Archive for April, 2009

NSMnow 1.4 – Sguil User Administration

Saturday, April 18th, 2009

There was too many updates and features added to this to warrant a stability update so we bumped the minor by one. We’re sure you want mind.

After a lot of encouragement, this release adds two new functions to the Adminstration scripts including:

  1. nsm_server_user-add
  2. nsm_server_user-del

These functions are designed to simplify user access administration to the NSM server components.

In addition we have udpated the links to the new Snort 2.8.4 release as well as the barnyard2-1.4 release. In the event that snort 2.8.3.x branch is used on Ubuntu systems the scripts will now automagically patch the source as appropriate.

Thanks for all the feedback and keep it coming! :)

Barnyard2-1.4 … Core updates

Saturday, April 18th, 2009

With Snort 2.8.4 recently released, a number of core changes within the barnyard2 code have occured. These changes are those that primarily rely on snort’s detection routines and unified2 file structure.

Two significant issues have been identified and subsequently fixed with help from Jason Wallace. The two issues resolved were:

  1. Blank waldo file permissions on creation (doh!)
  2. Incorrect classification of snort dynamic rules (the compiled “so” rules)

Grab the latest release and let us know how it goes!