Monthly Archives: March 2005

Dirvish Guide for Snapshot Style Backups

I have nearly finished my guide for using Dirvish for snapshot style backups.

SANS Blacksburg, VA Day 8 / Departure

I finally left Blacksburg, VA around 8:40. It was overcast, but cleared up as I drove south. I managed to avoid getting lost the whole way back. The initial leg of the journey, back down I-81 and then I-77 through a moderately large group of mountains, was breathtaking. It had been [...]

SANS Blacksburg, VA Day 7 / Lecture 6

Our final day of class, we discussed various attacks and ways of correlating data to corroborate events. Class ended by 4:30. Some people stayed behind for a final, quick presentation on advanced data correlation and analysis.
Everywhere the ground was blanketed with a few inches of snow. It was rather breathtaking, but had [...]

SANS Blacksburg, VA Day 6 / Lecture 5

I seem to have discovered the Solitare crowd today. Several people plugging away, hardly working. I’d surf the Web instead, but that’s just me.
Finally discussing IDS deployment.
It snowed this evening. It was quite lovely. I watched from within the eating establishment chosen for abuse in downtown Blacksburg this evening. It [...]

SANS Blacksburg, VA Day 5 / Lecture 4

Attended a BOF on incident handling, which was discussed at length.
Setup BASE for monitoring Snort logging to MySQL.

SANS Blacksburg, VA Day 4 / Lecture 3

Today we discussed stuff.
The evening BOF I attended was about wireless deployments. We discussed deployments and products at length before moving into wired network management for nearly two hours. The most popular discussion was dealing with p2p traffic and malicious activity. Users simply moving to another port when they’re cut off is [...]

SANS Blacksburg, VA Day 3 / Lecture 2

Today it was exceedingly windy, and thus frigid cold outside. It lightly snowed some throughout the day.
We covered more tcpdump output, IDS evasion and insertion, and a review of bitmasking. The WiFi issue had not entirely resolved itself. In the morning DHCP leasing was broken campus wide. Later in the day [...]

Configured BASE for Snort on Debian

Configuring BASE for Snort on Debian GNU/Linux was surprisingly easy. A little familiarity with using MySQL grant syntax and policy is needed. The rest is smooth sailing if all the tools are on the same box, and only a bind away if MySQL is listening only on 127.0.0.1 and needs to be listening [...]

SANS Blacksburg, VA Day 2 / Lecture 1

I wandered out of bed around 8:20. I scarfed down some food and drove off to VT for the day. When I arrived, there was a large line for WiFi card registration, which I skipped. When I entered the auditorium I quickly discovered there were far more people than effective workspace. [...]

SANS Blacksburg, VA Day 1

I finally arose around 10. I discovered I turned the laptop off when I turned off the lamp. The battery was dead.
I spent some time messing with WiFi in an attempt to determine the weather for the day. The Weather Channel on the TV was quite useless, as per usual. Since [...]