Snort + stream4 patch for 1.9.1
- [Snort-users] SNMP request UDP
- [Snort-users] snmp support under rh 8
- [Snort-users] snmp traps for snort
- [Snort-users] SNMP?
- [Snort-users] Snort & RHL 9
- [Snort-users] Snort (any version) with Barnyard logging payload in hex
- [Snort-users] snort + email + alert
- [Snort-users] snort -A unsock feature
- [Snort-users] snort -r output
- [Snort-users] snort -r output (Absent jusqu'au 29/07/2002)
- [Snort-users] snort 1-9-1 W2K ISDN not working
- [Snort-users] Snort 1.9.1, 1.9.1 chrooted and 2.0 rc4, Barnyard, Mudpit RPMs for RedHat 7.3, 8.0 and 9
- [Snort-users] snort 2 / mysql / static/ undefined reference to uncompress
- [Snort-users] Snort 2.0
- [Snort-users] Snort 2.0 and Barnyard 0.1.0
- [Snort-users] Snort 2.0 and SnortCenter
- [Snort-users] Snort 2.0 as a Windows Service??
- [Snort-users] Snort 2.0 changes?
- [Snort-users] Snort 2.0 dropping packets
- [Snort-users] Snort 2.0 isn't alerting
- [Snort-users] Snort 2.0 not logging any alerts
- [Snort-users] Snort 2.0 Released!
- [Snort-users] Snort 2.0 Upgrade - Sensor is very chatty
- [Snort-users] Snort 2.0.0 & syslog
- [Snort-users] Snort 2.0.0 & syslog (solved)
- [Snort-users] Snort 2.0.0 logging everything when using (session: printable)
- [Snort-users] snort 2.0.0 on Tru64 5.1
|