Re: Compiling so_rules for FreeBSD 13

Carlos Lopez via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <[email protected]>
Tested but it seems so_rules are not processed under FreeBSD …

    https://github.com/shirkdog/pulledpork3
      _____ ____
     `----,\    )   PulledPork v3.0.0.4
      `--==\\  /    Lowcountry yellow mustard bbq sauce is the best bbq sauce. Fight me.
       `--==\\/
     .-~~~~-.Y|\\_  Copyright (C) 2021 Noah Dietrich, Colin Grady, Michael Shirk
  @_/        /  66\_  and the PulledPork Team!
    |    \   \   _(")
     \   /-| ||'--'   Rules give me wings!
      \_\  \_\\
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Loading configuration file:  /usr/local/etc/pulledpork/pulledpork.conf
Processing LightSPD ruleset
Preparing to modify rules by sid file
Completed processing all rulesets and local rules:
 - Collected Rules:  Rules(loaded:46254, enabled:36946, disabled:9308)
 - Collected Policies:
    - Policy(name:none, rules:0)
    - Policy(name:connectivity, rules:519)
    - Policy(name:balanced, rules:9073)
    - Policy(name:security, rules:19480)
    - Policy(name:max-detect, rules:36946)
Writing rules to:  /usr/local/etc/pulledpork/snort.rules
Writing policy file to:  /usr/local/etc/pulledpork/pulledpork.states
Program execution complete.



On 5 Jan 2022, at 13:39, Noah Dietrich <[email protected]<mailto:[email protected]>> wrote:

Hello,
I pushed a new version to github with this functionality. It hasn't been fully tested yet, but it works on my machine.

On Wed, Dec 29, 2021 at 8:56 AM Carlos Lopez <[email protected]<mailto:[email protected]>> wrote:
Many thanks Noah. Sure, all machines are the same architecture: amd64.


On 29 Dec 2021, at 08:54, Noah Dietrich <[email protected]<mailto:[email protected]>> wrote:

Assuming your machines are the same architecture, I can't think of any reasons you can't compile the .so rules on one machine and copy them to another one, assuming you're copying all the required files (stub rules mostly). If the architectures or available libraries are different, you could have issues.

Noah


On Tue, Dec 28, 2021 at 9:14 AM Carlos Lopez <[email protected]<mailto:[email protected]>> wrote:
Perfect. Many thanks Noah. Only one question: I am using a different FreeBSD server than the one running snort to manage the rules, do I have to take into consideration anything to compile the so_rules and pass them?


On 28 Dec 2021, at 08:57, Noah Dietrich <[email protected]<mailto:[email protected]>> wrote:

I'm working on this feature in PP3 now, it should be available soon.

Noah


On Tue, Dec 28, 2021 at 8:53 AM Carlos Lopez via Snort-users <[email protected]<mailto:[email protected]>> wrote:
Hi all,

I have installed snort 3.1.19.0 under a FreeBSD 13 host and all it is working. Actually, I am using text (registered) rules only, but I would like to use Talos_LightSPD rules. For rule management I am using pulledpork3.

What would be the proper procedure to compile the so_rules and have pulledpork3 generate all the associated files?

Regards.
_______________________________________________
Snort-users mailing list
[email protected]<mailto:[email protected]>
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

        To unsubscribe, send an email to:
        [email protected]<mailto:[email protected]>

Please visit http://blog.snort.org<http://blog.snort.org/> to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.