<?xml version="1.0"?>
<rss version="2.0"><channel><title>Discussing Manual Installation for IIS with PostgreSQL Logging Latest Topics</title><link>https://www.winsnort.com/forum/13-discussing-manual-installation-for-iis-with-postgresql-logging/</link><description>Discussing Manual Installation for IIS with PostgreSQL Logging Latest Topics</description><language>en</language><item><title>Barnyard2 test doesn't show snort exiting</title><link>https://www.winsnort.com/topic/311-barnyard2-test-doesnt-show-snort-exiting/</link><description><![CDATA[
<p>
	Hi,
</p>

<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">In the tutorial, it shows this:</span>
</p>

<p>
	If all the tests are passed, the following is a confirmation that the Barnyard2 configuration file is good. </p>
<p></p>


<p>
	<strong><span style="font-size:10pt;font-family:'Courier New';">Barnyard2 successfully loaded configuration file!</span></strong><span style="font-size:10pt;font-family:'Courier New';"></span></p>
<p></p>


<p>
	<b><span style="font-size:10pt;font-family:'Courier New';color:#FF0000;">Snort exiting</span></b></p>
<p><b></b></p>
<b></b>


<p>
	<strong><span style="font-size:10pt;font-family:'Courier New';">database: Closing connection to database "snort"</span></strong>
</p>

<p>
	<strong><span style="font-size:10pt;font-family:'Courier New';">*********************</span></strong><span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;"></span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;"></span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;"></span></p>
<p> I ran the test.</p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">Barnyard2 spooler: Event cache size set to [32768]</span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">INFO database: Defaulting Reconnect/Transaction Error limit to 10</span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">INFO database: Defaulting Reconnect sleep time to 5 second</span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">database: compiled support for (postgresql)</span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">database: configured to use postgresql</span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">database: schema version = 107</span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">database:           host = winids</span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">database:           user = snort</span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">database:  database name = snort</span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">database:    sensor name = WinIDS-Home</span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">database:      sensor id = 1</span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">database:     sensor cid = 1</span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">database:  data encoding = hex</span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">database:   detail level = full</span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">database:     ignore_bpf = no</span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">database: using the "log" facility</span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;"></span></p>
<p> </p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">        --== Initialization Complete ==--</span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;"></span></p>
<p> </p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">  ______   -*&gt; Barnyard2 &lt;*-</span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">/ ,,_  \  Version 2.1.14 (Build 337)</span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">|o"  )~|  By Ian Firns (SecurixLive): <a href="http://www.securixlive.com/" rel="external nofollow">http://www.securixlive.com/</a></span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">+ '''' +  (C) Copyright 2008-2013 Ian Firns &lt;<a href="mailto:firnsy@securixlive.com" rel="">firnsy@securixlive.com</a>&gt;</span></p>
<p></p>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;"></span></p>
<p> </p>


<p>
	<b><span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">This is what my configuration showed at the end of test.</span></b><span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;"></span></p>
<p></p>
<br />
	 


<p>
	<b><span style="font-size:11pt;font-family:Calibri, sans-serif;color:#FF0000;">Barnyard2 successfully loaded configuration file!</span></b></p>
<p><b></b></p>
<b></b>


<p>
	<b><span style="font-size:11pt;font-family:Calibri, sans-serif;color:#FF0000;">Barnyard2 exiting</span></b></p>
<p><b></b></p>
<b></b>


<p>
	<b><span style="font-size:11pt;font-family:Calibri, sans-serif;color:#FF0000;">database: Closing connection to database "snort"</span></b></p>
<p><b></b></p>
<b></b>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;"></span></p>
<p></p>
<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;"></span><p></p>
<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">Does it have to say “snort exiting” to show that the Barnyard2 configuration is good?  If so, what do I need to check to make Barnyard2 test work correctly?</span>


<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">Thanks for your help,</span>
</p>

<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;">Bob</span>
</p>

<p>
	<span style="font-size:11pt;font-family:Calibri, sans-serif;color:#1F497D;"></span></p>
<p></p>
]]></description><guid isPermaLink="false">311</guid><pubDate>Tue, 11 Jun 2019 18:00:51 +0000</pubDate></item><item><title>Windows cannot start Windows service 'Snort'</title><link>https://www.winsnort.com/topic/292-windows-cannot-start-windows-service-snort/</link><description><![CDATA[
<iframe data-embedcontent="" frameborder="0" src="https://www.winsnort.com/topic/166-windows-could-not-start-the-snort-service/?do=embed"></iframe>
<p>
	I had the same issue as in this thread.  I was going to comment there but the forum said to start a new thread rather than reviving that one.
</p>

<p>
	 
</p>

<p>
	The issue seems to be that when the Windows service is created the path is set as;
</p>

<p>
	d:\winids\snort\bin\snort /SERVICE
</p>

<p>
	But it should be;
</p>

<p>
	d:\winids\snort\bin\snort.exe /SERVICE
</p>

<p>
	In the registry go to HKLM\SYSTEM\CurrentControlSet\Services\SnortSvc then edit the ImagePath entry to change the path
</p>
]]></description><guid isPermaLink="false">292</guid><pubDate>Tue, 28 Aug 2018 18:21:28 +0000</pubDate></item><item><title>barnyard2 configured for postgres database connect failed</title><link>https://www.winsnort.com/topic/154-barnyard2-configured-for-postgres-database-connect-failed/</link><description><![CDATA[
<p>After checking and double-checking the Barnyard2.conf file which is including the line</p>

<p><strong>'output database: log, postgresql, user=snort password=l0gg3r dbname=snort host=winids sensor_name=WinIDS-Home'</strong></p>

<p>The Barnyard2 configuration test fails with the following result-</p>

<p><strong>ERROR: database Connection to database 'snort' failed</strong></p>

<p><strong>Fatal Error, exiting database: Closing connection to database "snort"</strong></p>

<p>Any suggestions for resolving would be appreciated.</p>
]]></description><guid isPermaLink="false">154</guid><pubDate>Fri, 15 May 2015 15:59:30 +0000</pubDate></item><item><title>Mail.php error</title><link>https://www.winsnort.com/topic/276-mailphp-error/</link><description><![CDATA[
<p>
	PHP Warning: include_once(Mail.php): failed to open stream: No such file or directory in C:\winids\inetpub\wwwroot\base\includes\base_action.inc.php on line 29 PHP Warning: include_once(): Failed opening 'Mail.php' for inclusion (include_path='c:\winids\php;c:\winids\php\pear') in C:\winids\inetpub\wwwroot\base\includes\base_action.inc.php on line 29 PHP Warning: include_once(Mail/mime.php): failed to open stream: No such file or directory in C:\winids\inetpub\wwwroot\base\includes\base_action.inc.php on line 30 PHP Warning: include_once(): Failed opening 'Mail/mime.php' for inclusion (include_path='c:\winids\php;c:\winids\php\pear') in C:\winids\inetpub\wwwroot\base\includes\base_action.inc.php on line 30
</p>

<p>
	 
</p>

<p>
	 
</p>

<p><a href="https://www.winsnort.com/uploads/monthly_2017_08/598000a5dbb95_QQ20170801121616.png.302e9247f70b451fba65606f11439ddc.png" class="ipsAttachLink ipsAttachLink_image"><img data-fileid="174" src="https://www.winsnort.com/uploads/monthly_2017_08/598000a7556f3_QQ20170801121616.thumb.png.8636be2ccbd3dbad11d7256f836c4b3b.png" class="ipsImage ipsImage_thumbnailed" alt="QQ截图20170801121616.png"></a></p>]]></description><guid isPermaLink="false">276</guid><pubDate>Tue, 01 Aug 2017 04:16:43 +0000</pubDate></item><item><title>Barnyard2 test postgresql error</title><link>https://www.winsnort.com/topic/270-barnyard2-test-postgresql-error/</link><description><![CDATA[
<p>
	Hello,
</p>

<p>
	I'm going through the installation tutorial and everything has gone great until I got to the by2-test. I get the attached error and am looking for what I have done wrong.
</p>

<p>
	Thanks
</p>

<p><a class="ipsAttachLink" href="//www.winsnort.com/applications/core/interface/file/attachment.php?id=172">BY2Error.txt</a></p>]]></description><guid isPermaLink="false">270</guid><pubDate>Thu, 04 May 2017 15:58:30 +0000</pubDate></item><item><title>Http Error 502.2 - Bad Gateway when testing iis and php installation</title><link>https://www.winsnort.com/topic/264-http-error-5022-bad-gateway-when-testing-iis-and-php-installation/</link><description><![CDATA[
<p>
	Hello,
</p>

<p>
	(OK, this time, I'm pretty sure I have not forgotten any step)
</p>

<p>
	I am on Windows 8.1.
</p>

<p>
	When I type 'http://winids/temp.php' in the address bar of a web browser (IE or Firefox), I get a 502.2 error. Apparently, it's due to the REDIRECT_STATUS CGI variable not being set in php.ini. But according to the php website, this variable is not set for security reasons...
</p>

<p>
	I tried to do the previous steps again to make sure I had not forgotten anything, to no avail.
</p>

<p>
	If I change this variable, will it solve the problem? Is it safe to do so? Is there another way to solve this issue? Am I completely off-track?
</p>

<p>
	Thank you in advance for your answer.
</p>
]]></description><guid isPermaLink="false">264</guid><pubDate>Sun, 02 Apr 2017 16:00:28 +0000</pubDate></item><item><title>How to run the  The Windows Intrusion Detection System</title><link>https://www.winsnort.com/topic/240-how-to-run-the-the-windows-intrusion-detection-system/</link><description><![CDATA[<p>
	Hi ,First I wan to ask what command can run this program? Then, after I installed the system, i don't why the vpn cannot connect the remote desktop, is it related the system?
</p>
<p><a href="https://www.winsnort.com/uploads/monthly_2016_12/Untitled2.png.6e2c4a233fe7d098febc3af0e6fd864c.png" class="ipsAttachLink ipsAttachLink_image"><img data-fileid="140" src="https://www.winsnort.com/uploads/monthly_2016_12/Untitled2.thumb.png.c853da40aa675060b82820c9cb1afbb1.png" class="ipsImage ipsImage_thumbnailed" alt="Untitled2.png"></a></p>]]></description><guid isPermaLink="false">240</guid><pubDate>Wed, 14 Dec 2016 06:46:19 +0000</pubDate></item><item><title>Error:cannot read configuration file</title><link>https://www.winsnort.com/topic/239-errorcannot-read-configuration-file/</link><description><![CDATA[<p>
	how can i fix this problem???? i'm already to set the Handler Mappings
</p>
<p><a href="https://www.winsnort.com/uploads/monthly_2016_12/Untitled.png.e8c340c8f495f75a3578bfde6335bb21.png" class="ipsAttachLink ipsAttachLink_image"><img data-fileid="138" src="https://www.winsnort.com/uploads/monthly_2016_12/Untitled.thumb.png.18eb85185091dbb11fd3166f36660e22.png" class="ipsImage ipsImage_thumbnailed" alt="Untitled.png"></a></p>]]></description><guid isPermaLink="false">239</guid><pubDate>Mon, 12 Dec 2016 18:21:57 +0000</pubDate></item><item><title>Barnyard 2: Info Database: defaulting reconnect/transaction error limit to 10</title><link>https://www.winsnort.com/topic/235-barnyard-2-info-database-defaulting-reconnecttransaction-error-limit-to-10/</link><description><![CDATA[
<p>
	I've got an issue when running the test (by2-test)...<br />
	The test starts, and just hangs forever.<br />
	Here are the last few lines of the console:<br />
	Barnyard2 spooler: Event cache size set to [32768]<br />
	INFO database: Defaulting Reconnect/Transaction Error limit to 10<br />
	INFO database: Defaulting Reconnect sleep time to 5 second
</p>

<p>
	It's been a good 10 minutes so far.... I'll keep waiting, but I suspect that there is an issue reading the snort log file.<br />
	I did take a look at the log file, but it seems to be in binary... is this an issue?
</p>

<p>
	I have followed everything in the tutorial, but have changed from d:\winids to c:\winids
</p>

<p>
	Anybody have any ideas?
</p>
]]></description><guid isPermaLink="false">235</guid><pubDate>Fri, 14 Oct 2016 14:56:49 +0000</pubDate></item><item><title>Error when querying reference_system</title><link>https://www.winsnort.com/topic/226-error-when-querying-reference_system/</link><description><![CDATA[
<p>
	Hi, I tried to set up Snort by following the instruction on
</p>
<iframe data-embedcontent="" frameborder="0" src="https://www.winsnort.com/tutorials/article/1-installing-an-iis-web-server-logging-events-to-a-postgresql-database/?do=embed"></iframe>

<p>
	However when I try to verify the Barnyard2 configuration by running d:\winids\activators\by2-test , I saw the following error in postgres log file:
</p>

<p>
	2016-06-24 16:21:57 EDT LOG:  statement: SELECT `ref_system_id`, ref_system_name FROM reference_system;<br />
	2016-06-24 16:21:57 EDT DEBUG:  reaping dead processes<br />
	2016-06-24 16:21:57 EDT DEBUG:  server process (PID 804) exited with exit code 0<br />
	2016-06-24 16:21:57 EDT DEBUG:  attempting to remove WAL segments older than log file 000000000000000000000000<br />
	2016-06-24 16:21:57 EDT DEBUG:  SlruScanDirectory invoking callback on pg_subtrans/0000<br />
	2016-06-24 16:21:57 EDT ERROR:  operator does not exist: ` integer at character 8<br />
	2016-06-24 16:21:57 EDT HINT:  No operator matches the given name and argument type(s). You might need to add explicit type casts.<br />
	2016-06-24 16:21:57 EDT STATEMENT:  SELECT `ref_system_id`, ref_system_name FROM reference_system;<br />
	2016-06-24 16:21:57 EDT DEBUG:  forked new backend, pid=4056 socket=1320<br />
	2016-06-24 16:21:57 EDT DEBUG:  postgres child[4056]: starting with (<br />
	2016-06-24 16:21:57 EDT DEBUG:      postgres<br />
	2016-06-24 16:21:57 EDT DEBUG:  )<br />
	2016-06-24 16:21:57 EDT DEBUG:  InitPostgres<br />
	2016-06-24 16:21:57 EDT DEBUG:  my backend ID is 3<br />
	2016-06-24 16:21:57 EDT DEBUG:  StartTransaction<br />
	2016-06-24 16:21:57 EDT DEBUG:  name: unnamed; blockState:       DEFAULT; state: INPROGR, xid/subid/cid: 0/1/0, nestlvl: 1, children:<br />
	2016-06-24 16:21:57 EDT DEBUG:  shmem_exit(0): 1 before_shmem_exit callbacks to make
</p>

<p>
	It looks like it's expecting a column called " `ref_system_id` " in the table reference_system, while the column is just "ref_system_id" based on the script in D:\winids\barnyard2\schemas\create_postgres. Can you please advise what could have gone wrong here?
</p>

<p>
	 
</p>

<p>
	Thanks,
</p>

<p>
	Sally
</p>

<p>
	 
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">226</guid><pubDate>Fri, 24 Jun 2016 21:05:24 +0000</pubDate></item><item><title>Barnyard2 test fails with - ERROR: relations "schema" does not exist</title><link>https://www.winsnort.com/topic/222-barnyard2-test-fails-with-error-relations-schema-does-not-exist/</link><description><![CDATA[
<p>
	Barnyard2 test fails after making changes to barnyard2.conf given in instructions:
</p>

<p>
	ERROR database:postgresql_error: ERROR: relations "schema" does not exist
</p>

<p>
	LINE 1: SELECT vseq FROM schema
</p>

<p>
	ERROR database: executing Select() with Query [SELECT vseq FROM schema]
</p>

<p>
	ERROR: database problems with schema version, bailing...
</p>

<p>
	Fatal Error,Quitting
</p>

<p>
	barnyard2 exiting
</p>

<p>
	ERROR database: database: postgresql_error: ERROR:   relations "sensor" does not exist
</p>

<p>
	LINE 1: UPDATE sensor SET last_cid = 4294967295 WHERE sid = 0;
</p>

<p>
	database: closing connection to database "snort"
</p>
]]></description><guid isPermaLink="false">222</guid><pubDate>Mon, 09 May 2016 11:37:00 +0000</pubDate></item><item><title>Can't set daq bpf filter to '&#x2013;W'</title><link>https://www.winsnort.com/topic/213-cant-set-daq-bpf-filter-to-%E2%80%93w/</link><description><![CDATA[
<p>
	hi
</p>

<p>
	I just installed snort_2.9.8.0 on my 64bit windows 2008 r2 server.Before that I already installed .Net framework3.5 and  <span lang="en-us" style="font-size:10.5pt;font-family:Helvetica, sans-serif;color:#525252;background:#FFFFFF;" xml:lang="en-us">WinPcap_4_1_3</span> on the same server.
</p>

<p>
	However,when I start the snort programme using " <span lang="en-us" style="font-size:10.5pt;font-family:Helvetica, sans-serif;color:#525252;background:#FFFFFF;" xml:lang="en-us">d:\winids\snort\bin\snort –W</span> ",the system reflect with an error as the information below:
</p>

<p>
	C:\Users\Operator&gt;d:\winids\snort\bin\snort –W<br />
	Running in packet dump mode
</p>

<p>
	        --== Initializing Snort ==--<br />
	Initializing Output Plugins!<br />
	Snort BPF option: –W<br />
	pcap DAQ configured to passive.<br />
	The DAQ version does not support reload.<br />
	Acquiring network traffic from "\Device\NPF_{F2C3B9BA-92A1-44DC-B5A1-3F12E26623F<br />
	E}".<br />
	ERROR: Can't set DAQ BPF filter to '–W' (@P)!<br />
	Fatal Error, Quitting..
</p>

<p>
	anyone can help me solve this problem?
</p>

<p>
	thank you very much
</p>
]]></description><guid isPermaLink="false">213</guid><pubDate>Thu, 31 Mar 2016 01:56:34 +0000</pubDate></item><item><title>Barnyard2 - How long for test to complete?</title><link>https://www.winsnort.com/topic/202-barnyard2-how-long-for-test-to-complete/</link><description><![CDATA[
<p>
	<span style='font: 14px/22px "Helvetica Neue", Helvetica, Arial, sans-serif; color: rgb(82, 82, 82); text-transform: none; text-indent: 0px; letter-spacing: normal; word-spacing: 0px; float: none; white-space: normal; font-size-adjust: none; font-stretch: normal; background-color: rgb(255, 255, 255);'>How long should the by2-test run? </span>
</p>

<p>
	<span style='font: 14px/22px "Helvetica Neue", Helvetica, Arial, sans-serif; color: rgb(82, 82, 82); text-transform: none; text-indent: 0px; letter-spacing: normal; word-spacing: 0px; float: none; white-space: normal; font-size-adjust: none; font-stretch: normal; background-color: rgb(255, 255, 255);'>CPU is at 100% split between Barnyard and DB. I am guessing that it is running or configuring and I do not want to kill.</span>
</p>

<p>
	<span style='font: 14px/22px "Helvetica Neue", Helvetica, Arial, sans-serif; color: rgb(82, 82, 82); text-transform: none; text-indent: 0px; letter-spacing: normal; word-spacing: 0px; float: none; white-space: normal; font-size-adjust: none; font-stretch: normal; background-color: rgb(255, 255, 255);'>Recommendations appreciated.</span>
</p>

<p>
	 
</p>

<p>
	Never mind it finally finished. I guess the answer is a while. Thanks
</p>
]]></description><guid isPermaLink="false">202</guid><pubDate>Mon, 14 Dec 2015 22:42:06 +0000</pubDate></item><item><title>PHP Fails Http Error 500.19</title><link>https://www.winsnort.com/topic/172-php-fails-http-error-50019/</link><description><![CDATA[
<p>After making the edits and checking them three times. I'm looking for a little help.</p>

<p>When I run the php test I get : http error 500.19 0x80070021</p>

<p>module: iis web core</p>

<p>notification beginrequest</p>

<p>config error: This configuration section cannot b e used at this path. this happens when the section is locked at a parent level. locking is either by default  (overrideModeDefault=Deny"), or set explicitly by a location tag with overridemode="deny" or the legacy allowOverride="false"</p>

<p><strong>config file:</strong> <a rel="external nofollow">\\?d:\winids\inetpub\wwwroot.base\web.config</a></p>

<p><strong>config source</strong></p>

<p>8: &lt;/defaultDocument&gt;</p>

<p>9: <span style="color:rgb(255,0,0);">&lt;handlers&gt;</span></p>

<p>10:         &lt;remove name="PHP" /&gt;</p>
]]></description><guid isPermaLink="false">172</guid><pubDate>Mon, 15 Jun 2015 20:57:26 +0000</pubDate></item><item><title>Windows could not start the Snort service</title><link>https://www.winsnort.com/topic/166-windows-could-not-start-the-snort-service/</link><description><![CDATA[
<p>Using the commands in the tutorial to install snort as a service this is the path I end up with.  Is it correct?  The service won't start and results in-</p>

<p>"Windows could not start the Snort service on Local Computer"</p>

<p>"Path to executable:"</p>

<p>"d:\winids\Snort\bin\snort /SERVICE"</p>

<p> </p>

<p> </p>
]]></description><guid isPermaLink="false">166</guid><pubDate>Mon, 01 Jun 2015 20:47:47 +0000</pubDate></item><item><title>PHP fails with Error: 403 Forbiddon</title><link>https://www.winsnort.com/topic/163-php-fails-with-error-403-forbiddon/</link><description><![CDATA[
<p style="margin: 0in 0in 8pt;"><font color="#000000" face="Calibri" size="3">It appears when the PHP Handler Mappings is added to the IIS Webserver there may be times it fails to propagate those settings to the IIS Default Web Site. This causes an Error 403 Forbidden to appear in the browser window when the section titled <strong>Testing IIS, and the PHP installation</strong> is executed.</font></p>

<p style="margin: 0in 0in 8pt;"><font color="#000000" face="Calibri" size="3">There can be a couple of reasons why this Error: 403 Forbidden is being displayed.</font></p>

<ol><li style="margin: 0in 0in 8pt;"><font color="#000000" face="Calibri" size="3">The section titled <strong>Configuring IIS for PHP, and the Windows Intrusion Detection Systems security console</strong> was not correctly configured.</font></li>
	<li style="margin: 0in 0in 8pt;"><font color="#000000" face="Calibri" size="3">The section titled <strong>Configuring IIS for PHP, and the Windows Intrusion Detection Systems security console</strong> was correctly configured, but the PHP Handler Mappings did not propagate to the IIS Default Web Site.</font></li>
</ol><p style="margin: 0in 0in 8pt;"><font color="#000000" face="Calibri" size="3"><font color="#000000" face="Calibri" size="3">It is recommended to go back to the section labeled </font><strong><font face="Calibri">Configuring IIS for PHP, and the Windows Intrusion Detection Systems security console</font></strong><font face="Calibri">, recheck all the settings to make sure they are correct, and then retest the section labeled <strong>Testing IIS, and the PHP installation</strong>. If the 'PHP' test is successful then continue on with the tutorial. If not come back and complete the below.</font></font></p>

<p style="margin: 0in 0in 8pt;"><font color="#000000" face="Calibri" size="3">It's assumed that the Web Browser is still open, along with the terminal window. Close the Web Browser, and leave the terminal window open.</font></p>

<p style="margin: 0in 0in 8pt;"><font color="#000000" face="Calibri" size="3">In the open terminal type 'c:\windows\system32\inetsrv\iis.msc' (less the outside quotes), tap the<span style="mso-spacerun: yes;">  '</span>Enter' key, and the Internet Information Services (IIS) Manager opens.</font></p>

<p style="margin: 0in 0in 8pt;"><font color="#000000" face="Calibri" size="3"><strong>Note:</strong> The Internet Information Services (IIS) Manager may opens and ask 'Do you want to get started with...' left-click 'No'.</font></p>

<p style="margin: 0in 0in 8pt;"><font color="#000000" face="Calibri" size="3">On the left under 'Connections' the very top entry expand '&lt;server name&gt;', under &lt;server name&gt; expand 'Sites', left-click 'Default Web Site', in the center window titled 'Default Web Site Name' in the section labeled 'IIS', left-click highlighting 'Handler Mappings', on the right under 'Actions' and left-click 'Open Feature'.</font></p>

<p style="margin: 0in 0in 8pt;"><font color="#000000" face="Calibri" size="3">In the center window titled 'Handler Mappings' there may be or may not be a 'PHP' entry listed under the 'Name' column. Scroll down the window and if there is a 'PHP' entry under the 'Name' column then left-click highlighting the 'PHP' entry, on the right under 'Actions' left-click 'X Remove', a 'Confirm Remove' message appears, and left-click 'Yes'.</font></p>

<p style="margin: 0in 0in 8pt;"><font color="#000000" face="Calibri" size="3">On the right under 'Actions' left-click 'Add Script Map...', in the 'Request Path:' dialog box type '*.php' (less the outside quotes), in the 'Executable:' dialog box type 'd:\winids\php\php-cgi.exe' (less the outside quotes), in the 'Name:' dialog box type 'PHP' (less the outside quotes), left-click 'OK', the 'Add Script Map' notification message appears, left-click 'Yes', and exit the Internet Information Services (IIS) Manager.</font></p>

<p style="margin: 0in 0in 8pt;"><font color="#000000" face="Calibri" size="3"> </font><font color="#000000" face="Calibri" size="3">At the CMD prompt type 'iisreset /restart' (less the outside quotes), and tap the 'Enter' key.</font></p>

<p style="margin: 0in 0in 8pt;"><font color="#000000" face="Calibri" size="3"> </font><font face="Calibri"><font size="3"><font color="#000000">Go back to the section labeled <strong>Testing IIS, and the PHP installation</strong> and continue.</font></font></font></p>
]]></description><guid isPermaLink="false">163</guid><pubDate>Fri, 29 May 2015 21:26:14 +0000</pubDate></item><item><title>Can't Run 'create_postgresql' Get Permission Denied</title><link>https://www.winsnort.com/topic/153-cant-run-create_postgresql-get-permission-denied/</link><description><![CDATA[
<p>When I try to run the command \i d:\winids\barnyard2\schemas\create_postgresql;</p>

<p>or try to run any of the other \i commands under the install tutorial heading of "Creating the Windows Intrusion Detection System Database Tables "</p>

<p>the result is always "d:: Permission denied"</p>

<p>I've tried many things to try and get around this blockage but I've not been successful.  Any suggestions would be appreciated.</p>
]]></description><guid isPermaLink="false">153</guid><pubDate>Thu, 14 May 2015 13:23:40 +0000</pubDate></item><item><title>No preprocessor configured for policy 0</title><link>https://www.winsnort.com/topic/147-no-preprocessor-configured-for-policy-0/</link><description><![CDATA[
<p>Hi Morpheus,</p>

<p>First let me thank you for the awesome resources that you have provided, your tutorials are really good.</p>

<p>I have just configured my winids to receive it rule updates using pulled pork as described in your tutorial. I followed all the steps and passed all the tests, however when I restarted the computer the barnyard window is stuck waiting for new data, when I run snort itself I get the following messages</p>

<p>WARNING: No preprocessors configured for policy 0.<br>
05/06-13:17:32.947576 10.58.3.86:56494 -&gt; x.x.x.x:x<br>
TCP TTL:128 TOS:0x0 ID:17032 IpLen:20 DgmLen:76 DF<br>
***A**** Seq: 0xF428D7BA  Ack: 0x85718FD9  Win: 0x347  TcpLen: 56<br>
TCP Options (3) =&gt; NOP NOP Sack: <a href="mailto:34161@58605" rel="external nofollow">34161@58605</a><br>
 </p>

<p>any help would be greatly appreciated.</p>
]]></description><guid isPermaLink="false">147</guid><pubDate>Wed, 06 May 2015 12:26:56 +0000</pubDate></item><item><title>Can't extract winids-cssp-x32.zip file</title><link>https://www.winsnort.com/topic/123-cant-extract-winids-cssp-x32zip-file/</link><description><![CDATA[<p>Hello!</p>
<p> </p>
<p>I have troubles extracting winids-cssp-x32.zip file, password <span style="color:rgb(40,40,40);font-family:Helvetica, arial, sans-serif;">w1nsn03t.c0m is not accepted, and my WinRar refuses to extract files :/</span></p>
<p> </p>
<p><span style="color:rgb(40,40,40);font-family:Helvetica, arial, sans-serif;">Please Help!</span></p>
]]></description><guid isPermaLink="false">123</guid><pubDate>Mon, 16 Feb 2015 01:01:04 +0000</pubDate></item></channel></rss>
