<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>R-fx Networks &#187; ips</title>
	<atom:link href="http://www.rfxn.com/tag/ips/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rfxn.com</link>
	<description> Linux Software &#38; Blog</description>
	<lastBuildDate>Sat, 24 Jul 2010 19:50:09 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>(ATF) Aggregate Threat Feed</title>
		<link>http://www.rfxn.com/atf-aggregate-threat-feed/</link>
		<comments>http://www.rfxn.com/atf-aggregate-threat-feed/#comments</comments>
		<pubDate>Mon, 03 May 2010 03:51:50 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[apf]]></category>
		<category><![CDATA[atf]]></category>
		<category><![CDATA[ips]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=203</guid>
		<description><![CDATA[For my first post back into things in awhile (a long while), I thought I would introduce everyone to the sexyness that i&#8217;ve called the Aggregate Threat Feed or ATF for short. This feed is derived from threat data at work, namely our network edge IPS (a custom snort implementation, another post on that later) <a href="http://www.rfxn.com/atf-aggregate-threat-feed/" class="more-link">More &#62;</a>]]></description>
		<wfw:commentRss>http://www.rfxn.com/atf-aggregate-threat-feed/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Linux Malware Detectection</title>
		<link>http://www.rfxn.com/linux-malware-detectection/</link>
		<comments>http://www.rfxn.com/linux-malware-detectection/#comments</comments>
		<pubDate>Mon, 19 Oct 2009 05:35:06 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[ips]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[snort]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=149</guid>
		<description><![CDATA[[ UPDATE: Linux Malware Detect has been released ]
I have the last few weeks been working on a new project for malware detection on Linux web servers, it is already at a pre-release version in use at work and it has shown phenomenal promise.
Right to it, some background&#8230; On a daily basis the network I <a href="http://www.rfxn.com/linux-malware-detectection/" class="more-link">More &#62;</a>]]></description>
		<wfw:commentRss>http://www.rfxn.com/linux-malware-detectection/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Snorting the Web Farm</title>
		<link>http://www.rfxn.com/the-power-of-snort-custom-rules/</link>
		<comments>http://www.rfxn.com/the-power-of-snort-custom-rules/#comments</comments>
		<pubDate>Wed, 10 Jun 2009 22:24:36 +0000</pubDate>
		<dc:creator>Ryan M.</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[HowTo]]></category>
		<category><![CDATA[ips]]></category>
		<category><![CDATA[snort]]></category>

		<guid isPermaLink="false">http://www.rfxn.com/?p=113</guid>
		<description><![CDATA[Here are some rules for you snort freaks to chew on that I have found useful in web heavy environments.
alert tcp $HTTP_SERVERS $HTTP_PORTS -&#62; any any (msg:"ET ATTACK RESPONSE x2300 phpshell detected"; content:"Locus7Shell"; nocase; classtype:web-application-activity; reference:url,www.rfxn.com; sid:300010; rev:1;)
alert tcp $HTTP_SERVERS $HTTP_PORTS -&#62; any any (msg:"ET ATTACK RESPONSE RFI Scanner detected"; content:"RFI Scanner"; classtype:web-application-activity; reference:url,www.rfxn.com; sid:300020; <a href="http://www.rfxn.com/the-power-of-snort-custom-rules/" class="more-link">More &#62;</a>]]></description>
		<wfw:commentRss>http://www.rfxn.com/the-power-of-snort-custom-rules/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
