<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Sguil - Intuitive GUI for Network Security Monitoring with Snort</title>
	<atom:link href="http://www.darknet.org.uk/2007/06/sguil-intuitive-gui-for-network-security-monitoring-with-snort/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2007/06/sguil-intuitive-gui-for-network-security-monitoring-with-snort/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<pubDate>Fri, 21 Nov 2008 00:24:13 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: Torvaun</title>
		<link>http://www.darknet.org.uk/2007/06/sguil-intuitive-gui-for-network-security-monitoring-with-snort/#comment-59096</link>
		<dc:creator>Torvaun</dc:creator>
		<pubDate>Tue, 05 Jun 2007 07:54:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/06/sguil-intuitive-gui-for-network-security-monitoring-with-snort/#comment-59096</guid>
		<description>Ooh, new toy to play with, on company time no less.  Will review and report back later.</description>
		<content:encoded><![CDATA[<p>Ooh, new toy to play with, on company time no less.  Will review and report back later.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Darknet</title>
		<link>http://www.darknet.org.uk/2007/06/sguil-intuitive-gui-for-network-security-monitoring-with-snort/#comment-58967</link>
		<dc:creator>Darknet</dc:creator>
		<pubDate>Sun, 03 Jun 2007 09:43:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/06/sguil-intuitive-gui-for-network-security-monitoring-with-snort/#comment-58967</guid>
		<description>&lt;strong&gt;mubix:&lt;/strong&gt; I'd echo what Hanashi said, you are better off configuring your sensors properly so they don't generate the alert rather than filtering it out in the results. It's pretty easy to setup and I do like it, I tend to use the web-based systems more though as I find them more portable (I can access from anywhere).

&lt;strong&gt;Hanashi:&lt;/strong&gt; Will add the source link in when your FAQ is back up. I don't tend to link source for tool/software posts at it can be assumed the text is from the site being linked to. Cheers!</description>
		<content:encoded><![CDATA[<p><strong>mubix:</strong> I&#8217;d echo what Hanashi said, you are better off configuring your sensors properly so they don&#8217;t generate the alert rather than filtering it out in the results. It&#8217;s pretty easy to setup and I do like it, I tend to use the web-based systems more though as I find them more portable (I can access from anywhere).</p>
<p><strong>Hanashi:</strong> Will add the source link in when your FAQ is back up. I don&#8217;t tend to link source for tool/software posts at it can be assumed the text is from the site being linked to. Cheers!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hanashi</title>
		<link>http://www.darknet.org.uk/2007/06/sguil-intuitive-gui-for-network-security-monitoring-with-snort/#comment-58921</link>
		<dc:creator>Hanashi</dc:creator>
		<pubDate>Fri, 01 Jun 2007 17:46:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/06/sguil-intuitive-gui-for-network-security-monitoring-with-snort/#comment-58921</guid>
		<description>mubix, &lt;a href="http://wiki.sguil.net" rel="nofollow"&gt;NSMWiki&lt;/a&gt;, the official Sguil wiki, has a section for &lt;a href="http://wiki.sguil.net/nsmwiki/index.php?title=Sguil_Installation_and_HOWTO_Guides" rel="nofollow"&gt;Installation and HOWTO guides&lt;/a&gt;.  You'll find some pretty detailed instructions, which should take some of the pain out of it.  If you're on RHEL, you can even use &lt;a href="http://instantnsm.sourceforge.net" rel="nofollow"&gt;InstantNSM&lt;/a&gt; to automate most of the install.  

And yes, you can configure sguil to ignore alerts like that, but it's probably better to tune Snort itself so that they are never generated in the first place.

BTW, most of the text in this article was cribbed from the Sguil FAQ.  Thanks to the Darknet folks for promoting sguil, just please remember to cite your source next time.</description>
		<content:encoded><![CDATA[<p>mubix, <a href="http://wiki.sguil.net" rel="nofollow">NSMWiki</a>, the official Sguil wiki, has a section for <a href="http://wiki.sguil.net/nsmwiki/index.php?title=Sguil_Installation_and_HOWTO_Guides" rel="nofollow">Installation and HOWTO guides</a>.  You&#8217;ll find some pretty detailed instructions, which should take some of the pain out of it.  If you&#8217;re on RHEL, you can even use <a href="http://instantnsm.sourceforge.net" rel="nofollow">InstantNSM</a> to automate most of the install.  </p>
<p>And yes, you can configure sguil to ignore alerts like that, but it&#8217;s probably better to tune Snort itself so that they are never generated in the first place.</p>
<p>BTW, most of the text in this article was cribbed from the Sguil FAQ.  Thanks to the Darknet folks for promoting sguil, just please remember to cite your source next time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mubix</title>
		<link>http://www.darknet.org.uk/2007/06/sguil-intuitive-gui-for-network-security-monitoring-with-snort/#comment-58915</link>
		<dc:creator>mubix</dc:creator>
		<pubDate>Fri, 01 Jun 2007 15:31:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/06/sguil-intuitive-gui-for-network-security-monitoring-with-snort/#comment-58915</guid>
		<description>The people from SQUIL gave a talk at ShmooCon 06 and I was quite impressed with it then, but I never had the time to dedicate to get it working. Dark, have you gotten it working and, if so, do you like it? Does it have Snort configuration options? Can I tell it to ignore the very annoying "DOUBLE DECODING ATTACK" alert?</description>
		<content:encoded><![CDATA[<p>The people from SQUIL gave a talk at ShmooCon 06 and I was quite impressed with it then, but I never had the time to dedicate to get it working. Dark, have you gotten it working and, if so, do you like it? Does it have Snort configuration options? Can I tell it to ignore the very annoying &#8220;DOUBLE DECODING ATTACK&#8221; alert?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
