nsmjunkie.blogspot.com
NSM Junkie: Hello World
http://nsmjunkie.blogspot.com/2008/05/hello-world.html
Always changing, hopefully growing. Friday, May 9, 2008. Welcome to the NSM Junkie blog, network security monitoring and other security topics as seen by cnk. Subscribe to: Post Comments (Atom). OSSEC v1.5 Released. Its about time . . . mass sql injection variant. View my complete profile.
nsmjunkie.blogspot.com
NSM Junkie: June 2010
http://nsmjunkie.blogspot.com/2010_06_01_archive.html
Always changing, hopefully growing. Thursday, June 24, 2010. Ongoing Mass SQLi attempts. I'm continuing to see ongoing SQLi attempts using the same injection technique we saw a couple of weeks ago. As one would expect the third-party site hosting the malicious JavaScript keeps changing. Below is a list of both the source IP addresses of the attempted SQLi attack as well as the script URL they're trying to inject:. Last Updated 24-Jun-2010 12:45 EDT*. Source IP addresses of SQLi attacks:. 2010-06-07 13:31...
nsmjunkie.blogspot.com
NSM Junkie: Sguil client error with Ubuntu 10.04
http://nsmjunkie.blogspot.com/2010/05/sguil-client-error-with-ubuntu-1004.html
Always changing, hopefully growing. Tuesday, May 11, 2010. Sguil client error with Ubuntu 10.04. After running Ubuntu 10.04 at home for a couple of weeks I decided to go ahead and upgrade my work system. Everything went smooth until I went to launch the Sguil client. ERROR: Cannot fine the Iwidgets extension. The iwidgets package is part of the incr tcl extension and is. Available as a port/package most systems. See http:/ www.tcltk.com/iwidgets/ for more info. Itcl3 3.4 b1-2. After this operation, 10...
nsmjunkie.blogspot.com
NSM Junkie: Google Apps authentication and Splunk SSO
http://nsmjunkie.blogspot.com/2011/08/google-apps-authentication-and-splunk.html
Always changing, hopefully growing. Friday, August 26, 2011. Google Apps authentication and Splunk SSO. It's no secret, I 3 splunk. But I'm not here to tell you why you NEED splunk (just take my word for it). I'm here to let you know about splunk-auth-proxy. Splunk-auth-proxy is a simple node.js. Web app written in coffeescript. Which allows you to use Google Apps OpenID authentication to authenticate splunk access. It was written primarily by my co-worker Jonathan Rudenberg. With a little help from me.
nsmjunkie.blogspot.com
NSM Junkie: It's about time . . . mass sql injection variant
http://nsmjunkie.blogspot.com/2008/05/its-about-time-mass-sql-injection.html
Always changing, hopefully growing. Friday, May 9, 2008. It's about time . . . mass sql injection variant. It's been around 2 months since the ISC. And the Microsoft CSS security team. 1 First of all there was never an initial attempt to determine if the ASP page was vulnerable. The documented attack contained a simple injection check like this:. So why no injection check? Why not just attempt payload delivery and move on. 2 The only difference in the payload attempt was a new script tag:. I tried wgetti...
nsmjunkie.blogspot.com
NSM Junkie: OSSEC v1.5 Released
http://nsmjunkie.blogspot.com/2008/05/ossec-v15-released.html
Always changing, hopefully growing. Friday, May 9, 2008. OSSEC v1.5 Released. Yeah I know this is old news by now but I just wanted to congratulate dcid on the latest OSSEC release! Http:/ www.ossec.net/main/ossec-v15-released. I'm really excited about the new centralized agent control functionality. With this feature centralized configuration management shouldn't be far off. If you aren't running OSSEC yet you should definitely check it out! Subscribe to: Post Comments (Atom). OSSEC v1.5 Released.
nsmjunkie.blogspot.com
NSM Junkie: February 2009
http://nsmjunkie.blogspot.com/2009_02_01_archive.html
Always changing, hopefully growing. Monday, February 2, 2009. Here's how I configured OSSEC to send alerts to Splunk:. In ossec.conf add a syslog output block specifying your Splunk system IP address and the port your network input is listening on:. Server 172.10.2.3 /server. Now you need to enable the syslog output module and restart OSSEC:. On restart you'll see ossec-csyslogd starting up. Now for the Splunk side. The easiest method is by adding this stanza to inputs.conf:. Subscribe to: Posts (Atom).
nsmjunkie.blogspot.com
NSM Junkie: August 2011
http://nsmjunkie.blogspot.com/2011_08_01_archive.html
Always changing, hopefully growing. Friday, August 26, 2011. Google Apps authentication and Splunk SSO. It's no secret, I 3 splunk. But I'm not here to tell you why you NEED splunk (just take my word for it). I'm here to let you know about splunk-auth-proxy. Splunk-auth-proxy is a simple node.js. Web app written in coffeescript. Which allows you to use Google Apps OpenID authentication to authenticate splunk access. It was written primarily by my co-worker Jonathan Rudenberg. With a little help from me.