<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Inliniac &#187; Matt Jonkman</title>
	<atom:link href="http://www.inliniac.net/blog/tag/matt-jonkman/feed" rel="self" type="application/rss+xml" />
	<link>http://www.inliniac.net/blog</link>
	<description>Everything inline.</description>
	<lastBuildDate>Thu, 29 Jul 2010 19:38:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>DeepSec</title>
		<link>http://www.inliniac.net/blog/2008/11/30/deepsec.html</link>
		<comments>http://www.inliniac.net/blog/2008/11/30/deepsec.html#comments</comments>
		<pubDate>Sun, 30 Nov 2008 09:57:42 +0000</pubDate>
		<dc:creator>Victor Julien</dc:creator>
				<category><![CDATA[oisf]]></category>
		<category><![CDATA[deepsec]]></category>
		<category><![CDATA[Matt Jonkman]]></category>

		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=180</guid>
		<description><![CDATA[Last month I attended the DeepSec conference in Vienna. I enjoyed it a great deal. It was good to be back in Vienna. Had a few good meetings with my friend Adi with who I work on the Vuurmuur project. I assisted Matt Jonkman in his Snort Signature writing class. We had a nice group [...]]]></description>
			<content:encoded><![CDATA[<p>Last month I attended the DeepSec conference in Vienna. I enjoyed it a great deal. It was good to be back in Vienna. Had a few good meetings with my friend Adi with who I work on the Vuurmuur project.</p>
<p>I assisted Matt Jonkman in his Snort Signature writing class. We had a nice group of people and using the Emerging Threats SandNet we could deal with pretty interesting samples to write signatures for. Even though my expertise is more on the code level of Snort I felt I could still contribute something to the sessions.</p>
<p>On the last day Matt and I did the first Open Infosec Foundation brainstorm session. I think it was very useful and the crowd was very responsive. After this encouraging experience we are planning to attend more conferences to do similar sessions. Suggestions about which conferences would be interesting (and why) are very welcome!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.inliniac.net/blog/2008/11/30/deepsec.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>First SidReporter statistics available</title>
		<link>http://www.inliniac.net/blog/2008/10/30/first-sidreporter-statistics-available.html</link>
		<comments>http://www.inliniac.net/blog/2008/10/30/first-sidreporter-statistics-available.html#comments</comments>
		<pubDate>Thu, 30 Oct 2008 15:11:37 +0000</pubDate>
		<dc:creator>Victor Julien</dc:creator>
				<category><![CDATA[SidReporter]]></category>
		<category><![CDATA[Matt Jonkman]]></category>

		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=175</guid>
		<description><![CDATA[Matt Jonkman just announced that the first stats of SidReporter are available here. Matt writes: These will become more interesting the more sites we have reporting, so please consider running  the client. It&#8217;s painless, anonymous, and will contribute to us greatly improving the signature base we all use. It will be interesting to see what [...]]]></description>
			<content:encoded><![CDATA[<p>Matt Jonkman just <a href="http://www.emergingthreats.net/index.php/component/content/article/1-latest/127-initial-sidreporter-statistics-online.html">announced</a> that the first stats of SidReporter are available <a href="http://www.emergingthreats.net/index.php/sidreporter-statistics.html">here</a>. Matt writes:</p>
<blockquote><p>These will become more interesting the more sites we have reporting, so please consider running  the client. It&#8217;s painless, anonymous, and will contribute to us greatly improving the signature base we all use.</p></blockquote>
<p>It will be interesting to see what data this can bring us. Congrats Matt!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.inliniac.net/blog/2008/10/30/first-sidreporter-statistics-available.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>First OISF brainstorming session on Deepsec</title>
		<link>http://www.inliniac.net/blog/2008/10/23/first-oisf-brainstorming-session-on-deepsec.html</link>
		<comments>http://www.inliniac.net/blog/2008/10/23/first-oisf-brainstorming-session-on-deepsec.html#comments</comments>
		<pubDate>Thu, 23 Oct 2008 09:02:21 +0000</pubDate>
		<dc:creator>Victor Julien</dc:creator>
				<category><![CDATA[oisf]]></category>
		<category><![CDATA[deepsec]]></category>
		<category><![CDATA[Matt Jonkman]]></category>

		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=172</guid>
		<description><![CDATA[Next November I will be attending Deepsec in Vienna. Matt Jonkman is giving a workshop there and I will be helping/assisting him with it, it&#8217;s called &#8216;Protocol Analysis for Writing Snort Signatures&#8217;. If you&#8217;re interested, sign up for it! While we are there we will also host the first brainstorming session for OISF. The idea [...]]]></description>
			<content:encoded><![CDATA[<p>Next November I will be attending <a href="http://deepsec.net">Deepsec</a> in Vienna. Matt Jonkman is giving a workshop there and I will be helping/assisting him with it, it&#8217;s called &#8216;Protocol Analysis for Writing Snort Signatures&#8217;. If you&#8217;re interested, sign up for it! While we are there we will also host the first brainstorming session for <a href="http://www.openinfosecfoundation.org/">OISF</a>. The idea is to get together with everyone thats interested and talk about how our next generation IDS/IPS should look like. But it&#8217;s not just about the technology, we also seek input about how to organize the project, about licensing, etc. So if you&#8217;re at Deepsec and got some time to spare, be sure to join us in the brainstorming session!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.inliniac.net/blog/2008/10/23/first-oisf-brainstorming-session-on-deepsec.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SidReporter beta2 released</title>
		<link>http://www.inliniac.net/blog/2008/08/21/sidreporter-beta2-released.html</link>
		<comments>http://www.inliniac.net/blog/2008/08/21/sidreporter-beta2-released.html#comments</comments>
		<pubDate>Thu, 21 Aug 2008 15:08:42 +0000</pubDate>
		<dc:creator>Victor Julien</dc:creator>
				<category><![CDATA[Sguil]]></category>
		<category><![CDATA[SidReporter]]></category>
		<category><![CDATA[Emerging Threats]]></category>
		<category><![CDATA[Matt Jonkman]]></category>

		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=147</guid>
		<description><![CDATA[A little over a week ago the second beta of the SidReporter from Emerging Threats was released (see http://www.emergingthreats.net/content/view/95/1/). I&#8217;ve been working with Matt Jonkman to setup this new project at Emerging Threats, mostly in writing the reporter scripts. I think it&#8217;s an exciting new project that could provide the community with great information. As [...]]]></description>
			<content:encoded><![CDATA[<p>A little over a week ago the second beta of the SidReporter from <a href="http://www.emergingthreats.net/">Emerging Threats</a> was released (see <a href="http://www.emergingthreats.net/content/view/95/1/">http://www.emergingthreats.net/content/view/95/1/</a>). I&#8217;ve been working with Matt Jonkman to setup this new project at Emerging Threats, mostly in writing the reporter scripts. I think it&#8217;s an exciting new project that could provide the community with great information. As Matt <a href="http://www.emergingthreats.net/content/view/93/1/">wrote</a> on the initial announcement:</p>
<blockquote><p>&#8220;As mentioned a few weeks ago, we&#8217;ve been working to bring out tool to anonymously report IDS/IPS hits. Similar to DShield&#8217;s firewall log reporting, we believe we can make some incredible data inferences with this information, as well as help improve the quality of our signatures while giving us all feedback to tune our rulesets.</p>
<p>But that&#8217;s just the start. As with DShield&#8217;s data, I think we&#8217;ll run into benefits to the community that we can&#8217;t even imagine until we start to look at the data.&#8221;</p></blockquote>
<p>The next step for the reporter is adding support for getting the events from Sguil. Expect to see that soon!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.inliniac.net/blog/2008/08/21/sidreporter-beta2-released.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Snortsam patch for Snort 2.8.0.1</title>
		<link>http://www.inliniac.net/blog/2008/01/08/new-snortsam-patch-for-snort-2801.html</link>
		<comments>http://www.inliniac.net/blog/2008/01/08/new-snortsam-patch-for-snort-2801.html#comments</comments>
		<pubDate>Tue, 08 Jan 2008 12:30:53 +0000</pubDate>
		<dc:creator>Victor Julien</dc:creator>
				<category><![CDATA[IPv6]]></category>
		<category><![CDATA[Snort]]></category>
		<category><![CDATA[Snortsam]]></category>
		<category><![CDATA[Emerging Threats]]></category>
		<category><![CDATA[Matt Jonkman]]></category>

		<guid isPermaLink="false">http://www.inliniac.net/blog/2008/01/08/new-snortsam-patch-for-snort-2801.html</guid>
		<description><![CDATA[Matt Jonkman of Emerging Threats asked me to have a look at the existing Snortsam 2.8.0.1 patch as people were continuing to report problems with it. I updated it to compile without compiler warnings, build cleanly with debugging enabled, build cleanly with Snort&#8217;s IPv6 support enabled and added a check so it won&#8217;t act on [...]]]></description>
			<content:encoded><![CDATA[<p>Matt Jonkman of <a href="http://www.emergingthreats.net/" target="_blank">Emerging Threats</a> asked me to have a look at the existing Snortsam 2.8.0.1 patch as people were continuing to report problems with it. I updated it to compile without compiler warnings, build cleanly with debugging enabled, build cleanly with Snort&#8217;s IPv6 support enabled and added a check so it won&#8217;t act on alerts in IPv6 packets since the Snortsam framework does not support IPv6. Finally I removed the patch script so it&#8217;s provided as a &#8216;normal&#8217; diff. Here is the patch: <a href="http://www.inliniac.net/files/snortsam-2.8.0.1.diff">http://www.inliniac.net/files/snortsam-2.8.0.1.diff</a></p>
<p>Here are the instructions for getting your Snort 2.8.0.1 source patched:</p>
<p>Make sure you have a clean Snort 2.8.0.1 tree, then patch it:</p>
<p>cd snort-2.8.0.1<br />
patch -p1 &lt; ../snortsam-2.8.0.1.diff</p>
<p>Next, run &#8216;autojunk.sh&#8217; to update the build system (you need to have libtoolize, aclocal, autoheader, autoconf and automake installed). After this, configure and build Snort normally:</p>
<p>./configure &lt;your configure options&gt;<br />
make<br />
make install</p>
<p>Thats it.</p>
<p>Thanks to Matt Jonkman of <a href="http://www.emergingthreats.net/" target="_blank">Emerging Threats</a> for paying me to do this and CunningPike for doing the first iterations of the patch!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.inliniac.net/blog/2008/01/08/new-snortsam-patch-for-snort-2801.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Matt Jonkman leaves Bleeding Edge</title>
		<link>http://www.inliniac.net/blog/2007/11/17/matt-jonkman-leaves-bleeding-edge.html</link>
		<comments>http://www.inliniac.net/blog/2007/11/17/matt-jonkman-leaves-bleeding-edge.html#comments</comments>
		<pubDate>Sat, 17 Nov 2007 12:05:56 +0000</pubDate>
		<dc:creator>Victor Julien</dc:creator>
				<category><![CDATA[Snort]]></category>
		<category><![CDATA[Snort_inline]]></category>
		<category><![CDATA[Bleeding Edge]]></category>
		<category><![CDATA[Matt Jonkman]]></category>
		<category><![CDATA[Sensory Networks]]></category>

		<guid isPermaLink="false">http://www.inliniac.net/blog/2007/11/17/matt-jonkman-leaves-bleeding-edge.html</guid>
		<description><![CDATA[Matt Jonkman is stepping out of the Bleeding Edge project. He announced this here. Apparently Sensory Networks, one of the sponsors of the project, now owns it. It will be interesting to see if they will continue it, and if so, how. Honestly, I&#8217;m a bit skeptical, since to my knowledge not many Sensory people [...]]]></description>
			<content:encoded><![CDATA[<p>Matt Jonkman is stepping out of the <a href="http://www.bleedingthreats.net/" target="_blank">Bleeding Edge project</a>. He announced this <a href="http://www.bleedingthreats.net/index.php/2007/11/17/im-leaving-bleeding-threats/" target="_blank">here</a>. Apparently <a href="http://sensorynetworks.com/" target="_blank">Sensory Networks</a>, one of the sponsors of the project, now owns it. It will be interesting to see if they will continue it, and if so, how. Honestly, I&#8217;m a bit skeptical, since to my knowledge not many Sensory people are directly involved at this moment. Still I believe Sensory consists of good people. I did a contract job for them about a year ago, and enjoyed working with them.</p>
<p>I think I speak for many if I say &#8220;Thanks&#8221; for all the hard work Jonkman has done for Bleeding, and I really look forward to new projects he will start or get involved in! Thanks Matt!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.inliniac.net/blog/2007/11/17/matt-jonkman-leaves-bleeding-edge.html/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
