OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[Snort-users] RE: (Off List) Two items that are hard to digest...

From: Michael Steele (michaelssilicondefense.com)
Date: Thu Apr 17 2003 - 14:05:50 CDT


Chris,

 

There are hundreds if not thousands of Snort 1.9.1 users out there that
can't update to 2.0 at this time, and it doesn't matter what platform they
are on. Sure there is a fix for this Stream 4 vulnerability, but in turn
that opens up another vulnerability. So what are they to do?

 

All I can do as one person is let my concerns known and try to get some
constructive feedback so others out there know there is a definite problem,
and that they are not alone.

 

I absolutely have no ax to grind with anyone.

 

I try my best to help anyone that I can. If you posted a message in the
Snort Users group and I failed to reply then I'm truly sorry. I get a LOT of
personal email for support and that is a really good way to contact me.

-Michael
--
 Michael Steele | System Engineer / Support Technician
 mailto:michaelssilicondefense.com
 Silicon Defense - The Cyber-War Defense Company
 Website: http://www.silicondefense.com
 Snort: Open Source Network IDS - http://www.snort.org

  _____

From: L. Christopher Luther [mailto:CLutherXybernaut.com]
Sent: Thursday, April 17, 2003 11:07 AM
To: 'Michael Steele'

 

Michael,

I'm usually in 100% agreement (well okay, maybe only 90%) with all that you
say on this list. But after watching all the back-n-forth traffic generated
by your two questions, it would appear that you have some type of "axe to
grind" with someone(s) on the Snort team. Is the case?

I am in agreement with your desire to patch 1.9.1. Then again when I tried
to get my two sensors up to 1.9.x, the Win2K sensor just wouldn't take 1.9.x
install, and when I posted to this list I didn't even get a single response
of assistance with this one particular issue. So I'm now left with one
1.9.x WinNT4 sensor and one 1.8.7 Win2K sensor. I'm not even going to play
with Snort 2.x until I have *lots* of time on my hands 'cause I don't expect
the Win2K sensor to act any better with Snort 2.x.

- Christopher

 

-----Original Message-----
From: Michael Steele [mailto:michaelssilicondefense.com]
Sent: Thursday, April 17, 2003 10:46 AM
To: snort-userslists.sourceforge.net
Subject: [Snort-users] Two items that are hard to digest...

 

All,

Questions:

1. Why is Snort 1.9.1 not being patched? IMHO this is a big mistake as some
users are not ready for 2.0.x yet.

2. Why was there a 2.0.0 Release announcement when in fact there is no such
release? If you download the 2.0.0 release you get Snort 2.0.0 RC5 b72.

-Michael
--
 Michael Steele | System Engineer / Support Technician
 mailto:michaelssilicondefense.com
 Silicon Defense - The Cyber-War Defense Company
 Website: http://www.silicondefense.com
 Snort: Open Source Network IDS - http://www.snort.org

-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-userslists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-userslists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users