<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Inliniac &#187; Snortsam</title>
	<atom:link href="http://www.inliniac.net/blog/category/snortsam/feed" rel="self" type="application/rss+xml" />
	<link>http://www.inliniac.net/blog</link>
	<description>Everything inline.</description>
	<lastBuildDate>Wed, 11 Jan 2012 19:09:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>New Snortsam patch for Snort 2.8.0.1</title>
		<link>http://www.inliniac.net/blog/2008/01/08/new-snortsam-patch-for-snort-2801.html</link>
		<comments>http://www.inliniac.net/blog/2008/01/08/new-snortsam-patch-for-snort-2801.html#comments</comments>
		<pubDate>Tue, 08 Jan 2008 12:30:53 +0000</pubDate>
		<dc:creator>Victor Julien</dc:creator>
				<category><![CDATA[IPv6]]></category>
		<category><![CDATA[Snort]]></category>
		<category><![CDATA[Snortsam]]></category>
		<category><![CDATA[Emerging Threats]]></category>
		<category><![CDATA[Matt Jonkman]]></category>

		<guid isPermaLink="false">http://www.inliniac.net/blog/2008/01/08/new-snortsam-patch-for-snort-2801.html</guid>
		<description><![CDATA[Matt Jonkman of Emerging Threats asked me to have a look at the existing Snortsam 2.8.0.1 patch as people were continuing to report problems with it. I updated it to compile without compiler warnings, build cleanly with debugging enabled, build cleanly with Snort&#8217;s IPv6 support enabled and added a check so it won&#8217;t act on [...]]]></description>
			<content:encoded><![CDATA[<p>Matt Jonkman of <a href="http://www.emergingthreats.net/" target="_blank">Emerging Threats</a> asked me to have a look at the existing Snortsam 2.8.0.1 patch as people were continuing to report problems with it. I updated it to compile without compiler warnings, build cleanly with debugging enabled, build cleanly with Snort&#8217;s IPv6 support enabled and added a check so it won&#8217;t act on alerts in IPv6 packets since the Snortsam framework does not support IPv6. Finally I removed the patch script so it&#8217;s provided as a &#8216;normal&#8217; diff. Here is the patch: <a href="http://www.inliniac.net/files/snortsam-2.8.0.1.diff">http://www.inliniac.net/files/snortsam-2.8.0.1.diff</a></p>
<p>Here are the instructions for getting your Snort 2.8.0.1 source patched:</p>
<p>Make sure you have a clean Snort 2.8.0.1 tree, then patch it:</p>
<p>cd snort-2.8.0.1<br />
patch -p1 &lt; ../snortsam-2.8.0.1.diff</p>
<p>Next, run &#8216;autojunk.sh&#8217; to update the build system (you need to have libtoolize, aclocal, autoheader, autoconf and automake installed). After this, configure and build Snort normally:</p>
<p>./configure &lt;your configure options&gt;<br />
make<br />
make install</p>
<p>Thats it.</p>
<p>Thanks to Matt Jonkman of <a href="http://www.emergingthreats.net/" target="_blank">Emerging Threats</a> for paying me to do this and CunningPike for doing the first iterations of the patch!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.inliniac.net/blog/2008/01/08/new-snortsam-patch-for-snort-2801.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

