<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Snorby Spsa</title>
	<atom:link href="http://bailey.st/blog/snorby-spsa/feed/" rel="self" type="application/rss+xml" />
	<link>http://bailey.st/blog</link>
	<description>Useful bits of information in  an uncertain world.</description>
	<lastBuildDate>Sat, 21 Jan 2012 01:33:57 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Saeed</title>
		<link>http://bailey.st/blog/snorby-spsa/#comment-7998</link>
		<dc:creator>Saeed</dc:creator>
		<pubDate>Sat, 07 Jan 2012 12:50:03 +0000</pubDate>
		<guid isPermaLink="false">http://blog.bailey.st/?page_id=4#comment-7998</guid>
		<description>Hi,

How can i install this .iso file on a Hyper-V machine, I am going to trying installing but in the manual mentioned this .iso file is only for physical machine not VM.

I just tried on a Vmachine but after rebooting it asks for IP address.

So can anybody tell me how do i resolve this issue?

Regards,

Saeed</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>How can i install this .iso file on a Hyper-V machine, I am going to trying installing but in the manual mentioned this .iso file is only for physical machine not VM.</p>
<p>I just tried on a Vmachine but after rebooting it asks for IP address.</p>
<p>So can anybody tell me how do i resolve this issue?</p>
<p>Regards,</p>
<p>Saeed</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Saeed</title>
		<link>http://bailey.st/blog/snorby-spsa/#comment-7914</link>
		<dc:creator>Saeed</dc:creator>
		<pubDate>Thu, 05 Jan 2012 05:27:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.bailey.st/?page_id=4#comment-7914</guid>
		<description>Hi Guys,

Thanks for the very wonderful tool.

I would like to ask if we compare this IDS with any hardware based solution so what is the difference between them?

Is this tool beneficial for us to configure on our network?

Regards,

Saeed</description>
		<content:encoded><![CDATA[<p>Hi Guys,</p>
<p>Thanks for the very wonderful tool.</p>
<p>I would like to ask if we compare this IDS with any hardware based solution so what is the difference between them?</p>
<p>Is this tool beneficial for us to configure on our network?</p>
<p>Regards,</p>
<p>Saeed</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marios</title>
		<link>http://bailey.st/blog/snorby-spsa/#comment-7635</link>
		<dc:creator>Marios</dc:creator>
		<pubDate>Fri, 30 Dec 2011 18:10:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.bailey.st/?page_id=4#comment-7635</guid>
		<description>Hi Philip,

Many thanks and congratulations for the SmoothSec project. I am currently using SmoothSec 1.3 version and I was wondering whether a newer version will be available. 

Regards,
Marios</description>
		<content:encoded><![CDATA[<p>Hi Philip,</p>
<p>Many thanks and congratulations for the SmoothSec project. I am currently using SmoothSec 1.3 version and I was wondering whether a newer version will be available. </p>
<p>Regards,<br />
Marios</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Abraham</title>
		<link>http://bailey.st/blog/snorby-spsa/#comment-4962</link>
		<dc:creator>Abraham</dc:creator>
		<pubDate>Mon, 24 Oct 2011 23:30:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.bailey.st/?page_id=4#comment-4962</guid>
		<description>Hi Philip,
Please, how can I switch from console to gui?
I have used &quot;startx&quot; and &quot;sudo startx&quot; but is not working.
Thank you.</description>
		<content:encoded><![CDATA[<p>Hi Philip,<br />
Please, how can I switch from console to gui?<br />
I have used &#8220;startx&#8221; and &#8220;sudo startx&#8221; but is not working.<br />
Thank you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pbailey</title>
		<link>http://bailey.st/blog/snorby-spsa/#comment-4634</link>
		<dc:creator>pbailey</dc:creator>
		<pubDate>Thu, 13 Oct 2011 12:38:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.bailey.st/?page_id=4#comment-4634</guid>
		<description>Hello,
Snorby-SPSA is not longer developed, I&#039;ve moved to another project called smooth-sec 
http://bailey.st/blog/smooth-sec . Stay in touch.

Phillip</description>
		<content:encoded><![CDATA[<p>Hello,<br />
Snorby-SPSA is not longer developed, I&#8217;ve moved to another project called smooth-sec<br />
<a href="http://bailey.st/blog/smooth-sec" rel="nofollow">http://bailey.st/blog/smooth-sec</a> . Stay in touch.</p>
<p>Phillip</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Da Beave</title>
		<link>http://bailey.st/blog/snorby-spsa/#comment-4588</link>
		<dc:creator>Da Beave</dc:creator>
		<pubDate>Tue, 11 Oct 2011 23:58:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.bailey.st/?page_id=4#comment-4588</guid>
		<description>Let me know if you need any help with Sagan in Snorby-SPSA.  It&#039;s pretty straight forward,  but you can always catch me on freenode #sagan or via e-mail :)</description>
		<content:encoded><![CDATA[<p>Let me know if you need any help with Sagan in Snorby-SPSA.  It&#8217;s pretty straight forward,  but you can always catch me on freenode #sagan or via e-mail <img src='http://bailey.st/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: morgan</title>
		<link>http://bailey.st/blog/snorby-spsa/#comment-4142</link>
		<dc:creator>morgan</dc:creator>
		<pubDate>Fri, 23 Sep 2011 14:30:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.bailey.st/?page_id=4#comment-4142</guid>
		<description>If you have idiotically locked yourself out by changing the password and not noting it down - how can I reset the snorby password via command line?

Hello, 
If you are using Smooth-Sec you can run this script /root/script.utils/CleanAllEvents.sh , be careful that
this will erase all your events but will also reset the login credentials.

Best.</description>
		<content:encoded><![CDATA[<p>If you have idiotically locked yourself out by changing the password and not noting it down &#8211; how can I reset the snorby password via command line?</p>
<p>Hello,<br />
If you are using Smooth-Sec you can run this script /root/script.utils/CleanAllEvents.sh , be careful that<br />
this will erase all your events but will also reset the login credentials.</p>
<p>Best.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pbailey</title>
		<link>http://bailey.st/blog/snorby-spsa/#comment-3429</link>
		<dc:creator>pbailey</dc:creator>
		<pubDate>Sat, 06 Aug 2011 15:37:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.bailey.st/?page_id=4#comment-3429</guid>
		<description>@TomAng

Hi tom, 

thanks for your comment.

1) Snorby Spsa was the first ready to go intrusion detection distribution based on Snorby (first generation) and Snort. Smooth-Sec a new distribution equipped with suricata IDS and Snorby 2.0. Suricata is a new multithread  IDS/IPS engine, this mean that  if you have a multi-core monster machine allow you to use all the cores available.

2) If you want to use snort I recommend you to use directly InstaSnorby http://snorby.org/ - I don&#039;t recommend you to upgrade Snorby-Spsa.

3) If you want to use snort I recommend you to use directly InstaSnorby http://snorby.org/

Thanks again for you feedback.

Phillip</description>
		<content:encoded><![CDATA[<p>@TomAng</p>
<p>Hi tom, </p>
<p>thanks for your comment.</p>
<p>1) Snorby Spsa was the first ready to go intrusion detection distribution based on Snorby (first generation) and Snort. Smooth-Sec a new distribution equipped with suricata IDS and Snorby 2.0. Suricata is a new multithread  IDS/IPS engine, this mean that  if you have a multi-core monster machine allow you to use all the cores available.</p>
<p>2) If you want to use snort I recommend you to use directly InstaSnorby <a href="http://snorby.org/" rel="nofollow">http://snorby.org/</a> &#8211; I don&#8217;t recommend you to upgrade Snorby-Spsa.</p>
<p>3) If you want to use snort I recommend you to use directly InstaSnorby <a href="http://snorby.org/" rel="nofollow">http://snorby.org/</a></p>
<p>Thanks again for you feedback.</p>
<p>Phillip</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TomAng</title>
		<link>http://bailey.st/blog/snorby-spsa/#comment-3424</link>
		<dc:creator>TomAng</dc:creator>
		<pubDate>Sat, 06 Aug 2011 09:09:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.bailey.st/?page_id=4#comment-3424</guid>
		<description>Hi Phillip,

I got few questions :
1. what&#039;s the difference between Snorby Spsa and SmoothSec ?
2. any steps how update Snorby on both distro ? 
3. as Spsa is quite old, any steps how to install and configure Snort on SmoothSec ?

Regards,
Tom</description>
		<content:encoded><![CDATA[<p>Hi Phillip,</p>
<p>I got few questions :<br />
1. what&#8217;s the difference between Snorby Spsa and SmoothSec ?<br />
2. any steps how update Snorby on both distro ?<br />
3. as Spsa is quite old, any steps how to install and configure Snort on SmoothSec ?</p>
<p>Regards,<br />
Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ivan</title>
		<link>http://bailey.st/blog/snorby-spsa/#comment-1759</link>
		<dc:creator>Ivan</dc:creator>
		<pubDate>Thu, 21 Apr 2011 13:43:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.bailey.st/?page_id=4#comment-1759</guid>
		<description>Many thank&#039;s.  These are the tools i&#039;ve been looking for!!

@ivan
Hello, 
Please check our latest project http://bailey.st/blog/smooth-sec/ 
regards,
phillip</description>
		<content:encoded><![CDATA[<p>Many thank&#8217;s.  These are the tools i&#8217;ve been looking for!!</p>
<p>@ivan<br />
Hello,<br />
Please check our latest project <a href="http://bailey.st/blog/smooth-sec/" rel="nofollow">http://bailey.st/blog/smooth-sec/</a><br />
regards,<br />
phillip</p>
]]></content:encoded>
	</item>
</channel>
</rss>

