Re: snort.lua broken thus pulledpork doesn't discover snort

Dorian ROSSE via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <DB7P193MB034695AF8464C07D8C088808DAB99@DB7P193MB0346.EURP193.PROD.OUTLOOK.COM>
Joel,


I have success to download rules with pulledpork master,

Do you know how to download of rules from Talos with pulledpork master?

That is explained with pulledpork 3 but this program is broken,

Maybe I will ask to the support on GitHub if you don't know the answer,

For snort I will try this friday by fill what I need I think this could the repair,

Thanks you in advance for your answer and your help,

Regards.


Dorian Rosse.
________________________________
From: Joel Esler <[email protected]>
Sent: Monday, June 27, 2022 2:46:45 PM
To: Dorian ROSSE <[email protected]>
Cc: [email protected] <[email protected]>; [email protected] <[email protected]>
Subject: Re: [Snort-users] snort.lua broken thus pulledpork doesn't discover snort

This is a problem:

“ You need to define an oinkcode, please review the rule_url section of the pulledpork config file!
 at /usr/local/bin/pulledpork.pl line 2121.”

And this is a problem:

Parsing Rules file "/usr/local/etc/snort/snort.lua"
ERROR: /usr/local/etc/snort/snort.lua(1) Invalid configuration line: ---------------------------------------------------------------------------

—
Sent from my  iPhone

On Jun 26, 2022, at 15:59, Dorian ROSSE <[email protected]> wrote:


I found the answer for pulledpork : snort has go out rules for version 31210 but it doesn't go out rules after version 31210 !

now how to repair the problems for snort ?

as i have ever say but i repeat snort has losen all it working all line of command snort answer nothing,

thank you in advance to help myself repair snort,

regards.


dorian rosse.
________________________________
De : Joel Esler <[email protected]>
Envoyé : dimanche 26 juin 2022 19:56
À : Dorian ROSSE <[email protected]>
Cc : [email protected] <[email protected]>; [email protected] <[email protected]>
Objet : Re: [Snort-users] snort.lua broken thus pulledpork doesn't discover snort

A guarantee if you google “snort error 422” the whole first page will be answers to this problem.   I’ve answered this personally, probably a hundred times over the past 8 years.

—
Sent from my  iPhone

On Jun 26, 2022, at 13:53, Dorian ROSSE <[email protected]> wrote:


now pulledpork has a new error : it is error 422 !

snort has loosen all brain : all line of command launch for snort answere nothing !

what i need to do ?

thanks you in advance for your help,

regards.


dorian rosse.
________________________________
De : Dorian ROSSE <[email protected]>
Envoyé : dimanche 26 juin 2022 18:03
À : Joel Esler <[email protected]>
Cc : [email protected] <[email protected]>; [email protected] <[email protected]>
Objet : Re: [Snort-users] snort.lua broken thus pulledpork doesn't discover snort

Joel,


I have ever tried to repair without success thus I wait a real help instead of just an answer without help,

The snort.lua is the previous ever working before I install a new time the laptop I think there are some problems by the system for understand the some programs between itself,

Thanks you in advance to really help myself,

Regards.


Dorian Rosse.
________________________________
From: Joel Esler <[email protected]>
Sent: Sunday, June 26, 2022 2:28:00 PM
To: Dorian ROSSE <[email protected]>
Cc: [email protected] <[email protected]>; [email protected] <[email protected]>
Subject: Re: [Snort-users] snort.lua broken thus pulledpork doesn't discover snort

You have two different problems. I suggest you read your error messages.

—
Sent from my  iPhone

On Jun 24, 2022, at 17:35, Dorian ROSSE via Snort-users <[email protected]> wrote:


hello,


snort.lua broken thus pulledpork doesn't discover snort :
~/snort_src/pulledpork-master$ sudo /usr/local/bin/pulledpork.pl -c /usr/local/etc/pulledpork/pulledpork.conf -l -P -E -T

    https://github.com/shirkdog/pulledpork
      _____ ____
     `----,\    )
      `--==\\  /    PulledPork v0.8.0 - The only positive thing to come out of 2020...well this and take-out liquor!
       `--==\\/
     .-~~~~-.Y|\\_  Copyright (C) 2009-2021 JJ Cummings, Michael Shirk
  @_/        /  66\_  and the PulledPork Team!
    |    \   \   _(")
     \   /-| ||'--'  Rules give me wings!
      \_\  \_\\
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Use of uninitialized value $Value in pattern match (m//) at /usr/local/bin/pulledpork.pl line 167, <CONFIG> line 20.
readline() on closed filehandle FH at /usr/local/bin/pulledpork.pl line 1647.
Use of uninitialized value $Snort in ord at /usr/local/bin/pulledpork.pl line 1924.
You need to define an oinkcode, please review the rule_url section of the pulledpork config file!
 at /usr/local/bin/pulledpork.pl line 2121.
'''

'''sudo /usr/local/bin/snort -V
sudo: /usr/local/bin/snort : commande introuvable'''

'''snort -c /usr/local/etc/snort/snort.lua
Running in IDS mode

        --== Initializing Snort ==--
Initializing Output Plugins!
Initializing Preprocessors!
Initializing Plug-ins!
Parsing Rules file "/usr/local/etc/snort/snort.lua"
ERROR: /usr/local/etc/snort/snort.lua(1) Invalid configuration line: ---------------------------------------------------------------------------

Fatal Error, Quitting..
'''

thanks you in advance to help myself fully install snort and pulledpork for sanitize my network,

regards.


dorian rosse.

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

   To unsubscribe, send an email to:
   [email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.