<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-8710533.post7249226991183444865..comments</id><updated>2009-08-05T06:32:39.177-06:00</updated><title type='text'>Comments on Eric Conrad: Xfiltr8 Extrusion Detection Live CD</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.ericconrad.com/feeds/7249226991183444865/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8710533/7249226991183444865/comments/default'/><link rel='alternate' type='text/html' href='http://www.ericconrad.com/2009/08/xfiltr8-extrusion-detection-live-cd.html'/><author><name>Eric Conrad</name><uri>http://www.blogger.com/profile/04946059331360224891</uri><email>blogger12@ericconrad.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8710533.post-4118651504354153579</id><published>2009-08-05T06:32:39.177-06:00</published><updated>2009-08-05T06:32:39.177-06:00</updated><title type='text'>Hi Eric,

Xfiltr8 looks interesting!  A few questi...</title><content type='html'>Hi Eric,&lt;br /&gt;&lt;br /&gt;Xfiltr8 looks interesting!  A few questions:&lt;br /&gt;&lt;br /&gt;Is there a README somewhere that I&amp;#39;m missing?  &lt;br /&gt;&lt;br /&gt;I see that the LiveCD has Snort, BASE, and some Emerging Threats rules.  Have you considered using Sguil instead of BASE?  The NSMnow installer (http://www.securixlive.com/nsmnow/) can install Sguil and all its dependencies quickly and easily.  It also downloads and compiles the latest version of Snort automatically.  I&amp;#39;m using NSMnow in my Security Onion LiveCD.&lt;br /&gt;&lt;br /&gt;I see some Perl scripts in /usr/local/bin/ that appear to be for Squid reporting, but I can&amp;#39;t seem to find the Squid service itself.  What am I missing?&lt;br /&gt;&lt;br /&gt;Keep up the good work!&lt;br /&gt;&lt;br /&gt;Thanks,&lt;br /&gt;Doug Burks&lt;br /&gt;http://securityonion.blogspot.com/&lt;br /&gt;http://twitter.com/dougburks</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8710533/7249226991183444865/comments/default/4118651504354153579'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8710533/7249226991183444865/comments/default/4118651504354153579'/><link rel='alternate' type='text/html' href='http://www.ericconrad.com/2009/08/xfiltr8-extrusion-detection-live-cd.html?showComment=1249475559177#c4118651504354153579' title=''/><author><name>Doug Burks</name><uri>http://www.blogger.com/profile/13264220999894786719</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.ericconrad.com/2009/08/xfiltr8-extrusion-detection-live-cd.html' ref='tag:blogger.com,1999:blog-8710533.post-7249226991183444865' source='http://www.blogger.com/feeds/8710533/posts/default/7249226991183444865' type='text/html'/></entry></feed>