<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Smtp on Inliniac</title>
    <link>https://inliniac.net/blog/tag/smtp/</link>
    <description>Recent content in Smtp on Inliniac</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Tue, 11 Nov 2014 10:47:42 +0000</lastBuildDate>
    <atom:link href="https://inliniac.net/blog/tag/smtp/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>SMTP file extraction in Suricata</title>
      <link>https://inliniac.net/blog/2014/11/11/smtp-file-extraction-in-suricata/</link>
      <pubDate>Tue, 11 Nov 2014 10:47:42 +0000</pubDate>
      <guid>https://inliniac.net/blog/2014/11/11/smtp-file-extraction-in-suricata/</guid>
      <description>&lt;p&gt;In &lt;a href=&#34;http://suricata-ids.org/2014/11/06/suricata-2-1beta2-available/&#34;&gt;2.1beta2&lt;/a&gt; the long awaited SMTP file extraction support for Suricata finally appeared. It has been a long development cycle. Originally started by BAE Systems, it was picked up by Tom Decanio of FireEye Forensics Group (formerly nPulse Technologies) followed by a last round of changes from my side. But it&amp;rsquo;s here now.&lt;/p&gt;&#xA;&lt;p&gt;It contains:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;a MIME decoder&lt;/li&gt;&#xA;&lt;li&gt;updates to the SMTP parser to use the MIME decoder for extracting files&lt;/li&gt;&#xA;&lt;li&gt;SMTP JSON log, integrated with EVE&lt;/li&gt;&#xA;&lt;li&gt;SMTP message URL extraction and logging&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;As it uses the Suricata file handling API, it shares almost everything with the existing file handling for HTTP. The rule keyword work and the various logs work automatically with SMTP as well.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Suricata 1.1.1 released</title>
      <link>https://inliniac.net/blog/2011/12/07/suricata-1-1-1-released/</link>
      <pubDate>Wed, 07 Dec 2011 18:34:50 +0000</pubDate>
      <guid>https://inliniac.net/blog/2011/12/07/suricata-1-1-1-released/</guid>
      <description>&lt;p&gt;A maintenance update for the Suricata 1.1 series was just released. It fixed an important issue. In some cases Suricata could crash on SMTP traffic.&lt;/p&gt;&#xA;&lt;p&gt;The full announcement for the 1.1.1 release is &lt;a href=&#34;http://www.openinfosecfoundation.org/index.php/component/content/article/140-suricata-111-available&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Naturally, the issue has also been fixed in the 1.2 development branch.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
