[sniffer] Re: Update Script - Choice of WGET Parameter Prevents TimeStamping

2008-10-07 Thread Pete McNeil
/ corrections are reviewed and included in our updates. In any case they will be in the mailing list archives ;-) THANKS! _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you

[sniffer] Re: Update Script - Choice of WGET Parameter Prevents TimeStamping

2008-10-07 Thread Pete McNeil
. Best, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch

[sniffer] Re: Update Script - Choice of WGET Parameter Prevents TimeStamping

2008-10-07 Thread Pete McNeil
? snip/ Sorry--- the above was just me hitting the button before my brain caught up with my fingers. You did say that the compressed file would be output as .SNF -- _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC

[sniffer] Re: Update Script - Path apparently doesn't tolerate embadded blanks

2008-10-06 Thread Pete McNeil
program is calling another. Wherever possible it is usually best to use tilde to eliminate spaces in file or directory names -- otherwise the spaces are likely to be interpreted as breaks between command line parameters. Best, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC

[sniffer] Re: Update Script - Path apparently doesn't tolerate embadded blanks

2008-10-06 Thread Pete McNeil
just that there was nothing helpful in the product or documentation that would have lead me to conclude that either before or after it didnt work. There will be shortly. Thanks for your detailed posts! _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC

[sniffer] Re: Update Script - Path apparently doesn't tolerate embadded blanks

2008-10-06 Thread Pete McNeil
that but if it failed for him, why wouldn't it fail for others? You're right. We will need to tweak that in the installer if it isn't already. _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you

[sniffer] Testers wanted...

2008-10-06 Thread Pete McNeil
Please respond off list to support@ Thanks, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail

[sniffer] Re: .xml Error

2008-10-05 Thread Pete McNeil
as you would the entries in any ordinary text type log file. This link will show you how to interpret the log file: http://www.armresearch.com/support/articles/software/snfServer/logFiles/activityLogs.jsp Best, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC

[sniffer] Re: Sniffer 3.0 Installed

2008-10-04 Thread Pete McNeil
eReady.lck :CLEANUP if exist %RULEBASE_PATH%\%LICENSE_ID%.new del %RULEBASE_PATH%\%LICENSE_ID%.new if exist %WORKSPACE_PATH%\UpdateReady.lck del %WORKSPACE_PATH%\UpdateReady.lck :DONE ENDLOCAL -- Pete McNeil Chief Sci

[sniffer] Re: Sniffer 3.0 Installed

2008-10-04 Thread Pete McNeil
riting our installer too (Since it needs to modify/generate the getRulebase script. For the immediate future this discussion is archived and searchable and I will add a task to the web site project to describe some of these getRulebase.cmd scenarios. How does that sound? _M -- Pete McNeil Chief Scie

[sniffer] Re: FW: [sniffer] Re: Sniffer 3.0 Froze Mail Server

2008-10-04 Thread Pete McNeil
the failed tasks are manually removed -- since none of them is ever properly initialized none of the tasks can time out, fail, or shut down on their own. Hope this helps, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC.

[sniffer] Re: Sniffer Version 3 Install for FreeBSD?

2008-09-29 Thread Pete McNeil
. _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST

[sniffer] Re: Sniffer Version 3 Install for FreeBSD?

2008-09-29 Thread Pete McNeil
the process together. If I understand correctly, IMGate uses postfix and postfix allows for more than one filter. The provided filter scripts should get you started. Best, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC

[sniffer] Re: ASCII art spam

2008-09-25 Thread Pete McNeil
. I will research them with the team and we'll code up some rules for whatever is getting through. At the moment things are pretty quiet (99.7% nominal capture) and we're not seeing these in the traps. If they are on their way we would like to get them early (of course). Thanks, _M -- Pete

[sniffer] Re: Alt-n Security Gateway

2008-09-11 Thread Pete McNeil
be switching to Exchange. And want to use this product with it. -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe

[sniffer] Re: What's in a name - or - objects in mirror.exe are bigger than they appear

2008-09-06 Thread Pete McNeil
they're not cp/cs (easier to remember, sure, but not using the power, etc.). Thanks! This is what we've decided to do. _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you

[sniffer] What's in a name - or - objects in mirror.exe are bigger than they appear

2008-09-05 Thread Pete McNeil
that. My question is: Do any of our *nix users consider this to be an issue? Should we change the names of SNFServer.exe and SNFClient.exe in the *nix distribution to drop the .exe ? Feel free to email me directly if you wish. I look forward to your insights. Thanks, _M -- Pete McNeil Chief

[sniffer] Stampede - amazing!

2008-08-28 Thread Pete McNeil
this new herd. Theories, comments, and observations welcome. Thanks, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com

[sniffer] GBUdb Memory Requirements

2008-08-16 Thread Pete McNeil
size limit. Here is a link: http://www.armresearch.com/support/articles/software/snfServer/config/node/gbudb/database/condense/size-trigger.jsp Best, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent

[sniffer] Re: MDaemon latest

2008-08-07 Thread Pete McNeil
links here: http://www.armresearch.com/products/index.jsp Best, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com

[sniffer] Re: Am I ready to upgrade to version 3?

2008-08-05 Thread Pete McNeil
as it should be? I'll let Andy work on that with you to understand it and come up with a working solution. Thanks for the detail! _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you

[sniffer] Re: Am I ready to upgrade to version 3?

2008-08-04 Thread Pete McNeil
to that, too ;-) I don't think so. If you have gateways or other message processing systems in front of SNF you will want to be sure to tell GBUdb about them so that they can be skipped when SNF is determining the source IP for the message. The rest I think you covered. Best, _M -- Pete McNeil

[sniffer] Re: FW: Memory Usage of MessageSniffer 3

2008-08-01 Thread Pete McNeil
of increasing the signal to noise ratio for GBUdb as it learns which IPs to trust and which ones to suspect. Hope this helps, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you

[sniffer] Re: FW: Memory Usage of MessageSniffer 3

2008-08-01 Thread Pete McNeil
... When records are condensed they are more likely to be bounced off the cloud and get new data so what you might loose in fewer records you will gain in more frequent reflections. Hope this helps, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC

[sniffer] A few news items...

2008-07-31 Thread Pete McNeil
are in the works - pre-release versions and support are available. Plus the new XCI protocol makes access to SNF services as easy as a local TCP connection! Thanks! _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message

[sniffer] Re: FW: Memory Usage of MessageSniffer 3

2008-07-30 Thread Pete McNeil
list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode, E-mail to [EMAIL PROTECTED] To switch to the INDEX mode, E-mail to [EMAIL PROTECTED] Send administrative queries to [EMAIL PROTECTED] -- Pete McNeil Chief Scientist, Arm Research Labs

[sniffer] Re: Problem with Sniffer-Porn rule this morning

2008-07-18 Thread Pete McNeil
Hello Darin, Friday, July 18, 2008, 9:37:18 AM, you wrote: Pete, There appears to be a problem with rule 1984485 this morning. I'm getting a number of FP hits on it from AOL users. The rule has been pulled already. _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC

[sniffer] Re: Problem with Sniffer-Porn rule this morning

2008-07-18 Thread Pete McNeil
. Please check your snf_engine_cfg.log to see if the rule panic was picked up in your configuration. Best, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed

[sniffer] Re: Problem with Sniffer-Porn rule this morning

2008-07-18 Thread Pete McNeil
-- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST

[sniffer] Re: Problem with Sniffer-Porn rule this morning

2008-07-18 Thread Pete McNeil
bots would have queried the database for rules 20-40 minutes before you you received it. The rule may have still been in place at that time. _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you

[sniffer] Re: upgraded to 3.0

2008-07-18 Thread Pete McNeil
for the other (non source) distributions. When the next general revision is produced this change will be rolled in. Best, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are s

[sniffer] Re: MD - Headers in body

2008-07-17 Thread Pete McNeil
. Each line should end with CRLF and the first blank line should be CRLFCRLF. If you find something else in there then that's likely where the trouble is. Hope this helps, Best, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC

[sniffer] Upgraded Rulebase Delivery System

2008-07-12 Thread Pete McNeil
and theory rulebases should be delivered more quickly and more frequently. I will continue to monitor the system closely for any aberrations. Thanks, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent

[sniffer] Re: [Fwd: FW: [sniffer] Re: Upgraded Rulebase Delivery System]

2008-07-12 Thread Pete McNeil
see the .snf file, but the connection is closed immediately when the download starts. I'm working on this. I'm not sure what's causing it-- Apparently some option in wget. I have verified that some older scripts don't work. It appears to be related to whether gzip is accepted. _M -- Pete

[sniffer] Upgrades termporarily off-line.

2008-07-12 Thread Pete McNeil
complain that the file did not exist. I have tested non-compressed downloads and they appear to be working correctly again. Sorry for the trouble. I will keep you posted on our progress. _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC

[sniffer] Upgrades restored!

2008-07-12 Thread Pete McNeil
be no problems. Please let us know if you have any trouble. Thanks, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. PS: If you are still using the old version of SNF, or the old way of downloading rulebase files please upgrade as soon as you can. Thanks

[sniffer] SNF Client/Server Source (*nix) Update, Now 3.0.1.

2008-07-10 Thread Pete McNeil
Hello Sniffer Folks, We have published an update to the SNF Client/Server *nix distribution with the following features: * New V3-Fresh-Install-Readme.txt * Fixed minor error in SNFServer main.cpp when compiling on 64 bit. * Updates Tweaks to sample scripts. Best, _M -- Pete McNeil Chief

[sniffer] Re: It's official. SNF Version 3.0 is Ready!

2008-06-27 Thread Pete McNeil
responded to this last night on list. I'm guessing you didn't get that response so I'm responding to this new one directly (off list). _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you

[sniffer] Re: It's official. SNF Version 3.0 is Ready!

2008-06-27 Thread Pete McNeil
. Check your configuration file -- they may be turned off by default in that configuration. Here's some documentation on configuring SNF log files: http://www.armresearch.com/support/articles/software/snfServer/config/node/logs/index.jsp Hope this helps, _M -- Pete McNeil Chief Scientist, Arm

[sniffer] It's official. SNF Version 3.0 is Ready!

2008-06-26 Thread Pete McNeil
to the next upgrade... always work to do ;-) Cheers! _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail

[sniffer] Re: It's official. SNF Version 3.0 is Ready!

2008-06-26 Thread Pete McNeil
and we'll keep you posted. _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED

[sniffer] Bad rule alert: 1940812

2008-06-17 Thread Pete McNeil
character. We sincerely apologize for the inconvenience. Best, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com

[sniffer] Re: Bad rule alert: 1940812

2008-06-17 Thread Pete McNeil
-- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode, E

[sniffer] Re: Bad rule alert: 1940812

2008-06-17 Thread Pete McNeil
automatically added to your node's internal panic list rendering it inert. That probably explains why you have very few hits. Best, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you

[sniffer] Re: GBUdb dump

2008-06-17 Thread Pete McNeil
database ... checkpoint on-off='on' secs='3600'/ _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com

[sniffer] Re: Bad rule alert: 1940812

2008-06-17 Thread Pete McNeil
, but congratulations on the success of the first live test of auto-panic. (all previous tests were in the lab) :-) _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed

[sniffer] Re: Spam no using CAPTCHA!

2008-06-11 Thread Pete McNeil
-- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode, E

[sniffer] Re: Spam no using CAPTCHA!

2008-06-11 Thread Pete McNeil
CAPTCHA and let somebody else do the work. _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail

[sniffer] Final RC before Version 3 (fingers crossed)

2008-06-10 Thread Pete McNeil
and Command Line versions of the new SNF. Stay tuned! Best, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe

[sniffer] XYNTService -- Any Problems?

2008-05-09 Thread Pete McNeil
wheel right now -- not that it's hard, just that it's not necessary and we'd rather do other important stuff. Thanks! _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed

[sniffer] Re: XYNTService -- Any Problems?

2008-05-09 Thread Pete McNeil
... but we want something that we can deliver with the installer so it can be a (more or less) one click process. _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed

[sniffer] Re: XYNTService -- Any Problems?

2008-05-09 Thread Pete McNeil
uld require at least the same level of testing. All IMO of course. And well appreciated! :-) _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the

[sniffer] Re: XYNTService -- Any Problems?

2008-05-09 Thread Pete McNeil
the SNFServer executable as it is and then keep any service stub separate. There are a lot of advantages to this approach. I understand your point though. _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message

[sniffer] New version: Engine 24, MDPlugin 6

2008-04-25 Thread Pete McNeil
after 3 attempts the injector throws. Added 2 retries w/ 300ms delay to rename temp file to msg in XHDR inject code. If rename fails after 3 attempts the injector throws. Added IPTest logging. -- Best, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC

[sniffer] Re: Source distribution corrected re: snf2check utility

2008-04-24 Thread Pete McNeil
@ and include your configuration log and config files. Thanks, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E

[sniffer] Source distribution corrected re: snf2check utility

2008-04-21 Thread Pete McNeil
in the SNF2Check directory. NO OTHER MODIFICATIONS WERE MADE ;-) Best, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com

[sniffer] RePost Overview of Upgrade Process from 2.3x SNF to 2-9 (V3) SNF

2008-04-18 Thread Pete McNeil
new web site right now and your input will make it into our work. Thanks! _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer

[sniffer] MXScan for MailEnable

2008-03-07 Thread Pete McNeil
://www.mxuptime.com/screenshots/3b.jpg If you try this out please post a note to let us all know how it works for you. Thanks! _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed

[sniffer] Version 2-9rc1.8.2 Release Candidate (Std Test Package), and other plans/announcements!...

2008-03-07 Thread Pete McNeil
in snf_engine.xml to be more conservative. -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL

[sniffer] Re: Gateway solution

2008-03-06 Thread Pete McNeil
post XWall as an additional integration option. Thanks for the tip! _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com

[sniffer] Re: Proper way to setup a SNFServer on it's own box

2008-02-27 Thread Pete McNeil
this helps, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch

[sniffer] Bad Rule Alert - 1771029

2008-02-26 Thread Pete McNeil
) and destroyed moments ago (2008-02-06 16:10:00). Our sincere apologies, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com

[sniffer] Re: Ideal config for scaleable solution?

2008-02-22 Thread Pete McNeil
-- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode, E-mail

[sniffer] Re: Ideal config for scaleable solution?

2008-02-22 Thread Pete McNeil
of SA SNF is superior to either on it's own if you have the technical resources. _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer

[sniffer] Re: Updated - did I forgot anything?

2008-02-04 Thread Pete McNeil
e RBL score. I have updated the wiki: http://kb.armresearch.com/index.php?title=Message_Sniffer.TechnicalDetails.ResultCodes#Core_Rule_Group_.26_GBUdb_Result_Codes _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This me

[sniffer] Re: snfilter - linux - postfix

2008-02-02 Thread Pete McNeil
it only requires the adjustment of a node and that operation will itself be journalized first. Thanks for keeping us posted. Hope this helps, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you

[sniffer] Re: snfilter - linux

2008-01-27 Thread Pete McNeil
look for any errors in your logs that might indicate why the SNFServer stopped. _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer

[sniffer] Re: snfilter - linux - postfix

2008-01-27 Thread Pete McNeil
for weeks and months on various platforms -- almost without exception it only stops when I tell it to stop (including earlier test versions). If you come across any new info please let me know. If there is a bug I want it gone ;-) Thanks! _M -- Pete McNeil Chief Scientist, Arm Research Labs

[sniffer] New reference settings for GBUdb ranges.

2008-01-22 Thread Pete McNeil
the default settings for the production release, however we will continue to refine these settings through our research prior to (and following) the production release (planned in Q1). Best, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC

[sniffer] Re: GBUdb question

2008-01-22 Thread Pete McNeil
can be done now. Some may be done in the future. I look forward to seeing an example of your header. Hope this helps, Thanks, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you

[sniffer] Re: New reference settings for GBUdb ranges.

2008-01-22 Thread Pete McNeil
, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode

[sniffer] Re: New reference settings for GBUdb ranges.

2008-01-22 Thread Pete McNeil
gateways or an email address where you legitimately receive spam (such as an abuse reporting address) then you will want to tell GBUdb about those so that it doesn't get the wrong idea about them. If you have more questions then please let us know. Hope this helps, _M -- Pete McNeil Chief

[sniffer] Re: GBUdb question

2008-01-22 Thread Pete McNeil
significantly and dramatically reduce leakage without adding false positives. Hope this helps, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer

[sniffer] Re: Postfix

2008-01-16 Thread Pete McNeil
' error='ERROR_MSG_FILE'/ This I belive is because the msg file that is send to sniffer has a wrong format. - If true - how do we setup the right format for sniffer? -- Pete McNeil Chief Scientist, Arm Research Labs, LLC

[sniffer] Re: Postfix

2008-01-16 Thread Pete McNeil
' error='ERROR_MSG_FILE'/ This I belive is because the msg file that is send to sniffer has a wrong format. - If true - how do we setup the right format for sniffer? -- Pete McNeil Chief Scientist, Arm Research Labs, LLC

[sniffer] Re: Rule Database copy question

2008-01-16 Thread Pete McNeil
on the rule database to check the file before I copy it, but it would be great to know if SNFServer.exe has loaded the latest copy that I have copied to the c:\snf directory. SNFServer will indicate that the new rulebase was loaded in it's log file. Hope this helps, _M -- Pete McNeil Chief

[sniffer] Re: ERROR_SYNC_FAILED

2008-01-16 Thread Pete McNeil
base status - Our system sends back information on the latest rulebase file. * GBUdb reflections - Our system sends back GBUdb reflections (same format as above) corresponding to any alerts that your system sends us. This allows your system to learn from the cloud. _M -- Pete McNeil Chief Sc

[sniffer] Re: Sniffer Win32 command line output

2008-01-10 Thread Pete McNeil
this helps, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch

[sniffer] Re: Sniffer Win32 command line output

2008-01-10 Thread Pete McNeil
Hello Shawn, Following up a bit... Most likely you're using a Process object to call the SNFClient. If I've read the MS docs correctly you will want to get the "exit code" once SNFClient finishes. http://msdn2.microsoft.com/en-us/library/system.diagnostics.process.exitcode(VS.71).aspx

[sniffer] Re: I got a strong attack today

2008-01-04 Thread Pete McNeil
before being accepted), and graylisting which, while sometimes problematic, currently provides some pretty good protection against dumb-bot attacks. (Note that the newer bot softwares out there easily defy gray listing so it's effectiveness is dropping quickly) Hope this helps, Best, _M -- Pete

[sniffer] Re: I got a strong attack today

2008-01-04 Thread Pete McNeil
list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode, E-mail to [EMAIL PROTECTED] To switch to the INDEX mode, E-mail to [EMAIL PROTECTED] Send administrative queries to [EMAIL PROTECTED] -- Pete McNeil Chief Scientist, Arm Research Labs

[sniffer] Re: I got a strong attack today

2008-01-04 Thread Pete McNeil
keep us posted. Thanks, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED

[sniffer] Re: The new version of SNF

2007-12-28 Thread Pete McNeil
features we want to add to make it easier to administer and extend. That release will happen Q1. Thanks, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed

[sniffer] Re: re subscriptions to list

2007-11-29 Thread Pete McNeil
direction. Please help us keep this forum active, positive, and informative. Thanks, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. * One of the biggest problems with technology is that as people come up the learning curve they tend to forget what it was like when they didn't know

[sniffer] Re: FTP access to snf rulebase files is no longer available.

2007-11-23 Thread Pete McNeil
-then you upload the compressed version. Hope this helps, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com

[sniffer] Re: Was: Database Compiler Upgrades Now: When will the new version be out of beta?

2007-11-16 Thread Pete McNeil
efficient you are likely to run a different number of concurrent messages than before. This will effect how the resources on the machine are used. You might try adjusting the number of threads you allow. See previous discussions on this error for guidelines and fixes. Hope this helps, _M -- Pete

[sniffer] Re: Database Compiler Upgrades

2007-11-15 Thread Pete McNeil
Hello Robert, Thursday, November 15, 2007, 4:42:25 PM, you wrote: Timing on release to production? We are continuously improving our back-end systems. There is no specific timing for any of the many projects. The current hardware upgrade process will be completed this week. _M -- Pete

[sniffer] Database Compiler Upgrades

2007-11-15 Thread Pete McNeil
back-end systems online to take advantage of our new hardware. Thanks for your patience and support! _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing

[sniffer] Re: Was: Database Compiler Upgrades Now: When will the new version be out of beta?

2007-11-15 Thread Pete McNeil
is documentation -- that takes time, and we are working on it. Hope this helps, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer

[sniffer] Re: SNF V2-9b1.5 Released - Please Upgrade

2007-11-07 Thread Pete McNeil
is remembering about 94K IPs. Spam is about 95% of your traffic -- a little on the high side, but still nominal. From what I can see everything is running normally. _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message

[sniffer] Re: SNF V2-9b1.5 Released - Please Upgrade

2007-11-06 Thread Pete McNeil
to switch back if desired, and existing update mechanisms can remain unchanged until you are ready to make a permanent switch. Hope this helps, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you

[sniffer] Re: SNF V2-9b1.5 Released - Please Upgrade

2007-11-06 Thread Pete McNeil
-one-in='5' symbol='20'/ sample on-off='on' probability='0.8' grab-one-in='5' passthrough='no' passthrough-symbol='0'/ /black caution on-off='on' symbol='40' edge probability='0.3' confidence='0.0'/ edge probability='0.7' confidence='0.3'/ /caution Thanks, _M -- Pete McNeil

[sniffer] Re: XCI Error!: snf_EngineHandler::MaxEvals

2007-11-03 Thread Pete McNeil
that the max evals condition is directly connected to the SNF Server shutdowns. SNFServer should tell us why it shuts down when that happens and we should be able to get that info if we run it from the command line and capture it's output. Hope this helps, _M -- Pete McNeil Chief Scientist, Arm Research

[sniffer] Re: SNF V2-9b1.5 Released - Please Upgrade

2007-11-03 Thread Pete McNeil
that some sessions will fail from time to time when congestion is high, but it should not be a problem overall. The system is designed to survive outages without causing trouble. _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC

[sniffer] Re: XCI Error!: snf_EngineHandler::MaxEvals

2007-11-02 Thread Pete McNeil
.err file then I may need to look at the client code again. Hope this helps, Thanks, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer

[sniffer] Re: XCI Error!: snf_EngineHandler::MaxEvals

2007-11-02 Thread Pete McNeil
-30ms range consistently. Hope this helps, Thanks, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E

[sniffer] Re: Beta

2007-10-17 Thread Pete McNeil
status data then please share it with the SNF community. In the mean time - we have done extensive testing and monitoring throughout the development process. High availability is (has always been) a design requirement and we're confident SNF can deliver that. Hope this helps, _M -- Pete McNeil Chief

[sniffer] Re: Beta

2007-10-16 Thread Pete McNeil
not account for any appreciable bandwidth. Similarly, the GBUdb protocol is designed to share information sparsely so that no appreciable bandwidth or CPU capacity is required. Please let me know if I missed the mark on your questions. Hope this helps, _M -- Pete McNeil Chief Scientist, Arm Research

[sniffer] Bad Rule: 1604021

2007-10-15 Thread Pete McNeil
in timing are inevitable since all rulebases are compiled individually. If you have the ability to release and rescan from quarantine based on SNF rule IDs then we recommend executing that process against this rule id: 1604021. Hope this helps, Thanks, _M -- Pete McNeil Chief Scientist, Arm Research

[sniffer] Re: Beta

2007-10-15 Thread Pete McNeil
messages start going through and you should quickly get an idea of what looks correct. Once you're confident in that setup then you can run the SNFServer using srvany or firedaemon or your other favorite utility that runs programs as a service. Hope this helps, _M -- Pete McNeil Chief Scientist, Arm

<    1   2   3   4   5   6   7   8   9   10   >