www.pudn.com > ids_snort.zip > CREDITS


$Id: CREDITS,v 1.10 2001/01/02 09:53:11 fygrave Exp $ 
 
Sebastian	 
	* Added TOS decoding and logging 
 
Ron Gula	 
	* Provided lots of advice and signatures  Check out his network IDS 
	  Dragon at www.securitywizards.com 
 
Mike Borella	 
	* Made some libpcap code that was actually easy enough to follow along 
          in so that even idiots like myself could do something like this.   
          Mike's a cool dude (and he listens to Slayer), check his stuff out 
          at www.borella.net 
 
Jed Pickel	 
	* Sent in the RAW packet decoder routine 
	* Database output plugin module 
	* XML output plugin module 
 
Chris Sylvain	 
	* Added HP-UX and S/Linux code, plus the "-x" command line switch. 
 
Damien Daspit	 
	* Provided the WinPopup code and some other bug fixes, plus helped me 
	  debug a nasty problem with the rules parser. 
 
Sebastien L.	 
	* Ideas guy and RPM guru, he's been a help behind the scenes lately. 
 
CyberPsychotic 	 
	* configure.in Sparc alignment updates 
	* daemon mode code 
	* lots of help debugging the 1.2 release on OpenBSD/Sparc 
	* new ftpd buffer overflow rule 
	* UnixSock alerting code 
	* NULL/Loopback decoder 
	* my right hand man in Snort development, constantly working on  
	  new stuff and enhancements for the system 
 
Nick Rogness and Jim Forster   
	* lots o' rules, bug reports 
 
Scott McIntyre  
	* Happy 99 virus rule 
	* wacky FBSD bugs and attendant help with said bugs 
	* also spotted the otn_tmp NULL bug in 1.3 
	* tons of debug info and help! 
 
Ron Snyder  
	* IP address negation operator code 
	* Bug hunter extrordinaire 
 
Jonathan Emery  
	* Ran Purify on the Snort source and tracked down some nasty buggage 
 
Aaron Smith  
	* non-promiscuous mode patch 
	* logging code streamlining 
 
Dug Song & Torbjorn Wictorin    
	* Torbjorn spotted it first, but Dug sent in a kick ass bug report so  
	  they both get credit for finding the otn_tmp NULL bug in LogPkt. 
 
Max Vision  
	* Ideas, debug help, lots of rules 
 
Dragos Ruiu  
	* Ideas guy, keeps me honest :) 
        * Author of defrag preprocessor 
 
Colin Haxton  
	* Timestamp bugfix, debug help 
 
Worm5er  
	* Master Debugger, he's always got the best bugs! :) 
 
Lance Spitzner  
	* Thank Lance for the session keyword! 
	* Lots of debug help, suggestions 
 
Christian Lademann  
	* The Man!  Added the rules file variable and include code.  This man 
	  should have a place in every Snort user's heart. ;) 
	* Added the ISDN for Linux support/decoders 
 
Christian Hammers  
	* Maintains the Debian distro of Snort, sends me nice bug reports. 
 
Michael Henry  
	* Sent in the URL decoder that eventually became the http_decode 
	  preprocessor 
 
Bob Beck  
	* Sent in a few security patches, some advice  
 
Sebastian  
	* Linux PPC testing. 
	* Great help with tracking down `loopback failure' problem. 
 
Patrick Mullen  
	* snort portscan preprocessor. 
	* great helper on the project. 
 
Herb Commodore  
	* `--with-libpcap' fixes to configure.in. 
 
John Wilson  
	* New implementation of insensitive pattern match code. 
 
Mike Caughran  
	* Great help with porting snort to AIX platform. 
 
Astaroth  
	* Added Tru64/Alpha support. 
 
Daniel Monjar  
	* More Tru64/Alpha diffs. 
 
Ralf Hildebrandt  
	* HP-UX debugger and ombudsman. 
 
Stuart Staniford-Chen  
	* Ideas guy, he's been bouncing around ideas for better output 
	  classification in Snort. 
	* Wrote snortsnarf.pl, a CGI/HTML program for organizing Snort output. 
 
Yen-Ming Chen  
	* Wrote the excellent snort-stat.pl statistical analysis script for  
	  Snort alerts. 
	* Wrote a nice PHP front-end for the Snort alerting mechanism. 
 
Erich Meier  
	* Lots of help debugging debugging! 
	* ip tos plugin. 
 
Denis Ducamp  
	* Solaris debugging and patching. 
 
Boa  
	* Great help with the addition of Token Ring support to Snort. 
 
Anthony Stevens  
	* Contributed the Guardian firewall response system to Snort. 
 
Andrew R. Baker  
	* Contributed the snort-sort alert analysis script. 
	* Tweaked various other Snort analysis scripts. 
 
J Cheesman  
	* Enhanced the PID logging code to be more robust. 
 
"Mark Hindess"  
	* Added the RPC application layer detection plugin 
 
Dave Wreski  
	* Provided support and help diagnosing problems with the 1.6.2 
          config scripts 
    * Snort-HOWTO paper.       
 
Bo  
	* Provided fixes for my idiotic configure.in antics in version 1.6.2 
  
Peter Weinberger  
	* Added code to fill in full transport protocol names 
 
Dave Dittrich  
	* Provided a little patch to fix daemon mode alert filenames 
 
Christopher Cramer  
    * Author of the TCP stream preprocessor! (spp_tcp_stream) 
 
Joe Stewart  
    * Added UNICODE and NULL byte attack detection to http_decode preproc 
 
Thomas Zajic  
	* Provided some sanity check fixes for the PID file 
 
Jason Ish  
	* Cleaned up the plugin template files 
 
Paul Herman  
	* Contributed a patch to clean up sloppy strlen/strncpy interactions 
 
Todd Lewis  
	* Big new addition to the project, idea/code generator extrordinaire :) 
 
Phil Wood  
	* Master debugger, got the IP/bidirectional code back on its feet after 
	  the addition of IP lists 
    * Numerous other bugpointers, tweaks etc. 
 
Dr SuSE  
	* Helps out with docs, answering questions on the mailing list, etc. 
 
Joe McAlerney  
	* sp_reference plugin, constant helper on the project 
 
James Hoagland  
	* SPADE statiscal anomaly detection plugin, lots of other help and  
	  advice 
 
 Maciek Szarpak  
	* Author of the react/respond plugins