<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Random Insanity</title>
	<atom:link href="http://randominsanity.net.nz/blog/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://randominsanity.net.nz/blog</link>
	<description>Random Insanity since 1981</description>
	<lastBuildDate>Fri, 13 Aug 2010 11:28:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Ok so&#8230;</title>
		<link>http://randominsanity.net.nz/blog/?p=1549</link>
		<comments>http://randominsanity.net.nz/blog/?p=1549#comments</comments>
		<pubDate>Fri, 13 Aug 2010 11:28:24 +0000</pubDate>
		<dc:creator>hoppers99</dc:creator>
				<category><![CDATA[Programming]]></category>
		<category><![CDATA[Facebook]]></category>

		<guid isPermaLink="false">http://randominsanity.net.nz/blog/?p=1549</guid>
		<description><![CDATA[&#8230; the last attempt at an automatic post didn&#8217;t play nice. Not sure if it was a config error on this end or a fb issue in general (we all know it has plenty of issues!). =P Fingers crossed, this will work though! And assuming it does, good night all. =]]]></description>
			<content:encoded><![CDATA[<p class='fb-like'><iframe src='http://www.facebook.com/plugins/like.php?href=http://randominsanity.net.nz/blog/?p=1549&amp;layout=button_count&amp;show_faces=true&amp;width=260&amp;action=like&amp;colorscheme=light' scrolling='no' frameborder='0' allowTransparency='true' style='border:none; overflow:hidden; width:260px; height:26px'></iframe></p><p>&#8230; the last attempt at an automatic post didn&#8217;t play nice. Not sure if it was a config error on this end or a fb issue in general (we all know it has plenty of issues!). =P</p>
<p>Fingers crossed, this will work though! And assuming it does, good night all. =]</p>
]]></content:encoded>
			<wfw:commentRss>http://randominsanity.net.nz/blog/?feed=rss2&amp;p=1549</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>39 days to go&#8230;</title>
		<link>http://randominsanity.net.nz/blog/?p=1541</link>
		<comments>http://randominsanity.net.nz/blog/?p=1541#comments</comments>
		<pubDate>Fri, 13 Aug 2010 09:44:36 +0000</pubDate>
		<dc:creator>hoppers99</dc:creator>
				<category><![CDATA[Life]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[travel]]></category>

		<guid isPermaLink="false">http://randominsanity.net.nz/blog/?p=1541</guid>
		<description><![CDATA[So it&#8217;s now 39 days until I head for Aussie (all going to plan). So now I&#8217;m just doing a little setup so that if I get sufficiently motivated I can update the few of you who read this stuff on how the trips going. As well as the usual updates to base code and [...]]]></description>
			<content:encoded><![CDATA[<p class='fb-like'><iframe src='http://www.facebook.com/plugins/like.php?href=http://randominsanity.net.nz/blog/?p=1541&amp;layout=button_count&amp;show_faces=true&amp;width=260&amp;action=like&amp;colorscheme=light' scrolling='no' frameborder='0' allowTransparency='true' style='border:none; overflow:hidden; width:260px; height:26px'></iframe></p><p><a href="http://randominsanity.net.nz/blog/wp-content/uploads/130820102072.jpg"><img class="alignright size-full wp-image-1538" title="130820102072" src="http://randominsanity.net.nz/blog/wp-content/uploads/130820102072.jpg" alt="" width="252" height="336" /></a>So it&#8217;s now 39 days until I head for Aussie (all going to plan). So now I&#8217;m just doing a little setup so that if I get sufficiently motivated I can update the few of you who read this stuff on how the trips going.</p>
<p>As well as the usual updates to base code and tiding up of plugins, I&#8217;ve now hooked things up so that hopefully this will now bombard facebook with whatever I post as well, just to help the couple that tend to read things on here in the loop. =P</p>
<p>Finally got the new passport today (yes, a rather essential piece of the puzzle). Pitty it&#8217;s only valid for 5 years (my last one ran out in Jan 2009 but had had a 10 year life). Finalise tickets on tuesday.</p>
<p>It should be a great trip, with among other things some great photo opportunities to be had on a 2 week bus trip covering a pile of Aussie along the way. Not to mention the exciting/scary/confusing prospect of meeting what can be best described as meeting up with some long lost family.</p>
<p>But anyway, more to come&#8230; maybe. Lets see if this facebook plugin works or not!</p>
]]></content:encoded>
			<wfw:commentRss>http://randominsanity.net.nz/blog/?feed=rss2&amp;p=1541</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>And here we go&#8230;</title>
		<link>http://randominsanity.net.nz/blog/?p=1532</link>
		<comments>http://randominsanity.net.nz/blog/?p=1532#comments</comments>
		<pubDate>Fri, 13 Aug 2010 07:57:10 +0000</pubDate>
		<dc:creator>hoppers99</dc:creator>
				<category><![CDATA[Mobile]]></category>

		<guid isPermaLink="false">http://randominsanity.net.nz/blog/?p=1532</guid>
		<description><![CDATA[New passport arrived today!]]></description>
			<content:encoded><![CDATA[<p class='fb-like'><iframe src='http://www.facebook.com/plugins/like.php?href=http://randominsanity.net.nz/blog/?p=1532&amp;layout=button_count&amp;show_faces=true&amp;width=260&amp;action=like&amp;colorscheme=light' scrolling='no' frameborder='0' allowTransparency='true' style='border:none; overflow:hidden; width:260px; height:26px'></iframe></p><p>New passport arrived today!</p>

<a href='http://randominsanity.net.nz/blog/?attachment_id=1533' title='13082010207'><img width="112" height="150" src="http://randominsanity.net.nz/blog/wp-content/uploads/13082010207-112x150.jpg" class="attachment-thumbnail" alt="13082010207" title="13082010207" /></a>

]]></content:encoded>
			<wfw:commentRss>http://randominsanity.net.nz/blog/?feed=rss2&amp;p=1532</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>It feels inherently wrong&#8230;</title>
		<link>http://randominsanity.net.nz/blog/?p=1523</link>
		<comments>http://randominsanity.net.nz/blog/?p=1523#comments</comments>
		<pubDate>Thu, 25 Feb 2010 08:54:12 +0000</pubDate>
		<dc:creator>hoppers99</dc:creator>
				<category><![CDATA[Funnies]]></category>
		<category><![CDATA[Humour]]></category>
		<category><![CDATA[LOLCatz]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Telecom]]></category>

		<guid isPermaLink="false">http://randominsanity.net.nz/blog/?p=1523</guid>
		<description><![CDATA[&#8230; to be in a meeting in Auckland at 9am and be back in the office in Hawkes Bay mid afternoon. Yet that&#8217;s how todays been. 7am flight to Auckland. Cab into center city, making it just in time for the 9am meeting. Quick coffee after the meeting then cab back to the airport and [...]]]></description>
			<content:encoded><![CDATA[<p class='fb-like'><iframe src='http://www.facebook.com/plugins/like.php?href=http://randominsanity.net.nz/blog/?p=1523&amp;layout=button_count&amp;show_faces=true&amp;width=260&amp;action=like&amp;colorscheme=light' scrolling='no' frameborder='0' allowTransparency='true' style='border:none; overflow:hidden; width:260px; height:26px'></iframe></p><p>&#8230; to be in a meeting in Auckland at 9am and be back in the office in Hawkes Bay mid afternoon. Yet that&#8217;s how todays been.</p>
<p>7am flight to Auckland. Cab into center city, making it just in time for the 9am meeting. Quick coffee after the meeting then cab back to the airport and back to Napier. Stitting back at my desk by 3.</p>
<p>But anyway, I know no one really cares about such things. My real reason for dusting off the old blog was to post a couple of friggen halarious pic that I just found.</p>
<p><a href="http://randominsanity.net.nz/blog/wp-content/uploads/23749_350275391409_567976409_4783892_3615720_n.jpg"><img class="aligncenter size-full wp-image-1524" title="FUCK YOU" src="http://randominsanity.net.nz/blog/wp-content/uploads/23749_350275391409_567976409_4783892_3615720_n.jpg" alt="F U C K YOU" width="483" height="604" /></a></p>
<p>And another goodie&#8230;</p>
<p><a href="http://randominsanity.net.nz/blog/wp-content/uploads/25947_1208769108573_1509060487_30462260_6468844_n.jpg"><img class="aligncenter size-full wp-image-1525" title="Anger Management" src="http://randominsanity.net.nz/blog/wp-content/uploads/25947_1208769108573_1509060487_30462260_6468844_n.jpg" alt="Anger Management" width="448" height="336" /></a></p>
<p>Now, for all of you who have spent far too much time on the internet and delved into the world of chat rooms, have a laugh at <a href="http://ohmygle.blogspot.com/">OhMy!gle</a>. It&#8217;s friggen gold!</p>
<p>Anyways, enough boredom for one night. Enjoy!</p>
]]></content:encoded>
			<wfw:commentRss>http://randominsanity.net.nz/blog/?feed=rss2&amp;p=1523</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>I just wanna free-fall for a while&#8230;</title>
		<link>http://randominsanity.net.nz/blog/?p=1514</link>
		<comments>http://randominsanity.net.nz/blog/?p=1514#comments</comments>
		<pubDate>Sun, 13 Sep 2009 03:04:11 +0000</pubDate>
		<dc:creator>hoppers99</dc:creator>
				<category><![CDATA[Poetic]]></category>
		<category><![CDATA[Random]]></category>
		<category><![CDATA[Music]]></category>
		<category><![CDATA[Summer]]></category>

		<guid isPermaLink="false">http://randominsanity.net.nz/blog/?p=1514</guid>
		<description><![CDATA[So the end of the weekend is drawing nearer. It&#8217;s been a good one; the main event being a cocktail party for a 50th. Far too much alcohol but good fun coming up with some interesting mixes. Other than that, damn it&#8217;s been a nice sunny weekend. It&#8217;s definitely got me in the summer mood. [...]]]></description>
			<content:encoded><![CDATA[<p class='fb-like'><iframe src='http://www.facebook.com/plugins/like.php?href=http://randominsanity.net.nz/blog/?p=1514&amp;layout=button_count&amp;show_faces=true&amp;width=260&amp;action=like&amp;colorscheme=light' scrolling='no' frameborder='0' allowTransparency='true' style='border:none; overflow:hidden; width:260px; height:26px'></iframe></p><p>So the end of the weekend is drawing nearer. It&#8217;s been a good one; the main event being a cocktail party for a 50th. Far too much alcohol but good fun coming up with some interesting mixes.<span id="more-1514"></span></p>
<p>Other than that, damn it&#8217;s been a nice sunny weekend. It&#8217;s definitely got me in the summer mood. Shorts (much to the detriment of anyone without sunnies on =P ) and the house wide open. Won&#8217;t be long before we crank up the bbq I think. Not quite warm enough for the beach yet but I doubt that will be too far away either. And well the hay-fever has started to kick in but shit you can&#8217;t have everything good I guess. =P</p>
<p>Time to go get some sunshine and hope I don&#8217;t burn to a crisp! Here&#8217;s a bit of music with a good beat and some good lyrics:</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="560" height="340" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/qv3PJ1YSHFs&amp;hl=en&amp;fs=1&amp;rel=0&amp;color1=0x2b405b&amp;color2=0x6b8ab6" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="560" height="340" src="http://www.youtube.com/v/qv3PJ1YSHFs&amp;hl=en&amp;fs=1&amp;rel=0&amp;color1=0x2b405b&amp;color2=0x6b8ab6" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>And here&#8217;s a random pic for the day&#8230;</p>
<div id="attachment_1398" class="wp-caption aligncenter" style="width: 320px"><img class="size-full wp-image-1398" title="There's these moments - by MiCa" src="http://randominsanity.net.nz/blog/wp-content/uploads/There__s_these_moments___by_MiCa_uk.jpg" alt="There's these moments - by MiCa" width="310" height="414" /><p class="wp-caption-text">There&#39;s these moments - by MiCa...</p></div>
<p>The text for those who can&#8217;t read it is&#8230;</p>
<blockquote><p>It&#8217;s difficult to ignore what&#8217;s<br />
Really on the outside<br />
When the inside<br />
Is fighting this corpse so much.</p>
<p>With minutes left<br />
And the last hour gone<br />
The beginning hasn&#8217;t even<br />
Ended yet&#8230;</p></blockquote>
<p>Have a good one all!</p>
]]></content:encoded>
			<wfw:commentRss>http://randominsanity.net.nz/blog/?feed=rss2&amp;p=1514</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Men are from Mars, Women are from Venus</title>
		<link>http://randominsanity.net.nz/blog/?p=1513</link>
		<comments>http://randominsanity.net.nz/blog/?p=1513#comments</comments>
		<pubDate>Thu, 10 Sep 2009 22:27:08 +0000</pubDate>
		<dc:creator>hoppers99</dc:creator>
				<category><![CDATA[Humour]]></category>
		<category><![CDATA[Funnies]]></category>

		<guid isPermaLink="false">http://randominsanity.net.nz/blog/?p=1513</guid>
		<description><![CDATA[Here&#8217;s a prime example of &#8220;Men are from Mars, Women are from Venus&#8221; offered by an English professor from the university of Phoenix. The professor told his class one day. &#8220;Today we will experiment with a new form called the tandem story. The process is simple. Each person will pair off with the person sitting [...]]]></description>
			<content:encoded><![CDATA[<p class='fb-like'><iframe src='http://www.facebook.com/plugins/like.php?href=http://randominsanity.net.nz/blog/?p=1513&amp;layout=button_count&amp;show_faces=true&amp;width=260&amp;action=like&amp;colorscheme=light' scrolling='no' frameborder='0' allowTransparency='true' style='border:none; overflow:hidden; width:260px; height:26px'></iframe></p><p>Here&#8217;s a prime example of &#8220;Men are from Mars, Women are from Venus&#8221; offered by an English professor from the university of Phoenix.<span id="more-1513"></span></p>
<p>The professor told his class one day. &#8220;Today we will experiment with a new form called the tandem story. The process is simple. Each person will pair off with the person sitting to his or her immediate right. As homework tonight, one of you will write the first paragraph of a short story. You will then email your partner that paragraph and send another copy to me.</p>
<p>Your partner will read the first paragraph and then add another paragraph to the story and send it back, also sending another copy to me. The first person will then add a third paragraph, and so on back-and-forth. Remember to re-read what has been written each time in order to keep the story coherent. There is to be absolutely no talking outside of the emails and anything you wish to say must be written in the email. The story is over when both agree a conclusion has been reached.&#8221;</p>
<p>The following was actually turned in by two of his students, Rebecca and Gary.</p>
<p>&#8212;-</p>
<h3>The Story:</h3>
<p><em>(First paragraph by Rebecca)</em><br />
At first, Laurie couldn&#8217;t decide which kind of tea she wanted. The chamomile, which used to be her favourite for lazy evenings at home, now reminded her too much of Carl, who once said, in happier times, that he liked chamomile. But she felt she must now, at all costs, keep her mind off Carl. His possessiveness was suffocating, and if she thought about him too much her asthma started acting up again. So chamomile was out of the questions.</p>
<p><em>(Second paragraph by Gary)</em><br />
Meanwhile, Advanced Sergeant Carl Harris, leader of the attack squadron now in orbit over Skylon 4, had more important things to think about than the neuroses of an airheaded asthmatic bimbo named Laurie with whom he had spent one sweaty night over a year ago. &#8220;A.S. Harris to Geostation 17,&#8221; he said into his transgalactic communicator. &#8220;Polar orbit established. No sign of resistance so far&#8230;&#8221; But before he could sign off a bluish beam flashed out of nowhere and blasted a hole through his ship&#8217;s cargo bay. The jolt from the direct hit sent him flying out of his seat across the cockpit.</p>
<p><em>(Rebecca)</em><br />
He bumped his head and died almost immediately, but not before he felt one last pang of regret for physically brutalising the one woman who had ever had feelings for him. Soon afterwards, Earth stopped its pointless hostilities towards the peaceful farmers of Skylon 4. &#8220;Congress Passes Law Permanently Abolishing War and Space Travel,&#8221; Laurie read in her newspaper one morning. The news simultaneously excited her and bored here. She stared out the window, dreaming of her youth, when the days had passed unhurriedly and carefree, with no newspaper to read, no television to distract her form her sense of innocent wonder at the all the beautiful things around her. &#8220;Why must one lose one&#8217;s innocents to become a woman?&#8221; she wondered wistfully.</p>
<p><em>(Gary)</em><br />
Little did she know, but she had less than 10 seconds to live. Thousands of miles above the city, the Anudrian mothership launched the first of its lithium fusion missiles. The dim-witted wimpy peacenicks who pushed the Unilateral Aerospace disarmament Treaty through the congress had left Earth a defenceless target for the hostile alien empires who were determined to destroy the human race. Within two hours after the passage of the treaty the Anudrian ships were on  course for Earth, carrying enough fire-power to pulverise the entire planet. With no one to stop them, they swiftly initiated their diabolical plan. The lithium fusion missile entered the atmosphere unimpeded. The President, in his tip-secret mobile submarine headquarters on the ocean floor of the coast of Guam, felt the inconceivably massive explosion, which vaporised poor , stupid Laurie.</p>
<p><em>(Rebecca)</em><br />
This is absurd. I refuse to continue this mockery of literature. My writing partner is a violent, chauvinistic semi-literate adolescent.</p>
<p><em>(Gary)</em><br />
Yeah? Well, my writing partner is a self-centred tedious neurotic! whose attempts at writing are the literary equivalent of Valium. &#8220;Oh shall I have chamomile tea? Or shall I have some other sort of F**KING TEA???! Oh no, WHAT AM I to do? I&#8217;m such an air headed bimbo who reads too many Danielle Steele novels!&#8221;</p>
<p><em>(Rebecca)</em><br />
A**hole</p>
<p><em>(Gary)</em><br />
Bitch</p>
<p><em>(Rebecca)</em><br />
F**K YOU &#8211; YOU NEANDERTHAL!</p>
<p><em>(Gary)</em><br />
Go drink some tea &#8211; whore.</p>
<p><em>(Teacher)</em><br />
A+ &#8230;&#8230;. I really liked this one.</p>
]]></content:encoded>
			<wfw:commentRss>http://randominsanity.net.nz/blog/?feed=rss2&amp;p=1513</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Thursday, 10pm.</title>
		<link>http://randominsanity.net.nz/blog/?p=1512</link>
		<comments>http://randominsanity.net.nz/blog/?p=1512#comments</comments>
		<pubDate>Thu, 10 Sep 2009 10:51:55 +0000</pubDate>
		<dc:creator>hoppers99</dc:creator>
				<category><![CDATA[Demotivationals]]></category>
		<category><![CDATA[Funnies]]></category>
		<category><![CDATA[Humour]]></category>
		<category><![CDATA[LOLCatz]]></category>
		<category><![CDATA[Politically Incorrect]]></category>
		<category><![CDATA[snorby]]></category>
		<category><![CDATA[snort]]></category>

		<guid isPermaLink="false">http://randominsanity.net.nz/blog/?p=1512</guid>
		<description><![CDATA[10pm. 527548 events logged by Snort since 7pm last night (the last database purge). The vast majority of those was during office hours today; not surprising given the general peak traffic time on the network. Snorby is holding up well although ruby seems to consume a lot of resources, and I managed to crash the [...]]]></description>
			<content:encoded><![CDATA[<p class='fb-like'><iframe src='http://www.facebook.com/plugins/like.php?href=http://randominsanity.net.nz/blog/?p=1512&amp;layout=button_count&amp;show_faces=true&amp;width=260&amp;action=like&amp;colorscheme=light' scrolling='no' frameborder='0' allowTransparency='true' style='border:none; overflow:hidden; width:260px; height:26px'></iframe></p><div id="attachment_345" class="wp-caption aligncenter" style="width: 510px"><img class="size-full wp-image-345" title="battery-level-0" src="http://randominsanity.net.nz/blog/wp-content/uploads/battery-level-0.jpg" alt="Battery: 0%" width="500" height="375" /><p class="wp-caption-text">Battery: 0%</p></div>
<p>10pm. 527548 events logged by Snort since 7pm last night (the last database purge). The vast majority of those was during office hours today; not surprising given the general peak traffic time on the network. Snorby is holding up well although ruby seems to consume a lot of resources, and I managed to crash the server by using the email a report function (it tried to run an SQL query that was over 4.8 MILLION characters long &#8211; 2 hours at max system resources and it finally tipped over). Other than that all is looking good.<span id="more-1512"></span></p>
<p>Pretty shattered after staying up until after midnight toying with sensor rules, bed time soon. But thought I&#8217;d share some humour to help get you all through Friday.</p>
<div id="attachment_304" class="wp-caption aligncenter" style="width: 610px"><img class="size-full wp-image-304" title="A short story" src="http://randominsanity.net.nz/blog/wp-content/uploads/A-short-story.jpg" alt="A Short Story" width="600" height="660" /><p class="wp-caption-text">A Short Story</p></div>
<p>And a little motivation&#8230;</p>
<div id="attachment_428" class="wp-caption aligncenter" style="width: 410px"><img class="size-full wp-image-428" title="motivation" src="http://randominsanity.net.nz/blog/wp-content/uploads/motivation.jpg" alt="motivation" width="400" height="340" /><p class="wp-caption-text">Motivation</p></div>
<p>Just remember&#8230;</p>
<div id="attachment_434" class="wp-caption aligncenter" style="width: 410px"><img class="size-full wp-image-434" title="poster_effort" src="http://randominsanity.net.nz/blog/wp-content/uploads/poster_effort.jpg" alt="Effort" width="400" height="350" /><p class="wp-caption-text">Effort</p></div>
<p>So have a fun Friday one and all. Roll on caterday!!!</p>
<div id="attachment_196" class="wp-caption aligncenter" style="width: 810px"><img class="size-full wp-image-196" title="1163919784-1162667170980" src="http://randominsanity.net.nz/blog/wp-content/uploads/1163919784-1162667170980.jpg" alt="Time Portal to Caterday" width="800" height="600" /><p class="wp-caption-text">Time Portal to Caterday</p></div>
]]></content:encoded>
			<wfw:commentRss>http://randominsanity.net.nz/blog/?feed=rss2&amp;p=1512</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Running Snorby on Debian (lenny) with Snort, Barnyard2 and Apache2</title>
		<link>http://randominsanity.net.nz/blog/?p=1510</link>
		<comments>http://randominsanity.net.nz/blog/?p=1510#comments</comments>
		<pubDate>Wed, 09 Sep 2009 23:20:44 +0000</pubDate>
		<dc:creator>hoppers99</dc:creator>
				<category><![CDATA[Work]]></category>
		<category><![CDATA[ids]]></category>
		<category><![CDATA[snorby]]></category>
		<category><![CDATA[snort]]></category>

		<guid isPermaLink="false">http://randominsanity.net.nz/blog/?p=1510</guid>
		<description><![CDATA[I recently setup a Snort sensor on a dedicated box and initially had it all running and happy. Then I stumbled across Snorby, and thought &#8220;that looks pretty mint, I might try that out&#8221; as BASE just wasn&#8217;t doing it for me on its own. In this article I&#8217;ll try and piece together a little [...]]]></description>
			<content:encoded><![CDATA[<p class='fb-like'><iframe src='http://www.facebook.com/plugins/like.php?href=http://randominsanity.net.nz/blog/?p=1510&amp;layout=button_count&amp;show_faces=true&amp;width=260&amp;action=like&amp;colorscheme=light' scrolling='no' frameborder='0' allowTransparency='true' style='border:none; overflow:hidden; width:260px; height:26px'></iframe></p><p>I recently setup a <a title="Snort.org" href="http://www.snort.org/" target="_blank">Snort</a> sensor on a dedicated box and initially had it all running and happy. Then I stumbled across <a title="Snorby.org" href="http://www.snorby.org/" target="_blank">Snorby</a>, and thought &#8220;that looks pretty mint, I might try that out&#8221; as <a title="BASE" href="http://sourceforge.net/projects/secureideas/" target="_blank">BASE</a> just wasn&#8217;t doing it for me on its own. In this article I&#8217;ll try and piece together a little about what the initial set-up was and how I managed to get Snorby up and running (and how I managed to get stuck several times along the way).<span id="more-1510"></span></p>
<h3>Pre Snorby:</h3>
<p>Before I looked at installing Snorby I&#8217;d setup Snort, <a title="Barnyard2" href="http://www.securixlive.com/barnyard2/index.php" target="_blank">Barnyard2</a> and <a title="Apache.org" href="http://apache.org/" target="_blank">Apache2</a> with BASE. Snort was logging to a unified2 log file, which Barnyard2 was parsing and storing in a database as well as logging to syslog so I could get a rapid view that things were actually working prior to BASE being setup. Then BASE came in and grabbed info from the database to display in its standard fashion.</p>
<p>While this setup was pretty good and while BASE was able to generate some interesting stats, it wasn&#8217;t the most slick thing I&#8217;ve seen and its links to rule info and IP lookups etc seemed to have been invalidated due to updates in the websites or subscription requirements of the websites.</p>
<p>So then I stumbled across Snorby. It looked much more user friendly and appeared to generally just be a nicer system than BASE, so I thought why not. Initially I had intended to run both BASE and Snorby in different folders of the web root&#8230; that of course turned out to be a bust due to the nature of Ruby on Rails; a language I know nothing about and gave no thought to at the time.</p>
<h3>Installing Snorby:</h3>
<p>While Snorby can run all on its lonesome using Webrick (never done it but the interwebz told me so!), I had Apache running already and as I mentioned was still thinking that other stuff would be running along side. So, on the Snorby website I found the wiki page &#8220;<a href="http://wiki.github.com/mephux/Snorby/snorby-recipe-with-barnyard2-unified2-and-apache-jjc" target="_blank">http://wiki.github.com/mephux/Snorby/snorby-recipe-with-barnyard2-unified2-and-apache-jjc</a>&#8221; which after some later googling appears to just be an excerpt from &#8220;<a href="http://global-security.blogspot.com/2009/07/snorby-for-snort-recipe-with-barnyard2.html" target="_blank">http://global-security.blogspot.com/2009/07/snorby-for-snort-recipe-with-barnyard2.html</a>&#8220;.</p>
<p>Now that recipe was aimed at FreeBSD, which while I used to use, was somewhat different in it&#8217;s operation to Debian. That aside i thought I&#8217;d use it as my guide and just wing the differences between the ports of FreeBSD and Apt from Debian.</p>
<p>My first attempt (and failure) involved installing ruby and a few other packages from Apt. Never having dealt with it before all the references to &#8220;gem&#8221; and &#8220;rake&#8221; etc were foreign to me, so I installed a few other packages that looked related too. Short version; this all ended up in a nauseating mess of version incompatibilities, file path issues, and multiple versions of the same program floating around the system with different ones being used by different commands.</p>
<p>So I purged all those packages and grabbed ruby and rubygems tarballs. Installed those, and tried again. This time got closer, and actually got Snorby running, however with one issue&#8230; Any time I tried to view the detail of an event, I got an error. This was linked to their being no sensor info even though all the events were logging fine.</p>
<p>This could have possibly been resolved easily enough, had I been able to get into the command line debug console for Snorby. I&#8217;d jumped onto IRC and found Dustin Webber (aka &#8220;mephux&#8221;); the author of Snorby. Working with him we tried a pile of things and found that there was a hugely messed up mix of files and stuff. The most annoying error while trying to access the debug console was &#8220;Rails requires RubyGems &gt;= . Please install RubyGems and try again: http://rubygems.rubyforge.org&#8221; which given Snorby was installed and running seemed to indicate that Rails and RubyGems were there and playing together prior to this to get things going at all.</p>
<p>Everything was looking completely snotted so after around an hour of getting nowhere, I decided to start from scratch again. I de-installed anything vaguely resembling ruby, rails, gems etc. I also located and forcibly deleted any cached files, directories etc that bared any resemblance. I wanted to make sure it was REALLY cleared out!</p>
<p>The following is how I got things to work (or as near as I can remember) after that.</p>
<p>I grabbed ruby-1.8.7-p174.tar.gz and rubygems-1.3.5.tgz from their appropriate websites. While the recipie I was using as a guide didn&#8217;t mention the specific install of ruby itself, gems required it to install (I assume the ruby-gems port installs it as a dependency maybe).</p>
<p>Installing ruby was a stock standard untar, ./configure, make, make install. I did run configure with the &#8216;&#8211;enable-shared&#8217; flag this time which I hadn&#8217;t earlier, although I&#8217;m not sure if that made any difference at all. once that&#8217;s done, rubygems was a bit different, needing to run &#8220;ruby setup.rb&#8221; after untarring as the method to set it up.</p>
<p>Once that was done, things became a bit more standard. I&#8217;d already grabbed Snorby using git and placed it in /var/www/snorby/ (I made it lower case because I was expecting to have the &#8220;snorby&#8221; in a url, however the folder was named with a capital S when first grabbed.</p>
<p>The command sequence from there (I&#8217;m not listing the output to keep it brief) was&#8230;<br />
<code><br />
$ gem install prawn<br />
$ gem install rake<br />
$ gem install rails<br />
$ gem install dbd-mysql<br />
$ gem install passenger<br />
$ passenger-install-apache2-module<br />
</code><br />
At first I accidentally missed the rails one and dbd-mysql gave an error, but after I corrected my mistake it installed fine.</p>
<p>The passenger-install-apache2-module is one of a few scripts that passenger seems to have for getting things setup with different web servers. It is pretty helpful and takes you through a couple of steps to get things setup. It will tell you if you are missing anything it needs, and even gave the correct apt command to get anything it needed. At the end, it tells you three lines you need to add to your Apache config.</p>
<p>After that, it was time to get Snorby sorted again.</p>
<p>Setup database.yml and email.yml as per the normal docs. In my case I cut email.yml down to remove the authentication stuff.</p>
<p>As per the doco &#8220;rake gems:install&#8221; was next.</p>
<p>Next was the database.<br />
<code><br />
$ rake snorby:reset RAILS_ENV=production<br />
$ rake snorby:setup RAILS_ENV=production<br />
$ rake snorby:update RAILS_ENV=production<br />
</code><br />
Now, I&#8217;m not 100% convinced that I ether needed all three of these commands or any of them actually. I had the database setup already with barnyard logging to it. This process dropped the entire db and re-created the tables, but I can&#8217;t spot anything specific schema wise that Snorby added that wasn&#8217;t there before. However, while debugging these three command were given to me by Dustin as what was needed and I didn&#8217;t have the patience at the time to test different combinations or the knowledge of ruby to check the code for exactly what each did.</p>
<p>After that, restart Barnyard and Apache. Id also made the changes to the Apache DocumentRoot by now to work as per the global-security version of the recipe, these were left out of the one on the Snorby Wiki but seem essential to getting the ruby stuff working rather than just showing as files.</p>
<p>Browsing to the appropriate url it now all seemed go. I found I&#8217;d missed the iconv install but an &#8220;apt-get install libiconv-ruby&#8221; fixed that. I could see alerts being logged, the sensor showed fine, and now 16 hours later Snorby is running happily!</p>
<p>The two other things I did come across that I didn&#8217;t spot in the doco&#8217;s but that showed in the Apache logs were changing permissions on snorby/log/production.log and the snorby/tmp/ folder to allow the application logging and the generation of email attached PDF&#8217;s respectively. The log snippet that showed this up was:<br />
<code><br />
Rails Error: Unable to access log file. Please ensure that /var/www/snorby/log/production.log exists and is chmod 0666. The log level has been raised to WARN and the output directed to STDERR until the problem is fixed.<br />
spawn&gt; Exception in child[2924] - Errno::EACCES: Permission denied - /var/www/snorby/tmp/tmp-event.pdf<br />
</code></p>
<h3>Post Install:</h3>
<p>A huge thanks to Dustin for not only writing the thing, but for several hours of assistance in trying to track down the problems to get it working under my particular config.</p>
<p>Reflecting I think the first problem with lack of a sensor was because the Snorby install had blown away a perfectly good database, combined with barnyard2 not restarting properly causing it to manage to keep logging events when it reconnected to the db, but not recreating the sensor info in the db as that seems to be done on barnyard loading.</p>
<p>You may ask why barnyard didn&#8217;t reload properly&#8230; I &#8220;think&#8221; that may have been do to with the load the server was under: this sensor is in a very high traffic network so snort and barnyard were working their butts off to keep up with the traffic that was being sniffed &#8211; so even though barnyard was told to restart, I think it was still trying to finish the records it was working on inserting into the database, which was in the tens of thousands. I actually fully &#8220;kill -9&#8243;ed it at the last restart but previously I hand just told it to restart without checking process id&#8217;s etc.</p>
<p>I&#8217;ll try and update this post to clarify anything if I get questioned or if I feel motivated to expand anything into more detail. Feel free to post any questions you have on the install process  of Snorby or the other components here or go checkout the Snorby website for places to get help if you&#8217;re having trouble with Snorby itself. As I said, I know nothing of Ruby so my ability to assist with a lot of Snorby specific problems is probably pretty limited.</p>
<p><strong>Edit <small>[2009-09-10 13:09]</small>:</strong> Ok, so not everything was perfect. Turns out the cron jobs to do the daily/weekly/monthly reporting weren&#8217;t installed for some reason (apparently I&#8217;m not the only person to have this happen). To fix it:<br />
<code><br />
$ gem sources -a http://gems.github.com<br />
$ gem install javan-whenever<br />
$ whenever --update-crontab snorby --set environment=production<br />
</code><br />
and it should be all setup to run. =]</p>
<h3>Links:</h3>
<ul>
<li>Snorby Homepage: <a href="http://www.snorby.org/" target="_blank">http://www.snorby.org/</a></li>
<li>Snorby Wiki: <a href="http://wiki.github.com/mephux/Snorby" target="_blank">http://wiki.github.com/mephux/Snorby</a> <small>(has contact info and install doco)</small></li>
<li>Snort Homepage: <a href="http://www.snort.org/" target="_blank">http://www.snort.org/</a></li>
<li>Snort Additional Downloads: <a href="http://www.snort.org/downloads/additional-downloads/" target="_blank">http://www.snort.org/downloads/additional-downloads/</a> <small>(where I found BASE, Snorby, Barnyard2 and has a pile of other tools as well)</small></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://randominsanity.net.nz/blog/?feed=rss2&amp;p=1510</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Just a small reality check. Happy Monday all!</title>
		<link>http://randominsanity.net.nz/blog/?p=1509</link>
		<comments>http://randominsanity.net.nz/blog/?p=1509#comments</comments>
		<pubDate>Mon, 07 Sep 2009 05:49:56 +0000</pubDate>
		<dc:creator>hoppers99</dc:creator>
				<category><![CDATA[Demotivationals]]></category>
		<category><![CDATA[Funnies]]></category>
		<category><![CDATA[Humour]]></category>

		<guid isPermaLink="false">http://randominsanity.net.nz/blog/?p=1509</guid>
		<description><![CDATA[]]></description>
			<content:encoded><![CDATA[<p class='fb-like'><iframe src='http://www.facebook.com/plugins/like.php?href=http://randominsanity.net.nz/blog/?p=1509&amp;layout=button_count&amp;show_faces=true&amp;width=260&amp;action=like&amp;colorscheme=light' scrolling='no' frameborder='0' allowTransparency='true' style='border:none; overflow:hidden; width:260px; height:26px'></iframe></p><p><img class="size-full wp-image-1475" title="wishes_poster" src="http://randominsanity.net.nz/blog/wp-content/uploads/wishes_poster1.jpg" alt="When you wish upon a falling star..." width="400" height="335" /></p>
]]></content:encoded>
			<wfw:commentRss>http://randominsanity.net.nz/blog/?feed=rss2&amp;p=1509</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Inane halarity&#8230;</title>
		<link>http://randominsanity.net.nz/blog/?p=1508</link>
		<comments>http://randominsanity.net.nz/blog/?p=1508#comments</comments>
		<pubDate>Sat, 05 Sep 2009 09:30:34 +0000</pubDate>
		<dc:creator>hoppers99</dc:creator>
				<category><![CDATA[Funnies]]></category>
		<category><![CDATA[Images & Stuff]]></category>
		<category><![CDATA[Politically Incorrect]]></category>
		<category><![CDATA[Humour]]></category>

		<guid isPermaLink="false">http://randominsanity.net.nz/blog/?p=1508</guid>
		<description><![CDATA[The other day I was going through some old files looking for something and came across a s**tload of pics and stuff that I&#8217;d collected over the years and used to be on one of my old websites. So, instead of uploading things in gallery fashion as they were I thought I&#8217;d post a few [...]]]></description>
			<content:encoded><![CDATA[<p class='fb-like'><iframe src='http://www.facebook.com/plugins/like.php?href=http://randominsanity.net.nz/blog/?p=1508&amp;layout=button_count&amp;show_faces=true&amp;width=260&amp;action=like&amp;colorscheme=light' scrolling='no' frameborder='0' allowTransparency='true' style='border:none; overflow:hidden; width:260px; height:26px'></iframe></p><div id="attachment_361" class="wp-caption alignright" style="width: 290px"><img class="size-full wp-image-361 " title="black_out" src="http://randominsanity.net.nz/blog/wp-content/uploads/black_out.jpg" alt="Black Out" width="280" height="433" /><p class="wp-caption-text">Black Out</p></div>
<p>The other day I was going through some old files looking for something and came across a s**tload of pics and stuff that I&#8217;d collected over the years and used to be on one of my old websites. So, instead of uploading things in gallery fashion as they were I thought I&#8217;d post a few every now and then as I felt motivated.</p>
<p>So far, I&#8217;ve decided on a few obvious categories but I&#8217;m sure the list will grow. There&#8217;s everything from politically incorrect, to down right rude. The intent is not to offend, it&#8217;s all just a laugh. These pic&#8217;s come from all over the place, collected over years: if there is anything that belongs to you and you want it taken down, let me know &#8211; I make no claim of ownership of any of this stuff.</p>
<p>Here&#8217;s a few to set the mood and start the project off. =P</p>
<div id="attachment_371" class="wp-caption aligncenter" style="width: 433px"><img class="size-full wp-image-371 " title="Burk" src="http://randominsanity.net.nz/blog/wp-content/uploads/Burk.jpg" alt="Babies: Nutritional Facts..." width="423" height="600" /><p class="wp-caption-text">Babies: Nutritional Facts...</p></div>
<div id="attachment_385" class="wp-caption aligncenter" style="width: 460px"><img class="size-full wp-image-385 " title="CLINIC" src="http://randominsanity.net.nz/blog/wp-content/uploads/CLINIC.jpg" alt="... no comment." width="450" height="372" /><p class="wp-caption-text">... no comment.</p></div>
<div id="attachment_372" class="wp-caption aligncenter" style="width: 490px"><a href="http://randominsanity.net.nz/blog/wp-content/uploads/Burn-Baby-Burn.gif"><img class="size-full wp-image-372 " title="Burn Baby Burn" src="http://randominsanity.net.nz/blog/wp-content/uploads/Burn-Baby-Burn.gif" alt="Possibly not the best advertising to have on the page... =/" width="480" height="326" /></a><p class="wp-caption-text">Possibly not the best advertising to have on the page... =/</p></div>
]]></content:encoded>
			<wfw:commentRss>http://randominsanity.net.nz/blog/?feed=rss2&amp;p=1508</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
