<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; IPS</title>
	<atom:link href="http://www.darknet.org.uk/tag/ips/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Smooth-Sec &#8211; All In One Pre-Configured IDS/IPS System</title>
		<link>http://www.darknet.org.uk/2011/03/smooth-sec-all-in-one-pre-configured-idsips-system/</link>
		<comments>http://www.darknet.org.uk/2011/03/smooth-sec-all-in-one-pre-configured-idsips-system/#comments</comments>
		<pubDate>Tue, 22 Mar 2011 08:40:48 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[intrusion detection system]]></category>
		<category><![CDATA[intrusion-prevention-system]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[open source ids]]></category>
		<category><![CDATA[open source ips]]></category>
		<category><![CDATA[pre-configured ids]]></category>
		<category><![CDATA[turkey ids]]></category>
		<category><![CDATA[turnkey ids/ips]]></category>
		<category><![CDATA[turnkey ips]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3073</guid>
		<description><![CDATA[Smooth-Sec is a ready to-go IDS/IPS (Intrusion Detection/Prevention System) Linux distribution based on the multi threaded Suricata IDS/IPS engine and Snorby, the top notch web application for network security monitoring. Smooth-Sec is built on Ubuntu 10.04 LTS using the TurnKey Core base as development platform. Functionality is the key point that allows a user to [...]]]></description>
			<content:encoded><![CDATA[<p>Smooth-Sec is a ready to-go  IDS/IPS (Intrusion Detection/Prevention System) Linux distribution based on the multi threaded Suricata IDS/IPS engine and Snorby, the top notch web application for network security monitoring. Smooth-Sec is built on Ubuntu 10.04 LTS using the TurnKey Core base as development platform.</p>
<p>Functionality is the key point that allows a user to deploy a complete IDS/IPS System up and running out of the box within a few minutes, even for security beginners with minimal Linux experience.</p>
<p><strong>Features</strong></p>
<p><em><strong>Snorby</strong></em></p>
<ul>
<li>Metrics Metrics &#038; Reports</li>
<li>Classifications</li>
<li>Full packet and session data.</li>
<li>Settings Custom Settings</li>
<li>Hotkeys</li>
</ul>
<p><em><strong>Suricata</strong></em></p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<ul>
<li>Native IPv6 Support</li>
<li>Automatic protocol detection</li>
<li>Multi threaded</li>
<li>Native hardware acceleration support</li>
<li>Passive OS and Portscan detection</li>
<li>L7 Protocol awareness</li>
<li>IP Reputation using scoring threshold</li>
<li>Distributed blocking &#038; feedback</li>
<li>Global flowbits and variables</li>
</ul>
<p><strong>Details</strong></p>
<p><strong>Snorby login:</strong></p>
<p><strong>Snorby interface:</strong> https://ipaddress<br />
<strong>Username:</strong> snorby@snorby.org<br />
<strong>Password:</strong> snorby  (please change this password after the firts login)</p>
<p><strong>Ssh login:</strong></p>
<p><strong>Username:</strong> root<br />
<strong>Password:</strong> the password you have chose during the installation</p>
<p>You can download Smooth-Sec here:</p>
<p><a href="http://sourceforge.net/projects/smoothsec/files/SmoothSec-1.1.iso/download">SmoothSec-1.1.iso</a></p>
<p>Or read more <a href="http://bailey.st/blog/smooth-sec/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Smooth-Sec+%E2%80%93+All+In+One+Pre-Configured+IDS%2FIPS+System+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3073+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/03/smooth-sec-all-in-one-pre-configured-idsips-system/&amp;t=Smooth-Sec+%E2%80%93+All+In+One+Pre-Configured+IDS%2FIPS+System" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/03/smooth-sec-all-in-one-pre-configured-idsips-system/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/03/smooth-sec-all-in-one-pre-configured-idsips-system/&amp;title=Smooth-Sec+%E2%80%93+All+In+One+Pre-Configured+IDS%2FIPS+System" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/03/smooth-sec-all-in-one-pre-configured-idsips-system/&amp;title=Smooth-Sec+%E2%80%93+All+In+One+Pre-Configured+IDS%2FIPS+System" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/03/smooth-sec-all-in-one-pre-configured-idsips-system/&amp;title=Smooth-Sec+%E2%80%93+All+In+One+Pre-Configured+IDS%2FIPS+System" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/03/smooth-sec-all-in-one-pre-configured-idsips-system/&amp;title=Smooth-Sec+%E2%80%93+All+In+One+Pre-Configured+IDS%2FIPS+System" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F03%2Fsmooth-sec-all-in-one-pre-configured-idsips-system%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/03/smooth-sec-all-in-one-pre-configured-idsips-system/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Suricata &#8211; Open Source Next Generation Intrusion Detection and Prevention Engine</title>
		<link>http://www.darknet.org.uk/2010/05/suricata-open-source-next-generation-intrusion-detection-and-prevention-engine/</link>
		<comments>http://www.darknet.org.uk/2010/05/suricata-open-source-next-generation-intrusion-detection-and-prevention-engine/#comments</comments>
		<pubDate>Thu, 13 May 2010 09:22:36 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[intrusion detection engine]]></category>
		<category><![CDATA[intrusion detection system]]></category>
		<category><![CDATA[intrusion prevention engine]]></category>
		<category><![CDATA[intrusion-detection]]></category>
		<category><![CDATA[intrusion-prevention]]></category>
		<category><![CDATA[intrusion-prevention-system]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[open source intrusion detection]]></category>
		<category><![CDATA[open source intrusion prevention]]></category>
		<category><![CDATA[open-source]]></category>
		<category><![CDATA[Open-Source-Software]]></category>
		<category><![CDATA[suricata]]></category>
		<category><![CDATA[suricata engine]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2689</guid>
		<description><![CDATA[The Suricata Engine is an Open Source Next Generation Intrusion Detection and Prevention Engine. This engine is not intended to just replace or emulate the existing tools in the industry, but will bring new ideas and technologies to the field. Basically it&#8217;s a is a multi-threaded intrusion detection/prevention engine engine available from the Open Information [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>The Suricata Engine is an Open Source Next Generation Intrusion Detection and Prevention Engine. This engine is not intended to just replace or emulate the existing tools in the industry, but will bring new ideas and technologies to the field.</p>
<p>Basically it&#8217;s a is a multi-threaded intrusion detection/prevention engine engine available from the Open Information Security Foundation </p>
<p>OISF is part of and funded by the Department of Homeland Security&#8217;s Directorate for Science and Technology HOST program (Homeland Open Security Technology), by the the Navy&#8217;s Space and Naval Warfare Systems Command (SPAWAR), as well as through the very generous support of the members of the OISF Consortium. More information about the Consortium is available, as well as a list of our current Consortium Members. </p>
<p>The Suricata Engine and the HTP Library are available to use under the GPLv2. </p>
<p>The HTP Library is an HTTP normalizer and parser written by Ivan Ristic of Mod Security fame for the OISF. This integrates and provides very advanced processing of HTTP streams for Suricata. The HTP library is required by the engine, but may also be used independently in a range of applications and tools. </p>
<p>You can download Suricata v0.9 here:</p>
<p><a href="http://www.openinfosecfoundation.org/download/suricata-0.9.0.tar.gz">suricata-0.9.0.tar.gz</a></p>
<p></p>
<p>Or read more <a href="http://www.openinfosecfoundation.org/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Suricata+%E2%80%93+Open+Source+Next+Generation+Intrusion+Detection+and+Prevention+Engine+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2689+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/05/suricata-open-source-next-generation-intrusion-detection-and-prevention-engine/&amp;t=Suricata+%E2%80%93+Open+Source+Next+Generation+Intrusion+Detection+and+Prevention+Engine" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/05/suricata-open-source-next-generation-intrusion-detection-and-prevention-engine/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/05/suricata-open-source-next-generation-intrusion-detection-and-prevention-engine/&amp;title=Suricata+%E2%80%93+Open+Source+Next+Generation+Intrusion+Detection+and+Prevention+Engine" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/05/suricata-open-source-next-generation-intrusion-detection-and-prevention-engine/&amp;title=Suricata+%E2%80%93+Open+Source+Next+Generation+Intrusion+Detection+and+Prevention+Engine" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/05/suricata-open-source-next-generation-intrusion-detection-and-prevention-engine/&amp;title=Suricata+%E2%80%93+Open+Source+Next+Generation+Intrusion+Detection+and+Prevention+Engine" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/05/suricata-open-source-next-generation-intrusion-detection-and-prevention-engine/&amp;title=Suricata+%E2%80%93+Open+Source+Next+Generation+Intrusion+Detection+and+Prevention+Engine" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F05%2Fsuricata-open-source-next-generation-intrusion-detection-and-prevention-engine%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/05/suricata-open-source-next-generation-intrusion-detection-and-prevention-engine/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Hackers Target Home Users for Cash</title>
		<link>http://www.darknet.org.uk/2006/11/hackers-target-home-users-for-cash/</link>
		<comments>http://www.darknet.org.uk/2006/11/hackers-target-home-users-for-cash/#comments</comments>
		<pubDate>Wed, 01 Nov 2006 18:14:56 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General News]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[companies]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[Information-Security]]></category>
		<category><![CDATA[intrusion-detection]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[symantec-threat-report]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/11/hackers-target-home-users-for-cash/</guid>
		<description><![CDATA[Hackers are switching targets now, companies are getting too hard to break into due to the availability of decently configured perimeter kit like firewalls and IDS. Plus the information they do get if they manage to break in is often worthless commercially and really not worth the effort. So instead, they target the end user, [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Hackers are switching targets now, companies are getting too hard to break into due to the availability of decently configured perimeter kit like firewalls and IDS.</p>
<p>Plus the information they do get if they manage to break in is often worthless commercially and really not worth the effort.</p>
<p>So instead, they target the end user, home bankers, those who they can scam, con or phish!</p>
<blockquote><p>Consumers are now on the main target of malicious hackers intent on enriching themselves through the misery of others. Vulnerabilities in desktop applications and the increased use of stealth techniques are on the rise among members of the digital underground, according to the latest edition of Symantec&#8217;s Internet Security Threat Report.</p>
<p>The report, which covers the first half of 2006, suggests that consumer security protection is weak, leaving Joe Public easy prey to identity thieves, botnet herders and other financially motivated criminals. Crackers are using a variety of techniques to escape detection and remain on infected systems for longer. Symantec reckons assaults against consumers account for 86 per cent of all targeted attacks. Banks and other financial sector organisations are the second most prevalent target for internet attacks. Phishing attacks almost doubled during the reporting period.</p></blockquote>
<p>The information on your desktop could be valuable to someone&#8230;remember aswell spyware/adware companies are making tens of millions infecting users and just simply collecting information about Internet useage and surfing habits.</p>
<blockquote><p>In the first half of 2006, 18 per cent of all malicious code samples detected by Symantec had not been seen before, indicating that hackers are trying harder to evade detection by signature-based anti virus and intrusion prevention systems.</p>
<p>Phishers are also attempting to bypass filtering technologies by creating multiple randomised messages. In H1 2006, 157,477 unique phishing messages were detected, 81 per cent more than the previous six months. The financial services sector was the most heavily phished, accounting for 84 per cent of phishing sites tracked by the Symantec.</p></blockquote>
<p>This shows a BIG pickup in new and unique code, people are trying harder and getting smarter, phishers are starting to use the tricks spammers are already using. Loads of phishing.</p>
<p></p>
<p>Source: <a href="http://www.theregister.co.uk/2006/09/25/symantec_threat_report/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Hackers+Target+Home+Users+for+Cash+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D352+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/11/hackers-target-home-users-for-cash/&amp;t=Hackers+Target+Home+Users+for+Cash" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/11/hackers-target-home-users-for-cash/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/11/hackers-target-home-users-for-cash/&amp;title=Hackers+Target+Home+Users+for+Cash" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/11/hackers-target-home-users-for-cash/&amp;title=Hackers+Target+Home+Users+for+Cash" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/11/hackers-target-home-users-for-cash/&amp;title=Hackers+Target+Home+Users+for+Cash" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/11/hackers-target-home-users-for-cash/&amp;title=Hackers+Target+Home+Users+for+Cash" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F11%2Fhackers-target-home-users-for-cash%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/11/hackers-target-home-users-for-cash/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Impressive Open Source Intrusion Prevention &#8211; HLBR</title>
		<link>http://www.darknet.org.uk/2006/09/impressive-open-source-intrusion-prevention-hlbr/</link>
		<comments>http://www.darknet.org.uk/2006/09/impressive-open-source-intrusion-prevention-hlbr/#comments</comments>
		<pubDate>Thu, 14 Sep 2006 05:35:45 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[intrusion-prevention]]></category>
		<category><![CDATA[intrusion-prevention-system]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[nessus]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[open-source]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[snort]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[viruses]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/09/impressive-open-source-intrusion-prevention-hlbr/</guid>
		<description><![CDATA[It&#8217;s good to see work on open source tools in the countermeasure department aswell as the attack and penetration arena. It&#8217;s a shame since Snort and Nessus have gone semi-commercial. I hope more people invest their time in good IDS, Firewall and IPS systems, I love things like IPCop and hope to see more products [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>It&#8217;s good to see work on open source tools in the countermeasure department aswell as the attack and penetration arena.</p>
<p>It&#8217;s a shame since Snort and Nessus have gone semi-commercial.</p>
<p>I hope more people invest their time in good IDS, Firewall and IPS systems, I love things like IPCop and hope to see more products like HLBR.</p>
<p>HLBR is a brazilian project, started in november 2005, as a fork of the Hogwash project (started by Jason Larsen in 1996)</p>
<p>HLBR is an IPS (Intrusion Prevention System) that can filter packets directly in the layer 2 of the OSI model (so the machine doesn&#8217;t need even an IP address). Detection of malicious/anomalous traffic is done by rules based in signatures, and the user can add more rules. It is an efficient and versatile IPS, and it can even be used as bridge to honeypots and honeynets. Since it doesn&#8217;t make use of the operating system&#8217;s TCP/IP stack, it can be &#8220;invisible&#8221; to network access and attackers.</p>
<p>Since version 1.0, released in march 5th 2006, HLBR can use regular expressions to detect intrusion attempts, virus, worms, and phishing.</p>
<p>You can view the entire <a href="http://svn.sourceforge.net/viewvc/hlbr/tags/HLBR_1_1/hlbr/README.en?view=markup">HLBR README file here</a>.</p>
<p></p>
<p>Go to the <a href="http://hlbr.sourceforge.net/index-en.html">HLBR Homepage</a> for more information and downloads.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Impressive+Open+Source+Intrusion+Prevention+%E2%80%93+HLBR+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D126+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/09/impressive-open-source-intrusion-prevention-hlbr/&amp;t=Impressive+Open+Source+Intrusion+Prevention+%E2%80%93+HLBR" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/09/impressive-open-source-intrusion-prevention-hlbr/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/09/impressive-open-source-intrusion-prevention-hlbr/&amp;title=Impressive+Open+Source+Intrusion+Prevention+%E2%80%93+HLBR" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/09/impressive-open-source-intrusion-prevention-hlbr/&amp;title=Impressive+Open+Source+Intrusion+Prevention+%E2%80%93+HLBR" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/09/impressive-open-source-intrusion-prevention-hlbr/&amp;title=Impressive+Open+Source+Intrusion+Prevention+%E2%80%93+HLBR" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/09/impressive-open-source-intrusion-prevention-hlbr/&amp;title=Impressive+Open+Source+Intrusion+Prevention+%E2%80%93+HLBR" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F09%2Fimpressive-open-source-intrusion-prevention-hlbr%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/09/impressive-open-source-intrusion-prevention-hlbr/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TCPReplay suite 3.0.beta10. Released</title>
		<link>http://www.darknet.org.uk/2006/08/tcpreplay-suite-30beta10-released/</link>
		<comments>http://www.darknet.org.uk/2006/08/tcpreplay-suite-30beta10-released/#comments</comments>
		<pubDate>Sat, 12 Aug 2006 09:53:08 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[firewall-testing]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[intrusion-detection]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[networking-hacking]]></category>
		<category><![CDATA[penetration-testing]]></category>
		<category><![CDATA[tcp-tools]]></category>
		<category><![CDATA[tcpreplay]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/08/tcpreplay-suite-30beta10-released/</guid>
		<description><![CDATA[Another good tool updated! TCPReplay suite 3.0.beta10 has been released. For those that don&#8217;t know Tcpreplay is a suite of BSD licensed tools written by Aaron Turner for *NIX operating systems which gives you the ability to use previously captured traffic in libpcap format to test a variety of network devices. It allows you to [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Another good tool updated! TCPReplay suite 3.0.beta10 has been released.</p>
<p>For those that don&#8217;t know Tcpreplay is a suite of BSD licensed tools written by Aaron Turner for *NIX operating systems which gives you the ability to use previously captured traffic in libpcap format to test a variety of network devices. It allows you to classify traffic as client or server, rewrite Layer 2, 3 and 4 headers and finally replay the traffic back onto the network and through other devices such as switches, routers, firewalls, NIDS and IPS&#8217;s. Tcpreplay supports both single and dual NIC modes for testing both sniffing and inline devices.</p>
<p>Tcpreplay is used by numerous firewall, IDS, IPS and other networking vendors, enterprises, universities, labs and open source projects. </p>
<p>Beta10 contains a number of major enhancements as the code continues to stabilize for the 3.0 stable release.  The big changes include removing Libnet as a requirement, tcpprep and tcprewrite no longer requiring root access and improved packet timings for tcpreplay. There are also a number of smaller enhancements and bug fixes.</p>
<p>Also a lot of time has been spent updating the online manual on the wiki which covers most if not all the features of tcpreplay, tcpprep and tcprewrite.</p>
<p>This should be the final beta release and it&#8217;s expected to have the first release candidate in a month or so.  Please download and test!</p>
<p>You can download it here:</p>
<p><a href="http://sourceforge.net/projects/tcpreplay/">TCPReplay</a></p>
<p>The new Wikified manual is <a href="http://tcpreplay.synfin.net/trac/wiki/manual ">here</a>.</p>
<p></p>
<p>Download: http://prdownloads.sourceforge.net/tcpreplay/tcpreplay-3.0.beta10.tar.gz?download</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=TCPReplay+suite+3.0.beta10.+Released+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D312+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/08/tcpreplay-suite-30beta10-released/&amp;t=TCPReplay+suite+3.0.beta10.+Released" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/08/tcpreplay-suite-30beta10-released/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/08/tcpreplay-suite-30beta10-released/&amp;title=TCPReplay+suite+3.0.beta10.+Released" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/08/tcpreplay-suite-30beta10-released/&amp;title=TCPReplay+suite+3.0.beta10.+Released" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/08/tcpreplay-suite-30beta10-released/&amp;title=TCPReplay+suite+3.0.beta10.+Released" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/08/tcpreplay-suite-30beta10-released/&amp;title=TCPReplay+suite+3.0.beta10.+Released" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F08%2Ftcpreplay-suite-30beta10-released%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/08/tcpreplay-suite-30beta10-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>3Com&#8217;s TippingPoint Finds New IE Vulnerabilities</title>
		<link>http://www.darknet.org.uk/2006/06/3coms-tippingpoint-finds-new-ie-vulnerabilities/</link>
		<comments>http://www.darknet.org.uk/2006/06/3coms-tippingpoint-finds-new-ie-vulnerabilities/#comments</comments>
		<pubDate>Tue, 20 Jun 2006 07:27:29 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[3com]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[internet-exploder]]></category>
		<category><![CDATA[internet-explorer]]></category>
		<category><![CDATA[intrusion-detection]]></category>
		<category><![CDATA[intrusion-prevention]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[tippingpoint]]></category>
		<category><![CDATA[vunerabilities]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/06/3coms-tippingpoint-finds-new-ie-vulnerabilities/</guid>
		<description><![CDATA[What? New vulnerabilities in Internet Explorer? You can hack Internet Exploder Explorer? Never! 3Com Corp&#8217;s TippingPoint division has discovered and disclosed two critical new vulnerabilities in Microsoft&#8217;s Internet Explorer through 3Com&#8217;s Zero Day Initiative (ZDI). The vulnerabilities could have allowed an attacker to gain control of a PC if the user was logged in with [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>What? New vulnerabilities in Internet Explorer?</p>
<p>You can hack Internet <del datetime="2006-06-20T04:39:29+00:00">Exploder</del> Explorer? Never!</p>
<blockquote><p>3Com Corp&#8217;s TippingPoint division has discovered and disclosed two critical new vulnerabilities in Microsoft&#8217;s Internet Explorer through 3Com&#8217;s Zero Day Initiative (ZDI). </p>
<p>The vulnerabilities could have allowed an attacker to gain control of a PC if the user was logged in with administrative rights. </p></blockquote>
<p>Sounds a bit like an advert for TippingPoint to me.</p>
<blockquote><p>Under the ZDI, 3Com rewards researchers who, while keeping the vulnerabilities confidential, alert 3Com to these vulnerabilities. </p>
<p>3Com can in turn alert the software vendor so that a patch can be prepared, while IPS prepares the security filter and distributes it to customers.</p></blockquote>
<p>Interesting initiative though.</p>
<p></p>
<p>Source: <a href="http://star-techcentral.com/tech/story.asp?file=/2006/6/20/technology/20060620093012&#038;sec=technology">The Star</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=3Com%E2%80%99s+TippingPoint+Finds+New+IE+Vulnerabilities+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D259+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/06/3coms-tippingpoint-finds-new-ie-vulnerabilities/&amp;t=3Com%E2%80%99s+TippingPoint+Finds+New+IE+Vulnerabilities" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/06/3coms-tippingpoint-finds-new-ie-vulnerabilities/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/06/3coms-tippingpoint-finds-new-ie-vulnerabilities/&amp;title=3Com%E2%80%99s+TippingPoint+Finds+New+IE+Vulnerabilities" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/06/3coms-tippingpoint-finds-new-ie-vulnerabilities/&amp;title=3Com%E2%80%99s+TippingPoint+Finds+New+IE+Vulnerabilities" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/06/3coms-tippingpoint-finds-new-ie-vulnerabilities/&amp;title=3Com%E2%80%99s+TippingPoint+Finds+New+IE+Vulnerabilities" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/06/3coms-tippingpoint-finds-new-ie-vulnerabilities/&amp;title=3Com%E2%80%99s+TippingPoint+Finds+New+IE+Vulnerabilities" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F06%2F3coms-tippingpoint-finds-new-ie-vulnerabilities%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/06/3coms-tippingpoint-finds-new-ie-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

