Re: Question on update to http://3.1.36.0
David Melczer <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <BLAPR10MB5377F357035181110D907246A1949@BLAPR10MB5377.namprd10.prod.outlook.com> |
This is brilliant Priyanka, and works perfectly! Not sure how I missed that. Thank you for the assistance! -Dave David Z. Melczer | Director of Information Technology Greenbaum, Rowe, Smith & Davis LLP Delivery: 99 Wood Avenue South | Iselin, NJ | 08830 Mailing: P.O. Box 5600 | Woodbridge, NJ | 07095 T: 732.476.3284 | F: 732.476.3285 | vCard<http://www.greenbaumlaw.com/vcard-1999.vcf> [cid:[email protected]] greenbaumlaw.com<http://www.greenbaumlaw.com/> [cid:[email protected]]<https://www.linkedin.com/company/greenbaum-rowe-smith-&-davis-llp?trk=top_nav_home> [cid:[email protected]]<https://twitter.com/greenbaumlaw> [cid:[email protected]]<https://www.facebook.com/greenbaumlaw?fref=ts&ref=br_tf> From: Priyanka Bangalore Gurudev (prbg) <[email protected]> Sent: Tuesday, July 26, 2022 2:29 PM To: David Melczer <[email protected]>; Snort-users <[email protected]> Subject: Re: Question on update to http://3.1.36.0 *** External Email Message *** Hi David, file_id module is updated in 3.1.36.0<http://3.1.36.0>. File_id.file_rules and file_magic.lua are now file_id.rules_file and file_magic.rules Your new snort.lua post build would be updated to reflect this. file_id = { rules_file = 'file_magic.rules' } This information is available in the help-modules and documentation. LightSPD policies are also updated with this information. Thanks, Priyanka From: Snort-users <[email protected]<mailto:[email protected]>> on behalf of David Melczer <[email protected]<mailto:[email protected]>> Date: Tuesday, July 26, 2022 at 1:45 PM To: Snort-users <[email protected]<mailto:[email protected]>> Subject: [Snort-users] Question on update to 3.1.36.0<http://3.1.36.0> Good afternoon. I just upgraded from 3.1.32.0<http://3.1.32.0> to 3.1.36.0<http://3.1.36.0> by recompiling source. I’ve recompiled Snort, libdaq, and Snort_Extras as I have done every time in the past. I use the latest pulledpork3 to grab ruleset updates, and I use the LightSPD ruleset. For some reason, I keep getting this error, and the service now stops: ERROR: /usr/local/snort/etc/snort/snort.lua: can't find file_id.file_rules What is interesting is that if I comment out the file_magic section in snort.lua, everything works: -- see file_magic.lua for file id rules --file_id = --{ -- file_rules = file_magic --} The second I re-enable this config section, I get the error again. The file file_magic.lua DOES exist, and I do have the relevant include statement in section 1 of the snort.lua config file as follows: include 'snort_defaults.lua' include 'file_magic.lua' To the best of my knowledge, the file_magic.lua file has not changed at all, unless it changed as part of the 3.1.36.0<http://3.1.36.0> upgrade. There doesn’t seem to be any problem including snort_defaults.lua, but for some reason it is as though file_magic.lua is not picked up. Any ideas on what might have changed between 3.1.32.0<http://3.1.32.0> and 3.1.36.0<http://3.1.36.0> for this to no longer work? Thank you in advance! -Dave David Z. Melczer | Director of Information Technology Greenbaum, Rowe, Smith & Davis LLP Delivery: 99 Wood Avenue South | Iselin, NJ | 08830 Mailing: P.O. Box 5600 | Woodbridge, NJ | 07095 T: 732.476.3284 | F: 732.476.3285 | vCard<http://www.greenbaumlaw.com/vcard-1999.vcf> [cid:[email protected]] greenbaumlaw.com<http://www.greenbaumlaw.com/> [cid:[email protected]]<https://www.linkedin.com/company/greenbaum-rowe-smith-&-davis-llp?trk=top_nav_home> [cid:[email protected]]<https://twitter.com/greenbaumlaw> [cid:[email protected]]<https://www.facebook.com/greenbaumlaw?fref=ts&ref=br_tf> Disclaimer This e-mail (including any attachments) is intended only for the exclusive use of the individual to whom it is addressed. The information contained hereinafter may be proprietary, confidential, privileged and exempt from disclosure under applicable law. If the reader of this e-mail is not the intended recipient or agent responsible for delivering the message to the intended recipient, the reader is hereby put on notice that any use, dissemination, distribution or copying of this communication is strictly prohibited. If the reader has received this communication in error, please immediately notify the sender by telephone (732-549-5600) or e-mail and delete all copies of this e-mail and any attachments. Thank you. Disclaimer The information contained in this communication from the sender is confidential. It is intended solely for use by the recipient and others authorized to receive it. If you are not the recipient, you are hereby notified that any disclosure, copying, distribution or taking action in relation of the contents of this information is strictly prohibited and may be unlawful. This email has been scanned for viruses and malware, and may have been automatically archived by Mimecast Ltd, an innovator in Software as a Service (SaaS) for business. Providing a safer and more useful place for your human generated data. Specializing in; Security, archiving and compliance. To find out more visit the Mimecast website. _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
image001.jpg
(image/jpeg, 3.4 KB) - not displayed
image002.png
(image/png, 687 B) - not displayed
image003.png
(image/png, 670 B) - not displayed
image004.png
(image/png, 637 B) - not displayed