Barnyard2-1.6 beta 2 … automake, autoconf, autoAARGH!

June 29th, 2009 by firnsy

This small release fixes the automake horror that was preventing the host from being correctly identified during the configuration. Suffice to say that as good as the automake tools can be they also have the ability to become your worst nightmare and forever chasing your tail.

I caught my tail and have update the link on  the download page to the new beta.

Enjoy!

Barnyard2-1.6 beta 1 … Grab the bug spray!

June 17th, 2009 by firnsy

This release is the first round of 1.6 and has a number of bug fixes that address the following issues:

  1. Waldo files not being created or updated as expected.
  2. MySQL reconnect issues and obscure looping.
  3. The reference system file can now be explicitly set at the command line via “-R”.

There is still a known issue with compilation on FreeBSD (and I’m guessing *BSD/Mac machines) which has been tracked down to the autoconf files, configure.in and config.guess. That being said if you are an autoconf wizard and know why the barnyard2 configure does not call config.guess to ascertain the correct host then we want to hear from you. In the meantime you can explicitly set the host using:

# ./configure --host=`./config.guess`

Head over to the download page and test the new beta out. Your feedback is most welcome!

NSMnow 1.4.1 - New links.

May 30th, 2009 by firnsy

This release of NSMnow is primarily an update for the links to barnyard2 and Snort (due to it’s new site structure).

A bug with the automatic process management of  multiple sensors has been addressed and patched accordingly, thanks to Jon. B. Bayer for finding that one for us.

Some of the team will be looking at the adminstration a little closer over the next few months so if there are any pressing administrative features you believe should be included then be sure to let the dev team know about them.

Until then, grab the latest copy from the NSMnow download page and give it a spin.

Barnyard2-1.5 … Marking the end of May.

May 30th, 2009 by firnsy

With the end of the month nearing and all submitted bugs quashed we though it time to push out a final release of 1.5.

A number of beta’s were released throughout this cycle and we are very grateful to those who have taken the time to test the patches to make this push possible. Given the improved quality of response to this format we will continue to follow this for future releases.

A quick summary of the inclusions for the 1.5 series is:

  1. all, but one (alert_sf_socket), Snort plugins supported
  2. Snort 2.8.4.1 alignment
  3. reference system configuration
  4. updated PID file handling
  5. improved spo_database handling of mysql server connection drop outs.

Grab the latest from the barnyard2 download page.

Enjoy!

Barnyard2-1.5 beta 3 … Reconnecting!

May 8th, 2009 by firnsy

This third beta release introduces a few subtle improvements along with the usual bug fixes that have been reported to date.

The following improvements have made their way in:

  1. a more robust solution with MySQL reconnection issues.
  2. updated map structures to improve future scalability.
  3. experimental RPM spec support (courtesy Jason Haar)

The kinks are slowly being worked out and should a reasonably stable release should be out soon!

Barnyard2-1.5 beta 2 … Plugging the gaps.

May 5th, 2009 by firnsy

We’ve just released a second beta of 1.5 to fill a number of gaps (read omissions) that have appeared since the first release.

Some of these were plain silly such as missing header files, missing initialisation functions and missing configure parameters. A few though were some interesting corner situations that I’ve never come across with my unified2 files.

The feedback being provided and the bug reports are certainly ironing out the wrinkles for which we are very grateful.

Grab the beta while it’s HOT!

Barnyard2-1.5 beta … Not just a cosmetic makeover!

May 2nd, 2009 by firnsy

It is reassuring to hear (or should that be read) a lot of positive feedback and encouragement to continue our development.

So we have taken the comments on board and ran with it for this next beta release. We’ve decided to release this and consider it a beta given the large amount of code that hasn’t been fully soak tested. What is all this not fully tested code? Well as of this release we have integrated all of Snort’s plugins except for one (alert_sf_socket).

This was made available due to the large amount of refactoring in the spooler to centralise unified2 record processing and removing the large amount of duplication that was required in the output plugins.

All output plugins are aligned with those as of snort 2.8.4.1, with the new output plugins integrated in this release being:

  1. spo_alert_arrubaaction
  2. spo_alert_full
  3. spo_alert_prelude
  4. spo_alert_unixsock
  5. spo_csv
  6. spo_log_ascii
  7. spo_log_null
  8. spo_log_tcpdump

This should now allow a lot more users to begin trialling barnyard2 with unified2 logs and get this release stabilised.

NSMnow 1.4 - Sguil User Administration

April 18th, 2009 by firnsy

There was too many updates and features added to this to warrant a stability update so we bumped the minor by one. We’re sure you want mind.

After a lot of encouragement, this release adds two new functions to the Adminstration scripts including:

  1. nsm_server_user-add
  2. nsm_server_user-del

These functions are designed to simplify user access administration to the NSM server components.

In addition we have udpated the links to the new Snort 2.8.4 release as well as the barnyard2-1.4 release. In the event that snort 2.8.3.x branch is used on Ubuntu systems the scripts will now automagically patch the source as appropriate.

Thanks for all the feedback and keep it coming! :)

Barnyard2-1.4 … Core updates

April 18th, 2009 by firnsy

With Snort 2.8.4 recently released, a number of core changes within the barnyard2 code have occured. These changes are those that primarily rely on snort’s detection routines and unified2 file structure.

Two significant issues have been identified and subsequently fixed with help from Jason Wallace. The two issues resolved were:

  1. Blank waldo file permissions on creation (doh!)
  2. Incorrect classification of snort dynamic rules (the compiled “so” rules)

Grab the latest release and let us know how it goes!

The YubiKing Award

March 10th, 2009 by willo

The YubiKing Award is to encourage innovation, creativity and entrepreneurship within the YubiKey developer’s community.   So, if you’ve checked out our YubiPAM module and you liked what you saw. Then please login to the Yubico Wiki with your awesome little Yubikey and cast your vote for our YubiPAM module and any other projects that you deem worthy.  But hurry as voting closes Friday 13th March.