Re: Compiling so_rules for FreeBSD 13

Noah Dietrich <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <CA+N0JEwXFf4VEFt=+hO9MVaZ=QkpYuT4FbH6sk7armFv+wargA@mail.gmail.com>
Run it with -V for more verbose output.
Also make sure 'distro' is commented out

On Tue, Jan 11, 2022, 1:23 PM Carlos Lopez <[email protected]> wrote:

> Tested but it seems so_rules are not processed under FreeBSD …
>
>     https://github.com/shirkdog/pulledpork3
>       _____ ____
>      `----,\    )   PulledPork v3.0.0.4
>       `--==\\  /    Lowcountry yellow mustard bbq sauce is the best bbq
> sauce. Fight me.
>        `--==\\/
>      .-~~~~-.Y|\\_  Copyright (C) 2021 Noah Dietrich, Colin Grady, Michael
> Shirk
>   @_/        /  66\_  and the PulledPork Team!
>     |    \   \   _(")
>      \   /-| ||'--'   Rules give me wings!
>       \_\  \_\\
> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
> Loading configuration file:  /usr/local/etc/pulledpork/pulledpork.conf
> Processing LightSPD ruleset
> Preparing to modify rules by sid file
> Completed processing all rulesets and local rules:
>  - Collected Rules:  Rules(loaded:46254, enabled:36946, disabled:9308)
>  - Collected Policies:
>     - Policy(name:none, rules:0)
>     - Policy(name:connectivity, rules:519)
>     - Policy(name:balanced, rules:9073)
>     - Policy(name:security, rules:19480)
>     - Policy(name:max-detect, rules:36946)
> Writing rules to:  /usr/local/etc/pulledpork/snort.rules
> Writing policy file to:  /usr/local/etc/pulledpork/pulledpork.states
> Program execution complete.
>
>
>
> On 5 Jan 2022, at 13:39, Noah Dietrich <[email protected]> wrote:
>
> Hello,
> I pushed a new version to github with this functionality. It hasn't been
> fully tested yet, but it works on my machine.
>
> On Wed, Dec 29, 2021 at 8:56 AM Carlos Lopez <[email protected]> wrote:
>
>> Many thanks Noah. Sure, all machines are the same architecture: amd64.
>>
>>
>> On 29 Dec 2021, at 08:54, Noah Dietrich <[email protected]>
>> wrote:
>>
>> Assuming your machines are the same architecture, I can't think of any
>> reasons you can't compile the .so rules on one machine and copy them to
>> another one, assuming you're copying all the required files (stub rules
>> mostly). If the architectures or available libraries are different, you
>> could have issues.
>>
>> Noah
>>
>>
>> On Tue, Dec 28, 2021 at 9:14 AM Carlos Lopez <[email protected]> wrote:
>>
>>> Perfect. Many thanks Noah. Only one question: I am using a different
>>> FreeBSD server than the one running snort to manage the rules, do I have to
>>> take into consideration anything to compile the so_rules and pass them?
>>>
>>>
>>> On 28 Dec 2021, at 08:57, Noah Dietrich <[email protected]>
>>> wrote:
>>>
>>> I'm working on this feature in PP3 now, it should be available soon.
>>>
>>> Noah
>>>
>>>
>>> On Tue, Dec 28, 2021 at 8:53 AM Carlos Lopez via Snort-users <
>>> [email protected]> wrote:
>>>
>>>> Hi all,
>>>>
>>>> I have installed snort 3.1.19.0 under a FreeBSD 13 host and all it is
>>>> working. Actually, I am using text (registered) rules only, but I would
>>>> like to use Talos_LightSPD rules. For rule management I am using
>>>> pulledpork3.
>>>>
>>>> What would be the proper procedure to compile the so_rules and have
>>>> pulledpork3 generate all the associated files?
>>>>
>>>> Regards.
>>>> _______________________________________________
>>>> Snort-users mailing list
>>>> [email protected]
>>>> Go to this URL to change user options or unsubscribe:
>>>> https://lists.snort.org/mailman/listinfo/snort-users
>>>>
>>>>         To unsubscribe, send an email to:
>>>>         [email protected]
>>>>
>>>> Please visit http://blog.snort.org to stay current on all the latest
>>>> Snort news!
>>>>
>>>> Please follow these rules:
>>>> https://snort.org/faq/what-is-the-mailing-list-etiquette
>>>>
>>>
>>>
>>
>

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.