<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Inliniac</title>
	<atom:link href="http://www.inliniac.net/blog/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://www.inliniac.net/blog</link>
	<description>Everything inline.</description>
	<lastBuildDate>Mon, 22 Feb 2010 14:26:44 +0100</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Blocking comment spam using ModSecurity and realtime blacklists by Mod Security for Apache &#8211; Web Server Smart Firewall</title>
		<link>http://www.inliniac.net/blog/2007/02/23/blocking-comment-spam-using-modsecurity-and-realtime-blacklists.html/comment-page-1#comment-18934</link>
		<dc:creator>Mod Security for Apache &#8211; Web Server Smart Firewall</dc:creator>
		<pubDate>Mon, 22 Feb 2010 14:26:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=64#comment-18934</guid>
		<description>[...] http://www.inliniac.net/blog/2007/02/23/blocking-comment-spam-using-modsecurity-and-realtime-blackli... [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://www.inliniac.net/blog/2007/02/23/blocking-comment-spam-using-modsecurity-and-realtime-blackli.." rel="nofollow">http://www.inliniac.net/blog/2007/02/23/blocking-comment-spam-using-modsecurity-and-realtime-blackli..</a>. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Window scaling normalization in Snort_inline broken by design by Victor Julien</title>
		<link>http://www.inliniac.net/blog/2007/09/04/window-scaling-normalization-in-snort_inline-broken-by-design.html/comment-page-1#comment-18748</link>
		<dc:creator>Victor Julien</dc:creator>
		<pubDate>Mon, 15 Feb 2010 12:03:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/2007/09/04/window-scaling-normalization-in-snort_inline-broken-by-design.html#comment-18748</guid>
		<description>You need to make sure Snort_inline sees both sides of the traffic... so add a iptables rule for the return traffic as well...</description>
		<content:encoded><![CDATA[<p>You need to make sure Snort_inline sees both sides of the traffic&#8230; so add a iptables rule for the return traffic as well&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Window scaling normalization in Snort_inline broken by design by assen</title>
		<link>http://www.inliniac.net/blog/2007/09/04/window-scaling-normalization-in-snort_inline-broken-by-design.html/comment-page-1#comment-18718</link>
		<dc:creator>assen</dc:creator>
		<pubDate>Sun, 14 Feb 2010 09:07:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/2007/09/04/window-scaling-normalization-in-snort_inline-broken-by-design.html#comment-18718</guid>
		<description>Hy,

Debian 2.6.26-2-686 with snort-inline 2.6.1.5-1
--------------------------
snort_inline.conf-&gt; add as you recomment the statement 
preprocessor stream4:   disable_evasion_alerts, \
                        stream4inline, \
                        enforce_state drop, \
                        memcap 134217728, \
                        timeout 3600, \
                        truncate, \
                        window_size 3000, \
                        norm_wscale_max 14
-----------------------------


This is working smtp session (with ACCEPT rule in firewall.sh):

$IPTABLES -A FORWARD -i eth2 -p tcp -s 0.0.0.0/0 -d IP_ADDRESS_MAIL_SERVER --dport 25  -j ACCEPT

IP IP_ADDRESS_SENDER.54741 &gt; 192.168.1.200.25: S 2037140028:2037140028(0) win 5840 
IP 192.168.1.200.25 &gt; IP_ADDRESS_SENDER.54741: S 2476668242:2476668242(0) ack 2037140029 win 5792 
IP IP_ADDRESS_SENDER.54741 &gt; 192.168.1.200.25: . ack 1 win 92 
IP 192.168.1.200.25 &gt; IP_ADDRESS_SENDER.54741: P 1:71(70) ack 1 win 181 
IP IP_ADDRESS_SENDER.54741 &gt; 192.168.1.200.25: . ack 71 win 92 

This is with QUEUE rule in firewall.sh (doesn&#039;t work even with recommended option):
$IPTABLES -A FORWARD -i eth2 -p tcp -s 0.0.0.0/0 -d IP_ADDRESS_MAIL_SERVER --dport 25  -j QUEUE

The only effect from &quot;norm_wscale_max 14&quot; option iis the messages in /var/log/snort_inline/snort_inline-f* disappeared, but the smtp is not working again - as you can see below:

IP IP_ADDRESS_SENDER.39797 &gt; 192.168.1.200.25: S 1774669934:1774669934(0) win 5840 
IP 192.168.1.200.25 &gt;IP_ADDRESS_SENDER.39797: S 2214167916:2214167916(0) ack 1774669935 win 5792 
IP IP_ADDRESS_SENDER.39797 &gt; 192.168.1.200.25: . ack 1 win 92 
IP 192.168.1.200.25 &gt; IP_ADDRESS_SENDER.39797: S 2214167916:2214167916(0) ack 1774669935 win 5792 
IP IP_ADDRESS_SENDER.39797 &gt; 192.168.1.200.25: . ack 1 win 92 
IPIP_ADDRESS_SENDER.54741 &gt; 192.168.1.200.25: FP 0:5(5) ack 1 win 92 
IP 192.168.1.200.25 &gt; IP_ADDRESS_SENDER.39797: S 2214167916:2214167916(0) ack 1774669935 win 5792 
IP IP_ADDRESS_SENDER.39797 &gt; 192.168.1.200.25: . ack 1 win 92 
IP 192.168.1.200.25 &gt; IP_ADDRESS_SENDER.39797: S 2214167916:2214167916(0) ack 1774669935 win 5792 
IP IP_ADDRESS_SENDER.39797 &gt; 192.168.1.200.25: . ack 1 win 92 
-------------------------

Any suggestions?</description>
		<content:encoded><![CDATA[<p>Hy,</p>
<p>Debian 2.6.26-2-686 with snort-inline 2.6.1.5-1<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
snort_inline.conf-&gt; add as you recomment the statement<br />
preprocessor stream4:   disable_evasion_alerts, \<br />
                        stream4inline, \<br />
                        enforce_state drop, \<br />
                        memcap 134217728, \<br />
                        timeout 3600, \<br />
                        truncate, \<br />
                        window_size 3000, \<br />
                        norm_wscale_max 14<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>This is working smtp session (with ACCEPT rule in firewall.sh):</p>
<p>$IPTABLES -A FORWARD -i eth2 -p tcp -s 0.0.0.0/0 -d IP_ADDRESS_MAIL_SERVER &#8211;dport 25  -j ACCEPT</p>
<p>IP IP_ADDRESS_SENDER.54741 &gt; 192.168.1.200.25: S 2037140028:2037140028(0) win 5840<br />
IP 192.168.1.200.25 &gt; IP_ADDRESS_SENDER.54741: S 2476668242:2476668242(0) ack 2037140029 win 5792<br />
IP IP_ADDRESS_SENDER.54741 &gt; 192.168.1.200.25: . ack 1 win 92<br />
IP 192.168.1.200.25 &gt; IP_ADDRESS_SENDER.54741: P 1:71(70) ack 1 win 181<br />
IP IP_ADDRESS_SENDER.54741 &gt; 192.168.1.200.25: . ack 71 win 92 </p>
<p>This is with QUEUE rule in firewall.sh (doesn&#8217;t work even with recommended option):<br />
$IPTABLES -A FORWARD -i eth2 -p tcp -s 0.0.0.0/0 -d IP_ADDRESS_MAIL_SERVER &#8211;dport 25  -j QUEUE</p>
<p>The only effect from &#8220;norm_wscale_max 14&#8243; option iis the messages in /var/log/snort_inline/snort_inline-f* disappeared, but the smtp is not working again &#8211; as you can see below:</p>
<p>IP IP_ADDRESS_SENDER.39797 &gt; 192.168.1.200.25: S 1774669934:1774669934(0) win 5840<br />
IP 192.168.1.200.25 &gt;IP_ADDRESS_SENDER.39797: S 2214167916:2214167916(0) ack 1774669935 win 5792<br />
IP IP_ADDRESS_SENDER.39797 &gt; 192.168.1.200.25: . ack 1 win 92<br />
IP 192.168.1.200.25 &gt; IP_ADDRESS_SENDER.39797: S 2214167916:2214167916(0) ack 1774669935 win 5792<br />
IP IP_ADDRESS_SENDER.39797 &gt; 192.168.1.200.25: . ack 1 win 92<br />
IPIP_ADDRESS_SENDER.54741 &gt; 192.168.1.200.25: FP 0:5(5) ack 1 win 92<br />
IP 192.168.1.200.25 &gt; IP_ADDRESS_SENDER.39797: S 2214167916:2214167916(0) ack 1774669935 win 5792<br />
IP IP_ADDRESS_SENDER.39797 &gt; 192.168.1.200.25: . ack 1 win 92<br />
IP 192.168.1.200.25 &gt; IP_ADDRESS_SENDER.39797: S 2214167916:2214167916(0) ack 1774669935 win 5792<br />
IP IP_ADDRESS_SENDER.39797 &gt; 192.168.1.200.25: . ack 1 win 92<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>Any suggestions?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Contact by Ilya</title>
		<link>http://www.inliniac.net/blog/contact/comment-page-1#comment-18643</link>
		<dc:creator>Ilya</dc:creator>
		<pubDate>Mon, 08 Feb 2010 07:51:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?page_id=34#comment-18643</guid>
		<description>Dear Victor,

Why have you stopped working on Vuurmurr project? Ain&#039;t you no more interested in its evolutioning? Honestly say, I find your project very useful indeed and I&#039;d be glad to know it you&#039;ll continue working on it at least some more time.

Best wishes,
Ilya Egorov (Russia, Moscow)</description>
		<content:encoded><![CDATA[<p>Dear Victor,</p>
<p>Why have you stopped working on Vuurmurr project? Ain&#8217;t you no more interested in its evolutioning? Honestly say, I find your project very useful indeed and I&#8217;d be glad to know it you&#8217;ll continue working on it at least some more time.</p>
<p>Best wishes,<br />
Ilya Egorov (Russia, Moscow)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Contact by Emmanuel</title>
		<link>http://www.inliniac.net/blog/contact/comment-page-1#comment-18563</link>
		<dc:creator>Emmanuel</dc:creator>
		<pubDate>Thu, 04 Feb 2010 08:58:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?page_id=34#comment-18563</guid>
		<description>Hello

I am trying to implement an IPS using Snort on solaris 10

Any help on this in kind of manuals, HOWTOs, etc, will be appreciated,

Regards

Emmanuel</description>
		<content:encoded><![CDATA[<p>Hello</p>
<p>I am trying to implement an IPS using Snort on solaris 10</p>
<p>Any help on this in kind of manuals, HOWTOs, etc, will be appreciated,</p>
<p>Regards</p>
<p>Emmanuel</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Contact by Victor Julien</title>
		<link>http://www.inliniac.net/blog/contact/comment-page-1#comment-17930</link>
		<dc:creator>Victor Julien</dc:creator>
		<pubDate>Tue, 12 Jan 2010 21:34:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?page_id=34#comment-17930</guid>
		<description>Hi Kayvan, I have never tried using IMQ with Snort_inline or other NFQUEUE using programs. Does it work without IMQ? I seem to remember reading about IMQ having issues with ip_queue at the time, but my memory is fuzzy on this point.</description>
		<content:encoded><![CDATA[<p>Hi Kayvan, I have never tried using IMQ with Snort_inline or other NFQUEUE using programs. Does it work without IMQ? I seem to remember reading about IMQ having issues with ip_queue at the time, but my memory is fuzzy on this point.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Contact by Kayvan Javid</title>
		<link>http://www.inliniac.net/blog/contact/comment-page-1#comment-17908</link>
		<dc:creator>Kayvan Javid</dc:creator>
		<pubDate>Tue, 12 Jan 2010 11:39:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?page_id=34#comment-17908</guid>
		<description>Victor,

Congrats on Suricata.

I am trying to get snort_inline in nfqueue mode working with my traffic shaping using imq, on the same box (before you crucify me i know its not the best idea).

All goes well both start with all their required kernel modules fine, not like the good ol&#039;ip_queue days.  However it seems it breaks iptables, did you run into any complications like this ?</description>
		<content:encoded><![CDATA[<p>Victor,</p>
<p>Congrats on Suricata.</p>
<p>I am trying to get snort_inline in nfqueue mode working with my traffic shaping using imq, on the same box (before you crucify me i know its not the best idea).</p>
<p>All goes well both start with all their required kernel modules fine, not like the good ol&#8217;ip_queue days.  However it seems it breaks iptables, did you run into any complications like this ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on First Suricata release tomorrow by Tweets that mention First Suricata release tomorrow « Inliniac -- Topsy.com</title>
		<link>http://www.inliniac.net/blog/2009/12/30/first-suricata-release-tomorrow.html/comment-page-1#comment-17579</link>
		<dc:creator>Tweets that mention First Suricata release tomorrow « Inliniac -- Topsy.com</dc:creator>
		<pubDate>Thu, 31 Dec 2009 03:06:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=305#comment-17579</guid>
		<description>[...] This post was mentioned on Twitter by Victor Julien, Vivek Rajagopalan. Vivek Rajagopalan said: RT: @inliniac: First Suricata release tomorrow! http://is.gd/5GZ6Y - looking forward [...]</description>
		<content:encoded><![CDATA[<p>[...] This post was mentioned on Twitter by Victor Julien, Vivek Rajagopalan. Vivek Rajagopalan said: RT: @inliniac: First Suricata release tomorrow! <a href="http://is.gd/5GZ6Y" rel="nofollow">http://is.gd/5GZ6Y</a> &#8211; looking forward [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Libnet 1.1 IPv6 fixes and additions by anon</title>
		<link>http://www.inliniac.net/blog/2007/10/16/libnet-11-ipv6-fixes-and-additions.html/comment-page-1#comment-17314</link>
		<dc:creator>anon</dc:creator>
		<pubDate>Tue, 15 Dec 2009 21:56:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/2007/10/16/libnet-11-ipv6-fixes-and-additions.html#comment-17314</guid>
		<description>You could send your patch to this guy: http://github.com/sam-github/libnet/tree/libnet-1.1.4 ; he seems to have taken ownership of libnet .</description>
		<content:encoded><![CDATA[<p>You could send your patch to this guy: <a href="http://github.com/sam-github/libnet/tree/libnet-1.1.4" rel="nofollow">http://github.com/sam-github/libnet/tree/libnet-1.1.4</a> ; he seems to have taken ownership of libnet .</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Snort_inline updated to 2.8.3 in SVN by Yimbo</title>
		<link>http://www.inliniac.net/blog/2008/09/16/snort_inline-updated-to-283-in-svn.html/comment-page-1#comment-16541</link>
		<dc:creator>Yimbo</dc:creator>
		<pubDate>Fri, 13 Nov 2009 06:33:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=154#comment-16541</guid>
		<description>I got current snort_inline version 2.8.4.1. 
When I configured the source, I got an error &quot; Libpcre library version &gt;= 6.0 not found. So I installed pcre-8.0, but the error did not cleared.
I configured the source &#039;--with-libpcre-includes=/usr/include/ --with-libpcre-libraries=/usr/lib/&#039; option, but I got the same error. 
How can I fix this problem? 

Thanks in advance.</description>
		<content:encoded><![CDATA[<p>I got current snort_inline version 2.8.4.1.<br />
When I configured the source, I got an error &#8221; Libpcre library version &gt;= 6.0 not found. So I installed pcre-8.0, but the error did not cleared.<br />
I configured the source &#8216;&#8211;with-libpcre-includes=/usr/include/ &#8211;with-libpcre-libraries=/usr/lib/&#8217; option, but I got the same error.<br />
How can I fix this problem? </p>
<p>Thanks in advance.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
