<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7554630712114756330</id><updated>2012-01-28T01:53:10.356-05:00</updated><category term='snortsp'/><category term='security onion wiki'/><category term='sguil'/><category term='Youtube'/><category term='funny'/><category term='logs'/><category term='log management'/><category term='packet size limited during capture'/><category term='hex'/><category term='517'/><category term='501'/><category term='penetration testing'/><category term='nova hackers'/><category term='ollydbg'/><category term='Help kill Adobe Flash'/><category term='squert'/><category term='560'/><category term='vulnerabilities'/><category term='presentation'/><category term='binary'/><category term='rhel'/><category term='tail'/><category term='httpry'/><category term='isc2'/><category term='401'/><category term='grep'/><category term='linux security'/><category term='email'/><category term='vim'/><category term='remastersys'/><category term='intrusion detection'/><category term='tso'/><category term='snort'/><category term='while'/><category term='reversing'/><category term='553'/><category term='networkminer'/><category term='centos'/><category term='camera'/><category term='windows security'/><category term='tshark'/><category term='barnyard2'/><category term='security'/><category term='span'/><category term='barnyard'/><category term='pcapcat'/><category term='/etc/network/interfaces'/><category term='metasploit'/><category term='wireshark'/><category term='security onion'/><category term='bash'/><category term='etherape'/><category term='forensics'/><category term='computer security training'/><category term='tcp/ip'/><category term='timezone'/><category term='vortex'/><category term='nsm'/><category term='snort3'/><category term='whois'/><category term='sancp'/><category term='google code'/><category term='ids'/><category term='armitage'/><category term='base'/><category term='tap'/><category term='argus'/><category term='ssl'/><category term='security onion mailing list'/><category term='xplico'/><category term='network'/><category term='ubuntu'/><category term='bro'/><category term='sha1'/><category term='emerging threats'/><category term='mentor'/><category term='nftracker'/><category term='mail'/><category term='security onion issue tracker'/><category term='csaw'/><category term='gso'/><category term='tcpdump'/><category term='cryptography'/><category term='reconstructor'/><category term='GSEC'/><category term='grub'/><category term='db_autopwn'/><category term='javascript'/><category term='rsa'/><category term='wan'/><category term='fedora'/><category term='504'/><category term='dumbpig'/><category term='GIAC Security Expert'/><category term='decryption'/><category term='fwbuilder'/><category term='security essentials'/><category term='patching'/><category term='windows'/><category term='gcia'/><category term='snorby'/><category term='livecd'/><category term='ossec'/><category term='503'/><category term='HTML5'/><category term='afpacket'/><category term='linux'/><category term='apache'/><category term='securixlive'/><category term='pulledpork'/><category term='purge'/><category term='gmt'/><category term='gse'/><category term='Adobe Flash'/><category term='daemonlogger'/><category term='ethtool'/><category term='Defense in Depth'/><category term='pads'/><category term='nmap'/><category term='cissp'/><category term='nsmnow'/><category term='setup script'/><category term='ssh'/><category term='gpen'/><category term='issa'/><category term='daq'/><category term='sans'/><category term='google groups'/><category term='utc'/><category term='unified2'/><category term='suricata'/><category term='ethical hacking'/><category term='xubuntu'/><category term='https'/><category term='shmoocon'/><category term='full packet capture'/><category term='secunia psi'/><category term='command line'/><category term='md5'/><category term='gro'/><category term='mod_security'/><category term='8570'/><category term='441'/><title type='text'>Security Onion</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default?start-index=101&amp;max-results=100'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>132</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-3834774036404340115</id><published>2012-01-28T01:52:00.002-05:00</published><updated>2012-01-28T01:53:10.361-05:00</updated><title type='text'>Attention Shmoocon attendees!</title><content type='html'>&lt;span style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;If you're a fan of Security Onion, please vote for it for 2011 Toolsmith Tool of the Year!&lt;/span&gt;&lt;br /&gt;&lt;a href="http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html" style="background-color: white; color: #6699cc; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px; text-decoration: none;"&gt;http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-3834774036404340115?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/3834774036404340115/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=3834774036404340115' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/3834774036404340115'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/3834774036404340115'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2012/01/attention-shmoocon-attendees.html' title='Attention Shmoocon attendees!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-7382532539740620666</id><published>2012-01-26T16:30:00.000-05:00</published><updated>2012-01-26T16:30:52.371-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='bro'/><category scheme='http://www.blogger.com/atom/ns#' term='sguil'/><title type='text'>Security Onion 20120125 now available!</title><content type='html'>&lt;br /&gt;Security Onion 20120125 is now available! &amp;nbsp;This resolves the following issues:&lt;br /&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=203"&gt;Issue 203:&amp;nbsp;New users should have a more sensible default for Sguil client fonts&lt;/a&gt;&lt;br /&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=204"&gt;Issue 204:&amp;nbsp;/usr/local/sbin/nsm_server_del: line 192: [: eq: binary operator expected&lt;/a&gt;&lt;br /&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=206"&gt;Issue 206:&amp;nbsp;/usr/local/sbin/nsm_sensor_clean should purge old Bro logs&lt;/a&gt;&lt;br /&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=207"&gt;Issue 207:&amp;nbsp;Re-install /etc/skel/.bashrc to enable bash coloring&lt;/a&gt;&lt;br /&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=208"&gt;Issue 208:&amp;nbsp;Need a new ISO for NoVA Hackers presentation&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;New Users&lt;/b&gt;&lt;br /&gt;New users can download and install the 20120125 ISO image using the instructions &lt;a href="http://code.google.com/p/security-onion/wiki/Installation"&gt;here&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;In-place Upgrade&lt;/b&gt;&lt;br /&gt;Existing Security Onion users can perform an in-place upgrade using the following command (if you're behind a proxy, remember to set your proxy variables as described in the &lt;a href="http://code.google.com/p/security-onion/wiki/FAQ"&gt;FAQ&lt;/a&gt;):&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/blockquote&gt;&lt;br /&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-SvfCLVmZjsY/TyHEr29nHvI/AAAAAAAAAdo/YqcTFwzeoxM/s1600/Screen+Shot+2012-01-26+at+4.24.38+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="226" src="http://2.bp.blogspot.com/-SvfCLVmZjsY/TyHEr29nHvI/AAAAAAAAAdo/YqcTFwzeoxM/s640/Screen+Shot+2012-01-26+at+4.24.38+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Upgrade Process&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;b&gt;Feedback&lt;/b&gt;&lt;br /&gt;If you have any questions, please join our mailing list and ask away!&lt;br /&gt;&lt;a href="http://groups.google.com/group/security-onion"&gt;http://groups.google.com/group/security-onion&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Toolsmith Tool of the Year&lt;/b&gt;&lt;br /&gt;If you're a fan of Security Onion, please vote for it for 2011 Toolsmith Tool of the Year!&lt;br /&gt;&lt;a href="http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html"&gt;http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-7382532539740620666?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/7382532539740620666/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=7382532539740620666' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/7382532539740620666'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/7382532539740620666'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2012/01/security-onion-20120125-now-available.html' title='Security Onion 20120125 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-SvfCLVmZjsY/TyHEr29nHvI/AAAAAAAAAdo/YqcTFwzeoxM/s72-c/Screen+Shot+2012-01-26+at+4.24.38+PM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-2488088376713484126</id><published>2012-01-26T06:10:00.002-05:00</published><updated>2012-01-26T06:10:21.244-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='shmoocon'/><category scheme='http://www.blogger.com/atom/ns#' term='nova hackers'/><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><title type='text'>Upcoming Security Onion Presentations</title><content type='html'>&lt;br /&gt;I'll be giving a Shmoocon Firetalk on Saturday 1/28 at 7:40 PM:&lt;br /&gt;&lt;a href="http://www.novainfosecportal.com/2012/01/25/shmoocon-2012-firetalks-%E2%80%93-update-5-schedule/"&gt;http://www.novainfosecportal.com/2012/01/25/shmoocon-2012-firetalks-%E2%80%93-update-5-schedule/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I'll also be presenting Security Onion at the NoVA Hackers Shmoocon Epilogue on Monday 1/30 at 8:00 PM:&lt;br /&gt;&lt;a href="http://novahackers.blogspot.com/2012/01/shmoocon-epilogue-speakers-and-location.html"&gt;http://novahackers.blogspot.com/2012/01/shmoocon-epilogue-speakers-and-location.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If you're a fan of Security Onion, please vote for it for 2011 Toolsmith Tool of the Year!&lt;br /&gt;&lt;a href="http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html"&gt;http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-2488088376713484126?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/2488088376713484126/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=2488088376713484126' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/2488088376713484126'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/2488088376713484126'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2012/01/upcoming-security-onion-presentations.html' title='Upcoming Security Onion Presentations'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-4730462405826650801</id><published>2012-01-23T21:27:00.002-05:00</published><updated>2012-01-23T21:28:20.378-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><title type='text'>Security Onion Success Stories 2012</title><content type='html'>Last year, I received a few success stories from satisfied Security Onion users:&lt;br /&gt;&lt;a href="http://securityonion.blogspot.com/2011/05/security-onion-success-stories.html"&gt;http://securityonion.blogspot.com/2011/05/security-onion-success-stories.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Please share your Security Onion success story in the comments below!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If you're a fan of Security Onion, please vote for it for 2011 Toolsmith Tool of the Year!&lt;br /&gt;&lt;a href="http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html"&gt;http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-4730462405826650801?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/4730462405826650801/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=4730462405826650801' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/4730462405826650801'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/4730462405826650801'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2012/01/security-onion-success-stories-2012.html' title='Security Onion Success Stories 2012'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-7306825406814775989</id><published>2012-01-23T19:55:00.001-05:00</published><updated>2012-01-23T19:57:43.349-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='ossec'/><title type='text'>Security Onion 20120124 now available!</title><content type='html'>&lt;br /&gt;Security Onion 20120124 is now available! &amp;nbsp;This resolves the following issue:&lt;br /&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=140"&gt;Issue 140:&amp;nbsp;OSSEC agent needs to be integrated into NSM scripts&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;New Users&lt;/b&gt;&lt;br /&gt;New users can download and install the 20111103 ISO image using the instructions &lt;a href="http://code.google.com/p/security-onion/wiki/Installation"&gt;here&lt;/a&gt;. &amp;nbsp;The step marked "Install Security Onion updates" will automatically install this update.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;In-place Upgrade&lt;/b&gt;&lt;br /&gt;Existing Security Onion users can perform an in-place upgrade using the following command (if you're behind a proxy, remember to set your proxy variables as described in the &lt;a href="http://code.google.com/p/security-onion/wiki/FAQ"&gt;FAQ&lt;/a&gt;):&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/blockquote&gt;&lt;br /&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-nhcTEwbOwxM/Tx3-JvNDthI/AAAAAAAAAdg/az-d2iE54Gk/s1600/Screen+Shot+2012-01-23+at+7.40.33+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="216" src="http://2.bp.blogspot.com/-nhcTEwbOwxM/Tx3-JvNDthI/AAAAAAAAAdg/az-d2iE54Gk/s640/Screen+Shot+2012-01-23+at+7.40.33+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Upgrade Process&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-NgJL0J9Hws8/Tx36Qr0K-ZI/AAAAAAAAAdY/nG7heHQ74zw/s1600/Screen+Shot+2012-01-23+at+7.11.50+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="250" src="http://1.bp.blogspot.com/-NgJL0J9Hws8/Tx36Qr0K-ZI/AAAAAAAAAdY/nG7heHQ74zw/s640/Screen+Shot+2012-01-23+at+7.11.50+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;sudo service nsm status&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;b&gt;Feedback&lt;/b&gt;&lt;br /&gt;If you have any questions, please join our mailing list and ask away!&lt;br /&gt;&lt;a href="http://groups.google.com/group/security-onion"&gt;http://groups.google.com/group/security-onion&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Toolsmith Tool of the Year&lt;/b&gt;&lt;br /&gt;If you're a fan of Security Onion, please vote for it for 2011 Toolsmith Tool of the Year!&lt;br /&gt;&lt;a href="http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html"&gt;http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-7306825406814775989?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/7306825406814775989/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=7306825406814775989' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/7306825406814775989'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/7306825406814775989'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2012/01/security-onion-20120124-now-available.html' title='Security Onion 20120124 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-nhcTEwbOwxM/Tx3-JvNDthI/AAAAAAAAAdg/az-d2iE54Gk/s72-c/Screen+Shot+2012-01-23+at+7.40.33+PM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-4570581884688946731</id><published>2012-01-22T16:19:00.000-05:00</published><updated>2012-01-22T16:19:59.396-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='bro'/><title type='text'>Security Onion 20120123 now available!</title><content type='html'>&lt;br /&gt;Security Onion 20120123 is now available! &amp;nbsp;This resolves the following issues:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=191"&gt;Issue 191: Update NSM scripts to control Bro&lt;/a&gt;&lt;br /&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=202"&gt;Issue 202: If user selects only one interface, configure Bro as standalone&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Notes&lt;/b&gt;&lt;br /&gt;If you're only monitoring a single network interface, this update will configure Bro for standalone mode which will greatly increase performance!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;New Users&lt;/b&gt;&lt;br /&gt;New users can download and install the 20111103 ISO image using the instructions &lt;a href="http://code.google.com/p/security-onion/wiki/Installation"&gt;here&lt;/a&gt;. &amp;nbsp;The step marked "Install Security Onion updates" will automatically install this update.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;In-place Upgrade&lt;/b&gt;&lt;br /&gt;Existing Security Onion users can perform an in-place upgrade using the following command (if you're behind a proxy, remember to set your proxy variables as described in the &lt;a href="http://code.google.com/p/security-onion/wiki/FAQ"&gt;FAQ&lt;/a&gt;):&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/blockquote&gt;&lt;br /&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-VJwNzZmjnlk/Txx61BbOGvI/AAAAAAAAAdA/YbWotr0FlB4/s1600/Screen+Shot+2012-01-22+at+4.08.14+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="372" src="http://3.bp.blogspot.com/-VJwNzZmjnlk/Txx61BbOGvI/AAAAAAAAAdA/YbWotr0FlB4/s640/Screen+Shot+2012-01-22+at+4.08.14+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Upgrade Process&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-BqOqzDDBRaQ/Txx7F8wyLgI/AAAAAAAAAdI/t4Fc3B6RBXo/s1600/Screen+Shot+2012-01-22+at+4.09.24+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="212" src="http://3.bp.blogspot.com/-BqOqzDDBRaQ/Txx7F8wyLgI/AAAAAAAAAdI/t4Fc3B6RBXo/s640/Screen+Shot+2012-01-22+at+4.09.24+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;NSM scripts now control Bro&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;b&gt;Thanks&lt;/b&gt;&lt;br /&gt;Thanks to Seth Hall of the Bro project for his tuning suggestion!&lt;br /&gt;Thanks to Richard Bejtlich for his suggestion of updating the NSM scripts to control Bro!&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Feedback&lt;/b&gt;&lt;br /&gt;If you have any questions, please join our mailing list and ask away!&lt;br /&gt;&lt;a href="http://groups.google.com/group/security-onion"&gt;http://groups.google.com/group/security-onion&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Toolsmith Tool of the Year&lt;/b&gt;&lt;br /&gt;If you're a fan of Security Onion, please vote for it for 2011 Toolsmith Tool of the Year!&lt;br /&gt;&lt;a href="http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html"&gt;http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-4570581884688946731?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/4570581884688946731/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=4570581884688946731' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/4570581884688946731'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/4570581884688946731'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2012/01/security-onion-20120123-now-available.html' title='Security Onion 20120123 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-VJwNzZmjnlk/Txx61BbOGvI/AAAAAAAAAdA/YbWotr0FlB4/s72-c/Screen+Shot+2012-01-22+at+4.08.14+PM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-7952580965136449224</id><published>2012-01-22T00:35:00.002-05:00</published><updated>2012-01-22T00:39:41.220-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='pulledpork'/><category scheme='http://www.blogger.com/atom/ns#' term='suricata'/><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='snorby'/><title type='text'>Security Onion 20120119 now available!</title><content type='html'>&lt;br /&gt;Security Onion 20120119 is now available! &amp;nbsp;This resolves the following issues:&lt;br /&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=154"&gt;Issue 154:&amp;nbsp;Track pulledpork download status&lt;/a&gt;&lt;br /&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=160"&gt;Issue 160:&amp;nbsp;PulledPork should be using https for ET and ETPRO downloads&lt;/a&gt;&lt;br /&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=198"&gt;Issue 198:&amp;nbsp;Suricata 1.2.1&lt;/a&gt;&lt;br /&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=200"&gt;Issue 200:&amp;nbsp;PulledPork isn't handling so_rules properly&lt;/a&gt;&lt;br /&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=201"&gt;Issue 201:&amp;nbsp;snorby-db-fix is causing problems with large/busy snorby databases&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;For more information about Suricata 1.2.1, please see:&lt;br /&gt;&lt;a href="http://www.openinfosecfoundation.org/index.php/component/content/article/144-suricata-12-available"&gt;http://www.openinfosecfoundation.org/index.php/component/content/article/144-suricata-12-available&lt;/a&gt;&lt;br /&gt;&lt;a href="https://redmine.openinfosecfoundation.org/projects/suricata/wiki/Upgrading_Suricata_11_to_Suricata_12"&gt;https://redmine.openinfosecfoundation.org/projects/suricata/wiki/Upgrading_Suricata_11_to_Suricata_12&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.suricata-ips.net/index.php/component/content/article/145-suricata-121-available"&gt;http://www.suricata-ips.net/index.php/component/content/article/145-suricata-121-available&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Please also note that the new suricata.yaml will overwrite your existing suricata.yaml. &amp;nbsp;Your existing suricata.yaml will be backed up to /nsm/backup/20120119/NAME_OF_SENSOR/. &amp;nbsp;Please copy any customizations (HOME_NET, etc.) from the backup copy to the production copy /etc/nsm/NAME_OF_SENSOR/suricata.yaml.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;New Users&lt;/b&gt;&lt;br /&gt;New users can download and install the 20111103 ISO image using the instructions &lt;a href="http://code.google.com/p/security-onion/wiki/Installation"&gt;here&lt;/a&gt;. &amp;nbsp;The step marked "Install Security Onion updates" will automatically install this update.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;In-place Upgrade&lt;/b&gt;&lt;br /&gt;Existing Security Onion users can perform an in-place upgrade using the following command (if you're behind a proxy, remember to set your proxy variables as described in the &lt;a href="http://code.google.com/p/security-onion/wiki/FAQ"&gt;FAQ&lt;/a&gt;):&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/blockquote&gt;&lt;br /&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-j42lK4N4L74/TxuejcJDEzI/AAAAAAAAAco/1Mi8jxin_m4/s1600/Screen+Shot+2012-01-22+at+12.27.01+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="588" src="http://1.bp.blogspot.com/-j42lK4N4L74/TxuejcJDEzI/AAAAAAAAAco/1Mi8jxin_m4/s640/Screen+Shot+2012-01-22+at+12.27.01+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Upgrade begins&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-EikpMZBgCMk/Txuep-4uOiI/AAAAAAAAAcw/pxkuQ3pevWc/s1600/Screen+Shot+2012-01-22+at+12.28.03+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="588" src="http://4.bp.blogspot.com/-EikpMZBgCMk/Txuep-4uOiI/AAAAAAAAAcw/pxkuQ3pevWc/s640/Screen+Shot+2012-01-22+at+12.28.03+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Upgrade runs pulledpork_update.sh to update rules&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-Vf7TCHzKt34/Txuex8tRyFI/AAAAAAAAAc4/yTbMSH9H3qM/s1600/Screen+Shot+2012-01-22+at+12.28.17+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="576" src="http://4.bp.blogspot.com/-Vf7TCHzKt34/Txuex8tRyFI/AAAAAAAAAc4/yTbMSH9H3qM/s640/Screen+Shot+2012-01-22+at+12.28.17+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;pulledpork_update.sh restarts barnyard2 and the IDS engine&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;b&gt;Thanks&lt;/b&gt;&lt;br /&gt;Thanks to the Suricata team for their hard work on Suricata 1.2.1!&lt;br /&gt;Thanks to Scott Runnels for his assistance in testing this release!&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Toolsmith Tool of the Year&lt;/b&gt;&lt;br /&gt;If you're a fan of Security Onion, please vote for it for 2011 Toolsmith Tool of the Year!&lt;br /&gt;&lt;a href="http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html"&gt;http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-7952580965136449224?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/7952580965136449224/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=7952580965136449224' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/7952580965136449224'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/7952580965136449224'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2012/01/security-onion-20120119-now-available.html' title='Security Onion 20120119 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-j42lK4N4L74/TxuejcJDEzI/AAAAAAAAAco/1Mi8jxin_m4/s72-c/Screen+Shot+2012-01-22+at+12.27.01+AM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-1684951043477363172</id><published>2012-01-18T08:57:00.004-05:00</published><updated>2012-01-18T08:57:51.189-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='nova hackers'/><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><title type='text'>Security Onion Presentation at NoVA Hackers</title><content type='html'>I'll be presenting Security Onion at the NoVA Hackers Shmoocon Epilogue:&lt;br /&gt;&lt;a href="http://novahackers.blogspot.com/2012/01/shmoocon-epilogue-speakers-and-location.html"&gt;http://novahackers.blogspot.com/2012/01/shmoocon-epilogue-speakers-and-location.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 16px; line-height: 22px;"&gt;&lt;span style="font-size: 15px;"&gt;If you're a fan of Security Onion, please vote for it for 2011 Toolsmith Tool of the Year!&lt;/span&gt;&lt;/div&gt;&lt;div style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 16px; line-height: 22px;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;&lt;a href="http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html" style="background-color: white; color: #33aaff; line-height: 20px; text-decoration: none;"&gt;http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 16px; line-height: 22px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-1684951043477363172?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/1684951043477363172/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=1684951043477363172' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/1684951043477363172'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/1684951043477363172'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2012/01/security-onion-presentation-at-nova.html' title='Security Onion Presentation at NoVA Hackers'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-5378692415236121383</id><published>2012-01-16T00:42:00.001-05:00</published><updated>2012-01-17T07:29:44.579-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='snort'/><title type='text'>Security Onion 20120116 now available!</title><content type='html'>&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-679292465147511865" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-1026167962061048823" style="position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-3239612664775068121" style="position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="position: relative; width: 668px;"&gt;&lt;div style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;Security Onion 20120116 is now available! &amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;This resolves the following issue:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="color: #333333; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 20px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=170"&gt;Issue 170: Snort 2.9.2&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;For more information about Snort 2.9.2, please see:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-size: 15px; line-height: 20px;"&gt;&lt;span style="color: #333333; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;a href="http://blog.snort.org/2012/01/snort-292-scada-preprocessors.html"&gt;Snort 2.9.2: SCADA Preprocessors&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="position: relative; width: 668px;"&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-size: 15px; line-height: 20px;"&gt;&lt;span style="color: #333333; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;a href="http://www.snort.org/docs"&gt;http://www.snort.org/docs&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-size: 15px; line-height: 20px;"&gt;&lt;span style="color: #333333; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;a href="http://manual.snort.org/"&gt;http://manual.snort.org&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-size: 15px; line-height: 20px;"&gt;&lt;span style="color: #333333; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;Please note that if you are using the Registered (30-day delay) VRT ruleset you may need to wait until the rules are released for Snort 2.9.2.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 20px; line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;Please also note that the new snort.conf will overwrite your existing snort.conf. &amp;nbsp;Your existing snort.conf will be backed up to /nsm/backup/20120116/NAME_OF_SENSOR/. &amp;nbsp;Please copy any customizations (HOME_NET, etc.) from the backup copy to the production copy /etc/nsm/NAME_OF_SENSOR/snort.conf.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; font-size: 26px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;b style="background-color: white;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;New Users&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; font-size: 26px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;New users can download and install the 20111103 ISO image using the instructions&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Installation" style="color: #6699cc; font-size: 15px; line-height: 1.4; text-decoration: none;"&gt;here&lt;/a&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;. &amp;nbsp;The step marked "Install Security Onion updates" will automatically install this update.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 16px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;div style="font-size: 15px; line-height: 1.4;"&gt;&lt;div style="line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; line-height: 21px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif; font-weight: bold; line-height: 20px;"&gt;In-place Upgrade&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif;"&gt;(if you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="color: #336699; text-decoration: none;"&gt;FAQ&lt;/a&gt;):&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote style="line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; line-height: 21px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-m9RTtDO7fOM/TxO28TAoeoI/AAAAAAAAAcU/mUl3x4OGDhA/s1600/Screen+Shot+2012-01-16+at+12.13.21+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="396" src="http://3.bp.blogspot.com/-m9RTtDO7fOM/TxO28TAoeoI/AAAAAAAAAcU/mUl3x4OGDhA/s640/Screen+Shot+2012-01-16+at+12.13.21+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Upgrade script installs Snort 2.9.2 and launches PulledPork&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-_moY1V3beck/TxO3LxeIP-I/AAAAAAAAAcc/TAVNGJWEM2g/s1600/Screen+Shot+2012-01-16+at+12.13.44+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="156" src="http://1.bp.blogspot.com/-_moY1V3beck/TxO3LxeIP-I/AAAAAAAAAcc/TAVNGJWEM2g/s640/Screen+Shot+2012-01-16+at+12.13.44+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Once PulledPork completes, barnyard2 and Snort are restarted&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="post-body entry-content" id="post-body-679292465147511865" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;b&gt;Thanks&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-679292465147511865" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; line-height: 20px;"&gt;Thanks to the Snort team for their hard work on Snort 2.9.2!&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; line-height: 20px;"&gt;Thanks to Scott Runnels for his assistance in testing this release!&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-size: 15px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;If you're a fan of Security Onion, please vote for it for 2011 Toolsmith Tool of the Year!&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;&lt;a href="http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html" style="background-color: white; color: #33aaff; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; line-height: 20px; text-decoration: none;"&gt;http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-5378692415236121383?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/5378692415236121383/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=5378692415236121383' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/5378692415236121383'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/5378692415236121383'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2012/01/security-onion-20120116-now-available.html' title='Security Onion 20120116 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-m9RTtDO7fOM/TxO28TAoeoI/AAAAAAAAAcU/mUl3x4OGDhA/s72-c/Screen+Shot+2012-01-16+at+12.13.21+AM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-4921230510711527118</id><published>2012-01-13T10:38:00.002-05:00</published><updated>2012-01-13T10:38:52.950-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><title type='text'>Security Onion 20120114 now available!</title><content type='html'>&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-748397042573170916" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-5963825260147021281" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-4214352945040657091" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-7811273308954053320" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-3048260342287273383" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-318691752433369599" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 26px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;Security Onion 20120114 is now available! &amp;nbsp;&lt;/span&gt;&lt;span style="background-color: white; font-size: 15px; line-height: 1.4;"&gt;This resolves the following issue:&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=190"&gt;Issue 190:&amp;nbsp;typo in /etc/cron.d/bro&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; position: relative; width: 668px;"&gt;&lt;div style="font-size: 29px; line-height: 1.4;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 26px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;b style="background-color: white;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;New Users&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 26px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;New users can download and install the 20111103 ISO image using the instructions&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Installation" style="color: #6699cc; font-size: 15px; line-height: 1.4; text-decoration: none;"&gt;here&lt;/a&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;. &amp;nbsp;The step marked "Install Security Onion updates" will automatically install this update.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b style="font-size: 15px; line-height: 1.4;"&gt;In-place Upgrade&lt;/b&gt;&lt;br /&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command (if you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Proxy" style="color: #6699cc; font-size: 15px; line-height: 1.4; text-decoration: none;"&gt;FAQ&lt;/a&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;):&lt;/span&gt;&lt;br /&gt;&lt;blockquote class="tr_bq" style="font-size: 15px; line-height: 1.4;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/blockquote&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;Note that the upgrade script is cumulative and will upgrade any older version of Security Onion to the most recent version (including any updates in between).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="color: black; font-family: Times; font-size: medium; line-height: normal;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;If you're a fan of Security Onion, please vote for it for 2011 Toolsmith Tool of the Year!&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="color: black; font-family: Times; font-size: medium; line-height: normal;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;&lt;a href="http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html" style="background-color: white; color: #33aaff; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px; text-decoration: none;"&gt;http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-4921230510711527118?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/4921230510711527118/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=4921230510711527118' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/4921230510711527118'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/4921230510711527118'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2012/01/security-onion-20120114-now-available.html' title='Security Onion 20120114 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-748397042573170916</id><published>2012-01-13T09:58:00.001-05:00</published><updated>2012-01-13T09:58:25.594-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='bro'/><title type='text'>Security Onion 20120113 now available!</title><content type='html'>&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-5963825260147021281" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-4214352945040657091" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-7811273308954053320" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-3048260342287273383" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-318691752433369599" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;Security Onion 20120113 is now available! &amp;nbsp;&lt;/span&gt;&lt;span style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;This resolves the following issues:&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=147"&gt;Issue 147: Bro 2.0 integration&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=185"&gt;Issue 185: Syntax error clearing sensor data&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="background-color: white; font-size: 15px; line-height: 21px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;Note that this is just the initial integration of Bro. In the future, we'll switch Sguil's http_agent to use Bro's http.log and we'll also look at using Barnyard2 to send IDS alerts to Bro to give it a better understanding of your network.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;b style="background-color: white;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;New Users&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; position: relative; width: 668px;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;New users can download and install the 20111103 ISO image using the instructions&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Installation" style="color: #6699cc; font-size: 15px; line-height: 1.4; text-decoration: none;"&gt;here&lt;/a&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;. &amp;nbsp;The step marked "Install Security Onion updates" will automatically install this update.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b style="font-size: 15px; line-height: 1.4;"&gt;In-place Upgrade&lt;/b&gt;&lt;br /&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command (if you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Proxy" style="color: #6699cc; font-size: 15px; line-height: 1.4; text-decoration: none;"&gt;FAQ&lt;/a&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;):&lt;/span&gt;&lt;br /&gt;&lt;blockquote class="tr_bq" style="font-size: 15px; line-height: 1.4;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/blockquote&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;Note that the upgrade script is cumulative and will upgrade any older version of Security Onion to the most recent version (including any updates in between).&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 16px; line-height: 1.4; text-align: center;"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 18px; line-height: 1.4; text-align: center;"&gt;&lt;/div&gt;&lt;b style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 18px; line-height: 1.4;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;Screenshots&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 18px; line-height: 1.4; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 20px; line-height: 1.4; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-EIg_H0TiLR4/TxAv-lO79sI/AAAAAAAAAb8/34EZ9d3vbfU/s1600/Screen+Shot+2012-01-13+at+7.56.55+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="640" src="http://2.bp.blogspot.com/-EIg_H0TiLR4/TxAv-lO79sI/AAAAAAAAAb8/34EZ9d3vbfU/s640/Screen+Shot+2012-01-13+at+7.56.55+AM.png" width="624" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Upgrade Process&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-gn7lJ1CfrVk/TxAwR6gvnVI/AAAAAAAAAcE/AmXPAvgH_oY/s1600/Screen+Shot+2012-01-13+at+8.22.55+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="72" src="http://2.bp.blogspot.com/-gn7lJ1CfrVk/TxAwR6gvnVI/AAAAAAAAAcE/AmXPAvgH_oY/s640/Screen+Shot+2012-01-13+at+8.22.55+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;sudo broctl status&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-kTKzlbzb-Cg/TxAyYknS_RI/AAAAAAAAAcM/FFPwOvqmPxs/s1600/Screen+Shot+2012-01-13+at+8.30.42+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="32" src="http://4.bp.blogspot.com/-kTKzlbzb-Cg/TxAyYknS_RI/AAAAAAAAAcM/FFPwOvqmPxs/s640/Screen+Shot+2012-01-13+at+8.30.42+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Current Bro logs can be found in /nsm/bro/logs/current&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="post-body entry-content" id="post-body-318691752433369599" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;If you're a fan of Security Onion, please vote for it for 2011 Toolsmith Tool of the Year!&lt;/span&gt;&lt;br /&gt;&lt;a href="http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html" style="background-color: white; color: #33aaff; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px; text-decoration: none;"&gt;http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-748397042573170916?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/748397042573170916/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=748397042573170916' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/748397042573170916'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/748397042573170916'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2012/01/security-onion-20120113-now-available.html' title='Security Onion 20120113 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-EIg_H0TiLR4/TxAv-lO79sI/AAAAAAAAAb8/34EZ9d3vbfU/s72-c/Screen+Shot+2012-01-13+at+7.56.55+AM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-5963825260147021281</id><published>2012-01-06T16:39:00.000-05:00</published><updated>2012-01-06T16:39:15.018-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><title type='text'>Security Onion 20120107 now available!</title><content type='html'>&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-4214352945040657091" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-7811273308954053320" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-3048260342287273383" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-318691752433369599" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 18px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;Security Onion 20120107 is now available! &amp;nbsp;This resolves the following issue:&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=184"&gt;Issue 184:&amp;nbsp;reference.config needs to be updated&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; position: relative; width: 668px;"&gt;&lt;b style="font-size: 15px; line-height: 1.4;"&gt;New Users&lt;/b&gt;&lt;br /&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;New users can download and install the 20111103 ISO image using the instructions&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Installation" style="color: #6699cc; font-size: 15px; line-height: 1.4; text-decoration: none;"&gt;here&lt;/a&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;. &amp;nbsp;The step marked "Install Security Onion updates" will automatically install this update.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b style="font-size: 15px; line-height: 1.4;"&gt;In-place Upgrade&lt;/b&gt;&lt;br /&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command (if you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Proxy" style="color: #6699cc; font-size: 15px; line-height: 1.4; text-decoration: none;"&gt;FAQ&lt;/a&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;):&lt;/span&gt;&lt;br /&gt;&lt;blockquote class="tr_bq" style="font-size: 15px; line-height: 1.4;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/blockquote&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;Note that the upgrade script is cumulative and will upgrade any older version of Security Onion to the most recent version (including any updates in between).&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 16px; line-height: 1.4; text-align: center;"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 18px; line-height: 1.4; text-align: center;"&gt;&lt;/div&gt;&lt;b style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 18px; line-height: 1.4;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;Screenshots&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 18px; line-height: 1.4; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-gkx_2K1X78E/Twdp2tnOQVI/AAAAAAAAAb0/HNO6wjQoGIQ/s1600/Screen+Shot+2012-01-06+at+4.26.48+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="430" src="http://4.bp.blogspot.com/-gkx_2K1X78E/Twdp2tnOQVI/AAAAAAAAAb0/HNO6wjQoGIQ/s640/Screen+Shot+2012-01-06+at+4.26.48+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Upgrade Process&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="post-body entry-content" id="post-body-318691752433369599" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 18px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span style="font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: 15px; line-height: 20px;"&gt;If you're a fan of Security Onion, please vote for it for 2011 Toolsmith Tool of the Year!&lt;/span&gt;&lt;br /&gt;&lt;a href="http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html" style="background-color: white; color: #33aaff; font-size: 15px; line-height: 20px; text-decoration: none;"&gt;http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html&lt;/a&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-318691752433369599" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 18px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-318691752433369599" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 18px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-5963825260147021281?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/5963825260147021281/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=5963825260147021281' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/5963825260147021281'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/5963825260147021281'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2012/01/security-onion-20120107-now-available.html' title='Security Onion 20120107 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-gkx_2K1X78E/Twdp2tnOQVI/AAAAAAAAAb0/HNO6wjQoGIQ/s72-c/Screen+Shot+2012-01-06+at+4.26.48+PM.png' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-4214352945040657091</id><published>2012-01-06T09:54:00.000-05:00</published><updated>2012-01-06T09:54:29.851-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='etherape'/><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='vim'/><category scheme='http://www.blogger.com/atom/ns#' term='whois'/><title type='text'>Security Onion 20120106 now available!</title><content type='html'>&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-7811273308954053320" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-3048260342287273383" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-318691752433369599" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 18px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;Security Onion 20120106 is now available! &amp;nbsp;This resolves the following issues:&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=152"&gt;Issue 152: etherape&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=158"&gt;Issue 158: whois&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=178"&gt;Issue 178: nsm_sensor_ps-status shouldn't delete stale PID files&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=179"&gt;Issue 179: NSM watchdog should put timestamps in log file&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=180"&gt;Issue 180: vim&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=181"&gt;Issue 181: nsm_sensor_ps-restart should rotate current log file to TIMESTAMP&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=182"&gt;Issue 182: Setup needs to make sure MySQL is running if user chooses Server&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=183"&gt;Issue 183: Need to periodically remove invalid data from snorby database&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;b style="background-color: white;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;b style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;New Users&lt;/b&gt;&lt;br /&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;New users can download and install the 20111103 ISO image using the instructions&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Installation" style="color: #6699cc; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; text-decoration: none;"&gt;here&lt;/a&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;. &amp;nbsp;The step marked "Install Security Onion updates" will automatically install this update.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;In-place Upgrade&lt;/b&gt;&lt;br /&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command (if you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Proxy" style="color: #6699cc; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; text-decoration: none;"&gt;FAQ&lt;/a&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;):&lt;/span&gt;&lt;br /&gt;&lt;blockquote class="tr_bq" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/blockquote&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;Note that the upgrade script is cumulative and will upgrade any older version of Security Onion to the most recent version (including any updates in between).&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 16px; line-height: 1.4; text-align: center;"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; text-align: center;"&gt;&lt;/div&gt;&lt;b style="background-color: white;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;Screenshots&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; text-align: center;"&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-AoYJFU90sIY/TwcGulB2iII/AAAAAAAAAbs/EJ8IQuuJUOw/s1600/Screen+Shot+2012-01-06+at+8.43.01+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="252" src="http://3.bp.blogspot.com/-AoYJFU90sIY/TwcGulB2iII/AAAAAAAAAbs/EJ8IQuuJUOw/s640/Screen+Shot+2012-01-06+at+8.43.01+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Upgrade Process&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="post-body entry-content" id="post-body-318691752433369599" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 18px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span style="font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: 15px; line-height: 20px;"&gt;If you're a fan of Security Onion, please vote for it for 2011 Toolsmith Tool of the Year!&lt;/span&gt;&lt;br /&gt;&lt;a href="http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html" style="background-color: white; color: #33aaff; font-size: 15px; line-height: 20px; text-decoration: none;"&gt;http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-4214352945040657091?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/4214352945040657091/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=4214352945040657091' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/4214352945040657091'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/4214352945040657091'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2012/01/security-onion-20120106-now-available.html' title='Security Onion 20120106 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-AoYJFU90sIY/TwcGulB2iII/AAAAAAAAAbs/EJ8IQuuJUOw/s72-c/Screen+Shot+2012-01-06+at+8.43.01+AM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-7811273308954053320</id><published>2011-12-29T08:07:00.002-05:00</published><updated>2011-12-29T08:07:50.836-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='pads'/><title type='text'>Security Onion 20111229 now available!</title><content type='html'>&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-3048260342287273383" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-318691752433369599" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 18px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;Security Onion 20111229 is now available! &amp;nbsp;This resolves the following issues:&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=109"&gt;Issue 109: &amp;nbsp;Optional PADS or PRADS&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=115"&gt;Issue 115: &amp;nbsp;edit nsm_sensor_edit&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=162"&gt;Issue 162: &amp;nbsp;Process watchdog&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=164"&gt;Issue 164: &amp;nbsp;No sensor status info then server is down&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=173"&gt;Issue 173: &amp;nbsp;nsm_sensor_clean cronjob should output date to logfile&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 18px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 18px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;Thanks to Karolis for his work on integrating PADS into the distro!&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 18px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 18px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;&lt;b&gt;Notes&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;The PADS configuration file (/etc/nsm/SENSOR-NAME/pads.conf) contains a "network" variable which defaults to:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;192.168.0.0/16,10.0.0.0/8,172.16.0.0/12&lt;br /&gt;You will need to change this variable if you're monitoring public IP space.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;The new process watchdog runs every 5 minutes and will restart any sensor process that has crashed. &amp;nbsp;It will move the process's old log file to PROCESS.log.TIMESTAMP so that you can determine why the process crashed.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 18px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;b style="font-size: 15px; line-height: 1.4;"&gt;New Users&lt;/b&gt;&lt;br /&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;New users can download and install the 20111103 ISO image using the instructions&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Installation" style="color: #6699cc; font-size: 15px; line-height: 1.4; text-decoration: none;"&gt;here&lt;/a&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;. &amp;nbsp;The step marked "Install Security Onion updates" will automatically install this update.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b style="font-size: 15px; line-height: 1.4;"&gt;In-place Upgrade&lt;/b&gt;&lt;br /&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command (if you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Proxy" style="color: #6699cc; font-size: 15px; line-height: 1.4; text-decoration: none;"&gt;FAQ&lt;/a&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;):&lt;/span&gt;&lt;br /&gt;&lt;blockquote class="tr_bq" style="font-size: 15px; line-height: 1.4;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/blockquote&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;Note that the upgrade script is cumulative and will upgrade any older version of Security Onion to the most recent version (including any updates in between).&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 16px; line-height: 1.4; text-align: center;"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; text-align: center;"&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-zki7Dkjh9rc/TvxiwvqzJgI/AAAAAAAAAbY/41lLpMcpYq4/s1600/Screen+Shot+2011-12-29+at+7.52.56+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="572" src="http://1.bp.blogspot.com/-zki7Dkjh9rc/TvxiwvqzJgI/AAAAAAAAAbY/41lLpMcpYq4/s640/Screen+Shot+2011-12-29+at+7.52.56+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Upgrade Process&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-nMjVZJVvnXA/Tvxi1ZUVVUI/AAAAAAAAAbk/rEp7cYa67YY/s1600/Screen+Shot+2011-12-29+at+7.14.08+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="172" src="http://4.bp.blogspot.com/-nMjVZJVvnXA/Tvxi1ZUVVUI/AAAAAAAAAbk/rEp7cYa67YY/s640/Screen+Shot+2011-12-29+at+7.14.08+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;PADS events in Sguil&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="post-body entry-content" id="post-body-318691752433369599" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; position: relative; width: 668px;"&gt;&lt;span style="font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: 15px; line-height: 20px;"&gt;If you're a fan of Security Onion, please vote for it for 2011 Toolsmith Tool of the Year!&lt;/span&gt;&lt;br /&gt;&lt;a href="http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html" style="background-color: white; color: #33aaff; font-size: 15px; line-height: 20px; text-decoration: none;"&gt;http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-7811273308954053320?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/7811273308954053320/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=7811273308954053320' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/7811273308954053320'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/7811273308954053320'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/12/security-onion-20111229-now-available.html' title='Security Onion 20111229 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-zki7Dkjh9rc/TvxiwvqzJgI/AAAAAAAAAbY/41lLpMcpYq4/s72-c/Screen+Shot+2011-12-29+at+7.52.56+AM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-3048260342287273383</id><published>2011-12-27T13:04:00.001-05:00</published><updated>2011-12-27T13:38:54.586-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='networkminer'/><title type='text'>Security Onion 20111228 now available!</title><content type='html'>&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-318691752433369599" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;Security Onion 20111228 is now available! &amp;nbsp;This resolves the following issue:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=151"&gt;Issue 151:&amp;nbsp;NetworkMiner&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 21px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;b style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;New Users&lt;/b&gt;&lt;br /&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;New users can download and install the 20111103 ISO image using the instructions&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Installation" style="color: #6699cc; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; text-decoration: none;"&gt;here&lt;/a&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;. &amp;nbsp;The step marked "Install Security Onion updates" will automatically install this update.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;In-place Upgrade&lt;/b&gt;&lt;br /&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command (if you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Proxy" style="color: #6699cc; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; text-decoration: none;"&gt;FAQ&lt;/a&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;):&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class="tr_bq" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/blockquote&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span style="font-size: 15px; line-height: 1.4;"&gt;Note that the upgrade script is cumulative and will upgrade any older version of Security Onion to the most recent version (including any updates in between).&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-aI5NItPjBkM/TvoChP_7w5I/AAAAAAAAAbA/AvSwrRoLOxc/s1600/Screen+Shot+2011-12-27+at+12.30.52+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="256" src="http://3.bp.blogspot.com/-aI5NItPjBkM/TvoChP_7w5I/AAAAAAAAAbA/AvSwrRoLOxc/s640/Screen+Shot+2011-12-27+at+12.30.52+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Upgrade Process&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-Siu_jVE-5EA/TvoCnJtmUXI/AAAAAAAAAbM/c09dzq-DeNE/s1600/Screen+Shot+2011-12-27+at+12.32.09+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="181" src="http://1.bp.blogspot.com/-Siu_jVE-5EA/TvoCnJtmUXI/AAAAAAAAAbM/c09dzq-DeNE/s400/Screen+Shot+2011-12-27+at+12.32.09+PM.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;NetworkMiner menu entry&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="post-body entry-content" id="post-body-318691752433369599" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;If you're a fan of Security Onion, please vote for it for 2011 Toolsmith Tool of the Year!&lt;/span&gt;&lt;br /&gt;&lt;a href="http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html" style="background-color: white; color: #33aaff; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px; text-decoration: none;"&gt;http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html&lt;/a&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-318691752433369599" style="background-color: white; position: relative; width: 668px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-318691752433369599" style="background-color: white; position: relative; width: 668px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-3048260342287273383?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/3048260342287273383/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=3048260342287273383' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/3048260342287273383'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/3048260342287273383'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/12/security-onion-20111228-now-available.html' title='Security Onion 20111228 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-aI5NItPjBkM/TvoChP_7w5I/AAAAAAAAAbA/AvSwrRoLOxc/s72-c/Screen+Shot+2011-12-27+at+12.30.52+PM.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-318691752433369599</id><published>2011-12-27T10:22:00.002-05:00</published><updated>2011-12-27T10:23:49.622-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='snorby'/><title type='text'>Security Onion 20111227 now available!</title><content type='html'>&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;Security Onion 20111227 is now available! &amp;nbsp;This resolves the following issue:&lt;br /&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=172"&gt;Issue 172: Snorby Export-to-PDF results in error&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;New Users&lt;/b&gt;&lt;br /&gt;New users can download and install the 20111103 ISO image using the instructions&amp;nbsp;&lt;a href="http://code.google.com/p/security-onion/wiki/Installation" style="color: #6699cc; text-decoration: none;"&gt;here&lt;/a&gt;. &amp;nbsp;The step marked "Install Security Onion updates" will automatically install this update.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;In-place Upgrade&lt;/b&gt;&lt;br /&gt;Existing Security Onion users can perform an in-place upgrade using the following command (if you're behind a proxy, remember to set your proxy variables as described in the &lt;a href="http://code.google.com/p/security-onion/wiki/Proxy"&gt;FAQ&lt;/a&gt;):&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/blockquote&gt;Note that the upgrade script is cumulative and will upgrade any older version of Security Onion to the most recent version (including any updates in between).&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-IMlJ9yqjydg/TvnihduXqoI/AAAAAAAAAas/qXWKf69a6QQ/s1600/Screen+Shot+2011-12-27+at+10.13.33+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="434" src="http://1.bp.blogspot.com/-IMlJ9yqjydg/TvnihduXqoI/AAAAAAAAAas/qXWKf69a6QQ/s640/Screen+Shot+2011-12-27+at+10.13.33+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Upgrade Process&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="post-body entry-content" id="post-body-3335262646252015914" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span style="line-height: 20px;"&gt;If you're a fan of Security Onion, don't forget to vote for it for 2011 Toolsmith Tool of the Year!&lt;/span&gt;&lt;br style="line-height: 20px;" /&gt;&lt;a href="http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html" style="background-color: white; color: #33aaff; line-height: 20px; text-decoration: none;"&gt;http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-318691752433369599?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/318691752433369599/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=318691752433369599' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/318691752433369599'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/318691752433369599'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/12/security-onion-20111227-now-available.html' title='Security Onion 20111227 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-IMlJ9yqjydg/TvnihduXqoI/AAAAAAAAAas/qXWKf69a6QQ/s72-c/Screen+Shot+2011-12-27+at+10.13.33+AM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-3335262646252015914</id><published>2011-12-23T14:51:00.001-05:00</published><updated>2011-12-23T14:51:41.109-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='snorby'/><title type='text'>Security Onion 20111222 now available!</title><content type='html'>&lt;br /&gt;Security Onion 20111222 is now available! &amp;nbsp;This resolves the following issue:&lt;br /&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=51"&gt;Issue 51&lt;/a&gt;: Snorby&lt;br /&gt;&lt;br /&gt;Snorby is a modern web interface for Network Security Monitoring:&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-np0mTgnESs8/TvTbVcFHj2I/AAAAAAAAAag/8RnoOLRxrPQ/s1600/Screen+Shot+2011-12-23+at+2.49.03+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="492" src="http://1.bp.blogspot.com/-np0mTgnESs8/TvTbVcFHj2I/AAAAAAAAAag/8RnoOLRxrPQ/s640/Screen+Shot+2011-12-23+at+2.49.03+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;The new hotness&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;A few things to note:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;The Snorby database is totally separate from the Sguil database. &amp;nbsp;This means that you will have a separate user account to log into Snorby. &amp;nbsp;It also means that any events that you classify in Snorby are not reflected back into the Sguil database.&lt;/li&gt;&lt;li&gt;A new output is added to the barnyard2 configuration to send events to the Snorby database. &amp;nbsp;Remote sensors establish an SSH tunnel to the server to encrypt the MySQL traffic.&lt;/li&gt;&lt;li&gt;This is just the initial integration of Snorby. &amp;nbsp;In the future we'll add things like full packet capture support and Dustin's new unified2 library.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;b&gt;New Users&lt;/b&gt;&lt;br /&gt;New users can download and install the 20111103 ISO image using the instructions &lt;a href="http://code.google.com/p/security-onion/wiki/Installation"&gt;here&lt;/a&gt;. &amp;nbsp;The step marked "Install Security Onion updates" will automatically install this update.&lt;br /&gt;&lt;br /&gt;The Setup wizard has been updated to support Snorby. &amp;nbsp;You will create a username for Sguil/Squert and a separate username for Snorby (your email address). &amp;nbsp;The password that you enter will be used for both Sguil/Squert and Snorby.&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-fGYoqgkIdm8/TvTVueSeLjI/AAAAAAAAAY0/F_wCvGZuYyY/s1600/Screen+Shot+2011-12-23+at+2.22.25+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="147" src="http://3.bp.blogspot.com/-fGYoqgkIdm8/TvTVueSeLjI/AAAAAAAAAY0/F_wCvGZuYyY/s320/Screen+Shot+2011-12-23+at+2.22.25+PM.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Updated Setup Wizard&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-85eL5WQyq1w/TvTV2HktRCI/AAAAAAAAAZA/dXrQzzrv2VY/s1600/Screen+Shot+2011-12-23+at+2.23.02+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-85eL5WQyq1w/TvTV2HktRCI/AAAAAAAAAZA/dXrQzzrv2VY/s1600/Screen+Shot+2011-12-23+at+2.23.02+PM.png" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Entering email address for Snorby&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-qXg_FpnwzJM/TvTWFCFrTcI/AAAAAAAAAZM/NQNJxkWMBK0/s1600/Screen+Shot+2011-12-23+at+2.23.25+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="197" src="http://3.bp.blogspot.com/-qXg_FpnwzJM/TvTWFCFrTcI/AAAAAAAAAZM/NQNJxkWMBK0/s320/Screen+Shot+2011-12-23+at+2.23.25+PM.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Same password will be used for both Sguil/Squert and Snorby&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-t2qqNExUEXc/TvTY70WU49I/AAAAAAAAAZY/h_KAzq507CY/s1600/Screen+Shot+2011-12-23+at+2.04.51+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-t2qqNExUEXc/TvTY70WU49I/AAAAAAAAAZY/h_KAzq507CY/s1600/Screen+Shot+2011-12-23+at+2.04.51+PM.png" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Double-click the Snorby desktop shortcut&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-AgsnCxmK5D4/TvTZIXTGLrI/AAAAAAAAAZk/DqtZdU_1qbQ/s1600/Screen+Shot+2011-12-23+at+2.40.02+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="296" src="http://3.bp.blogspot.com/-AgsnCxmK5D4/TvTZIXTGLrI/AAAAAAAAAZk/DqtZdU_1qbQ/s400/Screen+Shot+2011-12-23+at+2.40.02+PM.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Login using the email address and password you specified in Setup&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-dlefYN9sfAs/TvTZZncFScI/AAAAAAAAAZw/YmUeO5FVPpM/s1600/Screen+Shot+2011-12-23+at+2.08.12+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="37" src="http://3.bp.blogspot.com/-dlefYN9sfAs/TvTZZncFScI/AAAAAAAAAZw/YmUeO5FVPpM/s400/Screen+Shot+2011-12-23+at+2.08.12+PM.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;If necessary, generate some IDS alerts using "curl http://testmyids.com"&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-dn7qq1acR3A/TvTZz1vxGMI/AAAAAAAAAZ8/1B0cIFtv5O0/s1600/Screen+Shot+2011-12-23+at+2.42.51+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="148" src="http://4.bp.blogspot.com/-dn7qq1acR3A/TvTZz1vxGMI/AAAAAAAAAZ8/1B0cIFtv5O0/s640/Screen+Shot+2011-12-23+at+2.42.51+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;View your IDS alerts on the Events tab&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;In-place Upgrade&lt;/b&gt;&lt;br /&gt;Existing Security Onion users can perform an in-place upgrade using the following command (if you're behind a proxy, remember to set your proxy variables as described in the FAQ):&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/blockquote&gt;Note that the upgrade script is cumulative and will upgrade any older version of Security Onion to the most recent version (including any updates in between).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If you have one or more slave sensors reporting to a central master server, always upgrade the master first!&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Since Snorby and Sguil have separate databases, your existing Sguil credentials will not allow you to log into Snorby. &amp;nbsp;The in-place upgrade process will generate a username and random password for your initial Snorby login. &amp;nbsp;You should immediately login with your temporary credentials and change them.&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-CJtnkPpQswg/TvTR8L72uzI/AAAAAAAAAW0/hi1EiHI3i2A/s1600/Screen+Shot+2011-12-23+at+2.04.12+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="152" src="http://4.bp.blogspot.com/-CJtnkPpQswg/TvTR8L72uzI/AAAAAAAAAW0/hi1EiHI3i2A/s640/Screen+Shot+2011-12-23+at+2.04.12+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Completing upgrade of an existing system&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="http://3.bp.blogspot.com/-VVbUJSgr5Ho/TvTSF415VbI/AAAAAAAAAXI/WFJnm_17LfM/s1600/Screen+Shot+2011-12-23+at+2.04.51+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-VVbUJSgr5Ho/TvTSF415VbI/AAAAAAAAAXI/WFJnm_17LfM/s1600/Screen+Shot+2011-12-23+at+2.04.51+PM.png" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption"&gt;Double-click the Snorby desktop shortcut or use the URL shown in the upgrade&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-B4VlOrI0i8k/TvTSXkmgI8I/AAAAAAAAAXU/Ie9JqqWfoN4/s1600/Screen+Shot+2011-12-23+at+2.05.32+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="297" src="http://3.bp.blogspot.com/-B4VlOrI0i8k/TvTSXkmgI8I/AAAAAAAAAXU/Ie9JqqWfoN4/s400/Screen+Shot+2011-12-23+at+2.05.32+PM.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Login using the credentials shown in the upgrade&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-t9Yl-lIL3cQ/TvTSvut4tQI/AAAAAAAAAXg/LZsqNCMtVkM/s1600/Screen+Shot+2011-12-23+at+2.05.49+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="32" src="http://3.bp.blogspot.com/-t9Yl-lIL3cQ/TvTSvut4tQI/AAAAAAAAAXg/LZsqNCMtVkM/s320/Screen+Shot+2011-12-23+at+2.05.49+PM.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Click "Settings" to change your username/password&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-hfh3YEK7xyk/TvTTJZEaFvI/AAAAAAAAAX4/Fx1TZg08alg/s1600/Screen+Shot+2011-12-23+at+2.06.47+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="400" src="http://3.bp.blogspot.com/-hfh3YEK7xyk/TvTTJZEaFvI/AAAAAAAAAX4/Fx1TZg08alg/s400/Screen+Shot+2011-12-23+at+2.06.47+PM.png" width="293" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Set your new credentials&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-tRVCgnVLJDM/TvTTP6W5OsI/AAAAAAAAAYE/qf-c_SWRd9A/s1600/Screen+Shot+2011-12-23+at+2.07.18+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="300" src="http://3.bp.blogspot.com/-tRVCgnVLJDM/TvTTP6W5OsI/AAAAAAAAAYE/qf-c_SWRd9A/s400/Screen+Shot+2011-12-23+at+2.07.18+PM.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Login using your new credentials&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-bmoFS50RaQU/TvTTV_SwLqI/AAAAAAAAAYQ/CWBvXJbwmvg/s1600/Screen+Shot+2011-12-23+at+2.08.12+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="37" src="http://2.bp.blogspot.com/-bmoFS50RaQU/TvTTV_SwLqI/AAAAAAAAAYQ/CWBvXJbwmvg/s400/Screen+Shot+2011-12-23+at+2.08.12+PM.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;If necessary, generate some alerts with "curl http://testmyids.com"&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-TfCqqGYHdgI/TvTaDI6fhuI/AAAAAAAAAaI/rpVTuXFZ6uE/s1600/Screen+Shot+2011-12-23+at+2.42.51+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="148" src="http://4.bp.blogspot.com/-TfCqqGYHdgI/TvTaDI6fhuI/AAAAAAAAAaI/rpVTuXFZ6uE/s640/Screen+Shot+2011-12-23+at+2.42.51+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;View your IDS alerts on the Events tab&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;If you're a fan of Security Onion, don't forget to vote for it for 2011 Toolsmith Tool of the Year!&lt;br /&gt;&lt;a href="http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html" style="background-color: white; color: #33aaff; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Merry Christmas!&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-3335262646252015914?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/3335262646252015914/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=3335262646252015914' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/3335262646252015914'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/3335262646252015914'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/12/security-onion-20111222-now-available.html' title='Security Onion 20111222 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-np0mTgnESs8/TvTbVcFHj2I/AAAAAAAAAag/8RnoOLRxrPQ/s72-c/Screen+Shot+2011-12-23+at+2.49.03+PM.png' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-8645904022002135543</id><published>2011-12-20T13:22:00.000-05:00</published><updated>2011-12-20T13:22:51.656-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><title type='text'>Security Onion is in the running for 2011 Toolsmith Tool of the Year!</title><content type='html'>Security Onion is in the running for 2011 Toolsmith Tool of the Year! &amp;nbsp;I know which one I'm voting for :)&lt;br /&gt;&lt;a href="http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html"&gt;http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-8645904022002135543?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/8645904022002135543/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=8645904022002135543' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/8645904022002135543'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/8645904022002135543'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/12/security-onion-is-in-running-for-2011.html' title='Security Onion is in the running for 2011 Toolsmith Tool of the Year!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-3383469592182571440</id><published>2011-12-14T14:43:00.000-05:00</published><updated>2011-12-14T14:43:29.845-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='purge'/><title type='text'>Security Onion 20111214 now available!</title><content type='html'>&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-7334691449603751704" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 1.4;"&gt;Security Onion 20111214 is now available! &amp;nbsp;This resolves the following issue:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;div class="post-body entry-content" id="post-body-7334691449603751704" style="position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=143"&gt;Issue 143: Need a better solution for purging at 90% disk usage&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 21px;"&gt;The previous purging method only removed old pcaps from the dailylogs directories. &amp;nbsp;The new method removes old pcaps but also purges old argus, httpry, and unified2 files. &amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-7334691449603751704" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 21px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-7334691449603751704" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 21px;"&gt;For those running multiple sensors on the same /nsm, the previous purging method would have deleted all pcaps from the first sensor before beginning to purge the second sensor. &amp;nbsp;The new method tries to delete more evenly across the sensors.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-7334691449603751704" style="background-color: white; position: relative; width: 668px;"&gt;&lt;b style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-7334691449603751704" style="background-color: white; position: relative; width: 668px;"&gt;&lt;b style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;New Users&lt;/b&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-7334691449603751704" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 1.4;"&gt;New users can download and install the 20111103 ISO image using the instructions&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Installation" style="color: #336699; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; text-decoration: none;"&gt;here&lt;/a&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 1.4;"&gt;. &amp;nbsp;The step marked "Install Security Onion updates" will automatically install this update.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;In-place Upgrade&lt;/b&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 1.4;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command (if you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="color: #336699; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; text-decoration: none;"&gt;FAQ&lt;/a&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 1.4;"&gt;):&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;blockquote class="tr_bq" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/blockquote&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 1.4;"&gt;Note that the upgrade script is cumulative and will upgrade any older version of Security Onion to the most recent version (including any updates in between).&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-7334691449603751704" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 21px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="post-body entry-content" id="post-body-7334691449603751704" style="position: relative; width: 668px;"&gt;&lt;b style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;Screenshots&lt;/b&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="http://4.bp.blogspot.com/-3P63YOu2oRg/Tuj3cSkOEpI/AAAAAAAAAWQ/lyVHPPR-1sY/s1600/Screen+Shot+2011-12-14+at+7.19.11+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="176" src="http://4.bp.blogspot.com/-3P63YOu2oRg/Tuj3cSkOEpI/AAAAAAAAAWQ/lyVHPPR-1sY/s640/Screen+Shot+2011-12-14+at+7.19.11+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="font-size: 13px;"&gt;&lt;b&gt;Upgrade Process&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Purging&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-7334691449603751704" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;/etc/cron.d/sensor-clean contains a cronjob that runs the purge hourly. &amp;nbsp;You can manually run the purge as follows:&lt;/span&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;sudo /usr/local/sbin/nsm --sensor --clean&lt;/span&gt;&lt;/blockquote&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-iASeAcmUre8/Tuj3yHpo4HI/AAAAAAAAAWg/VJ08fFhjl6c/s1600/Screen+Shot+2011-12-14+at+11.26.23+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="236" src="http://4.bp.blogspot.com/-iASeAcmUre8/Tuj3yHpo4HI/AAAAAAAAAWg/VJ08fFhjl6c/s640/Screen+Shot+2011-12-14+at+11.26.23+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;sudo /usr/local/sbin/nsm --sensor --clean&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-3383469592182571440?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/3383469592182571440/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=3383469592182571440' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/3383469592182571440'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/3383469592182571440'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/12/security-onion-20111214-now-available.html' title='Security Onion 20111214 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-3P63YOu2oRg/Tuj3cSkOEpI/AAAAAAAAAWQ/lyVHPPR-1sY/s72-c/Screen+Shot+2011-12-14+at+7.19.11+AM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-7334691449603751704</id><published>2011-12-12T16:22:00.000-05:00</published><updated>2011-12-13T06:11:08.854-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='suricata'/><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><title type='text'>Security Onion 20111213 now available!</title><content type='html'>&lt;br /&gt;Security Onion 20111213 is now available! &amp;nbsp;This resolves the following issues:&lt;br /&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=168"&gt;Issue 168: Suricata 1.1.1&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;If you are already using Suricata and have customized your suricata.yaml file, please note that it will be backed up to /nsm/backup/20111213/NAME-OF-SENSOR/ and then overwritten with the new config file. &amp;nbsp;Please copy any of your customizations (HOME_NET, etc.) from /nsm/backup/20111127/NAME-OF-SENSOR/suricata.yaml to the production copy /etc/nsm/NAME-OF-SENSOR/suricata.yaml.&lt;br /&gt;&lt;br /&gt;As noted &lt;a href="http://securityonion.blogspot.com/2011/11/notes-on-suricata-11-update.html"&gt;here&lt;/a&gt;, Suricata includes some anomaly detection in the form of&amp;nbsp;decoder-events.rules and stream-events.rules. &amp;nbsp;These two rulesets have been disabled in this update. &amp;nbsp;You can manually re-enable them if desired.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;New Users&lt;/b&gt;&lt;br /&gt;New users can download and install the 20111103 ISO image using the instructions &lt;a href="http://code.google.com/p/security-onion/wiki/Installation"&gt;here&lt;/a&gt;. &amp;nbsp;The step marked "Install Security Onion updates" will automatically install this update.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;In-place Upgrade&lt;/b&gt;&lt;br /&gt;Existing Security Onion users can perform an in-place upgrade using the following command (if you're behind a proxy, remember to set your proxy variables as described in the &lt;a href="http://code.google.com/p/security-onion/wiki/FAQ"&gt;FAQ&lt;/a&gt;):&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/blockquote&gt;Note that the upgrade script is cumulative and will upgrade any older version of Security Onion to the most recent version (including any updates in between).&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Switching to Suricata&lt;/b&gt;&lt;br /&gt;If you're currently running Snort and would like to switch to Suricata, use the following commands to stop Snort, change the ENGINE variable in the config file, and then run PulledPork to download the Suricata-specific ruleset (if running Emerging Threats rules):&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;sudo nsm_sensor_ps-stop --only-snort-alert&lt;br /&gt;sudo sed -i 's|ENGINE=snort|ENGINE=suricata|g' /etc/nsm/securityonion.conf&lt;br /&gt;sudo /usr/local/bin/pulledpork_update.sh&amp;nbsp;&lt;/blockquote&gt;&lt;br /&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-XGcIKV3S-xU/TuZwHW5NAiI/AAAAAAAAAWA/XyeFjprdCZs/s1600/Screen+Shot+2011-12-12+at+3.08.24+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="240" src="http://3.bp.blogspot.com/-XGcIKV3S-xU/TuZwHW5NAiI/AAAAAAAAAWA/XyeFjprdCZs/s640/Screen+Shot+2011-12-12+at+3.08.24+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Upgrade Process&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-7334691449603751704?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/7334691449603751704/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=7334691449603751704' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/7334691449603751704'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/7334691449603751704'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/12/security-onion-20111213-now-available.html' title='Security Onion 20111213 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-XGcIKV3S-xU/TuZwHW5NAiI/AAAAAAAAAWA/XyeFjprdCZs/s72-c/Screen+Shot+2011-12-12+at+3.08.24+PM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-3068967371755070496</id><published>2011-12-01T16:35:00.001-05:00</published><updated>2011-12-02T06:26:30.982-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='xplico'/><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='https'/><category scheme='http://www.blogger.com/atom/ns#' term='squert'/><title type='text'>Security Onion 20111202 now available!</title><content type='html'>&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-1543482178545517585" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-7884812677005820949" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-1970587185821497260" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-1455975386190798330" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-4728422209293164403" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="p1" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;Security Onion 20111202 is now available! &amp;nbsp;This resolves the following issue:&lt;/div&gt;&lt;div class="p1"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=139"&gt;Issue 139&lt;/a&gt;:&amp;nbsp;Squert needs HTTPS&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="p1" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 22px; line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 21px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="p1" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 22px; line-height: 1.4; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 21px;"&gt;This update will convert Squert and Xplico to HTTPS. &amp;nbsp;It will also automatically update any Squert/Xplico shortcuts contained within the Security Onion installation to use HTTPS. &amp;nbsp;If you have any Squert/Xplico bookmarks on any other computers in your network, you should just need to change them from HTTP to HTTPS.&lt;/span&gt;&lt;/div&gt;&lt;div class="p1" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 22px; line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 21px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="p1" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;b&gt;New Users&lt;/b&gt;&lt;/div&gt;&lt;div class="p6" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;New users can download and install the 20111103 ISO image using the instructions&amp;nbsp;&lt;span class="s1"&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Installation" style="color: #336699; text-decoration: none;"&gt;here&lt;/a&gt;. &amp;nbsp;The step marked "Install Security Onion updates" will automatically install this update.&lt;/span&gt;&lt;/div&gt;&lt;div class="p5" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="p1" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;b&gt;In-place Upgrade&lt;/b&gt;&lt;/div&gt;&lt;div class="p1" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command&amp;nbsp;(if you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="color: #336699; text-decoration: none;"&gt;&lt;span class="s3"&gt;FAQ&lt;/span&gt;&lt;/a&gt;):&lt;/div&gt;&lt;blockquote class="tr_bq" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/blockquote&gt;&lt;div class="p7" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;Note that the upgrade script is cumulative and will upgrade any older version of Security Onion to the most recent version (including any updates in between).&lt;/div&gt;&lt;div class="p7" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-zqofe6SQ6Lo/TtfzcYX3DNI/AAAAAAAAAV4/YdnYxyLuIIk/s1600/Screen+Shot+2011-12-01+at+4.29.14+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="506" src="http://1.bp.blogspot.com/-zqofe6SQ6Lo/TtfzcYX3DNI/AAAAAAAAAV4/YdnYxyLuIIk/s640/Screen+Shot+2011-12-01+at+4.29.14+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Upgrade Process&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-3068967371755070496?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/3068967371755070496/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=3068967371755070496' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/3068967371755070496'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/3068967371755070496'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/12/security-onion-20111202-now-available.html' title='Security Onion 20111202 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-zqofe6SQ6Lo/TtfzcYX3DNI/AAAAAAAAAV4/YdnYxyLuIIk/s72-c/Screen+Shot+2011-12-01+at+4.29.14+PM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-1543482178545517585</id><published>2011-12-01T05:56:00.001-05:00</published><updated>2011-12-01T06:13:16.082-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='pulledpork'/><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='sguil'/><title type='text'>Security Onion 20111201 now available!</title><content type='html'>&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-7884812677005820949" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-1970587185821497260" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-1455975386190798330" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-4728422209293164403" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="p1" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;Security Onion 20111201 is now available! &amp;nbsp;This resolves the following issues:&lt;/div&gt;&lt;div class="p1"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=157"&gt;Issue 157&lt;/a&gt;:&amp;nbsp;Update pulledpork.conf.master with new local_rules declaration&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="p1"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 21px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=159"&gt;Issue 159&lt;/a&gt;:&amp;nbsp;NSM scripts are storing initial Sguil credentials in /etc/nsm/securityonion/server.conf&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="p1"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 21px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="p1" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;b&gt;New Users&lt;/b&gt;&lt;/div&gt;&lt;div class="p6" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;New users can download and install the 20111103 ISO image using the instructions&amp;nbsp;&lt;span class="s1"&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Installation" style="color: #336699; text-decoration: none;"&gt;here&lt;/a&gt;. &amp;nbsp;The step marked "Install Security Onion updates" will automatically install this update.&lt;/span&gt;&lt;/div&gt;&lt;div class="p5" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="p1" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;b&gt;In-place Upgrade&lt;/b&gt;&lt;/div&gt;&lt;div class="p1" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command&amp;nbsp;(if you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="color: #336699; text-decoration: none;"&gt;&lt;span class="s3"&gt;FAQ&lt;/span&gt;&lt;/a&gt;):&lt;/div&gt;&lt;blockquote class="tr_bq" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/blockquote&gt;&lt;div class="p7" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;Note that the upgrade script is cumulative and will upgrade any older version of Security Onion to the most recent version (including any updates in between).&lt;/div&gt;&lt;div class="p7" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-rfRLnfYOi1A/TtdeceApyjI/AAAAAAAAAVw/uQEnjpi2qzg/s1600/Screen+Shot+2011-11-30+at+11.29.32+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="266" src="http://2.bp.blogspot.com/-rfRLnfYOi1A/TtdeceApyjI/AAAAAAAAAVw/uQEnjpi2qzg/s640/Screen+Shot+2011-11-30+at+11.29.32+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Upgrade Process&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-1543482178545517585?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/1543482178545517585/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=1543482178545517585' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/1543482178545517585'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/1543482178545517585'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/12/security-onion-20111201-now-available.html' title='Security Onion 20111201 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-rfRLnfYOi1A/TtdeceApyjI/AAAAAAAAAVw/uQEnjpi2qzg/s72-c/Screen+Shot+2011-11-30+at+11.29.32+AM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-7884812677005820949</id><published>2011-11-30T09:11:00.001-05:00</published><updated>2011-11-30T09:27:19.856-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='email'/><category scheme='http://www.blogger.com/atom/ns#' term='sguil'/><title type='text'>Security Onion 20111130 now available!</title><content type='html'>&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-1970587185821497260" style="background-color: white; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-1455975386190798330" style="background-color: white; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-4728422209293164403" style="background-color: white; font-size: 16px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;div class="p1" style="color: #333333; font-size: 15px; line-height: 1.4;"&gt;Security Onion 20111130 is now available! &amp;nbsp;This resolves the following issue:&lt;/div&gt;&lt;div class="p1" style="font-size: 15px; line-height: 1.4;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=144"&gt;&lt;span class="Apple-style-span" style="color: #0b5394;"&gt;&lt;span class="Apple-style-span"&gt;Issue 14&lt;/span&gt;4&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;&amp;nbsp;- sguild.email configuration not loading properly&lt;/span&gt;&lt;/div&gt;&lt;div class="p1" style="color: #333333; font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="p1" style="color: #333333; font-size: 15px; line-height: 1.4;"&gt;&lt;b&gt;New Users&lt;/b&gt;&lt;/div&gt;&lt;div class="p6" style="color: #333333; font-size: 15px; line-height: 1.4;"&gt;New users can download and install the new 20111103 ISO image using the instructions&amp;nbsp;&lt;span class="s1"&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Installation" style="color: #336699; text-decoration: none;"&gt;here&lt;/a&gt;. &amp;nbsp;The step marked "Install Security Onion updates" will automatically install this update.&lt;/span&gt;&lt;/div&gt;&lt;div class="p5" style="color: #333333; font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="p1" style="color: #333333; font-size: 15px; line-height: 1.4;"&gt;&lt;b&gt;In-place Upgrade&lt;/b&gt;&lt;/div&gt;&lt;div class="p1" style="color: #333333; font-size: 15px; line-height: 1.4;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command&amp;nbsp;(if you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="color: #336699; text-decoration: none;"&gt;&lt;span class="s3"&gt;FAQ&lt;/span&gt;&lt;/a&gt;):&lt;/div&gt;&lt;blockquote class="tr_bq" style="color: #333333; font-size: 15px; line-height: 1.4;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/blockquote&gt;&lt;div class="p7" style="color: #333333; font-size: 15px; line-height: 1.4;"&gt;Note that the upgrade script is cumulative and will upgrade any older version of Security Onion to the most recent version (including any updates in between).&lt;/div&gt;&lt;div class="p7" style="color: #333333; font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="color: #333333; margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/--4MLCj9qhlU/TtY7PjHQfrI/AAAAAAAAAVg/8-pyPbQe6gA/s1600/Screen+Shot+2011-11-30+at+8.09.02+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="134" src="http://3.bp.blogspot.com/--4MLCj9qhlU/TtY7PjHQfrI/AAAAAAAAAVg/8-pyPbQe6gA/s640/Screen+Shot+2011-11-30+at+8.09.02+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Upgrade Process&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="p7" style="color: #333333; font-size: 15px; line-height: 1.4;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-7884812677005820949?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/7884812677005820949/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=7884812677005820949' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/7884812677005820949'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/7884812677005820949'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/11/security-onion-20111130-now-available.html' title='Security Onion 20111130 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/--4MLCj9qhlU/TtY7PjHQfrI/AAAAAAAAAVg/8-pyPbQe6gA/s72-c/Screen+Shot+2011-11-30+at+8.09.02+AM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-5297697317690400255</id><published>2011-11-29T06:56:00.001-05:00</published><updated>2011-11-29T07:26:42.727-05:00</updated><title type='text'>Notes on Suricata 1.1 Update</title><content type='html'>A few quick notes on the &lt;a href="http://securityonion.blogspot.com/2011/11/security-onion-20111127-now-available.html"&gt;Suricata 1.1 update&lt;/a&gt;&amp;nbsp;and its default suricata.yaml configuration file:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;decoder-events.rules and stream-events.rules&lt;/b&gt;&lt;br /&gt;By default, suricata.yaml includes the following rules:&lt;br /&gt;&amp;nbsp;- decoder-events.rules&lt;br /&gt;&amp;nbsp;- stream-events.rules&lt;br /&gt;&lt;br /&gt;This results in alerts like these:&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-oQpEeyFh_UI/TtTMjjDKlNI/AAAAAAAAAVY/JperAwADX-c/s1600/Screen+Shot+2011-11-29+at+7.13.25+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="220" src="http://1.bp.blogspot.com/-oQpEeyFh_UI/TtTMjjDKlNI/AAAAAAAAAVY/JperAwADX-c/s640/Screen+Shot+2011-11-29+at+7.13.25+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Suricata stream events example&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;If you don't wish to see these alerts, simply comment out those two rules in /etc/nsm/NAME-OF-SENSOR/suricata.yaml and restart Suricata.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;EXTERNAL_NET&lt;/b&gt;&lt;br /&gt;By default, suricata.yaml sets EXTERNAL_NET to "!HOME_NET". &amp;nbsp;(The Snort default in snort.conf is "EXTERNAL_NET any".) &amp;nbsp;If you'd like to change this, simply make the change in /etc/nsm/NAME-OF-SENSOR/suricata.yaml and restart Suricata.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;How do I edit suricata.yaml and restart Suricata?&lt;/b&gt;&lt;br /&gt;If you have GUI access to your sensor, you can use the "IDS Config" menu entry as described here:&lt;br /&gt;&lt;a href="http://securityonion.blogspot.com/2011/09/security-onion-20110909-now-available.html"&gt;http://securityonion.blogspot.com/2011/09/security-onion-20110909-now-available.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Otherwise, you can do the following:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Modify&amp;nbsp;/etc/nsm/NAME-OF-SENSOR/suricata.yaml&amp;nbsp;using your favorite text editor.&lt;/li&gt;&lt;li&gt;Restart Suricata using the following command:&lt;br /&gt;sudo nsm --sensor --restart --only-snort-alert&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-5297697317690400255?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/5297697317690400255/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=5297697317690400255' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/5297697317690400255'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/5297697317690400255'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/11/notes-on-suricata-11-update.html' title='Notes on Suricata 1.1 Update'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-oQpEeyFh_UI/TtTMjjDKlNI/AAAAAAAAAVY/JperAwADX-c/s72-c/Screen+Shot+2011-11-29+at+7.13.25+AM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-924741423095467718</id><published>2011-11-27T16:04:00.001-05:00</published><updated>2011-11-27T21:43:14.662-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='suricata'/><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><title type='text'>Security Onion 20111127 now available!</title><content type='html'>&lt;span class="Apple-style-span" style="background-color: white; font-family: Times, 'Times New Roman', serif; line-height: 22px;"&gt;Security Onion 20111127 is now available! &amp;nbsp;This resolves the following issues:&lt;/span&gt;&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-1970587185821497260" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-1455975386190798330" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-4728422209293164403" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="p1" style="line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=134"&gt;Issue 134&lt;/a&gt; - Upgrade Suricata to 1.1&lt;/span&gt;&lt;/div&gt;&lt;div class="p1" style="line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=153"&gt;Issue 153&lt;/a&gt;&lt;span class="Apple-style-span"&gt; -&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: normal; white-space: pre-wrap;"&gt;When IDS Engine is Suricata, PulledPork needs to download Suricata version of ET rules&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="p1" style="line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="p1" style="line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif; line-height: 20px;"&gt;If you are already using Suricata and have customized your suricata.yaml file, please note that it will be backed up to /nsm/backup/20111127/NAME-OF-SENSOR/ and then overwritten with the new config file. &amp;nbsp;Please copy any of your customizations (HOME_NET, etc.) from /nsm/backup/20111127/NAME-OF-SENSOR/suricata.yaml to the production copy /etc/nsm/NAME-OF-SENSOR/suricata.yaml.&lt;/span&gt;&lt;/div&gt;&lt;div class="p1" style="line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="p1" style="line-height: 1.4;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;New Users&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="p6" style="line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;New users can download and install the 20111103 ISO image using the instructions&amp;nbsp;&lt;span class="s1"&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Installation" style="text-decoration: none;"&gt;here&lt;/a&gt;. &amp;nbsp;The step marked "Install Security Onion updates" will automatically install this update.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="p5" style="line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="p1" style="line-height: 1.4;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;In-place Upgrade&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="p1" style="line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command&amp;nbsp;(if you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="text-decoration: none;"&gt;&lt;span class="s3"&gt;FAQ&lt;/span&gt;&lt;/a&gt;):&lt;/span&gt;&lt;/div&gt;&lt;blockquote class="tr_bq" style="line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/span&gt;&lt;/blockquote&gt;&lt;div class="p7" style="line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;Note that the upgrade script is cumulative and will upgrade any older version of Security Onion to the most recent version (including any updates in between).&lt;/span&gt;&lt;/div&gt;&lt;div class="p7" style="line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="p7" style="line-height: 1.4;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;Switching to Suricata&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="p7" style="line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;If you're currently running Snort and would like to switch to Suricata, use the following commands to stop Snort, change the ENGINE variable in the config file, and then run PulledPork to download the Suricata-specific ruleset (if running Emerging Threats rules):&lt;/span&gt;&lt;/div&gt;&lt;div class="p7" style="line-height: 1.4;"&gt;&lt;blockquote class="tr_bq"&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;sudo nsm_sensor_ps-stop --only-snort-alert&lt;br /&gt;sudo sed -i 's|ENGINE=snort|ENGINE=suricata|g' /etc/nsm/securityonion.conf&lt;br /&gt;sudo /usr/local/bin/pulledpork_update.sh&lt;span class="s1"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;div class="p7"&gt;&lt;b style="line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;Screenshots&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Xz-9WlL_mQ0/TtLSmqkjz5I/AAAAAAAAAVQ/Lay0Ad-CTpM/s1600/Screen+Shot+2011-11-27+at+7.14.54+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;span class="Apple-style-span" style="color: black; font-family: Times, 'Times New Roman', serif;"&gt;&lt;img border="0" height="444" src="http://1.bp.blogspot.com/-Xz-9WlL_mQ0/TtLSmqkjz5I/AAAAAAAAAVQ/Lay0Ad-CTpM/s640/Screen+Shot+2011-11-27+at+7.14.54+PM.png" width="640" /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif; font-size: small;"&gt;Upgrade Process&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="p7"&gt;&lt;b style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-924741423095467718?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/924741423095467718/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=924741423095467718' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/924741423095467718'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/924741423095467718'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/11/security-onion-20111127-now-available.html' title='Security Onion 20111127 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-Xz-9WlL_mQ0/TtLSmqkjz5I/AAAAAAAAAVQ/Lay0Ad-CTpM/s72-c/Screen+Shot+2011-11-27+at+7.14.54+PM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-6761062438967541839</id><published>2011-11-17T09:31:00.001-05:00</published><updated>2011-11-23T17:25:33.936-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='ossec'/><title type='text'>Follow-up on OSSEC alerts for packet loss</title><content type='html'>&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;This is a follow-up to my recent post "&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;a href="http://securityonion.blogspot.com/2011/11/how-do-i-receive-email-when-my-sensor.html"&gt;How do I receive an email when my sensor stops receiving traffic?&lt;/a&gt;". &amp;nbsp;That post explains the core idea which I have since refined.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;b&gt;Refinement #1: Tell me which interface stopped receiving traffic&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;The first area of refinement is making the output a little more verbose so that, if we have multiple interfaces, we know exactly which interface stopped receiving traffic. &amp;nbsp;We do that by modifying the "bandwidth" command in&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;/var/ossec/etc/ossec.conf as follows:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&amp;nbsp; &amp;lt;localfile&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;log_format&amp;gt;command&amp;lt;/log_format&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;command&amp;gt;grep -v "^#" /etc/nsm/sensortab |awk '{print $1}' |while read SENSOR; do INTERFACE=`echo $SENSOR|cut -d\- -f3`; echo -n "$INTERFACE: "; tail -1 /nsm/sensor_data/$SENSOR/snort.st&lt;br /&gt;ats |cut -d\, -f3; done&amp;lt;/command&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;alias&amp;gt;bandwidth&amp;lt;/alias&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;lt;/localfile&amp;gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;b&gt;Refinement #2: Give me more flexibility in the OSSEC rule structure&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;The second area of refinement is implementing a tiered OSSEC rule structure. &amp;nbsp;This gives us more flexibility and troubleshooting capability. &amp;nbsp;We do this by editing&amp;nbsp;/var/ossec/rules/local_rules.xml and&amp;nbsp;replacing our previous single rule with these two rules:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&amp;nbsp;&amp;lt;rule id="100001" level="1"&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;if_sid&amp;gt;530&amp;lt;/if_sid&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;match&amp;gt;ossec: output: 'bandwidth':&amp;lt;/match&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;description&amp;gt;Bandwidth statistics from snort.stats&amp;lt;/description&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;lt;/rule&amp;gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;blockquote class="tr_bq"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&amp;nbsp; &amp;lt;rule id="100002" level="7"&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;if_sid&amp;gt;100001&amp;lt;/if_sid&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;regex&amp;gt;0.000&amp;lt;/regex&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;description&amp;gt;Bandwidth down to 0.000. &amp;nbsp;Please check interface, cabling, and tap/span!&amp;lt;/description&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;lt;/rule&amp;gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;The first rule just identifies "bandwidth" output and only logs it to disk (level 1 alerts do not generate email by default). &amp;nbsp;The second rule is a child rule of the first and alerts/emails (level 7) when bandwidth is down to 0.000.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Since we're now logging all "bandwidth" output, we can search for it in the OSSEC logs:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;blockquote class="tr_bq"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;grep "bandwidth" /var/ossec/logs/alerts/alerts.log&lt;br /&gt;2011 Nov 17 14:28:50 so-&amp;gt;bandwidth&lt;br /&gt;ossec: output: 'bandwidth': eth4: 8.940&lt;br /&gt;2011 Nov 17 14:28:50 so-&amp;gt;bandwidth&lt;br /&gt;ossec: output: 'bandwidth': eth5: 7.189&lt;br /&gt;2011 Nov 17 14:38:54 so-&amp;gt;bandwidth&lt;br /&gt;ossec: output: 'bandwidth': eth4: 8.920&lt;br /&gt;2011 Nov 17 14:38:54 so-&amp;gt;bandwidth&lt;br /&gt;ossec: output: 'bandwidth': eth5: 7.223&lt;/span&gt;&lt;/blockquote&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;b&gt;Refinement #3: Use Linux kernel's built-in packet counters instead of relying on snort.stats&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;The third area of refinement is not relying on snort.stats but instead using the Linux kernel's built-in packet counters. &amp;nbsp;(I hinted at this in the previous post.) &amp;nbsp;This could be used to replace the entire "bandwidth" configuration above, or to complement it for a belt-and-suspenders approach. &amp;nbsp;We start off by adding the following to /var/ossec/etc/ossec.conf:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&amp;nbsp; &amp;lt;localfile&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;log_format&amp;gt;command&amp;lt;/log_format&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;command&amp;gt;grep -v "^#" /etc/nsm/sensortab |awk '{print $4}' |while read SENSOR; do echo -n "$SENSOR: "; RX1=`ifconfig $SENSOR |awk '/RX packets/ {print $2}' |cut -d\: -f2`; sleep 300; RX2&lt;br /&gt;=`ifconfig $SENSOR |awk '/RX packets/ {print $2}' |cut -d\: -f2`; expr $RX2 - $RX1; done&amp;lt;/command&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;alias&amp;gt;packets_received&amp;lt;/alias&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;lt;/localfile&amp;gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;This follows the same format as the "bandwidth" command, but pulls the count of received packets from ifconfig, waits 5 minutes, pulls the RX count from ifconfig a second time, and subtracts the first from the second to get the total number of packets received in the 5-minute interval.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Next, we add these two rules to /var/ossec/rules/local_rules.xml:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;blockquote class="tr_bq"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&amp;nbsp; &amp;lt;rule id="100003" level="1"&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;if_sid&amp;gt;530&amp;lt;/if_sid&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;match&amp;gt;ossec: output: 'packets_received':&amp;lt;/match&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;description&amp;gt;Number of packets received in 5-minute interval&amp;lt;/description&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;lt;/rule&amp;gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;blockquote class="tr_bq"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&amp;lt;rule id="100004" level="7"&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;if_sid&amp;gt;100003&amp;lt;/if_sid&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;regex&amp;gt; 0&amp;lt;/regex&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;description&amp;gt;Received 0 packets in a 5-minute interval. &amp;nbsp;Please check interface, cabling, and tap/span!&amp;lt;/description&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;lt;/rule&amp;gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Since we're now logging all "packets_received" output, we can search for it in the OSSEC logs:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;blockquote class="tr_bq"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;grep "packets_received" /var/ossec/logs/alerts/alerts.log&lt;/span&gt;&lt;/blockquote&gt;&lt;blockquote class="tr_bq"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;2011 Nov 17 14:33:50 so-&amp;gt;packets_received&lt;br /&gt;ossec: output: 'packets_received': eth4: 70969&lt;br /&gt;2011 Nov 17 14:38:50 so-&amp;gt;packets_received&lt;br /&gt;ossec: output: 'packets_received': eth5: 63059&lt;br /&gt;2011 Nov 17 14:43:54 so-&amp;gt;packets_received&lt;br /&gt;ossec: output: 'packets_received': eth4: 71030&lt;br /&gt;2011 Nov 17 14:48:54 so-&amp;gt;packets_received&lt;br /&gt;ossec: output: 'packets_received': eth5: 67475&lt;/span&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;When the number of received packets drops to 0, rule 100004 triggers a level 7 alert, generating an email if configured to do so.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-6761062438967541839?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/6761062438967541839/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=6761062438967541839' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/6761062438967541839'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/6761062438967541839'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/11/follow-up-on-ossec-alerts-for-packet.html' title='Follow-up on OSSEC alerts for packet loss'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-1970587185821497260</id><published>2011-11-17T09:09:00.001-05:00</published><updated>2011-11-18T06:38:25.948-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='barnyard2'/><title type='text'>Security Onion 20111118 now available!</title><content type='html'>&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-1455975386190798330" style="background-color: white; color: #333333; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-4728422209293164403" style="background-color: white; font-size: 16px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;div class="p1" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;Security Onion 20111118 is now available! &amp;nbsp;This resolves the following issue:&lt;/div&gt;&lt;div class="p1" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=141"&gt;Issue 141&lt;/a&gt; - Upgrade Barnyard2&lt;/div&gt;&lt;div class="p1" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="p1" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;b&gt;New Users&lt;/b&gt;&lt;/div&gt;&lt;div class="p6" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;New users can download and install the new 20111103 ISO image using the instructions&amp;nbsp;&lt;span class="s1"&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Installation" style="color: #336699; text-decoration: none;"&gt;here&lt;/a&gt;&amp;nbsp;and then follow the In-Place Upgrade instructions below.&lt;/span&gt;&lt;/div&gt;&lt;div class="p5" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="p1" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;b&gt;In-place Upgrade&lt;/b&gt;&lt;/div&gt;&lt;div class="p1" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command&amp;nbsp;(if you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="color: #336699; text-decoration: none;"&gt;&lt;span class="s3"&gt;FAQ&lt;/span&gt;&lt;/a&gt;):&lt;/div&gt;&lt;blockquote class="tr_bq" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/blockquote&gt;&lt;div class="p7" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;Note that the upgrade script is cumulative and will upgrade any older version of Security Onion to the most recent version (including any updates in between).&lt;/div&gt;&lt;div class="p7" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-CWXhRnyvQUc/TsUV3nQ65HI/AAAAAAAAAU8/ABCioF4KfN0/s1600/Screen+Shot+2011-11-16+at+3.54.11+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="192" src="http://1.bp.blogspot.com/-CWXhRnyvQUc/TsUV3nQ65HI/AAAAAAAAAU8/ABCioF4KfN0/s640/Screen+Shot+2011-11-16+at+3.54.11+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Upgrade Process&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-1970587185821497260?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/1970587185821497260/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=1970587185821497260' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/1970587185821497260'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/1970587185821497260'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/11/security-onion-20111118-now-available.html' title='Security Onion 20111118 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-CWXhRnyvQUc/TsUV3nQ65HI/AAAAAAAAAU8/ABCioF4KfN0/s72-c/Screen+Shot+2011-11-16+at+3.54.11+PM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-1455975386190798330</id><published>2011-11-16T14:11:00.001-05:00</published><updated>2011-11-17T06:24:43.160-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='ossec'/><title type='text'>Security Onion 20111116 now available!</title><content type='html'>&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-4728422209293164403" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="p1" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;Security Onion 20111116 is now available! &amp;nbsp;This resolves the following issue:&lt;/div&gt;&lt;div class="p1"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=150"&gt;&lt;span class="Apple-style-span" style="line-height: 1.4;"&gt;Issue 1&lt;/span&gt;50&lt;/a&gt;&lt;span class="Apple-style-span" style="line-height: 1.4;"&gt;&amp;nbsp;-&lt;/span&gt;&amp;nbsp;Ensure that OSSEC timezone matches the host's timezone&lt;/span&gt;&lt;/div&gt;&lt;div class="p2" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="p1" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;b&gt;New Users&lt;/b&gt;&lt;/div&gt;&lt;div class="p6" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;New users can download and install the new 20111103 ISO image using the instructions&amp;nbsp;&lt;span class="s1"&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Installation" style="text-decoration: none;"&gt;here&lt;/a&gt;&amp;nbsp;and then follow the In-Place Upgrade instructions below.&lt;/span&gt;&lt;/div&gt;&lt;div class="p5" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="p1" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;b&gt;In-place Upgrade&lt;/b&gt;&lt;/div&gt;&lt;div class="p1" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command&amp;nbsp;(if you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="text-decoration: none;"&gt;&lt;span class="s3"&gt;FAQ&lt;/span&gt;&lt;/a&gt;):&lt;/div&gt;&lt;blockquote class="tr_bq" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/blockquote&gt;&lt;div class="p7" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;Note that the upgrade script is cumulative and will upgrade any older version of Security Onion to the most recent version (including any updates in between).&lt;/div&gt;&lt;div class="p7" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-tnh_yI109Dg/TsQMBuuKRxI/AAAAAAAAAU0/crOeObD3PQ0/s1600/Screen+Shot+2011-11-16+at+2.09.21+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="410" src="http://4.bp.blogspot.com/-tnh_yI109Dg/TsQMBuuKRxI/AAAAAAAAAU0/crOeObD3PQ0/s640/Screen+Shot+2011-11-16+at+2.09.21+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Upgrade Process&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="p7" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-1455975386190798330?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/1455975386190798330/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=1455975386190798330' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/1455975386190798330'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/1455975386190798330'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/11/security-onion-20111116-now-available.html' title='Security Onion 20111116 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-tnh_yI109Dg/TsQMBuuKRxI/AAAAAAAAAU0/crOeObD3PQ0/s72-c/Screen+Shot+2011-11-16+at+2.09.21+PM.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-5713572453972848966</id><published>2011-11-15T06:49:00.001-05:00</published><updated>2011-11-15T11:40:02.112-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='span'/><category scheme='http://www.blogger.com/atom/ns#' term='snort'/><category scheme='http://www.blogger.com/atom/ns#' term='ossec'/><category scheme='http://www.blogger.com/atom/ns#' term='tap'/><title type='text'>How do I receive an email when my sensor stops receiving traffic?</title><content type='html'>Recently, I logged into Sguil and noticed that a normally busy sensor had no current alerts. &amp;nbsp;I looked at the full packet capture logs for the sensor and determined that it hadn't received any traffic from the tap in a while. &amp;nbsp;We resolved the issue with the tap and started seeing traffic again, but I also resolved to create an automated notification for the next time this happens.&lt;br /&gt;&lt;br /&gt;Snort is&amp;nbsp;already writing bandwidth statistics to&amp;nbsp;/nsm/sensor_data/$SENSOR/snort.stats and we are going to use OSSEC to monitor the file and send email when the bandwidth drops to 0. &amp;nbsp;We could possibly write an OSSEC decoder to have it parse snort.stats directly, but let's instead use&amp;nbsp;&lt;a href="http://www.ossec.net/doc/manual/monitoring/process-monitoring.html"&gt;OSSEC's process monitoring feature&lt;/a&gt; so that we can perhaps extend this in the future to use the Linux kernel's built-in packet counters. &amp;nbsp;For now, we're going to rely on snort.stats.&lt;br /&gt;&lt;div class="p1"&gt;&lt;br /&gt;The first thing we need to do is obtain the full path to the snort.stats file(s) by determining the interfaces that are being monitored by Sguil. &amp;nbsp;We do this by searching /etc/nsm/sensortab for any lines that are not commented out and piping to awk to print just the first column:&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;grep -v "^#" /etc/nsm/sensortab |awk '{print $1}'&lt;/blockquote&gt;&lt;div class="p1"&gt;For each of the sensors in the output of the previous command, we want to look at the most recent bandwidth statistics, so we pipe to a while-loop and use "tail -1" on the respective snort.stats file:&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;grep -v "^#" /etc/nsm/sensortab |awk '{print $1}' |while read SENSOR; do tail -1 /nsm/sensor_data/$SENSOR/snort.stats; done&lt;/blockquote&gt;&lt;div class="p1"&gt;snort.stats is a CSV file and we only want the third column of data, so we pipe the previous command to cut and tell it the delimiter is a comma and to output the third field:&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;grep -v "^#" /etc/nsm/sensortab |awk '{print $1}' |while read SENSOR; do tail -1 /nsm/sensor_data/$SENSOR/snort.stats; done |cut -d\, -f3&lt;/blockquote&gt;Here's some sample output for a sensor with two monitored interfaces:&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;3.481&lt;br /&gt;0.089&lt;/blockquote&gt;We now have a nice single command that OSSEC can run periodically to retrieve the bandwidth of our monitored interfaces. &amp;nbsp;We add this as a "command" in /var/ossec/etc/ossec.conf and give it an alias of "bandwidth":&lt;br /&gt;&lt;div class="p1"&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&amp;nbsp; &amp;lt;localfile&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;log_format&amp;gt;command&amp;lt;/log_format&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;command&amp;gt;grep -v "^#" /etc/nsm/sensortab |awk '{print $1}' |while read SENSOR; do tail -1 /nsm/sensor_data/$SENSOR/snort.stats; done |cut -d\, -f3&amp;lt;/command&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;alias&amp;gt;bandwidth&amp;lt;/alias&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;lt;/localfile&amp;gt;&lt;/blockquote&gt;&lt;div class="p1"&gt;Upon restart, OSSEC will periodically run the command, but won't do anything with the output until we add a rule to tell it what to do. &amp;nbsp;We add the following rule to /var/ossec/rules/local_rules.xml to check the output hourly (every 3600 seconds) and see if the bandwidth value has gone down to 0.000:&lt;/div&gt;&lt;div class="p1"&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&amp;nbsp; &amp;lt;rule id="100001" level="7" ignore="3600"&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;if_sid&amp;gt;530&amp;lt;/if_sid&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;match&amp;gt;ossec: output: 'bandwidth':&amp;lt;/match&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;regex&amp;gt;0.000&amp;lt;/regex&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;description&amp;gt;Bandwidth down to 0.000. &amp;nbsp;Please check interface, cabling, and tap/span!&amp;lt;/description&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;lt;/rule&amp;gt;&lt;/blockquote&gt;&lt;div class="p1"&gt;If we didn't already have OSSEC configured to send email, we could do so by adding the following to the &amp;lt;global&amp;gt; section of&amp;nbsp;/var/ossec/etc/ossec.conf:&lt;/div&gt;&lt;div class="p1"&gt;&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;&amp;nbsp; &amp;nbsp; &amp;lt;email_notification&amp;gt;yes&amp;lt;/email_notification&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;email_to&amp;gt;YOUR.USERNAME@YOUR-DOMAIN.COM&amp;lt;/email_to&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;smtp_server&amp;gt;YOUR-SMTP-RELAY.YOUR-DOMAIN.COM&amp;lt;/smtp_server&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;email_from&amp;gt;OSSEC@YOUR-DOMAIN.COM&amp;lt;/email_from&amp;gt;&lt;/blockquote&gt;&lt;div class="p1"&gt;Next, we restart OSSEC to activate the new configuration:&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;sudo service ossec restart&lt;/blockquote&gt;&lt;div class="p1"&gt;Finally, we simulate traffic loss and receive an email like the following:&lt;/div&gt;&lt;div&gt;&lt;blockquote&gt;OSSEC HIDS Notification.&lt;br /&gt;2011 Nov 15 06:47:45&lt;br /&gt;Received From: securityonion-&amp;gt;bandwidth&lt;br /&gt;Rule: 100001 fired (level 7) -&amp;gt; "Bandwidth down to 0.000. &amp;nbsp;Please check interface, cabling, and tap/span!"&lt;br /&gt;Portion of the log(s):&lt;br /&gt;ossec: output: 'bandwidth': 0.000&lt;/blockquote&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;&lt;b&gt;Update&lt;/b&gt;:&amp;nbsp;&lt;a href="https://plus.google.com/u/0/111329543725174220559/posts/FxHZyDY1M7Z"&gt;A question over on Google+&lt;/a&gt;&amp;nbsp;prompted the following clarification:&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white; line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;Security Onion has Snort's perfmonitor configured for 300-second intervals by default, which means that the value we're inspecting would be the average traffic for 5 minutes. My deployments have enough constant traffic that 0.000 for 5 minutes is a pretty good indicator of failure. YMMV!&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-5713572453972848966?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/5713572453972848966/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=5713572453972848966' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/5713572453972848966'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/5713572453972848966'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/11/how-do-i-receive-email-when-my-sensor.html' title='How do I receive an email when my sensor stops receiving traffic?'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-4728422209293164403</id><published>2011-11-03T07:19:00.001-04:00</published><updated>2011-11-03T07:25:35.567-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='bro'/><title type='text'>Security Onion 20111103 now available!</title><content type='html'>&lt;br /&gt;&lt;div class="p1"&gt;Security Onion 20111103 is now available! &amp;nbsp;This resolves the following issues:&lt;/div&gt;&lt;div class="p1"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=138"&gt;Issue 138&lt;/a&gt; - Time for a new ISO image&lt;/div&gt;&lt;div class="p1"&gt;&lt;span class="s1"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=136"&gt;Issue 136&lt;/a&gt;&lt;/span&gt; - Setup script should automatically set OS timezone to UTC&lt;/div&gt;&lt;div class="p1"&gt;&lt;span class="s1"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=137"&gt;Issue 137&lt;/a&gt;&lt;/span&gt; - Bro 2.0 Beta&lt;/div&gt;&lt;div class="p2"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="p1"&gt;Please note that Bro 2.0 Beta installs to /usr/local/bro/.&lt;/div&gt;&lt;div class="p3"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="p1"&gt;For more information about Bro 2.0 Beta, please see:&lt;/div&gt;&lt;div class="p4"&gt;&lt;span class="s2"&gt;&lt;a href="http://blog.bro-ids.org/2011/10/public-beta-of-bro-20-released.html"&gt;http://blog.bro-ids.org/2011/10/public-beta-of-bro-20-released.html&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="p4"&gt;&lt;span class="s2"&gt;&lt;a href="http://bro-ids.org/documentation-beta/quickstart.bro.html"&gt;http://bro-ids.org/documentation-beta/quickstart.bro.html&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="p4"&gt;&lt;span class="s2"&gt;&lt;a href="http://bro-ids.org/documentation-beta/index.html"&gt;http://bro-ids.org/documentation-beta/index.html&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="p5"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="p6"&gt;&lt;b&gt;New Users&lt;/b&gt;&lt;/div&gt;&lt;div class="p6"&gt;New users can download and install the new 20111103 ISO image using the instructions &lt;span class="s1"&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/Installation"&gt;here&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;&lt;div class="p5"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="p1"&gt;&lt;b&gt;In-place Upgrade&lt;/b&gt;&lt;/div&gt;&lt;div class="p1"&gt;Existing Security Onion users can perform an in-place upgrade using the following command&amp;nbsp;(if you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ"&gt;&lt;span class="s3"&gt;FAQ&lt;/span&gt;&lt;/a&gt;):&lt;/div&gt;&lt;blockquote class="tr_bq"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/blockquote&gt;&lt;div class="p7"&gt;Note that the upgrade script is cumulative and will upgrade any older version of Security Onion to the most recent version (including any updates in between).&lt;/div&gt;&lt;div class="p7"&gt;&lt;br /&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-6910333346473661742" style="background-color: white; position: relative; width: 668px;"&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-yOFVA6ZqOn4/Tq7ncJzZdDI/AAAAAAAAAUM/8LU21-s1Qs8/s1600/Screen+Shot+2011-10-31+at+2.19.50+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="268" src="http://2.bp.blogspot.com/-yOFVA6ZqOn4/Tq7ncJzZdDI/AAAAAAAAAUM/8LU21-s1Qs8/s640/Screen+Shot+2011-10-31+at+2.19.50+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Upgrade Process&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-6910333346473661742" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-6910333346473661742" style="background-color: white; color: #333333; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-eoX65rd9WZs/Tq738UF9HyI/AAAAAAAAAUc/AKM6rBvI8wQ/s1600/Screen+Shot+2011-10-31+at+3.32.15+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="262" src="http://1.bp.blogspot.com/-eoX65rd9WZs/Tq738UF9HyI/AAAAAAAAAUc/AKM6rBvI8wQ/s640/Screen+Shot+2011-10-31+at+3.32.15+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: x-small;"&gt;&lt;b&gt;&lt;i&gt;Completing Upgrade&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-6910333346473661742" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-87pFKyb-e6U/TrJ0uMKA2HI/AAAAAAAAAUk/gpxPElfWikM/s1600/Screen+Shot+2011-11-03+at+7.01.52+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="70" src="http://3.bp.blogspot.com/-87pFKyb-e6U/TrJ0uMKA2HI/AAAAAAAAAUk/gpxPElfWikM/s640/Screen+Shot+2011-11-03+at+7.01.52+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Bro 2.0 Beta in /usr/local/bro/bin/bro&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-6910333346473661742" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-4728422209293164403?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/4728422209293164403/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=4728422209293164403' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/4728422209293164403'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/4728422209293164403'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/11/security-onion-20111103-now-available.html' title='Security Onion 20111103 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-yOFVA6ZqOn4/Tq7ncJzZdDI/AAAAAAAAAUM/8LU21-s1Qs8/s72-c/Screen+Shot+2011-10-31+at+2.19.50+PM.png' height='72' width='72'/><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-6910333346473661742</id><published>2011-10-28T06:46:00.000-04:00</published><updated>2011-10-28T06:46:18.608-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='afpacket'/><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='snort'/><category scheme='http://www.blogger.com/atom/ns#' term='daq'/><title type='text'>Security Onion 20111028 now available!</title><content type='html'>&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-679292465147511865" style="background-color: white; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-1026167962061048823" style="position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-3239612664775068121" style="position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="position: relative; width: 668px;"&gt;&lt;div style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;Security Onion 20111028 is now available! &amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;This resolves&amp;nbsp;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=135"&gt;Issue 135&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;by updating the NSM scripts to start Snort with the AFPACKET DAQ for higher performance. &amp;nbsp;For more information about the AFPACKET DAQ, please see:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;a href="http://manual.snort.org/node7.html"&gt;http://manual.snort.org/node7.html&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://vrt-blog.snort.org/2010/08/snort-29-essentials-daq.html" style="font-family: Arial, Helvetica, sans-serif; font-size: 15px; line-height: 20px;"&gt;http://vrt-blog.snort.org/2010/08/snort-29-essentials-daq.html&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 16px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;div style="font-size: 15px; line-height: 1.4;"&gt;&lt;div style="line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="line-height: 21px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif; font-weight: bold; line-height: 20px;"&gt;In-place Upgrade&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif;"&gt;(if you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="color: #336699; text-decoration: none;"&gt;FAQ&lt;/a&gt;):&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote style="line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; line-height: 21px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;br /&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-VHR4gpaSN_Q/TqlKa8S6GBI/AAAAAAAAAT8/4FG85Zig3Y8/s1600/Screen+Shot+2011-10-27+at+8.06.22+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="218" src="http://1.bp.blogspot.com/-VHR4gpaSN_Q/TqlKa8S6GBI/AAAAAAAAAT8/4FG85Zig3Y8/s640/Screen+Shot+2011-10-27+at+8.06.22+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Upgrade Process&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="post-body entry-content" id="post-body-679292465147511865" style="background-color: white; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-6910333346473661742?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/6910333346473661742/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=6910333346473661742' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/6910333346473661742'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/6910333346473661742'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/10/security-onion-20111028-now-available.html' title='Security Onion 20111028 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-VHR4gpaSN_Q/TqlKa8S6GBI/AAAAAAAAAT8/4FG85Zig3Y8/s72-c/Screen+Shot+2011-10-27+at+8.06.22+AM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-679292465147511865</id><published>2011-10-25T07:21:00.000-04:00</published><updated>2011-10-25T07:21:52.812-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='snort'/><title type='text'>Security Onion 20111025 now available!</title><content type='html'>&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 14px; line-height: 18px;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-1026167962061048823" style="position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-3239612664775068121" style="position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="position: relative; width: 668px;"&gt;&lt;div style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;Security Onion 20111025 is now available! &amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;This resolves &lt;a href="http://code.google.com/p/security-onion/issues/detail?id=84"&gt;Issue 84&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;by updating Snort to version 2.9.1.2 and its DAQ to version 0.6.2. &amp;nbsp;For more information about Snort 2.9.1.2, please see:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;a href="http://blog.snort.org/2011/10/snort-2912-has-been-posted.html"&gt;http://blog.snort.org/2011/10/snort-2912-has-been-posted.html&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="position: relative; width: 668px;"&gt;&lt;div style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;Please note that if you are using the Registered (30-day delay) VRT ruleset you will need to wait until the rules are released for Snort 2.9.1.2. &amp;nbsp;For more information, please see:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;a href="http://blog.snort.org/2011/10/vrt-rule-release-for-10202011-snort.html"&gt;http://blog.snort.org/2011/10/vrt-rule-release-for-10202011-snort.html&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;Please also note that the new snort.conf will overwrite your existing snort.conf. &amp;nbsp;Your existing snort.conf will be backed up to /nsm/backup/20111025/NAME_OF_SENSOR/. &amp;nbsp;Please copy any customizations (HOME_NET, etc.) from the backup copy to the production copy /etc/nsm/NAME_OF_SENSOR/snort.conf.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 21px;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="font-size: 16px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;div style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;div style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 21px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 15px; font-weight: bold; line-height: 20px;"&gt;In-place Upgrade&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 21px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;(i&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;f you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="color: #336699; line-height: 20px; text-decoration: none;"&gt;FAQ&lt;/a&gt;)&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 21px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 21px;"&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 21px;"&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-4Arz3GUJRwM/TqNpNh0F58I/AAAAAAAAATQ/F4G9WyBTxJs/s1600/Screen+Shot+2011-10-22+at+9.05.20+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="262" src="http://3.bp.blogspot.com/-4Arz3GUJRwM/TqNpNh0F58I/AAAAAAAAATQ/F4G9WyBTxJs/s640/Screen+Shot+2011-10-22+at+9.05.20+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Installing new packages&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Dz-cD1IIYzQ/TqNpVkdCCOI/AAAAAAAAATY/5jLVqbr6TPQ/s1600/Screen+Shot+2011-10-22+at+9.07.07+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="32" src="http://1.bp.blogspot.com/-Dz-cD1IIYzQ/TqNpVkdCCOI/AAAAAAAAATY/5jLVqbr6TPQ/s640/Screen+Shot+2011-10-22+at+9.07.07+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Backing up config files and copying new files into place&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-lgshbgNIWE8/TqNpjI3NfSI/AAAAAAAAATg/qpicSNsH55U/s1600/Screen+Shot+2011-10-22+at+9.08.07+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="210" src="http://2.bp.blogspot.com/-lgshbgNIWE8/TqNpjI3NfSI/AAAAAAAAATg/qpicSNsH55U/s640/Screen+Shot+2011-10-22+at+9.08.07+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Running PulledPork to download new ruleset&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-N0J35YGlOtI/TqNpvIkDEeI/AAAAAAAAATo/9yeUIYgixak/s1600/Screen+Shot+2011-10-22+at+9.08.26+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="122" src="http://2.bp.blogspot.com/-N0J35YGlOtI/TqNpvIkDEeI/AAAAAAAAATo/9yeUIYgixak/s640/Screen+Shot+2011-10-22+at+9.08.26+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Stopping the old Snort and starting the new Snort&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-ILe5aqmYQ08/TqNr9vvdzTI/AAAAAAAAATw/NS8whkAdjPA/s1600/Screen+Shot+2011-10-22+at+9.20.26+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="132" src="http://4.bp.blogspot.com/-ILe5aqmYQ08/TqNr9vvdzTI/AAAAAAAAATw/NS8whkAdjPA/s640/Screen+Shot+2011-10-22+at+9.20.26+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;snort -V&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-679292465147511865?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/679292465147511865/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=679292465147511865' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/679292465147511865'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/679292465147511865'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/10/security-onion-20111025-now-available.html' title='Security Onion 20111025 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-4Arz3GUJRwM/TqNpNh0F58I/AAAAAAAAATQ/F4G9WyBTxJs/s72-c/Screen+Shot+2011-10-22+at+9.05.20+PM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-1026167962061048823</id><published>2011-10-22T16:14:00.000-04:00</published><updated>2011-10-22T16:14:23.049-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='daemonlogger'/><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='full packet capture'/><category scheme='http://www.blogger.com/atom/ns#' term='snort'/><title type='text'>Security Onion 20111020 now available!</title><content type='html'>&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 14px; line-height: 18px;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-3239612664775068121" style="font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;Security Onion 20111020 is now available! &amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;This resolves &lt;a href="http://code.google.com/p/security-onion/issues/detail?id=133"&gt;Issue 133&lt;/a&gt; by updating the NSM scripts to spawn daemonlogger (instead of snort) for full packet capture. &amp;nbsp;Since daemonlogger is simpler than snort and specifically designed for packet capture, it is more efficient and possibly more secure.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;In addition, daemonlogger defaults to a snaplen of 65535, so this is a PARTIAL solution to the problem described &lt;a href="http://securityonion.blogspot.com/2011/10/when-is-full-packet-capture-not-full.html"&gt;here&lt;/a&gt;. &amp;nbsp;I emphasize that this only a partial solution because it only solves the full packet capture problem and not the packet reassembly problem. &amp;nbsp;NIC offloading should still be disabled to allow Snort to do proper target-based reassembly and thus minimize the likelihood of insertion/evasion attacks. &amp;nbsp;For more information, please see the &lt;a href="http://manual.snort.org/node7.html"&gt;Snort manual&lt;/a&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="font-size: 16px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;div style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;div style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 15px; font-weight: bold; line-height: 20px;"&gt;In-place Upgrade&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;(i&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;f you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="color: #336699; line-height: 20px; text-decoration: none;"&gt;FAQ&lt;/a&gt;)&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 21px;"&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-e8rtpYiO8xw/TqGjHkbh2ZI/AAAAAAAAATI/-JNnKZDOGuQ/s1600/Screen+Shot+2011-10-21+at+12.51.06+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="294" src="http://4.bp.blogspot.com/-e8rtpYiO8xw/TqGjHkbh2ZI/AAAAAAAAATI/-JNnKZDOGuQ/s640/Screen+Shot+2011-10-21+at+12.51.06+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Upgrade Process&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="post-body entry-content" id="post-body-3239612664775068121" style="font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 21px;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-1026167962061048823?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/1026167962061048823/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=1026167962061048823' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/1026167962061048823'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/1026167962061048823'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/10/security-onion-20111020-now-available.html' title='Security Onion 20111020 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-e8rtpYiO8xw/TqGjHkbh2ZI/AAAAAAAAATI/-JNnKZDOGuQ/s72-c/Screen+Shot+2011-10-21+at+12.51.06+PM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-7686288840732190777</id><published>2011-10-19T07:40:00.000-04:00</published><updated>2011-10-19T15:41:16.426-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tso'/><category scheme='http://www.blogger.com/atom/ns#' term='packet size limited during capture'/><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='/etc/network/interfaces'/><category scheme='http://www.blogger.com/atom/ns#' term='gso'/><category scheme='http://www.blogger.com/atom/ns#' term='snort'/><category scheme='http://www.blogger.com/atom/ns#' term='wireshark'/><category scheme='http://www.blogger.com/atom/ns#' term='gro'/><category scheme='http://www.blogger.com/atom/ns#' term='ethtool'/><title type='text'>When is full packet capture NOT full packet capture?</title><content type='html'>I was looking at some packets recently and noticed the Wireshark message "Packet size limited during capture". &amp;nbsp;This was strange since the packets came from a Sguil sensor performing full packet capture using Snort's default snaplen on a standard Ethernet connection (no Jumbo frames and no VLAN tags). &amp;nbsp;Drilling down into the packet capture, some of the packets were 2900 bytes and Snort was only capturing the first 1500 bytes. &amp;nbsp;The full packet capture was not "full" packet capture after all.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;So where did the 2900-byte packets come from?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The OS had enabled by default the following NIC offload features:&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/Large_segment_offload"&gt;tcp-segmentation-offload (tso)&lt;/a&gt;&lt;br /&gt;&lt;a href="http://lwn.net/Articles/188489/"&gt;generic-segmentation-offload (gso)&lt;/a&gt;&lt;br /&gt;&lt;a href="http://lwn.net/Articles/358910/"&gt;generic-receive-offload (gro)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;For more information about these features and their side effects, please see:&lt;br /&gt;&lt;a href="http://www.unleashnetworks.com/blog/?p=307"&gt;http://www.unleashnetworks.com/blog/?p=307&lt;/a&gt;&lt;br /&gt;&lt;a href="http://wiki.wireshark.org/CaptureSetup/Offloading"&gt;http://wiki.wireshark.org/CaptureSetup/Offloading&lt;/a&gt;&lt;br /&gt;&lt;a href="http://manual.snort.org/node7.html"&gt;http://manual.snort.org/node7.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.inliniac.net/blog/2007/04/20/snort_inline-and-tcp-segmentation-offloading.html"&gt;http://www.inliniac.net/blog/2007/04/20/snort_inline-and-tcp-segmentation-offloading.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I won't repeat all the information in those links, but I'll summarize by saying that the NIC was reassembling packets before being passed up the stack to Snort. &amp;nbsp;I disabled the offload features and then verified that this resulted in no more packets larger than 1500 bytes. &amp;nbsp;The packet capture truly was "full" packet capture.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;[ &lt;b&gt;UPDATE&lt;/b&gt;:&amp;nbsp;A reader asked why we couldn't simply change Snort's default snaplen to a larger value to capture the 2900-byte packets. &amp;nbsp;While it's true that would solve the "full" packet capture problem, another problem would remain. &amp;nbsp;Since the packets are being reassembled on the NIC, Snort is not able to properly perform target-based reassembly (see the Snort manual link above). &amp;nbsp;This opens the door for potential IDS evasion/insertion attacks. &amp;nbsp;NIC offload settings need to be disabled so that Snort sees the same packets the destination host does. ]&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Some NIC/driver combinations may disable these offload settings by default, while others enable it by default. &amp;nbsp;You should check your sensors now before you get into a situation where you really need that full packet capture and find out that you don't actually have it. &amp;nbsp;To check, run ethtool with the "-k" (lower-case k) option on the interface you'd like to check. &amp;nbsp;For example, to check eth0:&lt;/div&gt;&lt;div&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;ethtool -k eth0&lt;br /&gt;Offload parameters for eth0:&lt;br /&gt;rx-checksumming: on&lt;br /&gt;tx-checksumming: on&lt;br /&gt;scatter-gather: on&lt;br /&gt;tcp-segmentation-offload: on&lt;br /&gt;udp-fragmentation-offload: off&lt;br /&gt;generic-segmentation-offload: on&lt;br /&gt;generic-receive-offload: on&lt;br /&gt;large-receive-offload: off&lt;/span&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;div&gt;You should repeat this for every interface in your system, as you may have NICs from different manufacturers with different defaults.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You can set these options using the "-K" (upper-case K) option to ethtool and specify which option you'd like to set. &amp;nbsp;For example, to disable tcp-segmentation-offload for eth0:&lt;/div&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="background-color: white; white-space: pre;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;span class="pln"&gt;ethtool &lt;/span&gt;&lt;span class="pun"&gt;-&lt;/span&gt;&lt;span class="pln"&gt;K eth0 tso off&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div&gt;You can set multiple options in one "ethtool" command, but this can be problematic if your card doesn't support all of the settings. &amp;nbsp;To avoid this, you could invoke ethtool for each option like this:&lt;/div&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;ethtool -K eth0 rx off&lt;br /&gt;ethtool -K eth0 tx off&lt;br /&gt;ethtool -K eth0 sg off&lt;br /&gt;ethtool -K eth0 tso off&lt;br /&gt;ethtool -K eth0 ufo off&lt;br /&gt;ethtool -K eth0 gso off&lt;br /&gt;ethtool -K eth0 gro off&lt;br /&gt;ethtool -K eth0 lro off&amp;nbsp;&lt;/span&gt;&lt;/blockquote&gt;&lt;div&gt;Or we could simply wrap the ethtool command in a for-loop like this:&lt;/div&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="background-color: white; white-space: pre;"&gt;&lt;span class="Apple-style-span" style="font-family: Times, 'Times New Roman', serif;"&gt;&lt;span class="kwd"&gt;for&lt;/span&gt;&lt;span class="pln"&gt; i &lt;/span&gt;&lt;span class="kwd"&gt;in&lt;/span&gt;&lt;span class="pln"&gt; rx tx sg tso ufo gso gro lro&lt;/span&gt;&lt;span class="pun"&gt;;&lt;/span&gt;&lt;span class="pln"&gt; &lt;/span&gt;&lt;span class="kwd"&gt;do&lt;/span&gt;&lt;span class="pln"&gt; ethtool &lt;/span&gt;&lt;span class="pun"&gt;-&lt;/span&gt;&lt;span class="pln"&gt;K eth0 $i off&lt;/span&gt;&lt;span class="pun"&gt;;&lt;/span&gt;&lt;span class="pln"&gt; &lt;/span&gt;&lt;span class="kwd"&gt;done&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div&gt;These settings will remain in effect only while the OS is booted, so this needs to be applied at every boot. &amp;nbsp;This can be done by adding the above for-loop as a "post-up" command for each of the interfaces in /etc/network/interfaces. &amp;nbsp;If you're still using the graphical Network Manager to configure your interfaces, I've put together some documentation on disabling it and configuring interfaces and their offloading features via /etc/network/interfaces:&lt;/div&gt;&lt;div&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/NetworkConfiguration"&gt;http://code.google.com/p/security-onion/wiki/NetworkConfiguration&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;I'd really like some feedback on this:&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;What were your default settings? (ethtool -k eth0)&lt;/li&gt;&lt;li&gt;Did you have any problems disabling the offload features?&lt;/li&gt;&lt;li&gt;Did you notice any difference in performance after disabling the offload features?&lt;/li&gt;&lt;li&gt;Is there a better way of disabling offload features globally? &amp;nbsp;I tried putting the commands in /etc/rc.local and /etc/init/securityonion.conf, but the only way I could get it to work consistently was via /etc/network/interfaces as documented above.&lt;/li&gt;&lt;li&gt;I'm considering disabling offload features by default in the Security Onion Setup script. &amp;nbsp;Can anyone think of any reason why this might be a bad idea?&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-7686288840732190777?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/7686288840732190777/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=7686288840732190777' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/7686288840732190777'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/7686288840732190777'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/10/when-is-full-packet-capture-not-full.html' title='When is full packet capture NOT full packet capture?'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-8640341346378878230</id><published>2011-10-18T07:12:00.000-04:00</published><updated>2011-10-18T07:12:04.639-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><title type='text'>Security Onion: Network Security Monitoring in Minutes at BSides Atlanta</title><content type='html'>&lt;span class="Apple-style-span" style="background-color: white; color: #444444; font-family: Georgia, Palatino, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 21px; line-height: 27px;"&gt;I'll be presenting "Security Onion: Network Security Monitoring in Minutes" at&amp;nbsp;&lt;a class="  twitter-hashtag pretty-link" href="https://twitter.com/#!/search?q=%23BSidesATL" rel="nofollow" style="color: #1f98c7; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none; white-space: nowrap;" title="#BSidesATL"&gt;&lt;s class="hash" style="display: inline-block; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; opacity: 0.7; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none;"&gt;#&lt;/s&gt;&lt;b style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; white-space: normal;"&gt;BSidesATL&lt;/b&gt;&lt;/a&gt;&amp;nbsp;on Friday, November 4. &amp;nbsp;For more information, please see:&amp;nbsp;&lt;a class="twitter-timeline-link" data-display-url="goo.gl/w2yZg" data-expanded-url="http://goo.gl/w2yZg" href="http://t.co/LPS6xWAv" rel="nofollow" style="color: #1f98c7; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none;" target="_blank" title="http://goo.gl/w2yZg"&gt;http://goo.gl/w2yZg&lt;/a&gt;. &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #444444; font-family: Georgia, Palatino, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 21px; line-height: 27px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #444444; font-family: Georgia, Palatino, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 21px; line-height: 27px;"&gt;Hope to see you there!&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #444444; font-family: Georgia, Palatino, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 21px; line-height: 27px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-8640341346378878230?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/8640341346378878230/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=8640341346378878230' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/8640341346378878230'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/8640341346378878230'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/10/security-onion-network-security.html' title='Security Onion: Network Security Monitoring in Minutes at BSides Atlanta'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-8899243581950321285</id><published>2011-10-17T10:33:00.002-04:00</published><updated>2011-10-17T10:33:59.460-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='httpry'/><title type='text'>In Search Of Evil User Agents</title><content type='html'>I've got a guest blog post over at PaulDotCom describing how to find evil User Agents on your network using the new httpry functionality in Security Onion:&lt;br /&gt;&lt;a href="http://pauldotcom.com/2011/10/in-search-of-evil-user-agents.html"&gt;In Search Of Evil User Agents&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-8899243581950321285?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/8899243581950321285/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=8899243581950321285' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/8899243581950321285'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/8899243581950321285'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/10/in-search-of-evil-user-agents.html' title='In Search Of Evil User Agents'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-3239612664775068121</id><published>2011-10-14T07:31:00.000-04:00</published><updated>2011-10-14T07:31:31.702-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='httpry'/><title type='text'>Security Onion 20111013 now available!</title><content type='html'>&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;Security Onion 20111013 is now available! &amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;This simple update resolves &lt;a href="http://code.google.com/p/security-onion/issues/detail?id=131"&gt;Issue 131&lt;/a&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="font-size: 16px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;div style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;div style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 15px; font-weight: bold; line-height: 20px;"&gt;In-place Upgrade&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;(i&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;f you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="color: #336699; line-height: 20px; text-decoration: none;"&gt;FAQ&lt;/a&gt;)&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 21px;"&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-GSF_Z-UJZZE/TpgcJH8g7aI/AAAAAAAAAS4/JOVOYRurJu4/s1600/Screen+Shot+2011-10-14+at+7.22.43+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="130" src="http://2.bp.blogspot.com/-GSF_Z-UJZZE/TpgcJH8g7aI/AAAAAAAAAS4/JOVOYRurJu4/s640/Screen+Shot+2011-10-14+at+7.22.43+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Upgrade Process&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-3239612664775068121?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/3239612664775068121/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=3239612664775068121' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/3239612664775068121'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/3239612664775068121'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/10/security-onion-20111013-now-available.html' title='Security Onion 20111013 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-GSF_Z-UJZZE/TpgcJH8g7aI/AAAAAAAAAS4/JOVOYRurJu4/s72-c/Screen+Shot+2011-10-14+at+7.22.43+AM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-1918235618989788226</id><published>2011-10-01T22:54:00.000-04:00</published><updated>2011-10-01T22:54:25.223-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><title type='text'>Security Onion 20111001 now available!</title><content type='html'>&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4; position: relative; width: 668px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;Security Onion 20111001 is now available! &amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;This simple update resolves two issues in /usr/local/bin/pulledpork_update.sh:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="post-body entry-content" id="post-body-4140107779989800812" style="position: relative; width: 668px;"&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=127"&gt;Issue 127&lt;/a&gt; requests that /usr/local/bin/pulledpork_update.sh determine whether it is running interactively or via crontab and perform accordingly.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=87"&gt;A comment on Issue 87&lt;/a&gt; requests that the rule backups /etc/nsm/rules/backup/ be purged after a specified number of days.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;The default number of days is 30.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;This default can be overridden by setting the&amp;nbsp;$DAYSTOKEEP_RULE_BACKUPS variable in /etc/nsm/securityonion.conf.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;div style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 1.4;"&gt;&lt;div style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 15px; font-weight: bold; line-height: 20px;"&gt;In-place Upgrade&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;(i&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;f you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="color: #336699; line-height: 20px; text-decoration: none;"&gt;FAQ&lt;/a&gt;)&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-1918235618989788226?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/1918235618989788226/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=1918235618989788226' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/1918235618989788226'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/1918235618989788226'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/10/security-onion-20111001-now-available.html' title='Security Onion 20111001 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-4140107779989800812</id><published>2011-09-23T10:19:00.000-04:00</published><updated>2011-09-23T10:19:34.857-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='httpry'/><title type='text'>Security Onion 20110922 now available!</title><content type='html'>&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;Security Onion 20110922 is now available! &amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;This update resolves &lt;a href="http://code.google.com/p/security-onion/issues/detail?id=126"&gt;Issue 126&lt;/a&gt;. &amp;nbsp;It also&amp;nbsp;spawns instances of&amp;nbsp;&lt;a href="http://dumpsterventures.com/jason/httpry/"&gt;httpry&lt;/a&gt; and&amp;nbsp;&lt;a href="http://www.pintumbler.org/Code/hafs"&gt;httpry_agent&lt;/a&gt;&amp;nbsp;for each monitored interface. &amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;Thanks go to&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;a href="http://dumpsterventures.com/jason/httpry/"&gt;Jason Bittel&lt;/a&gt; for his work on &lt;a href="http://dumpsterventures.com/jason/httpry/"&gt;httpry&lt;/a&gt; and&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;a href="http://www.pintumbler.org/Code/hafs"&gt;Paul Halliday&lt;/a&gt; for his work on &lt;a href="http://www.pintumbler.org/Code/hafs"&gt;httpry_agent&lt;/a&gt;!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;b&gt;Please note!&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif;"&gt;httpry is going to be logging all HTTP traffic on every monitored interface and httpry_agent is going to be inserting those HTTP logs into the MySQL database so they can be queried in Sguil and SQueRT. &amp;nbsp;This may increase the load on your sensors and/or MySQL server.&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 15px; font-weight: bold; line-height: 20px;"&gt;In-place Upgrade&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;(i&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;f you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="color: #336699; line-height: 20px; text-decoration: none;"&gt;FAQ&lt;/a&gt;)&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&amp;nbsp;&lt;b&gt;Screenshots&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; text-align: center;"&gt;&lt;b&gt;&lt;/b&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-5MRKANT6w4o/TnyLiukgSYI/AAAAAAAAASc/IfVBHWO43gw/s1600/Screen+Shot+2011-09-23+at+9.36.46+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="640" src="http://4.bp.blogspot.com/-5MRKANT6w4o/TnyLiukgSYI/AAAAAAAAASc/IfVBHWO43gw/s640/Screen+Shot+2011-09-23+at+9.36.46+AM.png" width="560" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Upgrade Process&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-qWsZSffZ_kg/TnyMgBhQpmI/AAAAAAAAASk/rQGMD66NuH0/s1600/Screen+Shot+2011-09-23+at+9.40.58+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="134" src="http://1.bp.blogspot.com/-qWsZSffZ_kg/TnyMgBhQpmI/AAAAAAAAASk/rQGMD66NuH0/s640/Screen+Shot+2011-09-23+at+9.40.58+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="font-size: 13px; text-align: center;"&gt;&lt;b&gt;&lt;i&gt;httpry events are autocategorized so as not to clutter the main Sguil window&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Z2xoDloftQI/TnyM5RD0UpI/AAAAAAAAASo/pNCmsbDgFFw/s1600/Screen+Shot+2011-09-23+at+9.42.18+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="130" src="http://1.bp.blogspot.com/-Z2xoDloftQI/TnyM5RD0UpI/AAAAAAAAASo/pNCmsbDgFFw/s640/Screen+Shot+2011-09-23+at+9.42.18+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="font-size: 13px; text-align: center;"&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;If you're responding to an incident for an IP address, search for the IP and you'll see the httpry events are prefixed with "URL"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-AO1Iyn8W3AU/TnyNiR46UAI/AAAAAAAAASs/7eSQgcV_xuM/s1600/Screen+Shot+2011-09-23+at+9.45.26+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="60" src="http://4.bp.blogspot.com/-AO1Iyn8W3AU/TnyNiR46UAI/AAAAAAAAASs/7eSQgcV_xuM/s640/Screen+Shot+2011-09-23+at+9.45.26+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="font-size: 13px; text-align: center;"&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Clicking on a URL event will show further information in the Detail pane&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: right; margin-left: 1em; text-align: right;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-ln-Q167xdjU/TnyODAoCpsI/AAAAAAAAASw/wn4qFrV1bEY/s1600/Screen+Shot+2011-09-23+at+9.47.23+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-ln-Q167xdjU/TnyODAoCpsI/AAAAAAAAASw/wn4qFrV1bEY/s1600/Screen+Shot+2011-09-23+at+9.47.23+AM.png" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="font-size: 13px; text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Right-clicking on the Alert ID allows you to pull the entire transcript&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-QPEqD2d03uw/TnyPh_p4AXI/AAAAAAAAAS0/6TdH_r1ytQk/s1600/Screen+Shot+2011-09-23+at+9.53.22+AM.png" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="272" src="http://4.bp.blogspot.com/-QPEqD2d03uw/TnyPh_p4AXI/AAAAAAAAAS0/6TdH_r1ytQk/s640/Screen+Shot+2011-09-23+at+9.53.22+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="font-size: 13px; text-align: center;"&gt;&lt;b&gt;&lt;i&gt;SQueRT has an httpry search that will show all httpry logs&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-4140107779989800812?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/4140107779989800812/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=4140107779989800812' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/4140107779989800812'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/4140107779989800812'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/09/security-onion-20110922-now-available.html' title='Security Onion 20110922 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-5MRKANT6w4o/TnyLiukgSYI/AAAAAAAAASc/IfVBHWO43gw/s72-c/Screen+Shot+2011-09-23+at+9.36.46+AM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-829867497040695917</id><published>2011-09-20T08:16:00.000-04:00</published><updated>2011-09-20T08:16:29.797-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='squert'/><title type='text'>Security Onion 20110920 now available!</title><content type='html'>&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;Security Onion 20110920 is now available! &amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;This update &lt;a href="http://code.google.com/p/security-onion/issues/detail?id=43"&gt;enables IP-to-country mapping in the SQueRT web interface&lt;/a&gt;&amp;nbsp;(great for showing off to executives)!&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;b&gt;Please note!&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif;"&gt;This upgrade will make changes to the database and therefore it is recommended to backup your MySQL database and/or test the upgrade on a non-production system before deploying to production.&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px; text-align: left;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 15px; font-weight: bold; line-height: 20px;"&gt;In-place Upgrade&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;(i&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;f you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="color: #336699; line-height: 20px; text-decoration: none;"&gt;FAQ&lt;/a&gt;)&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&amp;nbsp;&lt;b&gt;Screenshots&lt;/b&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-JOJT0pAyUIA/TniBiW5CXcI/AAAAAAAAASY/J2-M2WWWiV0/s1600/Screen+Shot+2011-09-20+at+8.04.55+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="480" src="http://3.bp.blogspot.com/-JOJT0pAyUIA/TniBiW5CXcI/AAAAAAAAASY/J2-M2WWWiV0/s640/Screen+Shot+2011-09-20+at+8.04.55+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Upgrade Process&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-ttfPAS-ZxNk/Tnec0J1rWdI/AAAAAAAAASU/vjjlb3toEJc/s1600/Screen+Shot+2011-09-19+at+3.48.39+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="640" src="http://2.bp.blogspot.com/-ttfPAS-ZxNk/Tnec0J1rWdI/AAAAAAAAASU/vjjlb3toEJc/s640/Screen+Shot+2011-09-19+at+3.48.39+PM.png" width="578" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;SQueRT IP-to-country mapping&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div style="color: #333333; font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-829867497040695917?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/829867497040695917/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=829867497040695917' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/829867497040695917'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/829867497040695917'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/09/security-onion-20110920-now-available.html' title='Security Onion 20110920 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-JOJT0pAyUIA/TniBiW5CXcI/AAAAAAAAASY/J2-M2WWWiV0/s72-c/Screen+Shot+2011-09-20+at+8.04.55+AM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-1013439202306158872</id><published>2011-09-19T06:38:00.000-04:00</published><updated>2011-09-19T06:41:36.795-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='argus'/><title type='text'>Security Onion 20110919 now available!</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;Security Onion 20110919 is now available! &amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;This update does the following&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="white-space: pre-wrap;"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;ul style="line-height: 1.4; list-style-image: initial; list-style-position: initial; list-style-type: disc; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.5em; padding-bottom: 0px; padding-left: 2.5em; padding-right: 2.5em; padding-top: 0px;"&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px; white-space: pre-wrap;"&gt;Updates the NSMnow admin scripts to support argus.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px; white-space: pre-wrap;"&gt;Starts argus on all monitored interfaces.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px; white-space: pre-wrap;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px; white-space: pre-wrap;"&gt;Each argus instance will log to the following location:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px; white-space: pre-wrap;"&gt;/nsm/sensor_data/NAME-OF-SENSOR/argus/YYYY-MM-DD.log&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px; white-space: pre-wrap;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 15px; font-weight: bold; line-height: 20px;"&gt;In-place Upgrade&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;(i&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;f you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="color: #336699; line-height: 20px; text-decoration: none;"&gt;FAQ&lt;/a&gt;)&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px; text-align: center;"&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;div style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-zE1sJo0uwIg/TnVcwZ379JI/AAAAAAAAAR4/wzkEEgCjIUg/s1600/Screen+Shot+2011-09-17+at+10.43.01+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="390" src="http://3.bp.blogspot.com/-zE1sJo0uwIg/TnVcwZ379JI/AAAAAAAAAR4/wzkEEgCjIUg/s640/Screen+Shot+2011-09-17+at+10.43.01+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Upgrade script installs new NSM scripts and starts argus on all monitored interfaces (eth0, eth1, and eth2 in this case)&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-PRYA9qE5cgU/TnZCTyU5srI/AAAAAAAAASI/U-cB0CNMOGo/s1600/Screen+Shot+2011-09-18+at+3.10.35+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="110" src="http://2.bp.blogspot.com/-PRYA9qE5cgU/TnZCTyU5srI/AAAAAAAAASI/U-cB0CNMOGo/s640/Screen+Shot+2011-09-18+at+3.10.35+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Running argus processes&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-P6q4Qh8eW4k/TnZDJmi4S8I/AAAAAAAAASM/j4j_Pqkpw8E/s1600/Screen+Shot+2011-09-18+at+3.14.30+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="338" src="http://2.bp.blogspot.com/-P6q4Qh8eW4k/TnZDJmi4S8I/AAAAAAAAASM/j4j_Pqkpw8E/s640/Screen+Shot+2011-09-18+at+3.14.30+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="font-size: 13px; text-align: center;"&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Argus processes log to /nsm/sensor_data/NAME-OF-SENSOR/argus/YYYY-MM-DD.log&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-OTCcVx9YcXs/TnZD_cDAnzI/AAAAAAAAASQ/ei-IZu6kItM/s1600/Screen+Shot+2011-09-18+at+3.18.00+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="494" src="http://3.bp.blogspot.com/-OTCcVx9YcXs/TnZD_cDAnzI/AAAAAAAAASQ/ei-IZu6kItM/s640/Screen+Shot+2011-09-18+at+3.18.00+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="font-size: 13px; text-align: center;"&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Running one of the argus clients (ranonymize, to anonymize my IP addresses) on the argus logs&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-1013439202306158872?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/1013439202306158872/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=1013439202306158872' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/1013439202306158872'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/1013439202306158872'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/09/security-onion-20110919-now-available.html' title='Security Onion 20110919 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-zE1sJo0uwIg/TnVcwZ379JI/AAAAAAAAAR4/wzkEEgCjIUg/s72-c/Screen+Shot+2011-09-17+at+10.43.01+PM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-2807665137278070871</id><published>2011-09-16T06:54:00.000-04:00</published><updated>2011-09-16T06:54:05.755-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='httpry'/><category scheme='http://www.blogger.com/atom/ns#' term='argus'/><category scheme='http://www.blogger.com/atom/ns#' term='pcapcat'/><category scheme='http://www.blogger.com/atom/ns#' term='nftracker'/><title type='text'>Security Onion 20110915 now available!</title><content type='html'>&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;Security Onion 20110915 is now available! &amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;This update does the following&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="white-space: pre-wrap;"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul style="line-height: 1.4; list-style-image: initial; list-style-position: initial; list-style-type: disc; margin-bottom: 0.5em; margin-left: 0px; margin-right: 0px; margin-top: 0.5em; padding-bottom: 0px; padding-left: 2.5em; padding-right: 2.5em; padding-top: 0px;"&gt;&lt;li style="border-bottom-style: none; border-color: initial; border-left-style: none; border-right-style: none; border-top-style: none; border-width: initial; margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="white-space: pre-wrap;"&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=123#c3"&gt;fixes a minor bug in sguil-db-purge&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="border-bottom-style: none; border-color: initial; border-left-style: none; border-right-style: none; border-top-style: none; border-width: initial; margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="white-space: pre-wrap;"&gt;upgrades &lt;a href="http://www.qosient.com/argus/"&gt;Argus&lt;/a&gt; to version 3.0.4 (&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=122"&gt;Issue 122&lt;/a&gt;)&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="border-bottom-style: none; border-color: initial; border-left-style: none; border-right-style: none; border-top-style: none; border-width: initial; margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="white-space: pre-wrap;"&gt;upgrades &lt;a href="http://dumpsterventures.com/jason/httpry/"&gt;httpry&lt;/a&gt; to version 0.1.6 (&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=124"&gt;Issue 124&lt;/a&gt;)&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="border-bottom-style: none; border-color: initial; border-left-style: none; border-right-style: none; border-top-style: none; border-width: initial; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; white-space: pre-wrap;"&gt;installs &lt;a href="http://www.gamelinux.org/?p=193"&gt;nftracker&lt;/a&gt; (&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=54"&gt;Issue 54&lt;/a&gt;)&lt;/span&gt;&lt;/li&gt;&lt;li style="border-bottom-style: none; border-color: initial; border-left-style: none; border-right-style: none; border-top-style: none; border-width: initial; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; white-space: pre-wrap;"&gt;installs &lt;a href="http://blog.kiddaland.net/dw/pcapcat"&gt;pcapcat&lt;/a&gt; (&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=119"&gt;Issue 119&lt;/a&gt;)&lt;/span&gt;&lt;/li&gt;&lt;li style="border-bottom-style: none; border-color: initial; border-left-style: none; border-right-style: none; border-top-style: none; border-width: initial; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; white-space: pre-wrap;"&gt;cleans up existing menu entries and &lt;a href="http://code.google.com/p/security-onion/issues/detail?id=122#c3"&gt;adds new menu entries for Argus&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;In-place Upgrade&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;(i&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;f you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="color: #336699; line-height: 20px; text-decoration: none;"&gt;FAQ&lt;/a&gt;)&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-PGSF1MIkeh4/TnMqkigopHI/AAAAAAAAAR0/XJrYg9VVcO4/s1600/Screen+Shot+2011-09-16+at+6.52.26+AM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="640" src="http://3.bp.blogspot.com/-PGSF1MIkeh4/TnMqkigopHI/AAAAAAAAAR0/XJrYg9VVcO4/s640/Screen+Shot+2011-09-16+at+6.52.26+AM.png" width="278" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;New Argus menu&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-2807665137278070871?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/2807665137278070871/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=2807665137278070871' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/2807665137278070871'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/2807665137278070871'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/09/security-onion-20110915-now-available.html' title='Security Onion 20110915 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-PGSF1MIkeh4/TnMqkigopHI/AAAAAAAAAR0/XJrYg9VVcO4/s72-c/Screen+Shot+2011-09-16+at+6.52.26+AM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-3123964438280261955</id><published>2011-09-15T06:43:00.000-04:00</published><updated>2011-09-15T06:43:51.730-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><title type='text'>Security Onion 20110914 now available!</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;Security Onion 20110914 is now available! &amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;This will &lt;a href="http://code.google.com/p/security-onion/issues/detail?id=78"&gt;update the Setup script to use the new config file format&lt;/a&gt; and &lt;a href="http://code.google.com/p/security-onion/issues/detail?id=123"&gt;install a daily script to purge old alerts from the database&lt;/a&gt;.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: black; line-height: normal; white-space: pre-wrap;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;b&gt;PLEASE NOTE!&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="white-space: pre-wrap;"&gt;sguil-db-purge is scheduled to run &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="white-space: pre-wrap;"&gt;every day at 5:01 AM.  It will do the following:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="background-color: white; white-space: pre-wrap;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;stop sguild&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="background-color: white; white-space: pre-wrap;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;purge old events from the database&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="background-color: white; white-space: pre-wrap;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;repair the remaining MySQL tables&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="background-color: white; white-space: pre-wrap;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;start sguild&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span class="Apple-style-span" style="background-color: white; white-space: pre-wrap;"&gt;The default retention policy for the purge is 365 days.  &lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; white-space: pre-wrap;"&gt;If you would like to change this value, please change &lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; white-space: pre-wrap;"&gt;the DAYSTOKEEP variable in /etc/nsm/securityonion.conf.&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;The daily cron job logs its output to /var/log/nsm/sguil-db-purge.log.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;Since the purge script will be making changes to the database, it is recommended to backup your MySQL database and/or test the purge script on a non-production system before deploying to production.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;In-place Upgrade&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Existing Security Onion users can perform an in-place upgrade using the following command&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;(i&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;f you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="color: #336699; line-height: 20px; text-decoration: none;"&gt;FAQ&lt;/a&gt;)&lt;span class="Apple-style-span" style="color: #333333; line-height: 20px;"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, sans-serif; line-height: 20px;"&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-wjncmJD30ZE/TnEUy9iU4TI/AAAAAAAAARs/9OI5Ridn81U/s1600/Screen+Shot+2011-09-14+at+4.53.45+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="382" src="http://4.bp.blogspot.com/-wjncmJD30ZE/TnEUy9iU4TI/AAAAAAAAARs/9OI5Ridn81U/s640/Screen+Shot+2011-09-14+at+4.53.45+PM.png" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Upgrade process&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-QTc3tL7bTbQ/TnERPl6i_UI/AAAAAAAAARk/Wa3B2dyDy6o/s1600/Screen+Shot+2011-09-14+at+4.39.55+PM.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="640" src="http://3.bp.blogspot.com/-QTc3tL7bTbQ/TnERPl6i_UI/AAAAAAAAARk/Wa3B2dyDy6o/s640/Screen+Shot+2011-09-14+at+4.39.55+PM.png" width="638" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Purge script&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-3123964438280261955?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/3123964438280261955/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=3123964438280261955' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/3123964438280261955'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/3123964438280261955'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/09/security-onion-20110914-now-available.html' title='Security Onion 20110914 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-wjncmJD30ZE/TnEUy9iU4TI/AAAAAAAAARs/9OI5Ridn81U/s72-c/Screen+Shot+2011-09-14+at+4.53.45+PM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-6043804622159456332</id><published>2011-09-14T07:21:00.000-04:00</published><updated>2011-09-14T07:21:34.810-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><title type='text'>Security Onion 20110913 now available!</title><content type='html'>&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;Security Onion 20110913 is now available! &amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;This update upgrades the SQueRT web interface to version 0.9.3b. &amp;nbsp;Thanks go to &lt;a href="http://www.squertproject.org/"&gt;Paul Halliday&lt;/a&gt; at&amp;nbsp;&lt;a href="http://www.squertproject.org/"&gt;http://www.squertproject.org/&lt;/a&gt; for all of his hard work on this new version of SQueRT!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;b&gt;In-place Upgrade&lt;/b&gt;&lt;br /&gt;Existing Security Onion users can perform an in-place upgrade using the following command&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;(i&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;f you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="color: #336699; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px; text-decoration: none;"&gt;FAQ&lt;/a&gt;)&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-SRd5mj4qAI0/TnCMnav766I/AAAAAAAAARY/k9_NIAc7CU8/s1600/Screen+Shot+2011-09-14+at+7.13.53+AM.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="387" src="http://4.bp.blogspot.com/-SRd5mj4qAI0/TnCMnav766I/AAAAAAAAARY/k9_NIAc7CU8/s640/Screen+Shot+2011-09-14+at+7.13.53+AM.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="background-color: white; font-size: 15px; line-height: 20px;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;b&gt;&lt;i&gt;SQueRT Summary Tab&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;More screenshots can be found at the &lt;a href="http://www.squertproject.org/screenshots"&gt;SQueRT screenshots page&lt;/a&gt;.&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; font-size: 15px; line-height: 20px;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="background-color: white; font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="background-color: white; font-size: 15px; line-height: 20px;"&gt;&lt;div style="text-align: center;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-6043804622159456332?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/6043804622159456332/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=6043804622159456332' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/6043804622159456332'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/6043804622159456332'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/09/security-onion-20110913-now-available.html' title='Security Onion 20110913 now available!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-SRd5mj4qAI0/TnCMnav766I/AAAAAAAAARY/k9_NIAc7CU8/s72-c/Screen+Shot+2011-09-14+at+7.13.53+AM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-639579462930221173</id><published>2011-09-12T05:00:00.000-04:00</published><updated>2011-09-12T07:45:54.925-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><title type='text'>Security Onion 20110909 now available</title><content type='html'>&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;Security Onion 20110909 is now available! &amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;This upgrade adds some new menu entries to make IDS tuning a little easier. &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;The "IDS Rules" menu now has a new entry called "Add Local Rules" which will open /etc/nsm/rules/local.rules for editing using the "mousepad" GUI editor. &amp;nbsp;You can then add any rules that you want to maintain locally (outside of the downloaded VRT or Emerging Threats rulesets).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;A new menu called "IDS Config" was added with a new menu entry called "Configure IDS engine(s)". &amp;nbsp;This will list all of the IDS engines on your system and allow you to choose one to configure. &amp;nbsp;It will then open the proper config file for whatever IDS engine you're running. &amp;nbsp;After you save and close the config file, it will offer to restart the IDS engine for you.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;ul&gt;&lt;li style="font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;i&gt;Example #1&lt;/i&gt;&lt;/span&gt;&lt;/li&gt;&lt;ul&gt;&lt;li style="font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;Suppose you're currently running Snort and you choose eth0. &amp;nbsp;The program will open /etc/nsm/NAME_OF_YOUR_SENSOR-eth0/snort.conf for editing using the "mousepad" GUI editor.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;&lt;i&gt;Example #2&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;Suppose you're currently running Suricata and you choose eth1. &amp;nbsp;The program will open /etc/nsm/NAME_OF_YOUR_SENSOR-eth1/suricata.yaml for editing using the "mousepad" GUI editor.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;b&gt;In-place Upgrade&lt;/b&gt;&lt;br /&gt;Existing Security Onion users can perform an in-place upgrade using the following command&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;(i&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;f you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="color: #336699; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px; text-decoration: none;"&gt;FAQ&lt;/a&gt;)&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-RYQl_E3uTHg/Tmwnw1qjYLI/AAAAAAAAAQ8/Zl9tcxYB5hQ/s1600/Screen+Shot+2011-09-09+at+3.54.21+PM.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="309" src="http://2.bp.blogspot.com/-RYQl_E3uTHg/Tmwnw1qjYLI/AAAAAAAAAQ8/Zl9tcxYB5hQ/s320/Screen+Shot+2011-09-09+at+3.54.21+PM.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;b&gt;&lt;i&gt;New "Add Local Rules" menu entry under "IDS Rules"&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-On_mF3uPRW8/TmwoUG5aeEI/AAAAAAAAARE/X__8xyE8dNM/s1600/Screen+Shot+2011-09-09+at+3.55.44+PM.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="102" src="http://2.bp.blogspot.com/-On_mF3uPRW8/TmwoUG5aeEI/AAAAAAAAARE/X__8xyE8dNM/s320/Screen+Shot+2011-09-09+at+3.55.44+PM.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;b&gt;&lt;i&gt;Clicking the above menu entry opens /etc/nsm/rules/local.rules for editing&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-vH2LkSvMiw0/TmwojHux-MI/AAAAAAAAARI/12lbbJzBFhM/s1600/Screen+Shot+2011-09-09+at+3.56.58+PM.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/-vH2LkSvMiw0/TmwojHux-MI/AAAAAAAAARI/12lbbJzBFhM/s320/Screen+Shot+2011-09-09+at+3.56.58+PM.png" width="315" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;New "IDS Config" menu with "Configure IDS engine(s)" menu entry&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-2e4rPKr1dmM/Tmwo5KoIE3I/AAAAAAAAARM/yZ4twlJVyGQ/s1600/Screen+Shot+2011-09-09+at+3.57.27+PM.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="214" src="http://4.bp.blogspot.com/-2e4rPKr1dmM/Tmwo5KoIE3I/AAAAAAAAARM/yZ4twlJVyGQ/s320/Screen+Shot+2011-09-09+at+3.57.27+PM.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;"Configure IDS engine(s)" allows you to pick which engine to configure&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/--eH9BgLKmLs/TmwpEO3EvSI/AAAAAAAAARQ/Jrz-Dn8rnuY/s1600/Screen+Shot+2011-09-09+at+3.57.54+PM.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="185" src="http://2.bp.blogspot.com/--eH9BgLKmLs/TmwpEO3EvSI/AAAAAAAAARQ/Jrz-Dn8rnuY/s320/Screen+Shot+2011-09-09+at+3.57.54+PM.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;b&gt;&lt;i&gt;Selecting an engine opens that engine's config file for editing&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-mqB4Ec4yHpM/Tmwsm5Y7ZRI/AAAAAAAAARU/hrR-g7-bm5w/s1600/Screen+Shot+2011-09-10+at+11.35.27+PM.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="103" src="http://2.bp.blogspot.com/-mqB4Ec4yHpM/Tmwsm5Y7ZRI/AAAAAAAAARU/hrR-g7-bm5w/s320/Screen+Shot+2011-09-10+at+11.35.27+PM.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;b&gt;&lt;i&gt;After saving and closing the config file, you will have the option to restart the engine&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;b&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-639579462930221173?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/639579462930221173/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=639579462930221173' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/639579462930221173'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/639579462930221173'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/09/security-onion-20110909-now-available.html' title='Security Onion 20110909 now available'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-RYQl_E3uTHg/Tmwnw1qjYLI/AAAAAAAAAQ8/Zl9tcxYB5hQ/s72-c/Screen+Shot+2011-09-09+at+3.54.21+PM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-3152874634337021210</id><published>2011-09-10T22:32:00.004-04:00</published><updated>2011-09-10T23:42:28.940-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><title type='text'>Security Onion featured in Network World</title><content type='html'>&lt;a href="http://www.networkworld.com/community/user/3472"&gt;Scott Hogg&lt;/a&gt; wrote a great review of Security Onion here:&lt;br /&gt;&lt;a href="http://www.networkworld.com/community/node/78633"&gt;http://www.networkworld.com/community/node/78633&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-3152874634337021210?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/3152874634337021210/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=3152874634337021210' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/3152874634337021210'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/3152874634337021210'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/09/security-onion-featured-in-network.html' title='Security Onion featured in Network World'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-4265246462047387039</id><published>2011-07-26T07:04:00.001-04:00</published><updated>2011-07-26T11:37:41.123-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='503'/><category scheme='http://www.blogger.com/atom/ns#' term='sans'/><category scheme='http://www.blogger.com/atom/ns#' term='intrusion detection'/><title type='text'>tcpdump and ngrep</title><content type='html'>Yesterday, I tweeted the following:&lt;br /&gt;&lt;blockquote&gt;tcpdump -nnvvAi eth1 -s0 | grep "Doug Burks is teaching SANS SEC503 Intrusion Detection In-Depth in Portland"&lt;/blockquote&gt;&amp;nbsp;So what does it all mean?&lt;br /&gt;&lt;br /&gt;&lt;b&gt;-nn&lt;/b&gt; This option disables name resolution for IP addresses and port numbers. &amp;nbsp;Some versions of tcpdump do this with a single "-n", but the double "-nn" option should work on all of them.&lt;br /&gt;&lt;b&gt;vv&lt;/b&gt; This option enables Very Verbose output. &amp;nbsp;It wasn't strictly needed for the purposes of this command, but I'm in a habit of using it.&lt;br /&gt;&lt;b&gt;A &lt;/b&gt;This option prints just the ASCII text in the packets. &amp;nbsp;This is useful when looking for strings like&amp;nbsp;"Doug Burks is teaching SANS SEC503 Intrusion Detection In-Depth in Portland" or "c99shell".&lt;br /&gt;&lt;b&gt;i &lt;/b&gt;This option allows you to specify the Interface (in this case eth1). &amp;nbsp;eth1 on my Security Onion box at home is connected to a &lt;a href="http://www.dual-comm.com/products.htm"&gt;Dualcomm Switch Tap&lt;/a&gt; that monitors all ingress/egress of my home network. &amp;nbsp;Doesn't everybody do full packet capture at home?&lt;br /&gt;&lt;b&gt;-s0&lt;/b&gt; This option sets the snaplen. By default, tcpdump only captures 68 bytes and would therefore not see the entire payload of the HTTP connection. &amp;nbsp;Setting snaplen to 0 forces tcpdump to capture the entire packet regardless of its size.&lt;br /&gt;&lt;b&gt;grep &lt;/b&gt;Since we had tcpdump output in ASCII, we can easily use the standard grep command to look for interesting text strings.&lt;br /&gt;&lt;br /&gt;I was waiting on someone to ask the question "Why not use ngrep instead?". &amp;nbsp;tcpdump's advantage is that it is more universally available than ngrep. &amp;nbsp;If you're doing Incident Response on a Unix box of some kind, chances are that it already has tcpdump installed and you can use that to look for suspicious traffic as defined above. &lt;br /&gt;&lt;br /&gt;Most Unix boxes do not have ngrep installed by default. &amp;nbsp;But let's assume that you've got a dedicated IDS platform such as&amp;nbsp;&lt;cough&gt;&lt;a href="http://securityonion.blogspot.com/"&gt;Security Onion&lt;/a&gt;&lt;/cough&gt; which just so happens to include ngrep by default. &amp;nbsp;Here's the &amp;nbsp;ngrep version of the command:&lt;br /&gt;&lt;blockquote&gt;&amp;nbsp;ngrep -d eth1 -s0 "Doug Burks is teaching SANS SEC503 Intrusion Detection In-Depth in Portland"&lt;/blockquote&gt;Here we use the "-d eth1" option to force ngrep to listen on device eth1 and the "-s0" option to force ngrep to look at the entire packet. &amp;nbsp;Note that, unlike tcpdump's default snaplen of 68 bytes, ngrep defaults to 65536, so this option isn't strictly needed here, but is included for completeness. &amp;nbsp;After specifying these options, we simply tell ngrep what string to look for.&lt;br /&gt;&lt;br /&gt;Doug Burks is teaching SANS SEC503 Intrusion Detection In-Depth in Portland Oregon 8/22 - 8/27. &amp;nbsp;Sign up today!&lt;br /&gt;&lt;a href="http://www.sans.org/portland-2011-cs-2/description.php?tid=4866"&gt;http://www.sans.org/portland-2011-cs-2/description.php?tid=4866&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-4265246462047387039?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/4265246462047387039/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=4265246462047387039' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/4265246462047387039'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/4265246462047387039'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/07/tcpdump-and-ngrep.html' title='tcpdump and ngrep'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-2701440947077752602</id><published>2011-07-25T06:35:00.002-04:00</published><updated>2011-08-12T07:05:45.447-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='503'/><category scheme='http://www.blogger.com/atom/ns#' term='sans'/><category scheme='http://www.blogger.com/atom/ns#' term='intrusion detection'/><title type='text'>Doug Burks is teaching SANS SEC503 Intrusion Detection In-Depth in Portland 8/22 - 8/27</title><content type='html'>Doug Burks is teaching SANS SEC503 Intrusion Detection In-Depth in Portland Oregon 8/22 - 8/27. &amp;nbsp;For more information about the class, please see:&lt;br /&gt;&lt;a href="http://www.sans.org/portland-2011-cs-2/description.php?tid=4866"&gt;http://www.sans.org/portland-2011-cs-2/description.php?tid=4866&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Enter Discount Code COINS10 at the time of registration&amp;nbsp;to save $356 on Tuition!&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-2701440947077752602?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/2701440947077752602/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=2701440947077752602' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/2701440947077752602'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/2701440947077752602'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/07/doug-burks-is-teaching-sans-sec503.html' title='Doug Burks is teaching SANS SEC503 Intrusion Detection In-Depth in Portland 8/22 - 8/27'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-6349348292500204888</id><published>2011-07-14T06:56:00.002-04:00</published><updated>2011-07-14T06:57:17.165-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='nsm'/><category scheme='http://www.blogger.com/atom/ns#' term='pulledpork'/><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='sguil'/><category scheme='http://www.blogger.com/atom/ns#' term='emerging threats'/><title type='text'>Security Onion 20110714 now available</title><content type='html'>&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;Security Onion 20110714 is now available! &amp;nbsp;This release completes the PulledPork reconfiguration to ignore a&amp;nbsp;&lt;a href="http://blog.emergingthreatspro.com/2011/07/daily-update-summary-782011.html" style="color: #336699; text-decoration: none;"&gt;new Emerging Threats BLOCK category released on 7/8/2011&lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;Existing Security Onion users can perform an in-place upgrade to version 20110714 using the following command (i&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;f you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="color: #336699; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px; text-decoration: none;"&gt;FAQ&lt;/a&gt;)&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;:&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-6349348292500204888?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/6349348292500204888/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=6349348292500204888' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/6349348292500204888'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/6349348292500204888'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/07/security-onion-20110714-now-available.html' title='Security Onion 20110714 now available'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-5681499508351411398</id><published>2011-07-11T00:41:00.003-04:00</published><updated>2011-07-11T00:55:33.506-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='nsm'/><category scheme='http://www.blogger.com/atom/ns#' term='pulledpork'/><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='sguil'/><category scheme='http://www.blogger.com/atom/ns#' term='emerging threats'/><title type='text'>Security Onion 20110709 now available</title><content type='html'>&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;Security Onion 20110709 is now available! &amp;nbsp;This release configures PulledPork to ignore a &lt;a href="http://blog.emergingthreatspro.com/2011/07/daily-update-summary-782011.html"&gt;new Emerging Threats BLOCK category released on 7/8/2011&lt;/a&gt;.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;Existing Security Onion users can perform an in-place upgrade to version 20110709 using the following command (i&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;f you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;/span&gt;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ" style="color: #336699; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px; text-decoration: none;"&gt;FAQ&lt;/a&gt;)&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;:&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-5681499508351411398?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/5681499508351411398/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=5681499508351411398' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/5681499508351411398'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/5681499508351411398'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/07/security-onion-20110709-now-available.html' title='Security Onion 20110709 now available'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-2390831840235816326</id><published>2011-06-29T20:12:00.002-04:00</published><updated>2011-07-11T00:54:25.172-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='nsm'/><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='ossec'/><category scheme='http://www.blogger.com/atom/ns#' term='sguil'/><title type='text'>Security Onion 20110628 now available</title><content type='html'>Security Onion 20110628 is now available! &amp;nbsp;This release fixes two minor issues with the OSSEC Sguil agent.&lt;br /&gt;&lt;br /&gt;Existing Security Onion users can perform an in-place upgrade to version 20110628 using the following command (if you're behind a proxy, remember to set your proxy variables as described in the&amp;nbsp;&lt;a href="http://code.google.com/p/security-onion/wiki/FAQ"&gt;FAQ&lt;/a&gt;):&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh &amp;gt; ~/security-onion-upgrade.sh &amp;amp;&amp;amp; bash ~/security-onion-upgrade.sh"&lt;/span&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-2390831840235816326?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/2390831840235816326/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=2390831840235816326' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/2390831840235816326'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/2390831840235816326'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/06/security-onion-20110628-now-available.html' title='Security Onion 20110628 now available'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-232707757618519738</id><published>2011-06-22T06:51:00.000-04:00</published><updated>2011-06-22T06:51:14.516-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='timezone'/><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='gmt'/><category scheme='http://www.blogger.com/atom/ns#' term='utc'/><category scheme='http://www.blogger.com/atom/ns#' term='sguil'/><category scheme='http://www.blogger.com/atom/ns#' term='squert'/><title type='text'>Security Onion and UTC</title><content type='html'>Sguil uses UTC. &amp;nbsp;It does this for a few reasons:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;UTC avoids any timewarps when changing from standard time to daylight saving time and vice versa.&lt;/li&gt;&lt;li&gt;UTC allows for correlation when sensors are in different time zones.&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;Because Sguil uses UTC, it is recommended to set your Security Onion timezone to UTC. &amp;nbsp;Here's how:&lt;/div&gt;&lt;div&gt;&lt;blockquote&gt;echo "Etc/UTC" | sudo tee /etc/timezone&lt;br /&gt;sudo dpkg-reconfigure --frontend noninteractive tzdata&lt;/blockquote&gt;&lt;/div&gt;&lt;div&gt;For more information, please see:&lt;/div&gt;&lt;div&gt;&lt;a href="https://help.ubuntu.com/community/UbuntuTime"&gt;https://help.ubuntu.com/community/UbuntuTime&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-232707757618519738?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/232707757618519738/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=232707757618519738' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/232707757618519738'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/232707757618519738'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/06/security-onion-and-utc.html' title='Security Onion and UTC'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-6761714362981235790</id><published>2011-06-17T06:29:00.000-04:00</published><updated>2011-06-17T06:29:06.206-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='pulledpork'/><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><title type='text'>Security Onion 20110614</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;Security Onion 20110614 is now available! &amp;nbsp;This upgrade fixes a few issues with downloading rules and adds some new menu entries to make rule editing a little easier. &amp;nbsp;For more information, please see &lt;a href="http://code.google.com/p/security-onion/issues/detail?id=111"&gt;Issue 111&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;In-place Upgrade&lt;/b&gt;&lt;br /&gt;Existing Security Onion users can perform an in-place upgrade to version 20110614 using the following commands:&lt;br /&gt;&lt;blockquote&gt;wget http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh&lt;br /&gt;sudo bash security-onion-upgrade.sh&lt;/blockquote&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-a35NsiohWaI/TfspkJQgMEI/AAAAAAAAANc/e4NYnqiYStU/s1600/menu.PNG" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="154" src="http://4.bp.blogspot.com/-a35NsiohWaI/TfspkJQgMEI/AAAAAAAAANc/e4NYnqiYStU/s320/menu.PNG" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;New menu entries&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-O_Yh4WLUlfc/Tfspj3hOdSI/AAAAAAAAANY/Rb66jJfWGFg/s1600/disable.PNG" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="224" src="http://3.bp.blogspot.com/-O_Yh4WLUlfc/Tfspj3hOdSI/AAAAAAAAANY/Rb66jJfWGFg/s320/disable.PNG" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Clicking "Disable Downloaded Rules" opens disablesid.conf in a text editor&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-n_VEpW1mJ9E/TfspkcD09iI/AAAAAAAAANg/bkA6CzObpzA/s1600/pulledpork.PNG" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="207" src="http://3.bp.blogspot.com/-n_VEpW1mJ9E/TfspkcD09iI/AAAAAAAAANg/bkA6CzObpzA/s320/pulledpork.PNG" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Clicking "Rule update" will run PulledPork and restart Barnyard2/Snort&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-6761714362981235790?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/6761714362981235790/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=6761714362981235790' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/6761714362981235790'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/6761714362981235790'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/06/security-onion-20110614.html' title='Security Onion 20110614'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-a35NsiohWaI/TfspkJQgMEI/AAAAAAAAANc/e4NYnqiYStU/s72-c/menu.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-2859520251781602417</id><published>2011-06-13T06:23:00.004-04:00</published><updated>2011-06-14T06:04:35.108-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='sguil'/><category scheme='http://www.blogger.com/atom/ns#' term='squert'/><title type='text'>Security Onion 20110607 featuring Sguil 0.8, Squert 0.8.3, and more polish!</title><content type='html'>&lt;b&gt;Update: &amp;nbsp;Looks like the Security Onion 20110607 files haven't fully replicated to all Sourceforge mirrors yet. If you're having trouble downloading, please try later today.&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Update 2011/06/14 6:00 AM: Sourceforge is reporting that the Security Onion 20110607 files have replicated to at least 15 mirrors now.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Security Onion 20110607 is now available! &amp;nbsp;New features in this release are as follows:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Sguil 0.8 (now with more shininess and anti-aliased fonts!)&lt;/li&gt;&lt;li&gt;Squert 0.8.3 (now with user authentication!)&lt;/li&gt;&lt;li&gt;new tcl/tk packages (resolves a scaling issue when running in VMWare and allows for the anti-aliased fonts mentioned above)&lt;/li&gt;&lt;li&gt;httpry&lt;/li&gt;&lt;li&gt;a new Setup script (adds support for Sguil 0.8 and Squert 0.8.3 and also provides more information once Setup completes)&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;New Users&lt;/b&gt;&lt;br /&gt;New users can download the latest ISO image from &lt;a href="http://sourceforge.net/projects/security-onion/files/"&gt;here&lt;/a&gt;. &amp;nbsp;It should be noted that pentest tools have been removed from this ISO. &amp;nbsp;This includes metasploit, john, ophcrack, and steghide. &amp;nbsp;For more information, please see &lt;a href="http://code.google.com/p/security-onion/issues/detail?id=106&amp;amp;can=1&amp;amp;q=metasploit"&gt;Issue 106&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;In-place Upgrade&lt;/b&gt;&lt;br /&gt;Existing Security Onion users can perform an in-place upgrade to version 20110607 using the following commands:&lt;br /&gt;&lt;blockquote&gt;wget http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh&lt;br /&gt;sudo bash security-onion-upgrade.sh&lt;/blockquote&gt;It will then upgrade your box to the latest tcl/tk, Sguil, Squert, and Setup script. &amp;nbsp;If you have an existing Sguil database, it will run the Sguil DB upgrade, which will ask:&lt;br /&gt;&lt;blockquote&gt;Do you want to continue? &lt;b&gt;y&lt;/b&gt;&lt;br /&gt;Database password: &lt;b&gt;Press Enter to accept the default of "null" (unless you've changed the MySQL root password)&lt;/b&gt;&lt;br /&gt;DB schema needs to be updated: &lt;b&gt;Press Enter to accept the default of "y"&lt;/b&gt;&lt;br /&gt;Path to update...&lt;b&gt;Press Enter to accept the default&lt;/b&gt;&lt;/blockquote&gt;Please test the upgrade on test machines before upgrading your production machines.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Screenshots&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;img border="0" height="257" src="http://2.bp.blogspot.com/-jQuertfd34Y/TfXjAslVmFI/AAAAAAAAANA/SjTh9NnYAao/s640/upgrade_script.PNG" width="640" /&gt;&lt;span class="Apple-style-span" style="-webkit-text-decorations-in-effect: none; color: black;"&gt;&lt;b&gt;&lt;i&gt;Upgrade process&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-RN6mQCUfgKc/TfXjAHa3zwI/AAAAAAAAAM4/CRr6ab9BIv0/s1600/Sguil_login_window.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/-RN6mQCUfgKc/TfXjAHa3zwI/AAAAAAAAAM4/CRr6ab9BIv0/s320/Sguil_login_window.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;&amp;nbsp;Sguil login window&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-nrNJ0CW7Wqk/TfXjAZydSWI/AAAAAAAAAM8/db5YRRDwerQ/s1600/SQueRT_login.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="217" src="http://4.bp.blogspot.com/-nrNJ0CW7Wqk/TfXjAZydSWI/AAAAAAAAAM8/db5YRRDwerQ/s320/SQueRT_login.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Squert login window&amp;nbsp;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-2859520251781602417?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/2859520251781602417/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=2859520251781602417' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/2859520251781602417'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/2859520251781602417'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/06/security-onion-20110607-featuring-sguil.html' title='Security Onion 20110607 featuring Sguil 0.8, Squert 0.8.3, and more polish!'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-jQuertfd34Y/TfXjAslVmFI/AAAAAAAAANA/SjTh9NnYAao/s72-c/upgrade_script.PNG' height='72' width='72'/><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-3451356176321878217</id><published>2011-06-04T12:41:00.000-04:00</published><updated>2011-06-04T12:41:39.857-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='sans'/><title type='text'>Security Onion featured in SANS Student Project</title><content type='html'>Security Onion was featured in a SANS Student Project. &amp;nbsp;Russ McRee, Beth Binde, and Terrence O’Connor recently published&amp;nbsp;&lt;a href="http://www.sans.edu/student-files/projects/JWP-Binde-McRee-OConnor.pdf"&gt;Assessing Outbound&amp;nbsp;Traffic to Uncover&amp;nbsp;Advanced Persistent&amp;nbsp;Threat&lt;/a&gt;. &amp;nbsp;Great paper!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-3451356176321878217?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/3451356176321878217/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=3451356176321878217' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/3451356176321878217'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/3451356176321878217'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/06/security-onion-featured-in-sans-student.html' title='Security Onion featured in SANS Student Project'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-6516189772112150000</id><published>2011-05-24T06:16:00.000-04:00</published><updated>2011-05-24T06:16:16.216-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><title type='text'>Security Onion Success Stories</title><content type='html'>I received a couple of Security Onion Success Stories recently. &amp;nbsp;I appreciate Brett S. and Gene A. taking the time to say thanks. &amp;nbsp; It's a great source of encouragement and motivation for me to continue with the project. &amp;nbsp;If you would like to share your Security Onion Success Story, please post it in the Comments section. &amp;nbsp;Thanks!&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;Doug,&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;I wanted to thank you for providing Security Onion and maintaining it&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;so diligently. &amp;nbsp;I was a faculty advisor for the U.S. Coast Guard's&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;Cyber Defense Exercise this year. &amp;nbsp;Every year, the service academies&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;set up their networks and have NSA's red team try to bring down&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;servers and steal information. &amp;nbsp;For Coast Guard, the team is recruited&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;from the members of the only Networks course.&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;It was my first year with the cadets, and I had realized early that&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;the team had no IDS experience, and was thoroughly swamped just trying&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;to get the network up and running. &amp;nbsp;Security Onion to the rescue --&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;requiring just a few of the less experienced members with some&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;guidance, we were able to watch the more obvious attacks from outside&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;the firewall as well as the false positives from the exercise scoring&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;software. &amp;nbsp;It really was educational for the group -- rather than just&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;wondering what hit us, there was ample information in near real time&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;to figure out what was happening. &amp;nbsp; Knowing how to respond is another&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;story, of course.&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&amp;nbsp;In the end, Coast Guard placed 3rd, which is pretty good given the&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;size and amount of resources available compared to Air Force and&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;Army. &amp;nbsp;Some of the team have expressed interest in getting more&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;involved with configuration and fine-tuning Snort next year, because&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;they had first-hand experience with how it behaved under basic&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;defaults.&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;Thanks again for providing such a useful tool -- it significantly&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;enhanced the educational impact of the exercise.&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;Brett S.&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;Doug, Brett,&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&amp;nbsp;It wasn't just the USCG that was using Security Onion during the CDX.&amp;nbsp; We here at the Naval Postgraduate School also used Security Onion as a quick and easy IDS solution.&amp;nbsp; Of all the tools we employed during the exercise Security Onion was by far the easiest to get up and running and provided us with a great insight into the attacks used during the exercise.&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&amp;nbsp;Great job, Doug!&amp;nbsp; Keep up the good work.&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;Sincerely,&lt;/span&gt;&amp;nbsp;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;Gene A.&lt;/span&gt;&amp;nbsp;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-6516189772112150000?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/6516189772112150000/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=6516189772112150000' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/6516189772112150000'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/6516189772112150000'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/05/security-onion-success-stories.html' title='Security Onion Success Stories'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-595970054444232568</id><published>2011-05-02T21:14:00.001-04:00</published><updated>2011-05-04T15:45:30.969-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><title type='text'>Security Onion featured in ISSA Journal</title><content type='html'>I always look forward to Russ McRee's Toolsmith column in the ISSA Journal. &amp;nbsp;&lt;a href="http://holisticinfosec.org/toolsmith/pdf/may2011.pdf"&gt;This month's Toolsmith column features Security Onion!&lt;/a&gt; &amp;nbsp;Russ, thanks for the article and your kind words!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-595970054444232568?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/595970054444232568/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=595970054444232568' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/595970054444232568'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/595970054444232568'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/05/security-onion-featured-in-issa-journal.html' title='Security Onion featured in ISSA Journal'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-2965360844911183037</id><published>2011-04-07T06:30:00.000-04:00</published><updated>2011-04-07T06:30:03.537-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='suricata'/><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='snort'/><category scheme='http://www.blogger.com/atom/ns#' term='ids'/><category scheme='http://www.blogger.com/atom/ns#' term='sguil'/><title type='text'>Security Onion 20110321: Distributed Sguil Sensors</title><content type='html'>Security Onion 20110321 is now available! &amp;nbsp;This new version includes an updated Setup script that allows you to easily create a Sguil server and then create multiple Sguil sensors that report back to the Sguil server.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;How do I get it?&lt;/b&gt;&lt;br /&gt;New users can download the latest ISO image from &lt;a href="http://sourceforge.net/projects/security-onion/files/"&gt;here&lt;/a&gt;. &amp;nbsp;Existing Security Onion users can perform an in-place upgrade to version 20110321 using the following commands:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;wget http://downloads.sourceforge.net/project/security-onion/security-onion-upgrade.sh&lt;br /&gt;sudo bash security-onion-upgrade.sh&amp;nbsp;&lt;/blockquote&gt;Existing users, please note that running Setup on a previously configured system will remove any existing configuration.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;How do I create a Sguil server?&lt;/b&gt;&lt;br /&gt;You have three options:&lt;br /&gt;1. &amp;nbsp;Launch Setup and choose "Quick Setup". &amp;nbsp;This will install a Sguil server AND create a Sguil sensor for each ethernet interface on the server.&lt;br /&gt;2. &amp;nbsp;Launch Setup, choose&amp;nbsp;"Advanced Setup", and choose "Both". &amp;nbsp;This will install a Sguil server AND create a Sguil sensor for each ethernet interface on the server, but will give you more options than "Quick Setup".&lt;br /&gt;3. &amp;nbsp;Launch Setup, choose&amp;nbsp;"Advanced Setup", and choose "Server". &amp;nbsp;This will just install a Sguil server.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;How do I create a Sguil sensor?&lt;/b&gt;&lt;br /&gt;Launch Setup, choose "Advanced Setup", and choose "Sensor". &amp;nbsp;Enter the name/address of the Sguil server and a username that has sudo permissions on the server. &amp;nbsp;A terminal window will appear prompting you to login to the server to complete the server configuration.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Demo&lt;/b&gt;&lt;br /&gt;Download the latest ISO image from &lt;a href="http://sourceforge.net/projects/security-onion/files/"&gt;here&lt;/a&gt;.&lt;br /&gt;Boot the Security Onion ISO and choose Install from the boot menu.&lt;br /&gt;Standard Ubuntu installer appears. &amp;nbsp;Follow the prompts to complete your installation.&lt;br /&gt;Reboot into your new Security Onion installation and login using the username/password you specified in the previous step.&lt;br /&gt;Double-click the Setup desktop shortcut.&lt;br /&gt;Administrative password prompt appears. &amp;nbsp;Enter your password and click OK.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-2pI_Ql6gPdo/TZw-gg8J1hI/AAAAAAAAAKw/sf4PY3tpwSg/s1600/sudo.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="190" src="http://3.bp.blogspot.com/-2pI_Ql6gPdo/TZw-gg8J1hI/AAAAAAAAAKw/sf4PY3tpwSg/s320/sudo.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;Welcome screen appears. &amp;nbsp;Press Enter.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-bsatZD9Q3Nc/TZw-z6bni3I/AAAAAAAAAK0/dccK_ycjgM4/s1600/welcome.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="130" src="http://4.bp.blogspot.com/-bsatZD9Q3Nc/TZw-z6bni3I/AAAAAAAAAK0/dccK_ycjgM4/s320/welcome.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;Quick Setup screen appears. &amp;nbsp;Press Enter.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-gPdFm_DmedU/TZw_Xq3pnfI/AAAAAAAAAK4/gllZrr4cnn0/s1600/Quick_Setup.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="222" src="http://4.bp.blogspot.com/-gPdFm_DmedU/TZw_Xq3pnfI/AAAAAAAAAK4/gllZrr4cnn0/s320/Quick_Setup.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;Username screen appears. &amp;nbsp;Enter your desired Sguil username and press Enter.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-1_PiEt_XxwI/TZxCYDLvZEI/AAAAAAAAAK8/qJ3x5lbITzg/s1600/Username.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="129" src="http://4.bp.blogspot.com/-1_PiEt_XxwI/TZxCYDLvZEI/AAAAAAAAAK8/qJ3x5lbITzg/s320/Username.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Password screen appears. &amp;nbsp;Enter your desired Sguil password and press Enter.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-iMpUtzm_3Vs/TZxCkc1tuSI/AAAAAAAAALA/3JhPKqEiSt0/s1600/Password1.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="112" src="http://1.bp.blogspot.com/-iMpUtzm_3Vs/TZxCkc1tuSI/AAAAAAAAALA/3JhPKqEiSt0/s320/Password1.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Password confirmation screen appears. &amp;nbsp;Confirm your desired Sguil password and press Enter.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-4jmJztizelI/TZxC7fo6wrI/AAAAAAAAALI/8ofkOPtGd2s/s1600/Password2.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="91" src="http://1.bp.blogspot.com/-4jmJztizelI/TZxC7fo6wrI/AAAAAAAAALI/8ofkOPtGd2s/s320/Password2.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Settings confirmation screen appears. &amp;nbsp;Press Enter.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-G2bUhC-4ptg/TZxDH4saqKI/AAAAAAAAALM/N2OwDr7r1ew/s1600/confirm.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="201" src="http://4.bp.blogspot.com/-G2bUhC-4ptg/TZxDH4saqKI/AAAAAAAAALM/N2OwDr7r1ew/s320/confirm.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Setup creates the Sguil server and sensors and then starts all services.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-LkkKxbRJdyI/TZxDr1OZPUI/AAAAAAAAALQ/PYDM8qox-Pk/s1600/create1.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="119" src="http://1.bp.blogspot.com/-LkkKxbRJdyI/TZxDr1OZPUI/AAAAAAAAALQ/PYDM8qox-Pk/s320/create1.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-Abnsd0MquXk/TZxDsCK5IKI/AAAAAAAAALU/TNA4pSrbong/s1600/create2.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="102" src="http://3.bp.blogspot.com/-Abnsd0MquXk/TZxDsCK5IKI/AAAAAAAAALU/TNA4pSrbong/s320/create2.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-joyD6rmCVck/TZxDsSAsbZI/AAAAAAAAALY/7VjjI-a-5l4/s1600/create3.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="101" src="http://2.bp.blogspot.com/-joyD6rmCVck/TZxDsSAsbZI/AAAAAAAAALY/7VjjI-a-5l4/s320/create3.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-5lVOQ_kAGsk/TZxDsma3Q3I/AAAAAAAAALc/RsJINEUfUdU/s1600/create4.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="100" src="http://4.bp.blogspot.com/-5lVOQ_kAGsk/TZxDsma3Q3I/AAAAAAAAALc/RsJINEUfUdU/s320/create4.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Setup Complete screen appears. &amp;nbsp;Press Enter.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-EoxdGiKk2bg/TZxEQPm5D7I/AAAAAAAAALg/YhUYf2V3QCc/s1600/complete.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="138" src="http://3.bp.blogspot.com/-EoxdGiKk2bg/TZxEQPm5D7I/AAAAAAAAALg/YhUYf2V3QCc/s320/complete.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Double-click the Sguil desktop shortcut. &amp;nbsp;Login window appears. &amp;nbsp;Enter the Sguil username/password you specified in Setup.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-ZJ7punOQg-0/TZxElikoQkI/AAAAAAAAALk/7L2JNXLOtR4/s1600/login.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="235" src="http://3.bp.blogspot.com/-ZJ7punOQg-0/TZxElikoQkI/AAAAAAAAALk/7L2JNXLOtR4/s320/login.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Sensors window appears. &amp;nbsp;Click "Select All" and then click "Start Sguil".&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-n2ewFAvdacw/TZxE4MJ-RJI/AAAAAAAAALo/F_ZP5BM_K74/s1600/sensors.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="267" src="http://4.bp.blogspot.com/-n2ewFAvdacw/TZxE4MJ-RJI/AAAAAAAAALo/F_ZP5BM_K74/s640/sensors.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Sguil main window appears. &amp;nbsp;Simulate an attack by going to a terminal and typing "curl http://testmyids.com".&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-2LWf5ZFQGxc/TZ2Rw5805sI/AAAAAAAAAM0/ArWNtS3-rO0/s1600/attack_server.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="69" src="http://3.bp.blogspot.com/-2LWf5ZFQGxc/TZ2Rw5805sI/AAAAAAAAAM0/ArWNtS3-rO0/s320/attack_server.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;A new alert should appear in the Sguil window. &amp;nbsp;Notice that the sensor is named server-eth0, where "server" is the hostname and "eth0" is the interface that saw the traffic.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-dZzvwzUOuDE/TZxF8eFiWSI/AAAAAAAAALs/EjtfYPRXuwA/s1600/server_attack.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="304" src="http://3.bp.blogspot.com/-dZzvwzUOuDE/TZxF8eFiWSI/AAAAAAAAALs/EjtfYPRXuwA/s640/server_attack.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;We've now verified that the Sguil server is running correctly. &amp;nbsp;Let's go to our second machine and build a sensor.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;Boot the Security Onion ISO and choose Install from the boot menu.&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;Standard Ubuntu installer appears. &amp;nbsp;Follow the prompts to complete your installation.&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;Reboot into your new Security Onion installation and login using the username/password you specified in the previous step.&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;Double-click the Setup desktop shortcut.&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;Administrative password prompt appears. &amp;nbsp;Enter your password and click OK.&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-2pI_Ql6gPdo/TZw-gg8J1hI/AAAAAAAAAKw/sf4PY3tpwSg/s1600/sudo.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="190" src="http://3.bp.blogspot.com/-2pI_Ql6gPdo/TZw-gg8J1hI/AAAAAAAAAKw/sf4PY3tpwSg/s320/sudo.PNG" style="cursor: move;" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;Welcome screen appears. &amp;nbsp;Press Enter.&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-bsatZD9Q3Nc/TZw-z6bni3I/AAAAAAAAAK0/dccK_ycjgM4/s1600/welcome.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="130" src="http://4.bp.blogspot.com/-bsatZD9Q3Nc/TZw-z6bni3I/AAAAAAAAAK0/dccK_ycjgM4/s320/welcome.PNG" style="cursor: move;" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;Quick Setup screen appears. &amp;nbsp;Click "No, use Advanced Setup".&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-gPdFm_DmedU/TZw_Xq3pnfI/AAAAAAAAAK4/gllZrr4cnn0/s1600/Quick_Setup.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="222" src="http://4.bp.blogspot.com/-gPdFm_DmedU/TZw_Xq3pnfI/AAAAAAAAAK4/gllZrr4cnn0/s320/Quick_Setup.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;Components screen appears. &amp;nbsp;Click "Sensor" and click "OK".&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-67dbJOhAhjI/TZxHTuEaVBI/AAAAAAAAALw/EZu6VeUSXJ4/s1600/Components.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="174" src="http://4.bp.blogspot.com/-67dbJOhAhjI/TZxHTuEaVBI/AAAAAAAAALw/EZu6VeUSXJ4/s320/Components.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;Server Hostname screen appears. &amp;nbsp;Enter server hostname/address and press Enter.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-TYLEu_N2WZo/TZxHjVU7hPI/AAAAAAAAAL0/YzN1H04IVR8/s1600/hostname.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="91" src="http://3.bp.blogspot.com/-TYLEu_N2WZo/TZxHjVU7hPI/AAAAAAAAAL0/YzN1H04IVR8/s400/hostname.PNG" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;SSH Username screen appears. &amp;nbsp;Enter username on server and press Enter.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-ML1n5O8RF_M/TZxHztjWhmI/AAAAAAAAAL4/KXO5tUcv5ks/s1600/SSH.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="84" src="http://1.bp.blogspot.com/-ML1n5O8RF_M/TZxHztjWhmI/AAAAAAAAAL4/KXO5tUcv5ks/s320/SSH.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;IDS Engine screen appears. &amp;nbsp;Press Enter.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-8Bs0m1u57h4/TZxIFKYdOYI/AAAAAAAAAL8/5G0T_OZWIKg/s1600/Engine.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="129" src="http://1.bp.blogspot.com/-8Bs0m1u57h4/TZxIFKYdOYI/AAAAAAAAAL8/5G0T_OZWIKg/s320/Engine.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;Interfaces screen appears. &amp;nbsp;Select your desired interface(s) and click OK.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-fXAokBdE5s8/TZxIW1HepQI/AAAAAAAAAMA/qi_DW8LdLjU/s1600/Interfaces.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="168" src="http://2.bp.blogspot.com/-fXAokBdE5s8/TZxIW1HepQI/AAAAAAAAAMA/qi_DW8LdLjU/s320/Interfaces.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;Confirm Settings screen appears. &amp;nbsp;Click "Yes, proceed with the changes!".&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-QDpeudo6uQY/TZxIiHo2oTI/AAAAAAAAAME/bE6t7LmUC6k/s1600/sensor_confirm.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="169" src="http://1.bp.blogspot.com/-QDpeudo6uQY/TZxIiHo2oTI/AAAAAAAAAME/bE6t7LmUC6k/s320/sensor_confirm.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;Terminal appears prompting to accept SSH key of server. &amp;nbsp;Type "yes" and press Enter.&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Ug-G3Z5ZKCw/TZxJWCjobqI/AAAAAAAAAMM/Zbf151gGAjY/s1600/sensor2.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="55" src="http://1.bp.blogspot.com/-Ug-G3Z5ZKCw/TZxJWCjobqI/AAAAAAAAAMM/Zbf151gGAjY/s320/sensor2.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;Password prompt appears. &amp;nbsp;Enter password and press Enter.&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-uRek4VDb23M/TZxJWfIt7NI/AAAAAAAAAMQ/JftbARppcxo/s1600/sensor3.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="81" src="http://3.bp.blogspot.com/-uRek4VDb23M/TZxJWfIt7NI/AAAAAAAAAMQ/JftbARppcxo/s320/sensor3.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;Sudo prompt appears. &amp;nbsp;Enter password and press Enter.&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-5VpZ9fg8Gbg/TZxJWlp40sI/AAAAAAAAAMU/qFQwG3EHjrc/s1600/sensor4.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="60" src="http://1.bp.blogspot.com/-5VpZ9fg8Gbg/TZxJWlp40sI/AAAAAAAAAMU/qFQwG3EHjrc/s320/sensor4.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;Setup creates the Sguil sensor(s).&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-CoqiLmE3Tgs/TZxJV6LEglI/AAAAAAAAAMI/_9s910OYApo/s1600/sensor1.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="118" src="http://3.bp.blogspot.com/-CoqiLmE3Tgs/TZxJV6LEglI/AAAAAAAAAMI/_9s910OYApo/s320/sensor1.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&amp;nbsp;Setup starts all Sguil services.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-ZpCSW_2CpCY/TZxJWxnZ3SI/AAAAAAAAAMY/Ejvm9QWEb1s/s1600/sensor5.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="119" src="http://4.bp.blogspot.com/-ZpCSW_2CpCY/TZxJWxnZ3SI/AAAAAAAAAMY/Ejvm9QWEb1s/s320/sensor5.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Setup Complete screen appears. &amp;nbsp;Press Enter.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-5Ppk-wWIxnY/TZxJW-wn2UI/AAAAAAAAAMc/fXU1KJm07Vk/s1600/sensor6.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="140" src="http://2.bp.blogspot.com/-5Ppk-wWIxnY/TZxJW-wn2UI/AAAAAAAAAMc/fXU1KJm07Vk/s320/sensor6.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;Simulate an attack by opening a terminal and typing "curl http://testmyids.com". &amp;nbsp;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-JS3QbHF-KcY/TZ2RZqCQ-fI/AAAAAAAAAMw/G_DZfAFzTrI/s1600/attack.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="67" src="http://1.bp.blogspot.com/-JS3QbHF-KcY/TZ2RZqCQ-fI/AAAAAAAAAMw/G_DZfAFzTrI/s320/attack.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;At this point, we can return to our server. &amp;nbsp;In the Sguil window, click File and then click "Change monitored networks".&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;Sensor selection window appears. &amp;nbsp;Notice that there are new sensors named sensor-eth0, sensor-eth1, sensor-eth2, and sensor-ossec. &amp;nbsp;Select the new sensors and click "Start Sguil".&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-8_X8GcYsQa0/TZxKkPj-94I/AAAAAAAAAMg/LTKlp5xKre0/s1600/all_sensors.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="251" src="http://3.bp.blogspot.com/-8_X8GcYsQa0/TZxKkPj-94I/AAAAAAAAAMg/LTKlp5xKre0/s640/all_sensors.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;Click the "Agent Status" tab and verify that the the new sensors are checking in.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-xjHegyD16qY/TZ2OOx_G-5I/AAAAAAAAAMo/Sgm7ZVOGwog/s1600/sensor_status.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="364" src="http://1.bp.blogspot.com/-xjHegyD16qY/TZ2OOx_G-5I/AAAAAAAAAMo/Sgm7ZVOGwog/s640/sensor_status.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;Notice that there is a new alert with a sensor name of sensor-eth0, where "sensor" is the hostname of the sensor and "eth0" is the interface which saw the traffic.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-eBo74PZ9iB8/TZ2PY0SD4kI/AAAAAAAAAMs/gBuphzgLpQM/s1600/sguil_rocks.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="331" src="http://2.bp.blogspot.com/-eBo74PZ9iB8/TZ2PY0SD4kI/AAAAAAAAAMs/gBuphzgLpQM/s640/sguil_rocks.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;In this blog post, we've demonstrated how Security Onion can build an army of distributed Sguil sensors in just a few minutes.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-2965360844911183037?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/2965360844911183037/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=2965360844911183037' title='12 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/2965360844911183037'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/2965360844911183037'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/04/security-onion-20110321-distributed.html' title='Security Onion 20110321: Distributed Sguil Sensors'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-2pI_Ql6gPdo/TZw-gg8J1hI/AAAAAAAAAKw/sf4PY3tpwSg/s72-c/sudo.PNG' height='72' width='72'/><thr:total>12</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-7006357851005869133</id><published>2011-02-23T06:45:00.001-05:00</published><updated>2011-02-23T06:46:51.090-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><title type='text'>Security Onion 20110222 Resolves 2 Issues</title><content type='html'>I've uploaded a new security-onion-upgrade.sh script which resolves a couple of issues:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=80"&gt;http://code.google.com/p/security-onion/issues/detail?id=80&lt;/a&gt;&lt;br /&gt;&lt;a href="http://code.google.com/p/security-onion/issues/detail?id=87"&gt;http://code.google.com/p/security-onion/issues/detail?id=87&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;To download and run the upgrade script, open a terminal and execute the following:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;wget&amp;nbsp;http://downloads.sourceforge.net/project/security-onion/security-onion-upgrade.sh&lt;br /&gt;sudo bash security-onion-upgrade.sh&amp;nbsp;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-7006357851005869133?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/7006357851005869133/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=7006357851005869133' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/7006357851005869133'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/7006357851005869133'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/02/security-onion-20110222-resolves-2.html' title='Security Onion 20110222 Resolves 2 Issues'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-2019959965702500865</id><published>2011-01-22T13:36:00.001-05:00</published><updated>2011-01-22T13:47:08.734-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='sguil'/><title type='text'>Security Onion 20110122 fixes DNS error in Sguil</title><content type='html'>I received &lt;a href="http://code.google.com/p/security-onion/issues/detail?id=77"&gt;Issue 77&lt;/a&gt; in the Security Onion Issue Tracker. &amp;nbsp;The Issue describes an error when enabling Reverse DNS queries in Sguil. &amp;nbsp;I was able to duplicate the issue.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Prlv_CKbUdQ/TTsjWOmhRNI/AAAAAAAAAJ0/jP2FABEG_oM/s1600/Security_Onion_20110122_Sguil_libudp_error.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_Prlv_CKbUdQ/TTsjWOmhRNI/AAAAAAAAAJ0/jP2FABEG_oM/s1600/Security_Onion_20110122_Sguil_libudp_error.PNG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;I consulted with &lt;a href="http://twitter.com/bammv"&gt;Bamm Visscher&lt;/a&gt;&amp;nbsp;and he said this was due to Ubuntu's libudp-tcl package. &amp;nbsp;I removed libudp-tcl and Reverse DNS queries started working again.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Prlv_CKbUdQ/TTsiNUB4PII/AAAAAAAAAJw/42OcxBwHHBs/s1600/Security_Onion_20110122_Sguil_libudp_error_resolved.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_Prlv_CKbUdQ/TTsiNUB4PII/AAAAAAAAAJw/42OcxBwHHBs/s1600/Security_Onion_20110122_Sguil_libudp_error_resolved.PNG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;I've released a new upgrade script that fixes this issue automatically. &amp;nbsp;Just download security-onion-upgrade.sh from&amp;nbsp;&lt;a href="http://sourceforge.net/projects/security-onion/files/"&gt;http://sourceforge.net/projects/security-onion/files/&lt;/a&gt;&amp;nbsp;and run it like so:&lt;br /&gt;sudo bash security-onion-upgrade.sh&lt;br /&gt;&lt;br /&gt;It will then upgrade your Security Onion installation to version 20110122 and Reverse DNS queries should start working correctly.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-2019959965702500865?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/2019959965702500865/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=2019959965702500865' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/2019959965702500865'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/2019959965702500865'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/01/security-onion-20110122-fixes-dns-error.html' title='Security Onion 20110122 fixes DNS error in Sguil'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Prlv_CKbUdQ/TTsjWOmhRNI/AAAAAAAAAJ0/jP2FABEG_oM/s72-c/Security_Onion_20110122_Sguil_libudp_error.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-4542832831536968616</id><published>2011-01-20T07:10:00.001-05:00</published><updated>2011-01-20T08:35:51.168-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='squert'/><title type='text'>Introduction to Sguil and Squert: Part 4</title><content type='html'>&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;This post is the fourth in a multi-part series designed to introduce&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&amp;nbsp;&lt;a href="http://sguil.sourceforge.net/"&gt;Sguil&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="http://www.blogger.com/goog_1057432602"&gt;Squert&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;to beginners.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;I'm assuming you've already been through the steps in the previous posts in this series:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;a href="http://securityonion.blogspot.com/2011/01/introduction-to-sguil-and-squert-part-1.html"&gt;Introduction to Sguil and Squert: Part 1&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;a href="http://securityonion.blogspot.com/2011/01/introduction-to-sguil-and-squert-part-1.html"&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;a href="http://securityonion.blogspot.com/2011/01/introduction-to-sguil-and-squert-part-2.html"&gt;Introduction to Sguil and Squert: Part 2&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;a href="http://securityonion.blogspot.com/2011/01/introduction-to-sguil-and-squert-part-2.html"&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;a href="http://securityonion.blogspot.com/2011/01/introduction-to-sguil-and-squert-part-3.html"&gt;&lt;span class="Apple-style-span"&gt;Introduction to Sguil and Squert: Part&amp;nbsp;&lt;/span&gt;3&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="line-height: 20px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;In Part 3, we saw Sguil's killer feature of being able to pull session transcripts from the full packet captures to show an entire attack from beginning to end. &amp;nbsp;In Part 4, we're going to see one of Squert's killer features: alert visualization.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;Using the alerts from yesterday's demo, we display them in Squert.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Prlv_CKbUdQ/TTgkP5aZbXI/AAAAAAAAAJg/5iIABjbQ4K0/s1600/Security_Onion_20110116_Squert_sotm_create_visualization.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="312" src="http://1.bp.blogspot.com/_Prlv_CKbUdQ/TTgkP5aZbXI/AAAAAAAAAJg/5iIABjbQ4K0/s640/Security_Onion_20110116_Squert_sotm_create_visualization.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;Right above the alerts, we click "create" and are then prompted for some options. &amp;nbsp;We give it a name and keep the other options at their default settings.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Prlv_CKbUdQ/TTglIiOoC8I/AAAAAAAAAJk/dPuL4HOGInc/s1600/Security_Onion_20110116_Squert_sotm_visualize_this.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="78" src="http://4.bp.blogspot.com/_Prlv_CKbUdQ/TTglIiOoC8I/AAAAAAAAAJk/dPuL4HOGInc/s640/Security_Onion_20110116_Squert_sotm_visualize_this.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;We then click the "create" button and then a graph is generated of the alert data.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Prlv_CKbUdQ/TTglmWV325I/AAAAAAAAAJo/lEv1G_2Fs6w/s1600/Security_Onion_20110116_Squert_sotm_graph.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="404" src="http://1.bp.blogspot.com/_Prlv_CKbUdQ/TTglmWV325I/AAAAAAAAAJo/lEv1G_2Fs6w/s640/Security_Onion_20110116_Squert_sotm_graph.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="line-height: 20px;"&gt;We can then click on the graph to open a larger version and see more detail.&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-4542832831536968616?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/4542832831536968616/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=4542832831536968616' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/4542832831536968616'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/4542832831536968616'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/01/introduction-to-sguil-and-squert-part-4.html' title='Introduction to Sguil and Squert: Part 4'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Prlv_CKbUdQ/TTgkP5aZbXI/AAAAAAAAAJg/5iIABjbQ4K0/s72-c/Security_Onion_20110116_Squert_sotm_create_visualization.PNG' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-4974002148659510303</id><published>2011-01-20T06:44:00.000-05:00</published><updated>2011-01-20T06:44:33.190-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='setup script'/><category scheme='http://www.blogger.com/atom/ns#' term='sguil'/><title type='text'>Security Onion nsm_all_del script</title><content type='html'>This blog post will demonstrate the nsm_all_del script. &amp;nbsp;If you ran through Setup and configured your sensors but decide that you need to re-run Setup for some reason (perhaps you want to choose Advanced Setup to choose specific interfaces), then you need to run nsm_all_del first. &amp;nbsp;nsm_all_del will delete your current sensor configuration in preparation for running Setup again.&lt;br /&gt;&lt;br /&gt;Suppose I ran through Setup using Quick Setup which enumerated my ethernet interfaces and created Sguil sensors for eth0, eth1, and eth2. &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Prlv_CKbUdQ/TTgdJjwsxzI/AAAAAAAAAJI/KB1zfE4CRP4/s1600/Security_Onion_20110116_Setup_Quick_Setup_3_Ethernet_interfaces.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="288" src="http://2.bp.blogspot.com/_Prlv_CKbUdQ/TTgdJjwsxzI/AAAAAAAAAJI/KB1zfE4CRP4/s640/Security_Onion_20110116_Setup_Quick_Setup_3_Ethernet_interfaces.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Now suppose I want eth0 to be just a management interface with no Sguil sensor. &amp;nbsp;I need to run Setup again and choose Advanced Setup to exclude eth0, but first I need to run nsm_all_del to delete the current Sguil configuration.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Prlv_CKbUdQ/TTgd37sFgLI/AAAAAAAAAJM/Qbtb1316kvg/s1600/Security_Onion_20110116_nsm_all_del_menu.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="492" src="http://4.bp.blogspot.com/_Prlv_CKbUdQ/TTgd37sFgLI/AAAAAAAAAJM/Qbtb1316kvg/s640/Security_Onion_20110116_nsm_all_del_menu.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Once clicked, nsm_all_del displays a warning.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Prlv_CKbUdQ/TTgeJLFCnUI/AAAAAAAAAJQ/pFX0ULQQkpI/s1600/Security_Onion_20110116_nsm_all_del_warning.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="480" src="http://3.bp.blogspot.com/_Prlv_CKbUdQ/TTgeJLFCnUI/AAAAAAAAAJQ/pFX0ULQQkpI/s640/Security_Onion_20110116_nsm_all_del_warning.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;It then begins deleting sensors, asking for confirmation along the way.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Prlv_CKbUdQ/TTgedf5RypI/AAAAAAAAAJU/9FVwMKKt5HI/s1600/Security_Onion_20110116_nsm_all_del_deleting.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="478" src="http://3.bp.blogspot.com/_Prlv_CKbUdQ/TTgedf5RypI/AAAAAAAAAJU/9FVwMKKt5HI/s640/Security_Onion_20110116_nsm_all_del_deleting.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Once nsm_all_del completes, I then run Setup again and choose Advanced Setup so that I can choose which network interfaces should have Sguil sensors.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Prlv_CKbUdQ/TTge87h7MyI/AAAAAAAAAJY/W84f-acwWgM/s1600/Security_Onion_20110116_Setup_exclude_eth0.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_Prlv_CKbUdQ/TTge87h7MyI/AAAAAAAAAJY/W84f-acwWgM/s1600/Security_Onion_20110116_Setup_exclude_eth0.PNG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Once Setup completes, I login to Sguil and see that I only have Sguil sensors for eth1 and eth2.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Prlv_CKbUdQ/TTgf1R92s6I/AAAAAAAAAJc/BZHCK9cgsig/s1600/Security_Onion_20110116_Sguil_eth1_eth2.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="357" src="http://3.bp.blogspot.com/_Prlv_CKbUdQ/TTgf1R92s6I/AAAAAAAAAJc/BZHCK9cgsig/s640/Security_Onion_20110116_Sguil_eth1_eth2.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-4974002148659510303?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/4974002148659510303/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=4974002148659510303' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/4974002148659510303'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/4974002148659510303'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/01/security-onion-nsmalldel-script.html' title='Security Onion nsm_all_del script'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Prlv_CKbUdQ/TTgdJjwsxzI/AAAAAAAAAJI/KB1zfE4CRP4/s72-c/Security_Onion_20110116_Setup_Quick_Setup_3_Ethernet_interfaces.PNG' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-415500404844199296</id><published>2011-01-20T06:25:00.000-05:00</published><updated>2011-01-20T06:25:46.833-05:00</updated><title type='text'>Security Onion Upgrade Script</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: left;"&gt;This is a quick blog post to demonstrate the Security Onion Upgrade Script. &amp;nbsp;If you're running Security Onion 20110101 or newer, you can download and run the Security Onion Upgrade script to do an in-place upgrade. &amp;nbsp;In the screenshot below, you can see that I started with Security Onion 20110116 and then ran the following commands:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;wget&amp;nbsp;http://downloads.sourceforge.net/project/security-onion/security-onion-upgrade.sh&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;sudo bash security-onion-upgrade.sh&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;The upgrade script then upgraded the system to 20110117 and then to 20110118.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Prlv_CKbUdQ/TTgbW4e_oWI/AAAAAAAAAJE/uqk_SMk-nDY/s1600/Security_Onion_20110116_Upgrade_Script.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="478" src="http://4.bp.blogspot.com/_Prlv_CKbUdQ/TTgbW4e_oWI/AAAAAAAAAJE/uqk_SMk-nDY/s640/Security_Onion_20110116_Upgrade_Script.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-415500404844199296?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/415500404844199296/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=415500404844199296' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/415500404844199296'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/415500404844199296'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/01/security-onion-upgrade-script.html' title='Security Onion Upgrade Script'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Prlv_CKbUdQ/TTgbW4e_oWI/AAAAAAAAAJE/uqk_SMk-nDY/s72-c/Security_Onion_20110116_Upgrade_Script.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-6281356756152392568</id><published>2011-01-19T06:49:00.002-05:00</published><updated>2011-01-19T08:43:58.144-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='sguil'/><category scheme='http://www.blogger.com/atom/ns#' term='squert'/><title type='text'>Introduction to Sguil and Squert: Part 3</title><content type='html'>&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;This post is the third in a multi-part series designed to introduce&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&amp;nbsp;&lt;a href="http://sguil.sourceforge.net/"&gt;Sguil&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="http://www.pintumbler.org/Code/squert"&gt;Squert&lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&amp;nbsp;to beginners.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;I'm assuming you've already been through the steps in&amp;nbsp;&lt;a href="http://securityonion.blogspot.com/2011/01/introduction-to-sguil-and-squert-part-1.html"&gt;Introduction to Sguil and Squert: Part 1&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="http://securityonion.blogspot.com/2011/01/introduction-to-sguil-and-squert-part-2.html"&gt;Introduction to Sguil and Squert: Part 2&lt;/a&gt;.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;In Parts 1 and 2, we compared Sguil and Squert and showed how you can accomplish the same thing in both. &amp;nbsp;In Part 3, we're going to contrast them and see why we need both.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;Let's start with Sguil. &amp;nbsp;Sguil's killer feature is the ability to take an alert and pull a full session transcript. &amp;nbsp;By doing this, we not only see the traffic that triggered the alert, but also the traffic in the session that occurred before and after the alert. &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;Time for an example. &amp;nbsp;Download "Scan of the Month 19" from the Honeynet Project:&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;wget http://old.honeynet.org/scans/scan19/scan19.tar.gz&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;Expand the tarball:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;tar zxvf scan19.tar.gz&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;If you haven't already, log into Sguil so that you'll be able to see the alerts as they populate. &amp;nbsp;Now use tcpreplay to replay newdat3.log onto your eth0 interface (you may need/want to use a different interface, just make sure it's one that's being monitored by Sguil):&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;sudo tcpreplay -i eth0 -t newdat3.log&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;As soon as you hit Enter, switch over to your Sguil console so that you can see the alerts. &amp;nbsp;You should see something like this:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Prlv_CKbUdQ/TTbNEiEiS_I/AAAAAAAAAI0/5DDLAiGBcYs/s1600/Security_Onion_20110118_Sguil_SOTM19.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="248" src="http://2.bp.blogspot.com/_Prlv_CKbUdQ/TTbNEiEiS_I/AAAAAAAAAI0/5DDLAiGBcYs/s640/Security_Onion_20110118_Sguil_SOTM19.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;Go to either of the "GPL FTP SITE ..." events, right-click the Alert ID, and click Transcript. &amp;nbsp;A new window will appear like this:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Prlv_CKbUdQ/TTbOP_QWTrI/AAAAAAAAAI4/VCL4qYugcJ8/s1600/Security_Onion_20110118_Sguil_SOTM19_Transcript_top.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="572" src="http://3.bp.blogspot.com/_Prlv_CKbUdQ/TTbOP_QWTrI/AAAAAAAAAI4/VCL4qYugcJ8/s640/Security_Onion_20110118_Sguil_SOTM19_Transcript_top.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;It may take a few seconds to pull the entire transcript. &amp;nbsp;Once it does, you'll be able to scroll down and see the entire FTP attack, from the buffer overflow to the attacker catting the passwd file:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Prlv_CKbUdQ/TTbO4dTVd6I/AAAAAAAAAI8/pckWndLryPM/s1600/Security_Onion_20110118_Sguil_SOTM19_Transcript_passwd.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="572" src="http://1.bp.blogspot.com/_Prlv_CKbUdQ/TTbO4dTVd6I/AAAAAAAAAI8/pckWndLryPM/s640/Security_Onion_20110118_Sguil_SOTM19_Transcript_passwd.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px; line-height: 20px;"&gt;Can your commercial IDS do that? &amp;nbsp;Come back tomorrow to see one of the killer features that Squert has.&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7554630712114756330-6281356756152392568?l=securityonion.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityonion.blogspot.com/feeds/6281356756152392568/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7554630712114756330&amp;postID=6281356756152392568' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/6281356756152392568'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7554630712114756330/posts/default/6281356756152392568'/><link rel='alternate' type='text/html' href='http://securityonion.blogspot.com/2011/01/introduction-to-sguil-and-squert-part-3.html' title='Introduction to Sguil and Squert: Part 3'/><author><name>Doug Burks</name><uri>https://profiles.google.com/111329543725174220559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-KnuquXjhOo4/AAAAAAAAAAI/AAAAAAAAAPc/kcTssBBYnIc/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Prlv_CKbUdQ/TTbNEiEiS_I/AAAAAAAAAI0/5DDLAiGBcYs/s72-c/Security_Onion_20110118_Sguil_SOTM19.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7554630712114756330.post-7585318350117655674</id><published>2011-01-18T05:39:00.003-05:00</published><updated>2011-01-18T06:13:15.003-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security onion'/><category scheme='http://www.blogger.com/atom/ns#' term='sguil'/><category scheme='http://www.blogger.com/atom/ns#' term='squert'/><title type='text'>Introduction to Sguil and Squert: Part 2</title><content type='html'>&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;This post is the second in a multi-part series designed to introduce&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&amp;nbsp;&lt;a href="http://sguil.sourceforge.net/"&gt;Sguil&lt;/a&gt; and &lt;a href="http://www.pintumbler.org/Code/squert"&gt;Squert&lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&amp;nbsp;to beginners.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;I'm assuming you've already been through the steps in&amp;nbsp;&lt;a href="http://securityonion.blogspot.com/2011/01/introduction-to-sguil-and-squert-part-1.html"&gt;Introduction to Sguil and Squert: Part 1&lt;/a&gt;. &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;Before we get started with Part 2, we need to fix a bug in Security Onion's Squert configuration. &amp;nbsp;Download the &lt;a href="http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh/download"&gt;Security Onion Upgrade script&lt;/a&gt; and run it from a terminal like so:&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;sudo bash security-onion-upgrade.sh&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;Let's get started! &amp;nbsp;Generate an alert like you did previously using the &lt;a href="http://testmyids.com/"&gt;testmyids.com&lt;/a&gt; bookmark in Firefox. &amp;nbsp;If the page loads but you get no alert in Sguil, then Firefox loaded the page from cache and you'll need to do a Shift-Reload to force the browser to get a new copy of the page.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;In Sguil, make sure that "Show Packet Data" and "Show Rule" are enabled. &amp;nbsp;Now click the alert. &amp;nbsp;You should something like the following screenshot. &amp;nbsp;Notice that we can instantly see both the rule and the traffic that triggered the alert without any further navigation in the user interface.&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Prlv_CKbUdQ/TTTjvMsSOKI/AAAAAAAAAIc/epPqu8w9EHE/s1600/Security_Onion_20110116_Sguil_alert_rule_and_data.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="466" src="http://3.bp.blogspot.com/_Prlv_CKbUdQ/TTTjvMsSOKI/AAAAAAAAAIc/epPqu8w9EHE/s640/Security_Onion_20110116_Sguil_alert_rule_and_data.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;In Squert, set Status to Unclassified as we did before and click the "submit" button. &amp;nbsp;You should see something like the following. &amp;nbsp;Notice that we only see the Signature.&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_Prlv_CKbUdQ/TTTkuIctNPI/AAAAAAAAAIg/iPoyoCUtl9o/s1600/Security_Onion_20110116_Squert_alert_signature.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="392" src="http://1.bp.blogspot.com/_Prlv_CKbUdQ/TTTkuIctNPI/AAAAAAAAAIg/iPoyoCUtl9o/s640/Security_Onion_20110116_Squert_alert_signature.PNG" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 15px; line-height: 20px;"&gt;Click the View drop-dow
