<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Snort_inline: idea for an improved bait-and-switch</title>
	<atom:link href="http://www.inliniac.net/blog/2006/07/11/snort_inline-idea-for-an-improved-bait-and-switch.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.inliniac.net/blog/2006/07/11/snort_inline-idea-for-an-improved-bait-and-switch.html</link>
	<description>Everything inline.</description>
	<pubDate>Tue, 06 Jan 2009 10:32:57 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: jack whitsitt</title>
		<link>http://www.inliniac.net/blog/2006/07/11/snort_inline-idea-for-an-improved-bait-and-switch.html/comment-page-1#comment-1540</link>
		<dc:creator>jack whitsitt</dc:creator>
		<pubDate>Fri, 16 Feb 2007 18:56:10 +0000</pubDate>
		<guid isPermaLink="false">http://psh.poort.lan/blog/?p=5#comment-1540</guid>
		<description>In the original Bait and Switch (which Will reworked...nice job!), we just had iptables mark packets and let custom routing tables based on the markings do the rest of the work (which meant other iptables rules could be left alone).  It also meant your honeypot and prod server could have ducplicate IP's if you so desired.  Doing it in snort-inline is probably possible, but do you want your IDS doing all of that extra work?</description>
		<content:encoded><![CDATA[<p>In the original Bait and Switch (which Will reworked&#8230;nice job!), we just had iptables mark packets and let custom routing tables based on the markings do the rest of the work (which meant other iptables rules could be left alone).  It also meant your honeypot and prod server could have ducplicate IP&#8217;s if you so desired.  Doing it in snort-inline is probably possible, but do you want your IDS doing all of that extra work?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anonymous</title>
		<link>http://www.inliniac.net/blog/2006/07/11/snort_inline-idea-for-an-improved-bait-and-switch.html/comment-page-1#comment-7</link>
		<dc:creator>anonymous</dc:creator>
		<pubDate>Sun, 06 Aug 2006 22:13:07 +0000</pubDate>
		<guid isPermaLink="false">http://psh.poort.lan/blog/?p=5#comment-7</guid>
		<description>Will Metcalf is an excellent coder and any questioning of Will's methods, idea's, or code shall be seen as an act of treason and the violators shall be sentenced to a life time of QA work.</description>
		<content:encoded><![CDATA[<p>Will Metcalf is an excellent coder and any questioning of Will&#8217;s methods, idea&#8217;s, or code shall be seen as an act of treason and the violators shall be sentenced to a life time of QA work.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
