The Story of Snort
gRitteR writes "HNS is running a story of Martin Roesch, the creator of Snort where he tells the entire story of Snort in his words. Roesch covers seven years of development that made this tool one of the most important security software titles ever developed. It's interesting to get all the details on how Snort was initially conceived as well as how it is expected to develop further now after Check Point acquired Sourcefire. There are many technical details and interesting tidbits not available before."
Do we really care about this issue? It is irrelevant in Old Europe FB!!!
Anyone know if there's a transcript of this interview somewhere?
fuck slashdot.
Slashdotters: You are all a bunch of faggots.
Do you hear me, you repulsive faggots? NO DIGG.
Snort hark spit hrrrr knnnn plor ickie plar!
Damn. I was expecting something else. Now where's my dealer?
I think someone didn't check this out before it was posted... By someone I mean TACO.
"There are many technical details and interesting tidbits not available before."
And not any more.
Ok, what the hell is SNORT?
This seems to not be intended to be listened to by international Audience. He is talking quite fast and not too easy. a written form would be easier for people with other language backgrounds. I can live with it, as I'm used to the sound of american english, but a written form could help a lot.
Let me be the first to recommend n00bs pick up Snort for Dummies, perhaps the best "for Dummies" book I've read; a perfect primer. "If you want to get your feet wet or you've been tasked with deploying a snort system, this is a good way to start. In the typical, humorous, "for dummies" style, this book walks you through getting, setting up and using Snort and the ACID console. The book also covers how to maintain and tweak the system, once it is up and running. A good effort by the authors." For work or for home, there's really no reason not to learn an enterprise level IDS.
fak3r.com
I had the chance to chat with Marty in Baltimore in May 2001 and he basically said this about Snort:
1) I wrote it over a couple of weekends because I wasn't happy with TCPDump and the commercial tools at hand
2) Someday I hope to rewrite it
3) The extensible plug-in architecture saved my ass
4) I wish the commercial guys would quit ripping it off
However, it looks like an audio interview...don't have that kind of time anymore.
"So we had made this 'cocaine' stuff, and we had tried various methods of getting it into our bloodstream, but none of them seemed to be quick and easy. Then Martin gets this brilliant idea..."
SERVER STATUS: We are currently being Slashdotted. Please check back soon. Looks like their snort rules need some fixing
Finally! I've been waiting fourty years for a sequel to "The Story About Ping"!!!!!
the preceding comment is my own and in no way reflects the opinion of the Joint Chiefs of Staff
errr... an absolutely amazing quote in the link above : " If I'd known then that it would be my most famous accomplishment in life, I might have worked on it another day or two and added some more options."
the preceding comment is my own and in no way reflects the opinion of the Joint Chiefs of Staff
Hehehehe. I was just checking the thread to see if someone else was gonna mention it. If not, I was gonna say something about how nicely The Story of Snort would look next to The Story About Ping.
Be a real patriot: Question authority. Think for yourself. Formulate your own conclusions.
But you'll probably end up with a "(Score:2, Funny)" anyway.
Links to information:
First report: http://isc.sans.org/diary.php?storyid=770
Infocon Yellow: http://isc.sans.org/diary.php?storyid=772
Intrusion Detection: http://isc.sans.org/diary.php?storyid=782
Tool: http://isc.sans.org/diary.php?storyid=791
Hope everyone is safe..
On the off chance that the potential author of a "... For Dummies" or "Idiot's Guide To ..." book will see this, I just want to say that I refuse to purchase any book that forces me to place myself in one of those two categories. If I'm buying a book to learn about a subject, I am by definition neither a Dummy nor an Idiot. I may be ignorant about the subject, but I won't accept that I'm stupid because I need or want to buy a book to learn.
I doubt I'm alone. Oh, and for those who will say that I need to lighten up, trust me, I am very willing to poke fun at myself, and do so often. But I don't label myself a dummy or idiot (except when I am).
Blah.
A host is a host from coast to coast...
Unless it's down, or slow, or fails to POST!
probably one of the best tools ever developed for open-source / security community. I've got a bad feeling from this whole Check Point acquisition, especially with the major revamp in http://snort.org/. Thankfully there's still http://nessus.org/....wait. Fuck!
Ping this FB!!!
Is there a working transcript or a non-flash link? I'm not installing the key to pretty BLINKING annoyances just to read something interesting.
Nigger Association MOVIE [imdb.com] both believed that and committtes they are Come it just 0wnz.', confirming the Usenet posts. usenet. In 1995, Ass until I hit my
The Story of Snort?
Ask my filthy rich boss!
LKOS
I get the feeling one of the main draws to posting stories about Snort isn't so much the software but so they can make joke headlines and comments about narcotics.
Checkpoint Aquires Snort - Oct. 6, 2005
Snort up For Revamp, says Creator - May 24, 2004
Using Snort Stealthily - Sept. 13, 2002
Snort Creator Makes Good - July 1, 2002
Guardent To Sell Snort And Nessus - Dec. 14, 2001
Mike was killed in a car accident in November 2000.
For a minute there I thought the title of the story was:
...
The History of Snot
For just a second I was envisoning: Slashdot, news for nerds, boogers shat matters
I have a very small mind and must live with it.
-- E. Dijkstra
I got to meet Martin Roesch a month ago and got some pictures of us shaking hands to take home!
http://83p.unitedti.org/
BigAdmin has an article that describes storing Snort alert output in a MySQL database and using the web front end BASE to analyze the data. Sounded pretty interesting... http://www.sun.com/bigadmin/features/articles/snor t_base.html