<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Inliniac</title>
	<atom:link href="http://www.inliniac.net/blog/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://www.inliniac.net/blog</link>
	<description>Everything inline.</description>
	<lastBuildDate>Mon, 30 Jan 2012 16:49:09 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Comment on File extraction in Suricata by Petrus</title>
		<link>http://www.inliniac.net/blog/2011/11/29/file-extraction-in-suricata.html/comment-page-1#comment-29745</link>
		<dc:creator>Petrus</dc:creator>
		<pubDate>Mon, 30 Jan 2012 16:49:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=467#comment-29745</guid>
		<description>Thank you. Work in suricata 1.2.1 perfect.</description>
		<content:encoded><![CDATA[<p>Thank you. Work in suricata 1.2.1 perfect.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Differences between Snort and Snort_inline by Victor Julien</title>
		<link>http://www.inliniac.net/blog/2007/05/14/differences-between-snort-and-snort_inline.html/comment-page-1#comment-29736</link>
		<dc:creator>Victor Julien</dc:creator>
		<pubDate>Tue, 17 Jan 2012 10:13:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=74#comment-29736</guid>
		<description>You could try the &quot;strip&quot; command. See &quot;man strip&quot;. I have no experience with it.</description>
		<content:encoded><![CDATA[<p>You could try the &#8220;strip&#8221; command. See &#8220;man strip&#8221;. I have no experience with it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Differences between Snort and Snort_inline by Fred</title>
		<link>http://www.inliniac.net/blog/2007/05/14/differences-between-snort-and-snort_inline.html/comment-page-1#comment-29735</link>
		<dc:creator>Fred</dc:creator>
		<pubDate>Tue, 17 Jan 2012 10:02:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=74#comment-29735</guid>
		<description>I have installed Suricata，I want to downsize Suricata，so I strip Suricata，size is 1.4M，are there any way to make it smaller，thanks a lot.</description>
		<content:encoded><![CDATA[<p>I have installed Suricata，I want to downsize Suricata，so I strip Suricata，size is 1.4M，are there any way to make it smaller，thanks a lot.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Differences between Snort and Snort_inline by Victor Julien</title>
		<link>http://www.inliniac.net/blog/2007/05/14/differences-between-snort-and-snort_inline.html/comment-page-1#comment-29733</link>
		<dc:creator>Victor Julien</dc:creator>
		<pubDate>Tue, 17 Jan 2012 08:58:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=74#comment-29733</guid>
		<description>I&#039;m not involved in Snort or Snort_inline anymore, so please direct your questions on those to http://www.snort.org/

Alternatively, you can have a look at my new IDS/IPS project called Suricata. http://www.openinfosecfoundation.org/</description>
		<content:encoded><![CDATA[<p>I&#8217;m not involved in Snort or Snort_inline anymore, so please direct your questions on those to <a href="http://www.snort.org/" rel="nofollow">http://www.snort.org/</a></p>
<p>Alternatively, you can have a look at my new IDS/IPS project called Suricata. <a href="http://www.openinfosecfoundation.org/" rel="nofollow">http://www.openinfosecfoundation.org/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Differences between Snort and Snort_inline by Fred</title>
		<link>http://www.inliniac.net/blog/2007/05/14/differences-between-snort-and-snort_inline.html/comment-page-1#comment-29732</link>
		<dc:creator>Fred</dc:creator>
		<pubDate>Tue, 17 Jan 2012 08:44:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=74#comment-29732</guid>
		<description>Hello,I am new to snort,if I want to accomplish IPS(intrusion prevention system),could i just install snort_inline??Thank you!!</description>
		<content:encoded><![CDATA[<p>Hello,I am new to snort,if I want to accomplish IPS(intrusion prevention system),could i just install snort_inline??Thank you!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on File extraction in Suricata by Victor Julien</title>
		<link>http://www.inliniac.net/blog/2011/11/29/file-extraction-in-suricata.html/comment-page-1#comment-29726</link>
		<dc:creator>Victor Julien</dc:creator>
		<pubDate>Wed, 11 Jan 2012 07:48:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=467#comment-29726</guid>
		<description>2 things to check:

First and foremost, the files.rules file contains example rules. They are all disabled by default. Remove the # before them to enable the rules.

Second, the file extraction is heavily influenced by 3 other settings:
stream.reassembly.depth (defaults to 1mb, set larger if you want to extract larger files)

In the libhtp section, the request-body-limit and response-body-limit settings. Both default to just a few kb, set to 0 or a high value.</description>
		<content:encoded><![CDATA[<p>2 things to check:</p>
<p>First and foremost, the files.rules file contains example rules. They are all disabled by default. Remove the # before them to enable the rules.</p>
<p>Second, the file extraction is heavily influenced by 3 other settings:<br />
stream.reassembly.depth (defaults to 1mb, set larger if you want to extract larger files)</p>
<p>In the libhtp section, the request-body-limit and response-body-limit settings. Both default to just a few kb, set to 0 or a high value.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on File extraction in Suricata by Petrus</title>
		<link>http://www.inliniac.net/blog/2011/11/29/file-extraction-in-suricata.html/comment-page-1#comment-29725</link>
		<dc:creator>Petrus</dc:creator>
		<pubDate>Wed, 11 Jan 2012 07:41:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=467#comment-29725</guid>
		<description>Thank you. I left the settings in &quot;File&quot; section in this way:

– file:
enabled: yes
log-dir: files
force-magic: no

I added the rules: 

 - files.rules

when I run suricata, I do not give any error. Everything is fine, but do not extract any files in /var/log/suricata /files

Best Regards,</description>
		<content:encoded><![CDATA[<p>Thank you. I left the settings in &#8220;File&#8221; section in this way:</p>
<p>– file:<br />
enabled: yes<br />
log-dir: files<br />
force-magic: no</p>
<p>I added the rules: </p>
<p> &#8211; files.rules</p>
<p>when I run suricata, I do not give any error. Everything is fine, but do not extract any files in /var/log/suricata /files</p>
<p>Best Regards,</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on File extraction in Suricata by Victor Julien</title>
		<link>http://www.inliniac.net/blog/2011/11/29/file-extraction-in-suricata.html/comment-page-1#comment-29722</link>
		<dc:creator>Victor Julien</dc:creator>
		<pubDate>Tue, 10 Jan 2012 17:51:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=467#comment-29722</guid>
		<description>The &quot;filename&quot; in the &quot;file&quot; section does nothing.

log-dir is fine, although the files will go into /var/log/suricata directly. If you enter just &quot;files&quot; there, it goes into /var/log/suricata/files/</description>
		<content:encoded><![CDATA[<p>The &#8220;filename&#8221; in the &#8220;file&#8221; section does nothing.</p>
<p>log-dir is fine, although the files will go into /var/log/suricata directly. If you enter just &#8220;files&#8221; there, it goes into /var/log/suricata/files/</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on File extraction in Suricata by Petrus</title>
		<link>http://www.inliniac.net/blog/2011/11/29/file-extraction-in-suricata.html/comment-page-1#comment-29721</link>
		<dc:creator>Petrus</dc:creator>
		<pubDate>Tue, 10 Jan 2012 16:33:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=467#comment-29721</guid>
		<description>Hello,

¿?

  outputs:
  - console:
      enabled: yes
  - file:
      enabled: yes
      filename: /var/log/suricata/suricata.log
      log-dir: /var/log/suricata
      force-magic: no

Best Regards,</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>¿?</p>
<p>  outputs:<br />
  &#8211; console:<br />
      enabled: yes<br />
  &#8211; file:<br />
      enabled: yes<br />
      filename: /var/log/suricata/suricata.log<br />
      log-dir: /var/log/suricata<br />
      force-magic: no</p>
<p>Best Regards,</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on File extraction in Suricata by Victor Julien</title>
		<link>http://www.inliniac.net/blog/2011/11/29/file-extraction-in-suricata.html/comment-page-1#comment-29720</link>
		<dc:creator>Victor Julien</dc:creator>
		<pubDate>Tue, 10 Jan 2012 13:50:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=467#comment-29720</guid>
		<description>Indeed. Check the suricata.yaml that is part of the archive or your git checkout for more details.</description>
		<content:encoded><![CDATA[<p>Indeed. Check the suricata.yaml that is part of the archive or your git checkout for more details.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

