<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>An alchemists view from the bar</title>
	<atom:link href="http://leonward.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://leonward.wordpress.com</link>
	<description>Network Security Alchemy</description>
	<lastBuildDate>Sat, 14 Jan 2012 11:13:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='leonward.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>An alchemists view from the bar</title>
		<link>http://leonward.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://leonward.wordpress.com/osd.xml" title="An alchemists view from the bar" />
	<atom:link rel='hub' href='http://leonward.wordpress.com/?pushpress=hub'/>
		<item>
		<title>List of Mountain Bike films on iTunes</title>
		<link>http://leonward.wordpress.com/2012/01/14/list-of-mountain-bike-films-on-itunes/</link>
		<comments>http://leonward.wordpress.com/2012/01/14/list-of-mountain-bike-films-on-itunes/#comments</comments>
		<pubDate>Sat, 14 Jan 2012 11:13:18 +0000</pubDate>
		<dc:creator>leonward</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Mountain Bikes]]></category>

		<guid isPermaLink="false">http://leonward.wordpress.com/?p=533</guid>
		<description><![CDATA[I&#8217;m a big buyer of content via iTunes, however sometimes the search interface lets me down. I find it frustrating that there isn&#8217;t a way of listing content for an intrest group (such as MTB movies), and whenever I&#8217;m taking a long flight, I find a bike movie is perfect viewing. To help anyone else trying to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=leonward.wordpress.com&amp;blog=6873153&amp;post=533&amp;subd=leonward&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m a big buyer of content via iTunes, however sometimes the search interface lets me down. I find it frustrating that there isn&#8217;t a way of listing content for an intrest group (such as MTB movies), and whenever I&#8217;m taking a long flight, I find a bike movie is perfect viewing.</p>
<p>To help anyone else trying to find a list of decent MTB films that are all available on iTunes, perhaps the below could help. I&#8217;ll try to keep it updated as I dig out more over time. Simply search for the film name on iTunes and it should turn up in the store. Note that some of these are marked as TV shows rather than films.</p>
<p>Follow Me - http://www.anthillfilms.com/followme/</p>
<p>Vast &#8211; http://www.ionatefilms.com/</p>
<p>Here we go again - http://dh-productions.com/HereWeGoAgain/index.html</p>
<p>Life Cycles - http://www.lifecyclesfilm.com/</p>
<p><img class="aligncenter size-medium wp-image-534" title="Life Cycles" src="http://leonward.files.wordpress.com/2012/01/lifecycles.jpg?w=220&#038;h=300" alt="" width="220" height="300" /></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<br /> Tagged: <a href='http://leonward.wordpress.com/tag/mountain-bikes/'>Mountain Bikes</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/leonward.wordpress.com/533/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/leonward.wordpress.com/533/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/leonward.wordpress.com/533/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/leonward.wordpress.com/533/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/leonward.wordpress.com/533/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/leonward.wordpress.com/533/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/leonward.wordpress.com/533/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/leonward.wordpress.com/533/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/leonward.wordpress.com/533/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/leonward.wordpress.com/533/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/leonward.wordpress.com/533/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/leonward.wordpress.com/533/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/leonward.wordpress.com/533/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/leonward.wordpress.com/533/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=leonward.wordpress.com&amp;blog=6873153&amp;post=533&amp;subd=leonward&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://leonward.wordpress.com/2012/01/14/list-of-mountain-bike-films-on-itunes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8bf5331721efa2e5780016f58d071a57?s=96&#38;d=identicon&#38;r=R" medium="image">
			<media:title type="html">leonward</media:title>
		</media:content>

		<media:content url="http://leonward.files.wordpress.com/2012/01/lifecycles.jpg?w=220" medium="image">
			<media:title type="html">Life Cycles</media:title>
		</media:content>
	</item>
		<item>
		<title>Defining an Achievable Network Segmentation Process</title>
		<link>http://leonward.wordpress.com/2011/10/03/defining-an-achievable-network-segmentation-process/</link>
		<comments>http://leonward.wordpress.com/2011/10/03/defining-an-achievable-network-segmentation-process/#comments</comments>
		<pubDate>Mon, 03 Oct 2011 09:31:11 +0000</pubDate>
		<dc:creator>leonward</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://leonward.wordpress.com/?p=524</guid>
		<description><![CDATA[We all struggle balancing work and personal projects, but somehow I managed to combine both into one with the new Sourcefire blog (http://blog.sourcefire.com). I&#8217;ve had a blog posted there rather than here for once, so if you&#8217;re interested in network segmentation go take a read. The modern enterprise network has undertaken massive changes over recent [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=leonward.wordpress.com&amp;blog=6873153&amp;post=524&amp;subd=leonward&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>We all struggle balancing work and personal projects, but somehow I managed to combine both into one with the new Sourcefire blog <a href="http://blog.sourcefire.com">(http://blog.sourcefire.com).</a></p>
<p>I&#8217;ve had a blog posted there rather than here for once, so if you&#8217;re interested in network segmentation go take a read.</p>
<p>The modern enterprise network has undertaken massive changes over recent years. The adoption of cloud computing, consumerization, mobilization, and the explosion of the “app” markets, has driven us all to use technology in new ways. We must embrace these new technologies and the business edge that they can offer, but all the while we need to recognize that just below all of this new technology there is something supporting it that hasn’t changed. The security infrastructure they depend on to deliver safe and controlled service.</p>
<p>Read more here -&gt; <a href="http://blog.sourcefire.com/2011/09/defining-achievable-network.html">http://blog.sourcefire.com/2011/09/defining-achievable-network.html</a></p>
<p>-Leon</p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/leonward.wordpress.com/524/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/leonward.wordpress.com/524/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/leonward.wordpress.com/524/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/leonward.wordpress.com/524/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/leonward.wordpress.com/524/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/leonward.wordpress.com/524/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/leonward.wordpress.com/524/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/leonward.wordpress.com/524/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/leonward.wordpress.com/524/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/leonward.wordpress.com/524/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/leonward.wordpress.com/524/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/leonward.wordpress.com/524/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/leonward.wordpress.com/524/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/leonward.wordpress.com/524/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=leonward.wordpress.com&amp;blog=6873153&amp;post=524&amp;subd=leonward&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://leonward.wordpress.com/2011/10/03/defining-an-achievable-network-segmentation-process/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8bf5331721efa2e5780016f58d071a57?s=96&#38;d=identicon&#38;r=R" medium="image">
			<media:title type="html">leonward</media:title>
		</media:content>
	</item>
		<item>
		<title>Big OpenFPC release &#8211; 0.6</title>
		<link>http://leonward.wordpress.com/2011/06/13/big-openfpc-release-0-6/</link>
		<comments>http://leonward.wordpress.com/2011/06/13/big-openfpc-release-0-6/#comments</comments>
		<pubDate>Mon, 13 Jun 2011 12:37:48 +0000</pubDate>
		<dc:creator>leonward</dc:creator>
				<category><![CDATA[OpenFPC]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[snort]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[openfpc]]></category>
		<category><![CDATA[pcap]]></category>

		<guid isPermaLink="false">http://leonward.wordpress.com/?p=506</guid>
		<description><![CDATA[Pushing forwards closer to a 1.0 release for OpenFPC, one of the major components has now been updated &#8211; The GUI. To introduce this new release I&#8217;ve put together a short screen-cast of OpenFPC to show the installation, setup procedure, and a bit of general usage. So if you&#8217;re tasked with rolling together your own full [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=leonward.wordpress.com&amp;blog=6873153&amp;post=506&amp;subd=leonward&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Pushing forwards closer to a 1.0 release for OpenFPC, one of the major components has now been updated &#8211; The GUI.</p>
<p>To introduce this new release I&#8217;ve put together a short screen-cast of OpenFPC to show the installation, setup procedure, and a bit of general usage. So if you&#8217;re tasked with rolling together your own full packet capture/network traffic recorder/forensics system, perhaps you may want to take a look below.</p>
<span style="text-align:center; display: block;"><a href="http://leonward.wordpress.com/2011/06/13/big-openfpc-release-0-6/"><img src="http://img.youtube.com/vi/YcPUgs-fDPs/2.jpg" alt="" /></a></span>
<p>&nbsp;</p>
<p>For those who don&#8217;t want to sit through five minutes of video to see what the new GUI looks like, here are a few screenshots of the system in action.</p>

<a href='http://leonward.wordpress.com/2011/06/13/big-openfpc-release-0-6/0-6-extract/' title='0.6-extract'><img data-attachment-id='509' data-orig-size='912,725' data-liked='0'width="150" height="119" src="http://leonward.files.wordpress.com/2011/06/0-6-extract.png?w=150&#038;h=119" class="attachment-thumbnail" alt="0.6-extract" title="0.6-extract" /></a>
<a href='http://leonward.wordpress.com/2011/06/13/big-openfpc-release-0-6/0-6-sessions/' title='0.6-sessions'><img data-attachment-id='510' data-orig-size='913,736' data-liked='0'width="150" height="120" src="http://leonward.files.wordpress.com/2011/06/0-6-sessions.png?w=150&#038;h=120" class="attachment-thumbnail" alt="0.6-sessions" title="0.6-sessions" /></a>
<a href='http://leonward.wordpress.com/2011/06/13/big-openfpc-release-0-6/0-6-users/' title='0.6-users'><img data-attachment-id='511' data-orig-size='1093,661' data-liked='0'width="150" height="90" src="http://leonward.files.wordpress.com/2011/06/0-6-users.png?w=150&#038;h=90" class="attachment-thumbnail" alt="0.6-users" title="0.6-users" /></a>
<a href='http://leonward.wordpress.com/2011/06/13/big-openfpc-release-0-6/0-6-packets1/' title='0.6-packets1'><img data-attachment-id='512' data-orig-size='1402,809' data-liked='0'width="150" height="86" src="http://leonward.files.wordpress.com/2011/06/0-6-packets1.png?w=150&#038;h=86" class="attachment-thumbnail" alt="0.6-packets1" title="0.6-packets1" /></a>

<p>Version 0.6 is now available at  <a href="http://code.google.com/p/openfpc/downloads/list">http://code.google.com/p/openfpc/downloads/list</a> . Expect a few bugs, and if you report them, Ill own the task of fixing them.</p>
<p>-Leon</p>
<h1></h1>
<br /> Tagged: <a href='http://leonward.wordpress.com/tag/ids/'>IDS</a>, <a href='http://leonward.wordpress.com/tag/openfpc-2/'>openfpc</a>, <a href='http://leonward.wordpress.com/tag/pcap/'>pcap</a>, <a href='http://leonward.wordpress.com/tag/snort/'>snort</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/leonward.wordpress.com/506/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/leonward.wordpress.com/506/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/leonward.wordpress.com/506/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/leonward.wordpress.com/506/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/leonward.wordpress.com/506/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/leonward.wordpress.com/506/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/leonward.wordpress.com/506/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/leonward.wordpress.com/506/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/leonward.wordpress.com/506/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/leonward.wordpress.com/506/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/leonward.wordpress.com/506/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/leonward.wordpress.com/506/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/leonward.wordpress.com/506/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/leonward.wordpress.com/506/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=leonward.wordpress.com&amp;blog=6873153&amp;post=506&amp;subd=leonward&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://leonward.wordpress.com/2011/06/13/big-openfpc-release-0-6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8bf5331721efa2e5780016f58d071a57?s=96&#38;d=identicon&#38;r=R" medium="image">
			<media:title type="html">leonward</media:title>
		</media:content>

		<media:content url="http://leonward.files.wordpress.com/2011/06/0-6-extract.png?w=150" medium="image">
			<media:title type="html">0.6-extract</media:title>
		</media:content>

		<media:content url="http://leonward.files.wordpress.com/2011/06/0-6-sessions.png?w=150" medium="image">
			<media:title type="html">0.6-sessions</media:title>
		</media:content>

		<media:content url="http://leonward.files.wordpress.com/2011/06/0-6-users.png?w=150" medium="image">
			<media:title type="html">0.6-users</media:title>
		</media:content>

		<media:content url="http://leonward.files.wordpress.com/2011/06/0-6-packets1.png?w=150" medium="image">
			<media:title type="html">0.6-packets1</media:title>
		</media:content>
	</item>
		<item>
		<title>A new look for OpenFPC &#8211; New GUI in devopment</title>
		<link>http://leonward.wordpress.com/2011/04/25/a-new-look-for-openfpc-new-gui-in-devopment/</link>
		<comments>http://leonward.wordpress.com/2011/04/25/a-new-look-for-openfpc-new-gui-in-devopment/#comments</comments>
		<pubDate>Mon, 25 Apr 2011 18:56:35 +0000</pubDate>
		<dc:creator>leonward</dc:creator>
				<category><![CDATA[OpenFPC]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[gui]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[openfpc]]></category>

		<guid isPermaLink="false">http://leonward.wordpress.com/?p=496</guid>
		<description><![CDATA[Developing open source software has its ups and downs. It&#8217;s great to hear that your work is helping others solve problems they have, but on the flip-side some people simply love to focus on negatives and never offer to help improve through collaboration. A user of OpenFPC recently decided they didn&#8217;t like the web UI much, and rather [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=leonward.wordpress.com&amp;blog=6873153&amp;post=496&amp;subd=leonward&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Developing open source software has its ups and downs. It&#8217;s great to hear that your work is helping others solve problems they have, but on the flip-side some people simply love to focus on negatives and never offer to help improve through collaboration.</p>
<p>A user of OpenFPC recently decided they didn&#8217;t like the web UI much, and rather than simply complaining about it, they decided to collaborate and work on an overhaul. It&#8217;s efforts of people like this that make OSS all the more rewarding.</p>
<p>The UI isn&#8217;t quite ready to be released in an installable form, but I thought I would provide a couple of screenshots to wet current users appetite. David, thanks for your effort!</p>

<a href='http://leonward.wordpress.com/2011/04/25/a-new-look-for-openfpc-new-gui-in-devopment/gui2-2/' title='Extracting a session via an IDS event log '><img data-attachment-id='497' data-orig-size='1075,746' data-liked='0'width="150" height="104" src="http://leonward.files.wordpress.com/2011/04/gui2-2.png?w=150&#038;h=104" class="attachment-thumbnail" alt="Extracting a session via an IDS event log" title="Extracting a session via an IDS event log" /></a>
<a href='http://leonward.wordpress.com/2011/04/25/a-new-look-for-openfpc-new-gui-in-devopment/gui2-1/' title='Session results'><img data-attachment-id='498' data-orig-size='1077,743' data-liked='0'width="150" height="103" src="http://leonward.files.wordpress.com/2011/04/gui2-1.png?w=150&#038;h=103" class="attachment-thumbnail" alt="Session results" title="Session results" /></a>
<a href='http://leonward.wordpress.com/2011/04/25/a-new-look-for-openfpc-new-gui-in-devopment/gui2-3/' title='The Session search page'><img data-attachment-id='500' data-orig-size='1076,741' data-liked='0'width="150" height="103" src="http://leonward.files.wordpress.com/2011/04/gui2-3.png?w=150&#038;h=103" class="attachment-thumbnail" alt="The Session search page" title="The Session search page" /></a>

<br /> Tagged: <a href='http://leonward.wordpress.com/tag/gui/'>gui</a>, <a href='http://leonward.wordpress.com/tag/open-source/'>open source</a>, <a href='http://leonward.wordpress.com/tag/openfpc-2/'>openfpc</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/leonward.wordpress.com/496/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/leonward.wordpress.com/496/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/leonward.wordpress.com/496/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/leonward.wordpress.com/496/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/leonward.wordpress.com/496/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/leonward.wordpress.com/496/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/leonward.wordpress.com/496/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/leonward.wordpress.com/496/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/leonward.wordpress.com/496/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/leonward.wordpress.com/496/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/leonward.wordpress.com/496/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/leonward.wordpress.com/496/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/leonward.wordpress.com/496/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/leonward.wordpress.com/496/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=leonward.wordpress.com&amp;blog=6873153&amp;post=496&amp;subd=leonward&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://leonward.wordpress.com/2011/04/25/a-new-look-for-openfpc-new-gui-in-devopment/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8bf5331721efa2e5780016f58d071a57?s=96&#38;d=identicon&#38;r=R" medium="image">
			<media:title type="html">leonward</media:title>
		</media:content>

		<media:content url="http://leonward.files.wordpress.com/2011/04/gui2-2.png?w=150" medium="image">
			<media:title type="html">Extracting a session via an IDS event log</media:title>
		</media:content>

		<media:content url="http://leonward.files.wordpress.com/2011/04/gui2-1.png?w=150" medium="image">
			<media:title type="html">Session results</media:title>
		</media:content>

		<media:content url="http://leonward.files.wordpress.com/2011/04/gui2-3.png?w=150" medium="image">
			<media:title type="html">The Session search page</media:title>
		</media:content>
	</item>
		<item>
		<title>Immunet 3.0, ClamAV, and OpenFPC updates (including a blatant product plug)</title>
		<link>http://leonward.wordpress.com/2011/02/18/immunet-3-0-clamav-and-blatnt-plugs/</link>
		<comments>http://leonward.wordpress.com/2011/02/18/immunet-3-0-clamav-and-blatnt-plugs/#comments</comments>
		<pubDate>Fri, 18 Feb 2011 15:48:50 +0000</pubDate>
		<dc:creator>leonward</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[OpenFPC]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[immunet]]></category>
		<category><![CDATA[ClamAV]]></category>

		<guid isPermaLink="false">http://leonward.wordpress.com/?p=491</guid>
		<description><![CDATA[I&#8217;m always pretty careful to keep anything too commercial away from my blog, but from time to time something just has to give. Back in late (very late in fact) 2010, Sourcefire (those nice people who supply me with beer-money) purchased an exciting company called Immunet. Ill spare you the purchase details,  because it&#8217;s out-of-scope [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=leonward.wordpress.com&amp;blog=6873153&amp;post=491&amp;subd=leonward&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m always pretty careful to keep anything too commercial away from my blog, but from time to time something just has to give.</p>
<p>Back in late (very late in fact) 2010, Sourcefire (those nice people who supply me with beer-money) purchased an exciting company called Immunet. Ill spare you the <a href="http://blog.immunet.com/blog/2011/1/5/immunet-acquired-by-sourcefire.html">purchase details</a>,  because it&#8217;s out-of-scope for this quick update.</p>
<p>I&#8217;ve been aware of Immunet for quite some time but haven&#8217;t had a chance to really use their technology in anger because I&#8217;m a OSX/Linux user, but this changed a couple of weeks back. I recently needed to use a Windows XP VM to work with some win32 only software, I&#8217;ve had a virtual machine installed for ages and because it&#8217;s rarely used it&#8217;s rarely updated (bad Leon!). I probably spend less than an hour a year on this windows VM, I simply don&#8217;t have time to install updates because I only use it for quick tests (very bad Leon!).</p>
<p>Immunet&#8217;s cloud architecture is perfect for AV in this type of environment, I never need to update my signature pack because all detection is performed in the cloud. While trying to install some software from a USB key-fob that was shared around at a recent conference what popped up? Immunet kindly did it&#8217;s job and protected me from some malware nastiness. Now that was awesome.</p>
<p>Oh, by the way Immunet isn&#8217;t only awesome (because it saved me from my own stupidity), its also $free and uses Clam AV (that&#8217;s also free, but as in speech as well). If you&#8217;re using a Windows VM or real device without AV you know what you should do&#8230; Go install Immunet for free now <a href="http://www.immunet.com">http://www.immunet.com</a> . Go on do it now!</p>
<p>For those of you who read this blog for updates on OpenFPC, if you have any spare time please test the updated 0.5 <a href="http://code.google.com/p/openfpc/downloads/list">release</a>. There have been many changes at the back-end that I would like to get some feedback on. If it stops working or fails to start please let me know via the usual routes. You shouldn&#8217;t see many functional changes, but was a big massive re-write under the covers.</p>
<p>-Leon</p>
<br /> Tagged: <a href='http://leonward.wordpress.com/tag/clamav/'>ClamAV</a>, <a href='http://leonward.wordpress.com/tag/immunet/'>immunet</a>, <a href='http://leonward.wordpress.com/tag/security-2/'>security</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/leonward.wordpress.com/491/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/leonward.wordpress.com/491/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/leonward.wordpress.com/491/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/leonward.wordpress.com/491/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/leonward.wordpress.com/491/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/leonward.wordpress.com/491/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/leonward.wordpress.com/491/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/leonward.wordpress.com/491/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/leonward.wordpress.com/491/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/leonward.wordpress.com/491/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/leonward.wordpress.com/491/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/leonward.wordpress.com/491/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/leonward.wordpress.com/491/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/leonward.wordpress.com/491/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=leonward.wordpress.com&amp;blog=6873153&amp;post=491&amp;subd=leonward&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://leonward.wordpress.com/2011/02/18/immunet-3-0-clamav-and-blatnt-plugs/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8bf5331721efa2e5780016f58d071a57?s=96&#38;d=identicon&#38;r=R" medium="image">
			<media:title type="html">leonward</media:title>
		</media:content>
	</item>
		<item>
		<title>Insta-Snorby 0.4 with OpenFPC</title>
		<link>http://leonward.wordpress.com/2010/12/06/insta-snorby-0-4-with-openfpc/</link>
		<comments>http://leonward.wordpress.com/2010/12/06/insta-snorby-0-4-with-openfpc/#comments</comments>
		<pubDate>Mon, 06 Dec 2010 13:24:50 +0000</pubDate>
		<dc:creator>leonward</dc:creator>
				<category><![CDATA[OpenFPC]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[snort]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://leonward.wordpress.com/?p=480</guid>
		<description><![CDATA[Snorby had a big launch this weekend with an event that rivaled Apple in terms of hype and excitement! The two-dot-ooh-yeah release has reached the unwashed masses. The Snorby 2.0 feature that I&#8217;m most excited about is the inclusion of support for OpenFPC directly in the Snorby UI (but face it I&#8217;m kind of biased [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=leonward.wordpress.com&amp;blog=6873153&amp;post=480&amp;subd=leonward&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Snorby had a big launch this weekend with an event that rivaled Apple in terms of hype and excitement! The two-dot-ooh-yeah release has reached the unwashed masses.</p>
<p>The Snorby 2.0 feature that I&#8217;m most excited about is the inclusion of support for OpenFPC directly in the Snorby UI (but face it I&#8217;m kind of biased here). Many users of Snorby will be unaware of the OpenFPC project, and as they could be eager to try out the bleeding Snorby version, I thought I would include a quick how-to (below) of adding OpenFPC on to the Insta-Snorby appliance.</p>
<div id="attachment_481" class="wp-caption aligncenter" style="width: 310px"><a href="http://leonward.files.wordpress.com/2010/12/snorbyopenfpc.png"><img class="size-medium wp-image-481" title="Snorby and OpenFPC" src="http://leonward.files.wordpress.com/2010/12/snorbyopenfpc.png?w=300&#038;h=196" alt="" width="300" height="196" /></a><p class="wp-caption-text">OpenFPS and Snorby together</p></div>
<p>I wouldn&#8217;t expect real-world users of Snorby / OpenFPC to use the Insta-Snorby VM, but it&#8217;s a good introduction / test platform. As a guide to effort, the below ten steps should take about ten minutes to follow (including the download and updating of packages).</p>
<p>If you spot any errors please let me know, this is the bleeding edge after all.</p>
<h3>First the obvious bits&#8230;.</h3>
<p style="padding-left:30px;">1) Download the Insta-Snorby-0.4.iso</p>
<p style="padding-left:30px;">2) Install the .iso on to the hard disk of a virtual (or physical) machine</p>
<p style="padding-left:30px;">3) SSH in to the device as root.</p>
<h3>Now the less-obvious bits&#8230;</h3>
<p style="padding-left:30px;">4) Prepare the platform.</p>
<p><strong> </strong>Update the package archives. This is mandatory, it&#8217;s not being performed as part of good practice.</p>
<pre style="padding-left:30px;">root@Insta-Snorby ~#<strong> apt-get update</strong></pre>
<p>Install the dependancies from the Ubuntu package archive (note you can copy/paste the below into your ssh session rather than re-type).</p>
<pre style="padding-left:30px;"><strong>apt-get install apache2 daemonlogger tcpdump tshark libarchive-zip-perl \</strong>
<strong>libfilesys-df-perl libapache2-mod-php5 mysql-server php5-mysql \</strong>
<strong>libdatetime-perl libdbi-perl libdate-simple-perl php5-mysql \</strong>
<strong>libterm-readkey-perl libdate-simple-perl</strong></pre>
<p>5) Download the latest version of OpenFPC from <a href="http://code.google.com/p/openfpc/downloads/list">http://code.google.com/p/openfpc/downloads/list </a></p>
<pre style="padding-left:30px;">root@Insta-Snorby ~# <strong>wget http://openfpc.googlecode.com/files/openfpc-0.4-266.tgz</strong></pre>
<p>Note that 0.4-266 is &#8220;current&#8221; at the time of writing, but there is a lot of development happening right, so make sure you get the latest and don&#8217;t assume 0.4-266 is still &#8220;current&#8221;</p>
<p>6) Install OpenFPC</p>
<pre style="padding-left:30px;">root@Insta-Snorby ~# <strong>tar -zxf openfpc-0.4-266.tgz </strong></pre>
<pre style="padding-left:30px;">root@Insta-Snorby ~# <strong>cd openfpc-0.4-266/</strong></pre>
<pre style="padding-left:30px;">root@Insta-Snorby ~# <strong>./openfpc-install.sh install</strong></pre>
<p>You will be promoted to provide a password for the OpenFPC extract.cgi script. This password protects any attempts to pull out a pcap via the cgi interface used by Snorby via Apache&#8217;s basic auth. It saves the password to /etc/openfpc/apache2.passwd.<br />
You will need this username/pass to access any pcaps via Snorby, so <em>REMEMBER IT</em>!</p>
<p>7) Customize OpenFPC</p>
<p>OpenFPC is a client/server system, the openfpc-client does not need to be on the same physical host as the openfpc-queue daemon and therefore it listens on a network socket (default 4242). The default username and password is</p>
<p>Username: openfpc<br />
Password: openfpc</p>
<p><em><strong>If you want</strong></em> to change these, edit /etc/openfpc/openfpc-default.conf and set&#8230;</p>
<p>a) USER=openfpc=openfpc</p>
<p style="padding-left:30px;">Set this to whatever username/pass you desire e.g.<br />
USER=snorby=letmein</p>
<p>b) Change the user account that is used to pull PCAP files via the extract.cgi interface to one you have specified with a USER definition. e.g. for the above user definition I would use:</p>
<p style="padding-left:30px;">GUIUSER=snorby<br />
GUIUSER=letmein</p>
<p>8) Start up OpenFPC</p>
<p><span style="font-family:Consolas, Monaco, 'Courier New', Courier, monospace;line-height:18px;font-size:12px;white-space:pre;">root@Insta-Snorby ~/openfpc-0.4-266# <strong>openfpc &#8211;action start</strong> </span></p>
<pre>###############################################################################
[*] OpenFPC instance openfpc-example-proxy.conf
 -  NODENAME:              Example_Proxy
 -  DESCRIPTION:           "An example OpenFPC Proxy config. www.openfpc.org"
 -  STATUS :               DISABLED 
 -  PORT:                  4243
###############################################################################
[*] OpenFPC instance openfpc-default.conf 
 -  NODENAME:              Default_Node 
 -  DESCRIPTION:           "An OpenFPC node. www.openfpc.org" 
 -  STATUS :               ENABLED
 -  PORT:                  4242
 -  INTERFACE:             eth0
 -  FULL PACKET CAPTURE:   ENABLED
 -  PACKET STORE:          /var/tmp/openfpc/pcap
 -  SESSION DATA SEARCH:   DISABLED
Starting Daemonlogger (Default_Node)...                                    Done
Starting OpenFPC Queue Daemon (Default_Node)...                            Done</pre>
<p>9) Check communications and your openfpc username/password.</p>
<p>Use the command line tool openfpc-client to check things are working. The &#8211;action status will provide a status check of a remote OpenFPC instance.</p>
<pre>root@Insta-Snorby ~/openfpc-0.4-266# <strong>openfpc-client -a status</strong>
<strong> </strong>  
 * openfpc-client 0.4 *
Part of the OpenFPC project
Username: openfpc
Password for user openfpc : 
#################################### 
 OpenFPC Node name   :  Default_Node 
 OpenFPC Node Type   :  NODE
 OpenFPC Version     :  0.4
 Oldest Packet       :  1291638906 (Mon Dec  6 12:35:06 2010)
 Oldest Session      :  0 (Thu Jan  1 00:00:00 1970)
 Packet utilization  :  10% 
 Session utilization :  Disabled% 
 Session DB Size     :  Disabled rows 
 Session lag         :  0 files 
 Storage utilization :  10% 
 Packet space used   :  1867896 (1.87 GB)
 Session space used  :  Disabled (Disabled Bytes)
 Storage used        :  1867896 (1.87 GB)
 Load avg 1          :  0.04 
 Load avg 5          :  0.05 
 Load avg 15         :  0.08 
 Errors              :  0 
root@Insta-Snorby ~/openfpc-0.4-266#</pre>
<p>10) Configure the Snorby OpenFPC plugin</p>
<p>Navigate to the Snorby web interface, and browse to Administration.</p>
<div id="attachment_484" class="wp-caption aligncenter" style="width: 310px"><a href="http://leonward.files.wordpress.com/2010/12/snorby-admin.png"><img class="size-medium wp-image-484" title="Snorby Admin page" src="http://leonward.files.wordpress.com/2010/12/snorby-admin.png?w=300&#038;h=157" alt="" width="300" height="157" /></a><p class="wp-caption-text">Enable your OpenFPC integration here</p></div>
<ul>
<li>Check the box &#8220;Enable OpenFPC support&#8221;</li>
<li>Use the below URL for extraction
<ul>
<li>https://&lt;your Insta-snorby IP&gt;/openfpc/cgi-bin/extract.cgi</li>
</ul>
</li>
<li>Hit &#8220;Save Settings&#8221;</li>
</ul>
<p>Complete!</p>
<p>Now when you look at an IPS event, you will have a &#8220;Packet Capture&#8221; button that pulls out the complete session data via OpenFPC.</p>
<p>Many of the advanced OpenFPC capabilities are not addressed in this how-to such as connection/flow capture and searching, compressed extracts, reports, distributed extracts, horizontal scaling, etc etc but I&#8217;m keeping this How-to simple. If you want to know more, you know where to look <a href="http://www.openfpc.org">http://www.openfpc.org</a>.</p>
<p>-Leon</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/leonward.wordpress.com/480/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/leonward.wordpress.com/480/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/leonward.wordpress.com/480/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/leonward.wordpress.com/480/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/leonward.wordpress.com/480/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/leonward.wordpress.com/480/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/leonward.wordpress.com/480/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/leonward.wordpress.com/480/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/leonward.wordpress.com/480/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/leonward.wordpress.com/480/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/leonward.wordpress.com/480/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/leonward.wordpress.com/480/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/leonward.wordpress.com/480/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/leonward.wordpress.com/480/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=leonward.wordpress.com&amp;blog=6873153&amp;post=480&amp;subd=leonward&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://leonward.wordpress.com/2010/12/06/insta-snorby-0-4-with-openfpc/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8bf5331721efa2e5780016f58d071a57?s=96&#38;d=identicon&#38;r=R" medium="image">
			<media:title type="html">leonward</media:title>
		</media:content>

		<media:content url="http://leonward.files.wordpress.com/2010/12/snorbyopenfpc.png?w=300" medium="image">
			<media:title type="html">Snorby and OpenFPC</media:title>
		</media:content>

		<media:content url="http://leonward.files.wordpress.com/2010/12/snorby-admin.png?w=300" medium="image">
			<media:title type="html">Snorby Admin page</media:title>
		</media:content>
	</item>
		<item>
		<title>Pushing the OpenFPC project forward</title>
		<link>http://leonward.wordpress.com/2010/11/22/pushing-the-openfpc-project-forward/</link>
		<comments>http://leonward.wordpress.com/2010/11/22/pushing-the-openfpc-project-forward/#comments</comments>
		<pubDate>Mon, 22 Nov 2010 21:09:08 +0000</pubDate>
		<dc:creator>leonward</dc:creator>
				<category><![CDATA[OpenFPC]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[snort]]></category>
		<category><![CDATA[Sourcefire]]></category>

		<guid isPermaLink="false">http://leonward.wordpress.com/?p=477</guid>
		<description><![CDATA[A couple of people have been working harder than normal over the last couple of weeks. Edward, and I are happy to push out another OpenFPC test release to the world. Here is short list of highlights and changes, however there is one point to pay close attention to. A very kind web developer has [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=leonward.wordpress.com&amp;blog=6873153&amp;post=477&amp;subd=leonward&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A couple of people have been working harder than normal over the last couple of weeks. Edward, and I are happy to push out another OpenFPC test release to the world.</p>
<p>Here is short list of highlights and changes, however there is one point to pay close attention to.</p>
<p>A very kind web developer has started to help the team work on a central user interface for searching and extraction. Ill introduce him and his work in another future post, however in the short term thanks should be sent over to Eduardo!</p>
<p>0.3 Change highlights</p>
<ul>
<li>Multiple configs can co-exist on a single box</li>
<li>Sourcefire IPS event parsing fixed</li>
<li>Snort-Fast event type no longer required port numbers. Makes multi-session extracts more simple (http attacks for example)</li>
<li>Search via bpf (&#8211;bpf command line option to openfpc-client)</li>
<li>Passwords no longer echo to screen</li>
<li>New init scripts to work with the new openfpc command</li>
<li>LSB compliant init scripts</li>
<li>Better log output (wlog) and verbose message handeling</li>
<li>Added better example configs (openfpc-default.conf and openfpc-example-proxy.conf)</li>
<li>Enabling session data is now far more simple</li>
<li>Included web-ui, now enabled by default</li>
<li>Space now renders in GB rather than Bytes</li>
<li>Fixed performance hit on cx2db inserting half open sessions.</li>
<li>Improved help text</li>
<li>The out-of-the-box proxy and node configurations now work with each other</li>
<li>CGI interface for full packet integration with other tools</li>
</ul>
<p>As always, feedback and bugs are welcomed.</p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/leonward.wordpress.com/477/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/leonward.wordpress.com/477/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/leonward.wordpress.com/477/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/leonward.wordpress.com/477/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/leonward.wordpress.com/477/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/leonward.wordpress.com/477/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/leonward.wordpress.com/477/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/leonward.wordpress.com/477/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/leonward.wordpress.com/477/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/leonward.wordpress.com/477/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/leonward.wordpress.com/477/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/leonward.wordpress.com/477/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/leonward.wordpress.com/477/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/leonward.wordpress.com/477/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=leonward.wordpress.com&amp;blog=6873153&amp;post=477&amp;subd=leonward&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://leonward.wordpress.com/2010/11/22/pushing-the-openfpc-project-forward/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8bf5331721efa2e5780016f58d071a57?s=96&#38;d=identicon&#38;r=R" medium="image">
			<media:title type="html">leonward</media:title>
		</media:content>
	</item>
		<item>
		<title>An OpenFPC Example: Clustering packet capture over multiple links/devices/countries.</title>
		<link>http://leonward.wordpress.com/2010/09/24/an-openfpc-example-clustering-packet-capture-over-multiple-linksdevicescountries/</link>
		<comments>http://leonward.wordpress.com/2010/09/24/an-openfpc-example-clustering-packet-capture-over-multiple-linksdevicescountries/#comments</comments>
		<pubDate>Fri, 24 Sep 2010 12:42:49 +0000</pubDate>
		<dc:creator>leonward</dc:creator>
				<category><![CDATA[OpenFPC]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[openfpc]]></category>
		<category><![CDATA[snort]]></category>
		<category><![CDATA[traffic capture]]></category>

		<guid isPermaLink="false">http://leonward.wordpress.com/?p=468</guid>
		<description><![CDATA[It&#8217;s been a while since my last post, but it&#8217;s because I&#8217;ve been busy working on ofpc. To rectify that, I thought I would share some of the concepts that are behind how OpenFPC should be able to grow rapidly into a distributed system. One of the more useful features of ofpc is its self-referencing [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=leonward.wordpress.com&amp;blog=6873153&amp;post=468&amp;subd=leonward&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a while since my last post, but it&#8217;s because I&#8217;ve been busy working on ofpc. To rectify that, I thought I would share some of the concepts that are behind how OpenFPC should be able to grow rapidly into a distributed system.</p>
<p>One of the more useful features of ofpc is its self-referencing method for scaling out master/master/slave devices. This concept gets interest when I explain it to people, however it&#8217;s not really documented anywhere. So let me introduce it here with a working example&#8230;&#8230;</p>
<p>There are a few common situations where the master/slave relationship can provide real value via clustering.</p>
<ul>
<li>Geographically separated network links with guaranteed or possible asymmetric traffic paths</li>
<li>Multi-link trunks</li>
<li>High(er) speed links where you need to spread traffic load over multiple slaves</li>
</ul>
<p>Firstly, please forgive my terrible retro-diagram skills.</p>
<div id="attachment_469" class="wp-caption aligncenter" style="width: 571px"><a href="http://leonward.files.wordpress.com/2010/09/ofpc-cluster1.png"><img class="size-full wp-image-469" title="ofpc-cluster1" src="http://leonward.files.wordpress.com/2010/09/ofpc-cluster1.png?w=700" alt=""   /></a><p class="wp-caption-text">OpenFPC Cluster diagram</p></div>
<p><strong>So here&#8217;s the situation:</strong></p>
<p>There are two pipes between network &#8220;A&#8221; and network &#8220;B&#8221;, and for whatever the reason, you don&#8217;t know if the traffic you want to grab from the buffer could be in the archive of SLAVE1 or SLAVE2. You do know however it&#8217;s going to be in one <em><strong>or more</strong></em> of them. Combined they become one *logical* network link.</p>
<p>By requesting the data from the Master queue daemon responsible for these two devices (MASTER in the diagram here), without specifying which slave you want to route your request to, it will search/extract from all of the slaves below it. The master ofpc-queued doesn&#8217;t need to be on a separate bit of hardware, it&#8217;s just represented in the diagram that way.</p>
<p><strong>Here&#8217;s an example of it functioning in my test environment.</strong></p>
<pre style="padding-left:60px;">lward@UbuntuDesktop:~/code/openfpc$ <strong>./ofpc-client.pl  -a fetch \
 --src-addr=192.168.222.1 --dst-port=22</strong>
* ofpc-client.pl 0.1 *
Part of the OpenFPC project
Username: <strong>master</strong>
Password for user master :
#####################################
Filename: /tmp/extracted-ofpc-1284615954.pcap
Size    : <strong>7.0M</strong>
MD5     : a495c1f38dce3dc9dff50ead47a415ab
lward@UbuntuDesktop:~/code/openfpc$</pre>
<pre style="padding-left:60px;"></pre>
<p> </p>
<p>This ofpc request provided me with a 7MB pcap file made up from the traffic seen by &#8220;slave1&#8243; and &#8220;slave2&#8243;, it&#8217;s all merged together so I can inspect the traffic as the logical link processes it rather than what can be captured on one physical leg of the link. This isn&#8217;t limited to a maximum of two slaves, it can of course be many many more.</p>
<p>If for any given reason I would still prefer to only look at the traffic on one slave, I can either:</p>
<ul>
<li>Make an ofpc request directly to one of the ofpc-slave devices</li>
<li>Specify the device to focus on to the master</li>
</ul>
<p>For example&#8230;..</p>
<pre style="padding-left:60px;">lward@UbuntuDesktop:~/code/openfpc$ <strong>./ofpc-client.pl  -a fetch \
</strong><strong>--src-addr=192.168.222.1 --dst-port=22 -o 4240 --device slave2</strong></pre>
<pre style="padding-left:60px;">* ofpc-client.pl 0.1 *
Part of the OpenFPC project
Username: <strong>master</strong>
Password for user master :
#####################################
Filename: /tmp/extracted-ofpc-1284616271.pcap
Size    : <strong>6.0M</strong>
MD5     : 68132e2e12c16665913cb1e7f36336f3
lward@UbuntuDesktop:~/code/openfpc$<span style="font-family:Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif;line-height:19px;white-space:normal;font-size:13px;"> </span></pre>
<p>If you want to test this feature out, make sure you&#8217;re using the latest openfpc code out of svn.</p>
<p>-Leon</p>
<br /> Tagged: <a href='http://leonward.wordpress.com/tag/network/'>network</a>, <a href='http://leonward.wordpress.com/tag/openfpc-2/'>openfpc</a>, <a href='http://leonward.wordpress.com/tag/snort/'>snort</a>, <a href='http://leonward.wordpress.com/tag/traffic-capture/'>traffic capture</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/leonward.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/leonward.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/leonward.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/leonward.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/leonward.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/leonward.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/leonward.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/leonward.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/leonward.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/leonward.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/leonward.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/leonward.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/leonward.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/leonward.wordpress.com/468/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=leonward.wordpress.com&amp;blog=6873153&amp;post=468&amp;subd=leonward&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://leonward.wordpress.com/2010/09/24/an-openfpc-example-clustering-packet-capture-over-multiple-linksdevicescountries/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8bf5331721efa2e5780016f58d071a57?s=96&#38;d=identicon&#38;r=R" medium="image">
			<media:title type="html">leonward</media:title>
		</media:content>

		<media:content url="http://leonward.files.wordpress.com/2010/09/ofpc-cluster1.png" medium="image">
			<media:title type="html">ofpc-cluster1</media:title>
		</media:content>
	</item>
		<item>
		<title>OpenFPC Test Release</title>
		<link>http://leonward.wordpress.com/2010/09/10/openfpc-test-release/</link>
		<comments>http://leonward.wordpress.com/2010/09/10/openfpc-test-release/#comments</comments>
		<pubDate>Fri, 10 Sep 2010 17:35:10 +0000</pubDate>
		<dc:creator>leonward</dc:creator>
				<category><![CDATA[OpenFPC]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[openfpc]]></category>
		<category><![CDATA[pcap]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://leonward.wordpress.com/?p=465</guid>
		<description><![CDATA[The weekend has landed, and I have time to pull together some of the bits I need for an OpenFPC (Open Full Packet Capture) release, but I need your help. I know there are bugs that still need squishing (Master-mode install script for example), but if you have time and are interested, please help me [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=leonward.wordpress.com&amp;blog=6873153&amp;post=465&amp;subd=leonward&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The weekend has landed, and I have time to pull together some of the bits I need for an OpenFPC (Open Full Packet Capture) release, but I need your help.</p>
<p>I know there are bugs that still need squishing (Master-mode install script for example), but if you have time and are interested, please help me test out an alpha release. Go grab it from <a href="http://code.google.com/p/openfpc/downloads/list">here</a> (download the latest version number, it may change repeatedly over the next few days) and run the installer.</p>
<p>So far, I have only tested it on Ubuntu 10.4, the Redhat auto-dependency checking isn&#8217;t there yet but it should work on that platform if you have the required RPMs installed with a little tweaking.</p>
<p>So what are you waiting for!? Find problems, tell me where the install and setup falls down, and have some fun.</p>
<p>-Leon</p>
<br /> Tagged: <a href='http://leonward.wordpress.com/tag/openfpc-2/'>openfpc</a>, <a href='http://leonward.wordpress.com/tag/pcap/'>pcap</a>, <a href='http://leonward.wordpress.com/tag/security-2/'>security</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/leonward.wordpress.com/465/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/leonward.wordpress.com/465/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/leonward.wordpress.com/465/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/leonward.wordpress.com/465/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/leonward.wordpress.com/465/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/leonward.wordpress.com/465/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/leonward.wordpress.com/465/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/leonward.wordpress.com/465/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/leonward.wordpress.com/465/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/leonward.wordpress.com/465/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/leonward.wordpress.com/465/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/leonward.wordpress.com/465/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/leonward.wordpress.com/465/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/leonward.wordpress.com/465/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=leonward.wordpress.com&amp;blog=6873153&amp;post=465&amp;subd=leonward&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://leonward.wordpress.com/2010/09/10/openfpc-test-release/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8bf5331721efa2e5780016f58d071a57?s=96&#38;d=identicon&#38;r=R" medium="image">
			<media:title type="html">leonward</media:title>
		</media:content>
	</item>
		<item>
		<title>OpenFPC &#8211; An update: v0.2.97 available (woohoo!)</title>
		<link>http://leonward.wordpress.com/2010/08/02/openfpc-an-update-v0-2-97-available-woohoo/</link>
		<comments>http://leonward.wordpress.com/2010/08/02/openfpc-an-update-v0-2-97-available-woohoo/#comments</comments>
		<pubDate>Mon, 02 Aug 2010 21:53:08 +0000</pubDate>
		<dc:creator>leonward</dc:creator>
				<category><![CDATA[OpenFPC]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[fpcgui]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[openfpc]]></category>
		<category><![CDATA[pcap]]></category>
		<category><![CDATA[perl]]></category>
		<category><![CDATA[snort]]></category>

		<guid isPermaLink="false">http://leonward.wordpress.com/?p=457</guid>
		<description><![CDATA[It&#8217;s been a couple of months since I first posted about the OpenFPC project, so I thought it&#8217;s time that I provided a little update. Firstly, I need to throw some karma over to Edward Fjellskål (http://gamelinux.org), so&#8230; Edward++. Edward and I have merged the OpenFPC and FPCGUI projects, it makes way more sense to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=leonward.wordpress.com&amp;blog=6873153&amp;post=457&amp;subd=leonward&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a couple of months since I first posted about the OpenFPC project, so I thought it&#8217;s time that I provided a little update.</p>
<p>Firstly, I need to throw some karma over to Edward Fjellskål (http://gamelinux.org), so&#8230; Edward++.</p>
<p>Edward and I have merged the OpenFPC and FPCGUI projects, it makes way more sense to combine our efforts as our goals are similar while our approaches have been from different angles. We both see a need to unify all of the home-brew full-packet-capture/network forensics tools we see out there in the wild.</p>
<p>OpenFPC now has a new home, www.openfpc.org.  So, if you&#8217;re looking for a distributed wrapper for your daemonlogger instances, or if you&#8217;re still trying to get tcpdump to log in a ringbuffer and share access over multiple analysts, devices, and tools, head on over to <a href="http://www.openfpc.org/documentation/about">www.openfpc.org</a> to read all about it. Here are a couple of quick links for those who want to jump right in:</p>
<ul>
<li><a href="http://www.openfpc.org/screenshots">Screenshots</a></li>
<li><a href="http://www.openfpc.org/documentation/about">Deployment diagram, and operational concepts</a></li>
<li><a href="http://www.openfpc.org/documentation/install">Install guide</a></li>
<li><a href="http://www.openfpc.org/status">Project Status</a></li>
<li><a href="http://www.openfpc.org/downloads">Download</a></li>
</ul>
<p>I&#8217;m looking for people to help test and provide feedback now so I can fix problems and tweak things ahead of a full release.</p>
<p>Good luck, and please let me know your feedback.</p>
<p>-Leon</p>
<br /> Tagged: <a href='http://leonward.wordpress.com/tag/forensics/'>forensics</a>, <a href='http://leonward.wordpress.com/tag/fpcgui/'>fpcgui</a>, <a href='http://leonward.wordpress.com/tag/ids/'>IDS</a>, <a href='http://leonward.wordpress.com/tag/ips/'>IPS</a>, <a href='http://leonward.wordpress.com/tag/openfpc-2/'>openfpc</a>, <a href='http://leonward.wordpress.com/tag/pcap/'>pcap</a>, <a href='http://leonward.wordpress.com/tag/perl/'>perl</a>, <a href='http://leonward.wordpress.com/tag/snort/'>snort</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/leonward.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/leonward.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/leonward.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/leonward.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/leonward.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/leonward.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/leonward.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/leonward.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/leonward.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/leonward.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/leonward.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/leonward.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/leonward.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/leonward.wordpress.com/457/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=leonward.wordpress.com&amp;blog=6873153&amp;post=457&amp;subd=leonward&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://leonward.wordpress.com/2010/08/02/openfpc-an-update-v0-2-97-available-woohoo/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8bf5331721efa2e5780016f58d071a57?s=96&#38;d=identicon&#38;r=R" medium="image">
			<media:title type="html">leonward</media:title>
		</media:content>
	</item>
	</channel>
</rss>
