<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for Inliniac</title>
	<atom:link href="http://blog.inliniac.net/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.inliniac.net</link>
	<description>Everything inline.</description>
	<lastBuildDate>Tue, 23 Apr 2013 10:18:03 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>Comment on Suricata Lua scripting flowvar access by More on Suricata lua flowints &#124; Inliniac</title>
		<link>http://blog.inliniac.net/2013/04/18/suricata-lua-scripting-flowvar-access/comment-page-1/#comment-878</link>
		<dc:creator><![CDATA[More on Suricata lua flowints &#124; Inliniac]]></dc:creator>
		<pubDate>Tue, 23 Apr 2013 10:18:03 +0000</pubDate>
		<guid isPermaLink="false">http://blog.inliniac.net/?p=731#comment-878</guid>
		<description><![CDATA[[...] to yesterday&#8217;s flowint script and the earlier flowvar based counting script, this performs [...]]]></description>
		<content:encoded><![CDATA[<p>[...] to yesterday&#8217;s flowint script and the earlier flowvar based counting script, this performs [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Suricata Lua scripting flowint access by More on Suricata lua flowints &#124; Inliniac</title>
		<link>http://blog.inliniac.net/2013/04/22/suricata-lua-scripting-flowint-access/comment-page-1/#comment-877</link>
		<dc:creator><![CDATA[More on Suricata lua flowints &#124; Inliniac]]></dc:creator>
		<pubDate>Tue, 23 Apr 2013 10:18:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.inliniac.net/?p=748#comment-877</guid>
		<description><![CDATA[[...] &#8592; Previous [...]]]></description>
		<content:encoded><![CDATA[<p>[...] &larr; Previous [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Suricata Lua scripting flowvar access by Suricata Lua scripting flowint access &#124; Inliniac</title>
		<link>http://blog.inliniac.net/2013/04/18/suricata-lua-scripting-flowvar-access/comment-page-1/#comment-875</link>
		<dc:creator><![CDATA[Suricata Lua scripting flowint access &#124; Inliniac]]></dc:creator>
		<pubDate>Mon, 22 Apr 2013 16:16:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.inliniac.net/?p=731#comment-875</guid>
		<description><![CDATA[[...] few days ago I wrote about my Emerging Threats sponsored work to support flowvars from Lua scripts in [...]]]></description>
		<content:encoded><![CDATA[<p>[...] few days ago I wrote about my Emerging Threats sponsored work to support flowvars from Lua scripts in [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Setting up an IPS with Fedora 17, Suricata and Vuurmuur by John</title>
		<link>http://blog.inliniac.net/2012/10/13/setting-up-an-ips-with-fedora-17-suricata-and-vuurmuur/comment-page-1/#comment-853</link>
		<dc:creator><![CDATA[John]]></dc:creator>
		<pubDate>Sun, 24 Mar 2013 07:41:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.inliniac.net/?p=673#comment-853</guid>
		<description><![CDATA[Hi,

Thanks for the tutorial, it helped me a lot installing Suricata IPS on SL6! :)
I can see packets going through the NFQUEUE fine and the facebook website test rule you provide works fine too.
However, I&#039;m a little unsure of where to go from here. I&#039;ve installed Oinkmaster to automatically update the rules from EmeringThreats each day.
Do I need to individually configure rules to &#039;drop&#039; via Oinkmaster in order to get Suricata protecting the network?
There is lots if data showing up in fast.log, http.log, but I get the impression these are just alerts and nothing is actually being dropped.
In addition, if I enable drop logging, there are some packets being dropped, but it&#039;s not clear what for :(

Thanks,
John]]></description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Thanks for the tutorial, it helped me a lot installing Suricata IPS on SL6! <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
I can see packets going through the NFQUEUE fine and the facebook website test rule you provide works fine too.<br />
However, I&#8217;m a little unsure of where to go from here. I&#8217;ve installed Oinkmaster to automatically update the rules from EmeringThreats each day.<br />
Do I need to individually configure rules to &#8216;drop&#8217; via Oinkmaster in order to get Suricata protecting the network?<br />
There is lots if data showing up in fast.log, http.log, but I get the impression these are just alerts and nothing is actually being dropped.<br />
In addition, if I enable drop logging, there are some packets being dropped, but it&#8217;s not clear what for <img src='http://s0.wp.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p>Thanks,<br />
John</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Listening on multiple interfaces with Suricata by Song Liu</title>
		<link>http://blog.inliniac.net/2010/12/24/listening-on-multiple-interfaces-with-suricata/comment-page-1/#comment-843</link>
		<dc:creator><![CDATA[Song Liu]]></dc:creator>
		<pubDate>Sun, 17 Mar 2013 20:00:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=421#comment-843</guid>
		<description><![CDATA[In the separate traffic use case, it&#039;s better to use separate flow table (per interface). In this way, i think it will reduce the contention for the flow table.]]></description>
		<content:encoded><![CDATA[<p>In the separate traffic use case, it&#8217;s better to use separate flow table (per interface). In this way, i think it will reduce the contention for the flow table.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Fixing noise on Ubuntu Hardy 8.04, aka setting max_cstate by trillerpfeife</title>
		<link>http://blog.inliniac.net/2008/07/25/fixing-noise-on-ubuntu-hardy-804-aka-setting-max_cstate/comment-page-1/#comment-824</link>
		<dc:creator><![CDATA[trillerpfeife]]></dc:creator>
		<pubDate>Thu, 21 Feb 2013 01:07:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=137#comment-824</guid>
		<description><![CDATA[at markus and you many thanks!!]]></description>
		<content:encoded><![CDATA[<p>at markus and you many thanks!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Migrating from ModSecurity 1.9.4 to 2.0.4 by Ravisankar</title>
		<link>http://blog.inliniac.net/2007/01/20/migrating-from-modsecurity-194-to-204/comment-page-1/#comment-776</link>
		<dc:creator><![CDATA[Ravisankar]]></dc:creator>
		<pubDate>Thu, 17 Jan 2013 04:43:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=62#comment-776</guid>
		<description><![CDATA[i want to protect http://mysite.com/?ptrxcz_

Here i want to block request from ?ptrxcz_ this string . is it possible in modsecurity  1.9.4.]]></description>
		<content:encoded><![CDATA[<p>i want to protect <a href="http://mysite.com/?ptrxcz_" rel="nofollow">http://mysite.com/?ptrxcz_</a></p>
<p>Here i want to block request from ?ptrxcz_ this string . is it possible in modsecurity  1.9.4.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Suricata MD5 blacklisting by Matt Oney</title>
		<link>http://blog.inliniac.net/2012/06/09/suricata-md5-blacklisting/comment-page-1/#comment-775</link>
		<dc:creator><![CDATA[Matt Oney]]></dc:creator>
		<pubDate>Wed, 16 Jan 2013 19:26:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=523#comment-775</guid>
		<description><![CDATA[Has anyone set this up?  I was looking to set this up on a pretty large network and was wondering about processing power, etc.  If anyone can offer any suggestions about this please email me at matt_oney2002@yahoo.com]]></description>
		<content:encoded><![CDATA[<p>Has anyone set this up?  I was looking to set this up on a pretty large network and was wondering about processing power, etc.  If anyone can offer any suggestions about this please email me at <a href="mailto:matt_oney2002@yahoo.com">matt_oney2002@yahoo.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Suricata has experimental CUDA support by Sami J. Mäkinen</title>
		<link>http://blog.inliniac.net/2010/02/20/suricata-has-experimental-cuda-support/comment-page-1/#comment-773</link>
		<dc:creator><![CDATA[Sami J. Mäkinen]]></dc:creator>
		<pubDate>Thu, 10 Jan 2013 08:43:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=324#comment-773</guid>
		<description><![CDATA[Yes, I joined the mailing list. And yes, I will gladly help you testing CUDA support.]]></description>
		<content:encoded><![CDATA[<p>Yes, I joined the mailing list. And yes, I will gladly help you testing CUDA support.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Vuurmuur 0.8beta4 released by Stanislav Lechev [0xAF]</title>
		<link>http://blog.inliniac.net/2012/08/31/vuurmuur-0-8beta4-released/comment-page-1/#comment-754</link>
		<dc:creator><![CDATA[Stanislav Lechev [0xAF]]]></dc:creator>
		<pubDate>Mon, 07 Jan 2013 01:46:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.inliniac.net/?p=581#comment-754</guid>
		<description><![CDATA[Good to know that new versions are coming, after so much time. Thanks for your great work.]]></description>
		<content:encoded><![CDATA[<p>Good to know that new versions are coming, after so much time. Thanks for your great work.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
