<?xml version="1.0"?>
<rss version="2.0"><channel><title>Manually Installing an Apache2 Web Server logging events to a MySQL Database Latest Topics</title><link>http://www.winsnort.com/forum/15-manually-installing-an-apache2-web-server-logging-events-to-a-mysql-database/</link><description>Manually Installing an Apache2 Web Server logging events to a MySQL Database Latest Topics</description><language>en</language><item><title>500 Internel server error trying to open http://winids</title><link>http://www.winsnort.com/topic/316-500-internel-server-error-trying-to-open-httpwinids/</link><description><![CDATA[
<p>
	Thanks in advance
</p>

<p>
	referenced <a href="http://www.winsnort.com/topic/301-500-internal-server-error-when-trying-to-open-testphp/?do=findComment&amp;comment=1265" rel="" style="color:#3c6994;">500 Internal Server Error when trying to open ''test.php''</a> with no luck 
</p>

<p>
	OS: Win 10 (Not Activated) Intel core Duo 4Gb RAM
</p>

<p>
	Using WinIDS Apache 2 with MySQL tutorial 
</p>

<p>
	Used MBSA before winIDS process and after did not notice a change in report
</p>

<p>
	Per registry net frame work is up to date 
</p>

<p>
	I was able to see the test.php page and all other test completed per tutorial
</p>

<p>
	Barnyard2 shows a flow of packets 
</p>

<p>
	Attaching php.ini and httpd.conf 
</p>

<p>
	This is the first time installing all these tools any help is appreciated. 
</p>

<p>
	By the way these tutorials are awesome. 
</p>

<p>
	<a class="ipsAttachLink ipsAttachLink_image" href="http://www.winsnort.com/uploads/monthly_2019_12/5defcf9ef3c9e_500error.JPG.7cd956f7053439ba2d62d501b62f70b5.JPG" data-fileid="244" rel=""><img alt="500 error.JPG" class="ipsImage ipsImage_thumbnailed" data-fileid="244" src="http://www.winsnort.com/uploads/monthly_2019_12/5defcf9ef3c9e_500error.JPG.7cd956f7053439ba2d62d501b62f70b5.JPG" /></a>
</p>

<p>
	<a class="ipsAttachLink ipsAttachLink_image" href="http://www.winsnort.com/uploads/monthly_2019_12/installed-programs.JPG.8d2112fd5d0b075d069a96c6c9baeb58.JPG" data-fileid="245" rel=""><img alt="installed-programs.JPG" class="ipsImage ipsImage_thumbnailed" data-fileid="245" src="http://www.winsnort.com/uploads/monthly_2019_12/installed-programs.JPG.8d2112fd5d0b075d069a96c6c9baeb58.JPG" /></a>
</p>

<p>
	<a class="ipsAttachLink ipsAttachLink_image" href="http://www.winsnort.com/uploads/monthly_2019_12/netframework.JPG.7ca5221ac45c8221a425431585564460.JPG" data-fileid="246" rel=""><img alt="netframework.JPG" class="ipsImage ipsImage_thumbnailed" data-fileid="246" src="http://www.winsnort.com/uploads/monthly_2019_12/netframework.JPG.7ca5221ac45c8221a425431585564460.JPG" /></a>
</p>

<p>
	<a class="ipsAttachLink ipsAttachLink_image" href="http://www.winsnort.com/uploads/monthly_2019_12/5defcfa241d4d_pingwinIDSworks.JPG.9b5a6854a41ceac8499ff5399b760b13.JPG" data-fileid="247" rel=""><img alt="ping winIDS works.JPG" class="ipsImage ipsImage_thumbnailed" data-fileid="247" src="http://www.winsnort.com/uploads/monthly_2019_12/5defcfa241d4d_pingwinIDSworks.JPG.9b5a6854a41ceac8499ff5399b760b13.JPG" /></a>
</p>

<p>
	<a class="ipsAttachLink ipsAttachLink_image" href="http://www.winsnort.com/uploads/monthly_2019_12/testpage-works.JPG.d8baf82166479642e1414a2f8e0bec22.JPG" data-fileid="248" rel=""><img alt="testpage-works.JPG" class="ipsImage ipsImage_thumbnailed" data-fileid="248" src="http://www.winsnort.com/uploads/monthly_2019_12/testpage-works.JPG.d8baf82166479642e1414a2f8e0bec22.JPG" /></a>
</p>

<p>
	<a class="ipsAttachLink" href="http://www.winsnort.com/applications/core/interface/file/attachment.php?id=249" data-fileid="249" rel="">php.ini</a>
</p>

<p>
	<a class="ipsAttachLink" href="http://www.winsnort.com/applications/core/interface/file/attachment.php?id=250" data-fileid="250" rel="">httpd.conf</a>
</p>

<p><a href="http://www.winsnort.com/uploads/monthly_2019_12/apacheStatus.JPG.ce9e49d0fa3e4663d5227e7b07cd2ff4.JPG" class="ipsAttachLink ipsAttachLink_image"><img data-fileid="252" src="http://www.winsnort.com/uploads/monthly_2019_12/apacheStatus.JPG.ce9e49d0fa3e4663d5227e7b07cd2ff4.JPG" class="ipsImage ipsImage_thumbnailed" alt="apacheStatus.JPG"></a></p>]]></description><guid isPermaLink="false">316</guid><pubDate>Tue, 10 Dec 2019 17:09:06 +0000</pubDate></item><item><title>Error Alert could not be found in acid_event.</title><link>http://www.winsnort.com/topic/309-error-alert-could-not-be-found-in-acid_event/</link><description><![CDATA[
<p>
	sorry to bother you all, i trying to check arp spoofing on my winids system so i'm active the prepocrule used to detect arp spoofing. the rule look like this :
</p>

<p>
	alert ( msg: "ARPSPOOF_ARP_CACHE_OVERWRITE_ATTACK"; sid: 4; gid: 112; rev: 1; metadata: rule-type preproc ; classtype:bad-unknown; )
</p>

<p>
	 
</p>

<p>
	and it work it shown and give alert on barnyard2 &amp; visual syslog server it give alert like this :
</p>

<p>
	05/16-13:31:06.553294  [**] [112:4:1] spp_arpspoof: ARP Cache Overwrite Attack [**]
</p>

<p>
	 
</p>

<p>
	but the alert can't show on BASE it give error on BASE, the error look like this :
</p>

<p>
	"D:\winids\Apache24\htdocs\base\includes\base_cache.inc.php:776: ERROR: <br />
	3 alerts have NOT found their way into acid_event with sid = 4"<br />
	"D:\winids\Apache24\htdocs\base\includes\base_cache.inc.php:521: ERROR: Alert "4 - 9618" could NOT be found in acid_event"
</p>

<p>
	 
</p>

<p>
	what should i do to fix the error and make the alert can shown on BASE? 
</p>

<p>
	thank you so much
</p>

<p>
	- Fahmi
</p>
]]></description><guid isPermaLink="false">309</guid><pubDate>Thu, 16 May 2019 06:38:03 +0000</pubDate></item><item><title>Winids security console don't show any alert for icmp and udp protocols</title><link>http://www.winsnort.com/topic/308-winids-security-console-dont-show-any-alert-for-icmp-and-udp-protocols/</link><description><![CDATA[
<p>
	<span style="color:#272a34;">Hello everyone, sorry to bother you.I'm following the tutorial "Installing an Apache2 Web Server logging events to a MySQL Database" by Morpheus to my computer using windows 10 and it work, i can access the 'http://winids' on my browser. But i'm realize that my winids console dont show any alert for icmp and udp packet, so what i need to do to make the winids security console can work with icmp and udp packet. thank you so much.</span>
</p>

<p>
	 
</p>

<p><a href="http://www.winsnort.com/uploads/monthly_2019_05/5cd51e1fe186a_icmpudpraiso.PNG.cd244bc6ef1d1919ba0a718cbd5296e9.PNG" class="ipsAttachLink ipsAttachLink_image"><img data-fileid="227" src="http://www.winsnort.com/uploads/monthly_2019_05/5cd51e24a0175_icmpudpraiso.thumb.PNG.6b56f9e5dc23afaea5031fc315f2c1bf.PNG" class="ipsImage ipsImage_thumbnailed" alt="icmp udp ra iso.PNG"></a></p>]]></description><guid isPermaLink="false">308</guid><pubDate>Fri, 10 May 2019 06:46:08 +0000</pubDate></item><item><title>winids's server IP address can not be found when starting security console</title><link>http://www.winsnort.com/topic/304-winidss-server-ip-address-can-not-be-found-when-starting-security-console/</link><description><![CDATA[
<p>
	Hello everyone, sorry to bother you. Yesterday i'm following the tutorial  "I<span style="color:#272a34;">nstalling an Apache2 Web Server logging events to a MySQL Database" by Morpheus to my computer using windows 10 and it work, i can access the </span><span style="color:#525252;">'http://winids' on my browser. But today i cant access it. </span>
</p>

<p>
	<img alt="5c84a205e872e_gaisokbukawinids.PNG.6c8dbf2a15a62c032d492328563ace32.PNG" class="ipsImage ipsImage_thumbnailed" data-fileid="211" src="http://www.winsnort.com/uploads/monthly_2019_03/5c84a205e872e_gaisokbukawinids.PNG.6c8dbf2a15a62c032d492328563ace32.PNG" /></p>

<p>
	 
</p>

<p>
	<span style="color:#212121;">I can't even start Apache2.4 and error messages like this always appear.</span>
</p>

<p>
	<img alt="5c84a33b95eeb_erormsgapache.PNG.fcfa6d91070b0f3b59ea2223565ef2a6.PNG" class="ipsImage ipsImage_thumbnailed" data-fileid="212" src="http://www.winsnort.com/uploads/monthly_2019_03/5c84a33b95eeb_erormsgapache.PNG.fcfa6d91070b0f3b59ea2223565ef2a6.PNG" /></p>

<p>
	and when i test the barnyard config file, it show that "unknown mysql server host 'winids'.<img class="ipsImage ipsImage_thumbnailed" data-fileid="213" src="http://www.winsnort.com/uploads/monthly_2019_03/5c84bd21db42d_winidshosteror.PNG.a1ebd808ee585f182d6a80258d707501.PNG" alt="5c84bd21db42d_winidshosteror.PNG.a1ebd808ee585f182d6a80258d707501.PNG" /></p>

<p>
	what should i need to do so i can access the http://winids again?
</p>

<p>
	thank you so much and sorry to bother you all.
</p>
]]></description><guid isPermaLink="false">304</guid><pubDate>Sun, 10 Mar 2019 05:41:46 +0000</pubDate></item><item><title>Cannot Configuring Graphing for WinIDS security console</title><link>http://www.winsnort.com/topic/303-cannot-configuring-graphing-for-winids-security-console/</link><description><![CDATA[
<p>
	Hi everyone, 
</p>

<p>
	im novice about windows ids, and i need it to complete my bachelor thesis. so i have follow every single part of the tutorial "Installing an Apache2 Web Server logging events to a MySQL Database" by Morpheus to my computer using windows 10. But when i get to the part "Configuring Graphing for the Windows Intrusion Detection Systems (WinIDS) Security Console"  i cannot find the file graphing.zip . Where i can downloaded it, because i dont find it on tutorial? 
</p>

<p>
	what should i do to resolve the problem?
</p>

<p>
	Sorry to bother you, Thank you everyone and have a nice day.
</p>
]]></description><guid isPermaLink="false">303</guid><pubDate>Wed, 06 Mar 2019 08:44:28 +0000</pubDate></item><item><title>500 Internal Server Error when trying to open ''test.php''</title><link>http://www.winsnort.com/topic/301-500-internal-server-error-when-trying-to-open-testphp/</link><description><![CDATA[
<p>
	Hi everyone, 
</p>

<p>
	im really novice about windows ids, so i have follow every single part of the tutorial "Installing an Apache2 Web Server logging events to a MySQL Database" by Morpheus. but when i get to the part Testing Apache2, and the PHP installation, i got the 500 internal server error when trying to open 'http://winids/test.php' on my web browser. 
</p>

<p>
	 
</p>

<p>
	what should i do to resolve the problem?
</p>

<p>
	Thank you everyone and have a nice day.
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">301</guid><pubDate>Wed, 27 Feb 2019 09:39:01 +0000</pubDate></item><item><title>What is switch x for Adding Snort to Windows Servis Database</title><link>http://www.winsnort.com/topic/302-what-is-switch-x-for-adding-snort-to-windows-servis-database/</link><description><![CDATA[
<p>
	Sorry to bother you again. i have another problem with this part.
</p>

<p>
	 
</p>

<p>
	<a class="ipsAttachLink ipsAttachLink_image" data-fileid="205" href="http://www.winsnort.com/uploads/monthly_2019_02/5c77d38f8cc13_snortservice.PNG.443d8c33828b1f74a265ae8c085a8206.PNG" rel=""><img alt="5c77d3922a53f_snortservice.thumb.PNG.feacb97b2e48baea97dd6c3d3efcc419.PNG" class="ipsImage ipsImage_thumbnailed" data-fileid="205" src="http://www.winsnort.com/uploads/monthly_2019_02/5c77d3922a53f_snortservice.thumb.PNG.feacb97b2e48baea97dd6c3d3efcc419.PNG"></a>
</p>

<p>
	i don't know what number to replace the 'x'. is there a way to know I have to replace 'x' with what index number. Thank you very much.
</p>
]]></description><guid isPermaLink="false">302</guid><pubDate>Thu, 28 Feb 2019 12:15:43 +0000</pubDate></item><item><title>Base Configuration Error</title><link>http://www.winsnort.com/topic/286-base-configuration-error/</link><description><![CDATA[
<p>
	<span style="font-size:14px;">Why I got this error during BASE installation? Do I have something that I miss or wrong configuration?? anyone know any solution pls let me know</span>
</p>

<p>
	 
</p>

<p>
	<b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of MultipleElementCriteria::SanitizeElement() should be compatible with BaseCriteria::SanitizeElement() in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">292</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of MultipleElementCriteria::PrintForm() should be compatible with BaseCriteria::PrintForm() in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;">on line<span> </span></span><b style="color:#000000;">292</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of MultipleElementCriteria::AddFormItem() should be compatible with BaseCriteria::AddFormItem() in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">292</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of MultipleElementCriteria::SetFormItemCnt() should be compatible with BaseCriteria::SetFormItemCnt() in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">292</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of ProtocolFieldCriteria::Description() should be compatible with BaseCriteria::Description() in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">337</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of TimeCriteria::PrintForm() should be compatible with MultipleElementCriteria::PrintForm($field_list, $blank_field_string, $add_button_string) in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">932</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of IPAddressCriteria::SanitizeElement() should be compatible with MultipleElementCriteria::SanitizeElement($i) in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">1109</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of IPAddressCriteria::PrintForm() should be compatible with MultipleElementCriteria::PrintForm($field_list, $blank_field_string, $add_button_string) in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">1109</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of IPFieldCriteria::Description() should be compatible with ProtocolFieldCriteria::Description($human_fields) in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">1152</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of IPFieldCriteria::PrintForm() should be compatible with MultipleElementCriteria::PrintForm($field_list, $blank_field_string, $add_button_string) in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">1152</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of TCPPortCriteria::Description() should be compatible with ProtocolFieldCriteria::Description($human_fields) in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">1190</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of TCPPortCriteria::PrintForm() should be compatible with MultipleElementCriteria::PrintForm($field_list, $blank_field_string, $add_button_string) in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">1190</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of TCPFieldCriteria::Description() should be compatible with ProtocolFieldCriteria::Description($human_fields) in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">1234</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of TCPFieldCriteria::PrintForm() should be compatible with MultipleElementCriteria::PrintForm($field_list, $blank_field_string, $add_button_string) in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">1234</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of UDPPortCriteria::Description() should be compatible with ProtocolFieldCriteria::Description($human_fields) in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">1361</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of UDPPortCriteria::PrintForm() should be compatible with MultipleElementCriteria::PrintForm($field_list, $blank_field_string, $add_button_string) in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">1361</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of UDPFieldCriteria::Description() should be compatible with ProtocolFieldCriteria::Description($human_fields) in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">1398</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of UDPFieldCriteria::PrintForm() should be compatible with MultipleElementCriteria::PrintForm($field_list, $blank_field_string, $add_button_string) in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">1398</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of ICMPFieldCriteria::Description() should be compatible with ProtocolFieldCriteria::Description($human_fields) in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">1438</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of ICMPFieldCriteria::PrintForm() should be compatible with MultipleElementCriteria::PrintForm($field_list, $blank_field_string, $add_button_string) in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">1438</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Strict Standards</b><span style="color:#000000;">: Declaration of DataCriteria::PrintForm() should be compatible with MultipleElementCriteria::PrintForm($field_list, $blank_field_string, $add_button_string) in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">1634</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Warning</b><span style="color:#000000;">: Cannot modify header information - headers already sent by (output started at C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php:1361) in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_auth.inc.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">331</b><br style="color:#000000;" /><br style="color:#000000;" /><b style="color:#000000;">Warning</b><span style="color:#000000;">: Cannot modify header information - headers already sent by (output started at C:\xampp\htdocs\SnortV2\base-1.4.5\includes\base_state_citems.inc.php:1361) in<span> </span></span><b style="color:#000000;">C:\xampp\htdocs\SnortV2\base-1.4.5\index.php</b><span style="color:#000000;"><span> </span>on line<span> </span></span><b style="color:#000000;">53</b>
</p>
]]></description><guid isPermaLink="false">286</guid><pubDate>Sun, 04 Mar 2018 07:55:49 +0000</pubDate></item><item><title>Mysql archive database table error</title><link>http://www.winsnort.com/topic/278-mysql-archive-database-table-error/</link><description><![CDATA[
<p>
	Everything seems to work I have the system up but when I go to the <a href="http://winids/" rel="external nofollow">http://winids/</a> url, the page loads but I receive the error
</p>

<p>
	"Database ERROR"Database ERROR: Table'archive.acid_event' doesn't exist.
</p>

<p>
	I connect with sql developer to verify and it indeed doesn't.  Do I need to run the MySQL_ configuration again for the archive database?  or can I manually add the tables and row column data?  can someone provide the steps to do that?
</p>

<p>
	 thanks so much.. really looking forward to using this system I have been severely compromised on my home network and This is the final piece to hardening my home network.
</p>

<p>
	 
</p>

<p><a href="http://www.winsnort.com/uploads/monthly_2017_10/59d7bee941d41_winsnorterror.JPG.8ed4ee6f60a9d90b383ef76d27b8bc8f.JPG" class="ipsAttachLink ipsAttachLink_image"><img data-fileid="175" src="http://www.winsnort.com/uploads/monthly_2017_10/59d7bee941d41_winsnorterror.JPG.8ed4ee6f60a9d90b383ef76d27b8bc8f.JPG" class="ipsImage ipsImage_thumbnailed" alt="winsnort error.JPG"></a></p>]]></description><guid isPermaLink="false">278</guid><pubDate>Fri, 06 Oct 2017 17:35:40 +0000</pubDate></item><item><title>Snort and ids Comparism</title><link>http://www.winsnort.com/topic/275-snort-and-ids-comparism/</link><description><![CDATA[<p>
	I'm supposed to compare SNORT, Suricata, OSSIM, and OpenVAS, based on the strategy for intrusion detection. Can you help?
</p>]]></description><guid isPermaLink="false">275</guid><pubDate>Sun, 30 Jul 2017 15:58:02 +0000</pubDate></item><item><title>Snort for Windows</title><link>http://www.winsnort.com/topic/271-snort-for-windows/</link><description><![CDATA[
<p>
	I want to install snort for my windows 10.
</p>

<p>
	snort +base +barnyard2 +apache2.4+php 
</p>

<p>
	After i install barnyard.  i test it . then  i got this
</p>

<p>
	database mysql_error: Can't connect to local MySQL server through socket '/var/run/mysql.sock' (2 "No such file or directory")
</p>

<p>
	this error is not for windows. it is in linux  is it?
</p>

<p>
	now i do not know how to deal with it.
</p>

<p>
	hope someone can help me
</p>
]]></description><guid isPermaLink="false">271</guid><pubDate>Fri, 05 May 2017 06:36:37 +0000</pubDate></item><item><title>403 error when connectiing to security console</title><link>http://www.winsnort.com/topic/267-403-error-when-connectiing-to-security-console/</link><description><![CDATA[
<p>
	I completed every installation procedure successfully. However, when I try to connect to "http://winids" , I get a 403 error: The web page declined to show this webpage.
</p>

<p>
	Is there a permission error that I need to correct? Or what setting did I fail to modify correctly.
</p>

<p>
	Thanks,
</p>

<p>
	Greg
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">267</guid><pubDate>Tue, 25 Apr 2017 09:57:32 +0000</pubDate></item><item><title>Barnyard2 only showing local traffic and broadcasts.</title><link>http://www.winsnort.com/topic/230-barnyard2-only-showing-local-traffic-and-broadcasts/</link><description><![CDATA[
<p>
	WinIs is now up and working fine. No system errors or problems.
</p>

<p>
	Nice system!
</p>

<p>
	But it seems that i don't see any packet from other computers.
</p>

<p>
	What can be wrong?
</p>

<p>
	I see traffic to/ from the WinIds PC and some broadcasts but nothing else.
</p>

<p>
	The WInPCap is supposed to handle this. Is there any further config that needs to be done?
</p>

<p>
	I have 2 PCs connected to a small switch, wich in turn is connected to the corp network.
</p>

<p>
	I can see no traffic to the other PC.
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">230</guid><pubDate>Fri, 19 Aug 2016 08:36:42 +0000</pubDate></item><item><title>Api-ms-win-crt-runtime-I1-1-0.dll is missing</title><link>http://www.winsnort.com/topic/229-api-ms-win-crt-runtime-i1-1-0dll-is-missing/</link><description><![CDATA[
<p>
	I have Reach this point in the tutorial and everything has tested fine so far.
</p>

<p>
	<em>Adding Apache2 to the Windows Services Database</em>
</p>

<p>
	When running command: d:\winids\apache24\bin\httpd.exe -k install
</p>

<p>
	I get the: api-ms-win-crt-runtime-I1-1-0.dll is missing on the computer..... error.
</p>

<p>
	Command stops executing.
</p>

<p>
	 
</p>

<p>
	I read another post With similar problems.
</p>

<p>
	Uninstalled vcredist-2015_x64.exe and reinstalled.
</p>

<p>
	Ran the modder.vbs script. (It does not take several minutes. Less than one I Guess.)
</p>

<p>
	When reinnstalling vcredist-2015_x64.exe the above mentioned error shows up at the end.
</p>

<p>
	Here is an except from the install log.
</p>

<p>
	 
</p>

<p>
	[13C8:13CC][2016-08-12T13:29:40]i325: Registering dependency: {3ee5e5bb-b7cc-4556-8861-a00a82977d6c} on package provider: Microsoft.VS.VC_RuntimeAdditionalVSU_amd64,v14, package: vcRuntimeAdditional_x64<br />
	[13C8:13CC][2016-08-12T13:29:40]i301: Applying execute package: Windows81_x64, action: Install, path: C:\ProgramData\Package Cache\3ACBF3890FC9C8A6F3D2155ECF106028E5F55164\packages\Patch\x64\Windows8.1-KB2999226-x64.msu, arguments: '"C:\Windows\SysNative\wusa.exe" "C:\ProgramData\Package Cache\3ACBF3890FC9C8A6F3D2155ECF106028E5F55164\packages\Patch\x64\Windows8.1-KB2999226-x64.msu" /quiet /norestart'<br />
	[13C8:13CC][2016-08-12T13:29:40]e000: Error 0x80240017: Failed to execute MSU package.<br />
	[13E0:13E4][2016-08-12T13:29:40]e000: Error 0x80240017: Failed to configure per-machine MSU package.<br />
	[13E0:13E4][2016-08-12T13:29:40]i319: Applied execute package: Windows81_x64, result: 0x80240017, restart: None<br />
	[13E0:13E4][2016-08-12T13:29:40]e000: Error 0x80240017: Failed to execute MSU package.<br />
	[13C8:13CC][2016-08-12T13:29:40]i372: Session end, registration key: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}, resume: ARP, restart: None, disable resume: No<br />
	[13C8:13CC][2016-08-12T13:29:40]i371: Updating session, registration key: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}, resume: ARP, restart initiated: No, disable resume: No<br />
	[13E0:13E4][2016-08-12T13:29:41]i399: Apply complete, result: 0x80240017, restart: None, ba requested restart:  No<br />
	 
</p>

<p>
	Best regards
</p>

<p>
	Bigjoe
</p>

<p><a href="http://www.winsnort.com/uploads/monthly_2016_08/Vcredistx64_error.JPG.dba4d0f70ea67e8b7da987d093009d7d.JPG" class="ipsAttachLink ipsAttachLink_image"><img data-fileid="128" src="http://www.winsnort.com/uploads/monthly_2016_08/Vcredistx64_error.JPG.dba4d0f70ea67e8b7da987d093009d7d.JPG" class="ipsImage ipsImage_thumbnailed" alt="Vcredistx64_error.JPG"></a></p>]]></description><guid isPermaLink="false">229</guid><pubDate>Fri, 12 Aug 2016 11:43:54 +0000</pubDate></item><item><title>ERROR: Portscan log file 'log/\portscan.log' could not be opened: No such file or directory</title><link>http://www.winsnort.com/topic/223-error-portscan-log-file-logportscanlog-could-not-be-opened-no-such-file-or-directory/</link><description><![CDATA[
<p>
	Hello,
</p>

<p>
	I am following the Installing an IIS Web Server Logging events to a mysql database and I am receiving the following error when testing my conf file:
</p>

<p>
	 
</p>

<p>
	ERROR: Portscan log file 'log/\portscan.log' could not be opened: No such file or directory.
</p>

<p>
	Fatal Error, Quitting..
</p>

<p>
	My snort configuration file is configured as such
</p>

<p>
	preprocessor sfportscan: proto  { all } memcap { 10000000 } sense_level { low } logfile { \portscan.log }
</p>

<p>
	 
</p>

<p>
	any help would be greatly appreciated!
</p>

<p>
	Thanks!
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">223</guid><pubDate>Fri, 27 May 2016 14:27:16 +0000</pubDate></item><item><title>BASE bottom not updating</title><link>http://www.winsnort.com/topic/190-base-bottom-not-updating/</link><description><![CDATA[
<p>everything is working fine except the bottom of the front base screen where we select the issues:</p>

<p>any Ideas?</p>

<p><a class="ipsAttachLink ipsAttachLink_image" href="http://www.winsnort.com/uploads/monthly_2015_10/snort-base-fig1-145116.gif.561f2528a2b5c69da026fdca53c23330.gif"><img class="ipsImage ipsImage_thumbnailed" data-fileid="101" src="http://www.winsnort.com/uploads/monthly_2015_10/snort-base-fig1-145116.thumb.gif.13723e3262db4243adc656e79974ab2f.gif" alt="snort-base-fig1-145116.thumb.gif.13723e3"></a></p>
]]></description><guid isPermaLink="false">190</guid><pubDate>Mon, 19 Oct 2015 15:11:50 +0000</pubDate></item><item><title>Base Will Not Update</title><link>http://www.winsnort.com/topic/85-base-will-not-update/</link><description><![CDATA[<p>Okay, this is the second time I've run into this. I had the exact same results when I did the install using IIS and MySQL.  </p>
<p> </p>
<ul><li>I built by following line-for-line the posted instructions. </li>
<li>Barnyard, snort winsql checks were all successful. </li>
<li>Base starts up properly. </li>
<li>Base shows ONLY updates from the first day it was running</li>
</ul><p> </p>
<p>The base home page (and any other pages I open) shows the red 'events updated' message periodically in the upper part of the page. I get nothing, however, when I click on the menu items for Today's events or date limited searches. I'm guessing it has something to do with base configuration, but I don't know what it might be. </p>
<p> </p>
<p>Any ideas are welcome, I'd be more than happy to try anything you can suggest. </p>
<p> </p>
<p>Flonk</p>
]]></description><guid isPermaLink="false">85</guid><pubDate>Mon, 15 Sep 2014 23:28:53 +0000</pubDate></item><item><title>modder.vbs Win 8.1 enterprise</title><link>http://www.winsnort.com/topic/54-moddervbs-win-81-enterprise/</link><description><![CDATA[
<p>
	Cant get past: "Detecting Product Name" when running Modder.vbs
</p>

<p>
	------------------------------------------------------------------------------------------------------------------
</p>

<p>
	The OS Product Name is Windows 8.1 Enterprise, and is not supported!
</p>

<p>
	Supported Product Names: Windows XP SP3 / 7 SP1 / <span style="font-size: 18px;"><u><strong><span style="color: rgb(255, 0, 0);">8.x</span></strong></u></span>, Server 2003 SP2 / 2008<br>
	SP2, 2012 R2
</p>

<p>
	------------------------------------------------------------------------------------------------------------------
</p>

<p>
	Right now i am rewriting modder.vbs
</p>

<p>
	<a href="http://www.winsnort.com/uploads/monthly_08_2014/post-376-0-86575000-1406892357.png"><img alt="post-376-0-86575000-1406892357_thumb.png" data-fileid="14" src="http://www.winsnort.com/uploads/monthly_08_2014/post-376-0-86575000-1406892357_thumb.png"></a>
</p>
]]></description><guid isPermaLink="false">54</guid><pubDate>Fri, 01 Aug 2014 11:33:32 +0000</pubDate></item><item><title>Open Source TG Download Link Broken</title><link>http://www.winsnort.com/topic/49-open-source-tg-download-link-broken/</link><description><![CDATA[<p>Just FYI the link to download for the "Rules Documentation (opensource.tgz)" link is broken. It looks like the snort.org site moved it to this link </p>
<p> </p>
<p><a href="https://www.snort.org/downloads/community/opensource.tar.gzf" rel="external nofollow">https://www.snort.org/downloads/community/opensource.tar.gzf</a></p>
<p> </p>
<p>So just FYI on that. I got the file with no problem.</p>
<p> </p>
]]></description><guid isPermaLink="false">49</guid><pubDate>Mon, 28 Jul 2014 17:01:42 +0000</pubDate></item><item><title>MSVCR110.dll missing during apache2 config</title><link>http://www.winsnort.com/topic/48-msvcr110dll-missing-during-apache2-config/</link><description><![CDATA[
<p>
	Dear team 
</p>

<p>
	after running following command to configure apache
</p>

<p>
	d:\winids\apache24\bin\httpd.exe -k install
</p>

<p>
	i get the error -
</p>

<p>
	"Program can't start because MSVCR110.dll is missing from your system , Try reinstalling the program to fix this problem"
</p>

<p>
	I tried reinstallingthe MS Visual C ++ redistributable -  no improvement
</p>

<p>
	kindly advise
</p>

<p>
	thanks 
</p>

<p>
	dominic
</p>
]]></description><guid isPermaLink="false">48</guid><pubDate>Tue, 22 Jul 2014 13:08:55 +0000</pubDate></item><item><title>DAQ ERROR on win7 32 bit ent</title><link>http://www.winsnort.com/topic/47-daq-error-on-win7-32-bit-ent/</link><description><![CDATA[<div> </div>
<div>when i run this command,</div>
<div><span style="font-family:calibri, sans-serif;"><span style="font-size:11pt;">d:winidssnortbinsnort -c d:winidssnortetcsnort.conf -l d:winidssnortlog –i1 -T</span></span></div>
<div> </div>
<div><span style="font-family:calibri, sans-serif;"><span style="font-size:11pt;">i get the following error</span></span></div>
<div> </div>
<div> </div>
<div> </div>
<div>[ Number of patterns truncated to 20 bytes: 307 ]</div>
<div>pcap DAQ configured to passive.</div>
<div>The DAQ version does not support reload.</div>
<div>Acquiring network traffic from "DeviceNPF_{269A6487-19E1-42B4-A2B2-8A4494B3D49</div>
<div>6}".</div>
<div>ERROR: Can't set DAQ BPF filter to 'ûi1 -T' (ê¶O)!</div>
<div>Fatal Error, Quitting..</div>
<div> </div>
<div>do we need to install DAQ? we have not missed any step in the tutorial.</div>
<div> </div>
<div>thanks</div>
]]></description><guid isPermaLink="false">47</guid><pubDate>Sat, 19 Jul 2014 06:12:38 +0000</pubDate></item><item><title>Apache2 service error "service specific error occured:1 get help  NET HELPMSG 3547"</title><link>http://www.winsnort.com/topic/44-apache2-service-error-service-specific-error-occured1-get-help-net-helpmsg-3547/</link><description><![CDATA[<p>Dear Morpheus,</p>
<p> </p>
<p>i now have an issue with the apache service .</p>
<p> </p>
<p>I made all the changes as recommended in the d:winidsapache24confhttpd.conf file and </p>
<p>ran the</p>
<p> </p>
<p>d:/winidsapache24binhttp.exe -k</p>
<p> </p>
<p>to add the apache 2 to the windows  services database - this went through successfully - it first compained of a syntax error in httpd.conf which </p>
<p>was rectified and after the corection it installed the apache service</p>
<p> </p>
<p>However when i give the command </p>
<p> </p>
<p>net start apache2.4</p>
<p>i get an error "service specific error occured:1 get help  NET HELPMSG 3547"</p>
<p> </p>
<p>that in turn points to refer to the service document</p>
<p> </p>
<p>Kindly please advise</p>
<p> </p>
<p>sincere thanks </p>
<p> </p>
<p>dominic</p>
<p> </p>
<p> </p>
<p> </p>
]]></description><guid isPermaLink="false">44</guid><pubDate>Tue, 15 Jul 2014 08:16:12 +0000</pubDate></item><item><title>notepad2 and opensource.gz</title><link>http://www.winsnort.com/topic/43-notepad2-and-opensourcegz/</link><description><![CDATA[<p>hi ,</p>
<p> </p>
<p>Very nice document , it is indeed exhaustive and I appreciate the effort and initiative put in by Michael.</p>
<p>few small issues I faced so far.</p>
<p> </p>
<p>somehow the notpad2 did not get loaded</p>
<p>I downloaded and installed notepad++ it works fine</p>
<p> </p>
<p>secondly the file available on snort.org is opensource.tgz , while the document refers to opensource.gz , I believe they are both the same</p>
<p> </p>
<p>3rd - I am installing on a windows 2003 server - the modder.vbs script installs .NET 4 extended however when I tried to run tartools it failed complaining about the .NET environment , I had to go to enable windows features and then enable .NET after which the error went away.</p>
<p> </p>
<p> </p>
]]></description><guid isPermaLink="false">43</guid><pubDate>Sun, 13 Jul 2014 20:14:18 +0000</pubDate></item></channel></rss>
