<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>John Leach's Blog &#187; firestormnids</title>
	<atom:link href="http://johnleach.co.uk/words/archives/tag/firestormnids/feed" rel="self" type="application/rss+xml" />
	<link>http://johnleach.co.uk/words</link>
	<description>Stuff I think, see and do</description>
	<lastBuildDate>Fri, 18 Jun 2010 22:57:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>RedHat, Firestorm, 802.11b and rpm2html</title>
		<link>http://johnleach.co.uk/words/archives/2004/03/22/42/redhat-firestorm-80211b-and-rpm2html</link>
		<comments>http://johnleach.co.uk/words/archives/2004/03/22/42/redhat-firestorm-80211b-and-rpm2html#comments</comments>
		<pubDate>Mon, 22 Mar 2004 00:00:00 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[GNU/Linux]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[cicsco]]></category>
		<category><![CDATA[ecn]]></category>
		<category><![CDATA[fedora]]></category>
		<category><![CDATA[firestormnids]]></category>
		<category><![CDATA[linksys]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[nids]]></category>
		<category><![CDATA[qmail]]></category>
		<category><![CDATA[redhat]]></category>

		<guid isPermaLink="false">http://johnleach.co.uk/words/archives/2004/03/22/42/</guid>
		<description><![CDATA[I&#8217;ve been working on my qmail rpms for RedHat ES/AS/Fedora. I&#8217;ve even started some documentation. It&#8217;s all on my RedHat page. I&#8217;ve also been working on Firestorm, improving the arp decoder and developing my macwatch arpwatch clone. Hopefully this will appear in the latest Firestorm tree soon. I recently ditched my aging Linux wireless bridge/router/firewall [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been working on my qmail rpms for RedHat ES/AS/Fedora.  I&#8217;ve even   started some documentation.  It&#8217;s all on my <a href='/documents/redhatas'>RedHat page</a>.</p>
<p>I&#8217;ve also been working on Firestorm, improving the arp decoder and   developing my macwatch arpwatch clone.  Hopefully this will appear in the   latest Firestorm tree soon.</p>
<p>I recently ditched my aging Linux wireless bridge/router/firewall in favour   of a little Linksys device that cost no more than 60 pounds, uses   considerably less electricity and makes almost no noise.  The price is   impressive and even the device seems to work ok.  One thing it can&#8217;t deal   with properly at all is the TCP ECN flag.  The web admin port just sends a RST.  Can you believe a Cisco company would make this mistake?  Yes.  I   can.</p>
<p>Also, I&#8217;ve created an <a href='/documents/rpms/ByName.html'>rpm2html index</a> of all the RPMs in my   <a href='/downloads'>downloads</a> tree.  Some are old crap I&#8217;ve not   bothered deleting yet, but there is some stuff in there that will be useful   to someone (not just google).</p>
<p><a href='http://www.scaramanga.co.uk'>Gianni</a> will be home from Luxembourg soon.</p>
]]></content:encoded>
			<wfw:commentRss>http://johnleach.co.uk/words/archives/2004/03/22/42/redhat-firestorm-80211b-and-rpm2html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firestorm Debian packages</title>
		<link>http://johnleach.co.uk/words/archives/2004/02/10/41/firestorm-debian-packages</link>
		<comments>http://johnleach.co.uk/words/archives/2004/02/10/41/firestorm-debian-packages#comments</comments>
		<pubDate>Tue, 10 Feb 2004 00:00:00 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[Tech]]></category>
		<category><![CDATA[Debian]]></category>
		<category><![CDATA[firestormnids]]></category>

		<guid isPermaLink="false">http://johnleach.co.uk/words/archives/2004/02/10/41/</guid>
		<description><![CDATA[I&#8217;ve built some Firestorm debs for x86 from the latest snapshot (0.5.5-pre3). I had to remove a little bit of verbose debug code from the linux capture driver. available here..]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve built some Firestorm debs for x86 from the latest snapshot   (0.5.5-pre3).  I had to remove a little bit of verbose debug code from the linux capture driver.  <a href='/downloads/firestorm/debs/'>available   here.</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://johnleach.co.uk/words/archives/2004/02/10/41/firestorm-debian-packages/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ethereal ELOG support and keepalived</title>
		<link>http://johnleach.co.uk/words/archives/2004/02/09/40/ethereal-elog-support-and-keepalived</link>
		<comments>http://johnleach.co.uk/words/archives/2004/02/09/40/ethereal-elog-support-and-keepalived#comments</comments>
		<pubDate>Mon, 09 Feb 2004 00:00:00 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[Tech]]></category>
		<category><![CDATA[ethereal]]></category>
		<category><![CDATA[failover]]></category>
		<category><![CDATA[firestormnids]]></category>
		<category><![CDATA[nids]]></category>

		<guid isPermaLink="false">http://johnleach.co.uk/words/archives/2004/02/09/40/</guid>
		<description><![CDATA[Updated my Firestorm ELOG alert file support patch for Ethereal (0.10.0). Get it here. I&#8217;ve been playing with keepalived over the last couple of weeks. It&#8217;s basically an entire Linux HA cluster system. It does the job of heartbeat for failover and incorporates LVS for load balanced services. It looks really great but I&#8217;ve managed [...]]]></description>
			<content:encoded><![CDATA[<p>Updated my Firestorm ELOG alert file support patch for Ethereal (0.10.0).   Get it <a href='/downloads/firestorm/ethereal'>here.</a></p>
<p>I&#8217;ve been playing with <a href='http://keepalived.sourceforge.net'>keepalived</a> over the last couple   of weeks.  It&#8217;s basically an entire Linux HA cluster system.  It does the   job of heartbeat for failover and incorporates LVS for load balanced   services.  It looks really great but I&#8217;ve managed to upset it a few times by   restarting the daemon too much.   Also I&#8217;ve found using bonded ethernet   interfaces with multicast traffic results in multiple copies of the packets   coming out of bond0, which really confuses the keepalived anti-replay   sequence numbers (Hey, I&#8217;ve seen that packet already!).  I&#8217;ve reported it to   the keepalived guys and will do the same for the bonding people.  I&#8217;m not   sure whose problem it is to solve.</p>
]]></content:encoded>
			<wfw:commentRss>http://johnleach.co.uk/words/archives/2004/02/09/40/ethereal-elog-support-and-keepalived/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Qmail, RedHat and Firestorm</title>
		<link>http://johnleach.co.uk/words/archives/2003/12/11/37/qmail-redhat-and-firestorm</link>
		<comments>http://johnleach.co.uk/words/archives/2003/12/11/37/qmail-redhat-and-firestorm#comments</comments>
		<pubDate>Thu, 11 Dec 2003 00:00:00 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[Networks and Firewalls]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[coding]]></category>
		<category><![CDATA[firestormnids]]></category>
		<category><![CDATA[nids]]></category>
		<category><![CDATA[qmail]]></category>
		<category><![CDATA[redhat]]></category>
		<category><![CDATA[rhes]]></category>

		<guid isPermaLink="false">http://johnleach.co.uk/words/archives/2003/12/11/37/</guid>
		<description><![CDATA[I&#8217;ve built some packages of djbs software (qmail, daemontools, djbdns&#8230;) for RedHat ES. I&#8217;ve also been working on Firestorm again, primarily on my mac/arp watcher preprocessor. It now saves state between restarts, and reports on more nefarious ethernet/arp. It&#8217;ll be included in the next release of Firestorm.]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve built <a href='/documents/redhatas/index.html'>some packages</a> of <a href='http://cr.yp.to'>djbs</a> software (qmail, daemontools, djbdns&#8230;) for  RedHat ES.</p>
<p>I&#8217;ve also been working on <a href='/documents/firestorm/index.html'>Firestorm</a> again, primarily on my   mac/arp watcher preprocessor.  It now saves state between restarts, and reports on more nefarious ethernet/arp.  It&#8217;ll be included in the next release of Firestorm.</p>
]]></content:encoded>
			<wfw:commentRss>http://johnleach.co.uk/words/archives/2003/12/11/37/qmail-redhat-and-firestorm/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firestorm ethereal and RedHat Advanced Server</title>
		<link>http://johnleach.co.uk/words/archives/2003/08/15/29/firestorm-ethereal-and-redhat-advanced-server</link>
		<comments>http://johnleach.co.uk/words/archives/2003/08/15/29/firestorm-ethereal-and-redhat-advanced-server#comments</comments>
		<pubDate>Fri, 15 Aug 2003 00:00:00 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[GNU/Linux]]></category>
		<category><![CDATA[Networks and Firewalls]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Debian]]></category>
		<category><![CDATA[ethereal]]></category>
		<category><![CDATA[firestormnids]]></category>
		<category><![CDATA[nids]]></category>
		<category><![CDATA[redhat]]></category>
		<category><![CDATA[rhel]]></category>

		<guid isPermaLink="false">http://johnleach.co.uk/words/archives/2003/08/15/29/</guid>
		<description><![CDATA[I&#8217;ve ported my Ethereal ELOG patch to the latest version (0.9.14) and fixed a bug handling pcap captured alerts. Created Debian debs for powerpc and i386. Matt is working on some RPMS for RedHat 9 RedHat&#8217;s latest change of support plans for RedHat Linux seems to be doing what was intended, getting more people to [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve ported my Ethereal ELOG patch to the latest version (0.9.14) and fixed   a bug handling pcap captured alerts.  Created Debian debs for <a href='../downloads/firestorm/ethereal/debian/'>powerpc and i386</a>.  <a href='http://people.ecsc.co.uk/~matt'>Matt</a> is working on some RPMS for RedHat 9</p>
<p>RedHat&#8217;s latest change of support plans for RedHat Linux seems to be doing what was intended, getting more people to purchase Advanced Server (and the new Enterprise Server and Workstation) rather than leeching off them.  Good   for RedHat.  There have been too many idiots selling RedHat Linux-based   solutions expecting the coloured headgear company to do the hard work of beta testing, bug fixing etc.etc. for free.</p>
]]></content:encoded>
			<wfw:commentRss>http://johnleach.co.uk/words/archives/2003/08/15/29/firestorm-ethereal-and-redhat-advanced-server/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>mac/arpwatcher firestorm preprocessor and PIX tomfoolery</title>
		<link>http://johnleach.co.uk/words/archives/2003/05/28/21/macarpwatcher-firestorm-preprocessor-and-pix-tomfoolery</link>
		<comments>http://johnleach.co.uk/words/archives/2003/05/28/21/macarpwatcher-firestorm-preprocessor-and-pix-tomfoolery#comments</comments>
		<pubDate>Wed, 28 May 2003 00:00:00 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[Tech]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[Debian]]></category>
		<category><![CDATA[firestormnids]]></category>
		<category><![CDATA[nids]]></category>
		<category><![CDATA[pix]]></category>

		<guid isPermaLink="false">http://johnleach.co.uk/words/archives/2003/05/28/21/</guid>
		<description><![CDATA[I&#8217;m currently working on a preprocessor for the Firestorm NIDS to detect dodgy looking arp activity. So far it keeps track of hardware and protocol addresses in arp packets and alert if things change. It will soon monitor IP traffic too (and IPX/Appletalk etc. I guess) and detect a bunch of other ettercap style trickery. [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m currently working on a preprocessor for the <a href='http://www.scaramanga.co.uk/firestorm'>Firestorm</a> NIDS to detect   dodgy looking arp activity.  So far it keeps track of hardware and protocol   addresses in arp packets and alert if things change.  It will soon monitor   IP traffic too (and IPX/Appletalk etc. I guess) and detect a bunch of other   ettercap style trickery.</p>
<p>I&#8217;m also working with some Cisco PIX firewalls to make them play nice with   FreeS/WAN on Linux.  I&#8217;ll put some example configs up here at some   point.  I&#8217;m going to take the Cisco VPN exam and be one step closer to a   CCSP (I&#8217;m really not sure if this is a good or a bad thing career-wise).   The original Cisco press VPN book has some serious problems with factual   content.  The authors seems to have little understanding of the underlying   technology.  I guess you don&#8217;t need to know it to parrot-type the Cisco   commands in (or copy and paste them, as I often see) and charge 200 quid an   hour, but it would be nice to be a bit professional about things.</p>
<p>My Mozilla/Galeon is broken on Debian unstable.  Using gdb I found /usr/lib/mozilla/components/libimglib2.so to be the culprit, so just moved   it out the way.  I now have Galeon working with no images which suits me   fine.  In fact, as everything loads so quickly and is far less offensive to the   eye, I may keep it this way permanently.</p>
<pre><code>Program received signal SIGSEGV, Segmentation fault.
0x0de9de98 in NSGetModule () from/usr/lib/mozilla/components/libimglib2.so</code></pre>
]]></content:encoded>
			<wfw:commentRss>http://johnleach.co.uk/words/archives/2003/05/28/21/macarpwatcher-firestorm-preprocessor-and-pix-tomfoolery/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firestorm elog support for Ethereal</title>
		<link>http://johnleach.co.uk/words/archives/2003/03/05/16/firestorm-elog-support-for-ethereal</link>
		<comments>http://johnleach.co.uk/words/archives/2003/03/05/16/firestorm-elog-support-for-ethereal#comments</comments>
		<pubDate>Wed, 05 Mar 2003 00:00:00 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[Tech]]></category>
		<category><![CDATA[ethereal]]></category>
		<category><![CDATA[firestormnids]]></category>
		<category><![CDATA[nids]]></category>

		<guid isPermaLink="false">http://johnleach.co.uk/words/archives/2003/03/05/16/</guid>
		<description><![CDATA[I finally got a patch together to all Firestorm NIDS elog support to Ethereal. You can find the Ethereal patch and a screenshot within my downloads directory. I may put a couple of example elog files on there to play with too.]]></description>
			<content:encoded><![CDATA[<p>I finally got a patch together to all Firestorm NIDS elog support to   Ethereal.  You can find the Ethereal patch and a screenshot within my <a href='../downloads/firestorm/ethereal'>downloads directory</a>.  I may put a   couple of example elog files on there to play with too.</p>
]]></content:encoded>
			<wfw:commentRss>http://johnleach.co.uk/words/archives/2003/03/05/16/firestorm-elog-support-for-ethereal/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Liverpool and Firestorm NIDS Ethereal support</title>
		<link>http://johnleach.co.uk/words/archives/2002/12/19/12/liverpool-and-firestorm-nids-ethereal-support</link>
		<comments>http://johnleach.co.uk/words/archives/2002/12/19/12/liverpool-and-firestorm-nids-ethereal-support#comments</comments>
		<pubDate>Thu, 19 Dec 2002 00:00:00 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[Tech]]></category>
		<category><![CDATA[ethereal]]></category>
		<category><![CDATA[firestormnids]]></category>
		<category><![CDATA[nids]]></category>

		<guid isPermaLink="false">http://johnleach.co.uk/words/archives/2002/12/19/12/</guid>
		<description><![CDATA[I&#8217;ve been down near Liverpool for the last few days, but I still found time to work on my latest project, adding support for Firestorm NIDS alert elogs to Ethereal 0.9.8. See a screen shot. Ethereal seems nicely written and I&#8217;m not having too many problems adding support for new file formats and protocols.]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been down near Liverpool for the last few days, but I still found time   to work on my latest project, adding support for Firestorm NIDS alert elogs   to Ethereal 0.9.8.  See a    <a href='downloads/firestorm/ethereal/sshot01.png'>screen shot</a>.  Ethereal   seems nicely written and I&#8217;m not having too  many problems adding support for   new file formats and protocols.</p>
]]></content:encoded>
			<wfw:commentRss>http://johnleach.co.uk/words/archives/2002/12/19/12/liverpool-and-firestorm-nids-ethereal-support/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Linux 2.4.20, Clockspeed, Firestorm IPX and Macrostupid Coldfusion</title>
		<link>http://johnleach.co.uk/words/archives/2002/12/09/11/linux-2420-clockspeed-firestorm-ipx-and-macrostupid-coldfusion</link>
		<comments>http://johnleach.co.uk/words/archives/2002/12/09/11/linux-2420-clockspeed-firestorm-ipx-and-macrostupid-coldfusion#comments</comments>
		<pubDate>Mon, 09 Dec 2002 00:00:00 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[Tech]]></category>
		<category><![CDATA[coldfusion]]></category>
		<category><![CDATA[dell]]></category>
		<category><![CDATA[firestormnids]]></category>
		<category><![CDATA[ipx]]></category>
		<category><![CDATA[macromedia]]></category>
		<category><![CDATA[nids]]></category>

		<guid isPermaLink="false">http://johnleach.co.uk/words/archives/2002/12/09/11/</guid>
		<description><![CDATA[Upgraded to Linux 2.4.0 with a few patches such as Gianni&#8217;s ECSC security patches, FreeS/WAN IPSEC, CPUFreq and more. Now I&#8217;m losing time again on my Dell Inspiron 8200. Dan Bernstein&#8217;s Clockspeed isn&#8217;t helping; I don&#8217;t think it&#8217;s meant for drift such as this (caused my frequency scaling I think). I have also been putting [...]]]></description>
			<content:encoded><![CDATA[<p>Upgraded to Linux 2.4.0 with a few patches such as Gianni&#8217;s ECSC security   patches, FreeS/WAN IPSEC, CPUFreq and more.  Now I&#8217;m losing time again on my   Dell Inspiron 8200.  Dan Bernstein&#8217;s Clockspeed isn&#8217;t helping; I don&#8217;t think   it&#8217;s meant for drift such as this (caused my frequency scaling I think).</p>
<p>I have also been putting some time into the IPX support in Firestorm I   originally started.  I&#8217;ve fixed a couple of things Gianni broke during his   clean-up, and have begun work on a matcher.  This adds support for IPX in   snort signatures, which is kinda cute.
<p>Having lots of trouble getting Coldfusion &#8220;MX&#8221;(tm) to work on Linux for a   client.  It is invariably unstable and crashes thousands of times a second   (see diary: Nov 25 2002).  Macromedia want to charge us $500 to report this.   Apparently we&#8217;ll get our money back if it is confirmed as a genuine bug.   We&#8217;re considering billing for the bug hunting we&#8217;re doing for them instead.   With the tens of thousands of SIG4 and SIG11 crashes we&#8217;d be quids in   charging per bug.  Now <i>if only</i> an open-source project such as <a href='http://www.php.net'>PHP</a> existed.</p>
]]></content:encoded>
			<wfw:commentRss>http://johnleach.co.uk/words/archives/2002/12/09/11/linux-2420-clockspeed-firestorm-ipx-and-macrostupid-coldfusion/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Websense WISP and IPX updates</title>
		<link>http://johnleach.co.uk/words/archives/2002/09/27/4/websense-wisp-and-ipx-updates</link>
		<comments>http://johnleach.co.uk/words/archives/2002/09/27/4/websense-wisp-and-ipx-updates#comments</comments>
		<pubDate>Fri, 27 Sep 2002 00:00:00 +0000</pubDate>
		<dc:creator>john</dc:creator>
				<category><![CDATA[Tech]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[firestormnids]]></category>
		<category><![CDATA[ipx]]></category>
		<category><![CDATA[nids]]></category>
		<category><![CDATA[pix]]></category>
		<category><![CDATA[squid]]></category>
		<category><![CDATA[websense]]></category>
		<category><![CDATA[wisp]]></category>

		<guid isPermaLink="false">http://johnleach.co.uk/words/archives/2002/09/27/4/</guid>
		<description><![CDATA[Gianni, Matt and I spent a little time poking around at the Websense WISP protocol to see how likely it would be to get Squid working with it. We observered a Cisco PIX communicating with a Websense service running Linux. It seems pretty easy (which was strange as we&#8217;ve heard to the contrary from Websense [...]]]></description>
			<content:encoded><![CDATA[<p>Gianni, Matt and I spent a little time poking around at the Websense WISP protocol to see how likely it would be to get Squid working with it.  We observered a Cisco PIX communicating with a Websense service running Linux.   It seems pretty easy (which was strange as we&#8217;ve heard to the contrary from Websense themselves).  Gianni has knocked up a tool that can query a Websense server with a url to see if it is blocked.  If we need it we&#8217;ll build a squid redirector. (see http://www.scaramanga.co.uk )</p>
<p>New patch for IPX support on Firestorm.  Fixes a few lame bugs and possible remote DoSs Gianni pointed out to me.  Also improved the SAP support a little.</p>
]]></content:encoded>
			<wfw:commentRss>http://johnleach.co.uk/words/archives/2002/09/27/4/websense-wisp-and-ipx-updates/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
