<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The Tao of Signature Writing – Part 4</title>
	<atom:link href="http://sign.kaffenews.com/?feed=rss2&#038;p=71" rel="self" type="application/rss+xml" />
	<link>http://sign.kaffenews.com/?p=71</link>
	<description>Blogging the Science of Signature Analysis</description>
	<lastBuildDate>Mon, 05 Apr 2010 20:03:06 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Signature Analytics » Blog Archive » The Tao of Signature Writing &#8230; &#124; InfoSec Resources</title>
		<link>http://sign.kaffenews.com/?p=71&#038;cpage=1#comment-126</link>
		<dc:creator>Signature Analytics » Blog Archive » The Tao of Signature Writing &#8230; &#124; InfoSec Resources</dc:creator>
		<pubDate>Mon, 05 Apr 2010 20:03:06 +0000</pubDate>
		<guid isPermaLink="false">http://sign.kaffenews.com/?p=71#comment-126</guid>
		<description>[...] more from the original source: Signature Analytics » Blog Archive » The Tao of Signature Writing &#8230; AKPC_IDS += &quot;563,&quot;;Popularity: unranked [...]</description>
		<content:encoded><![CDATA[<p>[...] more from the original source: Signature Analytics » Blog Archive » The Tao of Signature Writing &#8230; AKPC_IDS += &quot;563,&quot;;Popularity: unranked [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fimz</title>
		<link>http://sign.kaffenews.com/?p=71&#038;cpage=1#comment-124</link>
		<dc:creator>fimz</dc:creator>
		<pubDate>Sat, 27 Mar 2010 01:24:17 +0000</pubDate>
		<guid isPermaLink="false">http://sign.kaffenews.com/?p=71#comment-124</guid>
		<description>Hi, 

Great article. This has however raised a question in my mind, rather confusion.

Ive seen the terms snort rules and snort signatures being used interchangeably across many texts. I would really like to know which is which. e.g.
which heading would the rule below come under:

Snort Rule example or Snort Signature Example:

alert udp $EXTERNAL_NET any -&gt; $HOME_NET 1434 (msg:&quot;MS-SQL Worm propagation attempt&quot;; content:&quot;&#124;04&#124;&quot;; depth:1; content:&quot;&#124;81 F1 03 01 04 9B 81 F1 0 1&#124;&quot;; content:&quot;sock&quot;; content:&quot;send&quot;; reference:bugtraq,5310; classtype:misc-attack; reference:bugtraq,5311; sid:2003; rev:2;)

Comments, help, pointers appreciated? Im sure there are others who have came across the same controversy.

Thanks, fimz</description>
		<content:encoded><![CDATA[<p>Hi, </p>
<p>Great article. This has however raised a question in my mind, rather confusion.</p>
<p>Ive seen the terms snort rules and snort signatures being used interchangeably across many texts. I would really like to know which is which. e.g.<br />
which heading would the rule below come under:</p>
<p>Snort Rule example or Snort Signature Example:</p>
<p>alert udp $EXTERNAL_NET any -&gt; $HOME_NET 1434 (msg:&#8221;MS-SQL Worm propagation attempt&#8221;; content:&#8221;|04|&#8221;; depth:1; content:&#8221;|81 F1 03 01 04 9B 81 F1 0 1|&#8221;; content:&#8221;sock&#8221;; content:&#8221;send&#8221;; reference:bugtraq,5310; classtype:misc-attack; reference:bugtraq,5311; sid:2003; rev:2;)</p>
<p>Comments, help, pointers appreciated? Im sure there are others who have came across the same controversy.</p>
<p>Thanks, fimz</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Signature Analyst</title>
		<link>http://sign.kaffenews.com/?p=71&#038;cpage=1#comment-8</link>
		<dc:creator>Signature Analyst</dc:creator>
		<pubDate>Tue, 23 Feb 2010 00:49:35 +0000</pubDate>
		<guid isPermaLink="false">http://sign.kaffenews.com/?p=71#comment-8</guid>
		<description>It is great review &amp; response to be honest. I have never gotten such a granular response. Definitely something to learn from... Thank you Joel.</description>
		<content:encoded><![CDATA[<p>It is great review &#038; response to be honest. I have never gotten such a granular response. Definitely something to learn from&#8230; Thank you Joel.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joel Esler</title>
		<link>http://sign.kaffenews.com/?p=71&#038;cpage=1#comment-7</link>
		<dc:creator>Joel Esler</dc:creator>
		<pubDate>Tue, 23 Feb 2010 00:42:14 +0000</pubDate>
		<guid isPermaLink="false">http://sign.kaffenews.com/?p=71#comment-7</guid>
		<description>http://blog.joelesler.net/2010/02/writing-snort-rules-is-harder-than-it-looks.html

Just some constructive feedback.  I&#039;m not trying to offend.</description>
		<content:encoded><![CDATA[<p><a href="http://blog.joelesler.net/2010/02/writing-snort-rules-is-harder-than-it-looks.html" rel="nofollow">http://blog.joelesler.net/2010/02/writing-snort-rules-is-harder-than-it-looks.html</a></p>
<p>Just some constructive feedback.  I&#8217;m not trying to offend.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Writing Snort Rules is harder than it looks &#124; Finshake</title>
		<link>http://sign.kaffenews.com/?p=71&#038;cpage=1#comment-6</link>
		<dc:creator>Writing Snort Rules is harder than it looks &#124; Finshake</dc:creator>
		<pubDate>Tue, 23 Feb 2010 00:41:53 +0000</pubDate>
		<guid isPermaLink="false">http://sign.kaffenews.com/?p=71#comment-6</guid>
		<description>[...] noticed this post today over at the &#8220;Tao of Signature Writing&#8221; blog, and to be honest I glanced over most [...]</description>
		<content:encoded><![CDATA[<p>[...] noticed this post today over at the &#8220;Tao of Signature Writing&#8221; blog, and to be honest I glanced over most [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
