Re: snort3 exited when pulledpork3 refresh data

"Vitalii Serhiiovych Horbatov -X \(vhorbato - SOFTSERVE INC at Cisco\) via Snort-users" <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <MWHPR11MB1358BAB247A7FCD93C24E98DDB189@MWHPR11MB1358.namprd11.prod.outlook.com>
Hi Jan,

Hi, interesting that Snort crashes with a segfault when it receives a SIGHUP.

Could you please enable generation of coredump files on your system, reproduce this problem and then upload the generated cordump and your snort3 binary to some file hosting?

As far as I understand, you are using ubuntu, here is an instruction on how to enable cordumps on it: https://askubuntu.com/questions/1349047/where-do-i-find-core-dump-files-and-how-do-i-view-and-analyze-the-backtrace-st.

Thanks in advance,
Vitalii!

From: Snort-users <[email protected]> on behalf of Jan Gardian via Snort-users <[email protected]>
Date: Monday, 5 December 2022, 09:57
To: [email protected] <[email protected]>
Subject: [Snort-users] snort3 exited when pulledpork3 refresh data
Hello,

I have installed snort3 with pulledpork3 with instruction from https://snort-org-site.s3.amazonaws.com/production/document_files/files/000/012/147/original/Snort_3.1.8.0_on_Ubuntu_18_and_20.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAU7AK5ITMJQBJPARJ%2F20221129%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20221129T090404Z&X-Amz-Expires=172800&X-Amz-SignedHeaders=host&X-Amz-Signature=23d3468de323ba69ec8cdbc8d6a9d083c86c695660eaf1367fe5baba90a94180

I added snort3 and pulledpork3 to systemd unit files as services and also with pulledpok3.timer.
Problem is that when I run pulledpork3 it will always send signal to reload snort3 but instead of reload it always got fatal and snort3 process stop.

Journal logs from pulledpork3:
"
Nov 30 16:04:43 example pulledpork.py[1223834]: Writing rules to:  /usr/local/etc/rules/pulledpork.rules
Nov 30 16:04:43 example pulledpork.py[1223834]: Writing blocklist file to:  /usr/local/etc/lists/default.blocklist
Nov 30 16:04:43 example pulledpork.py[1223834]: Sending Snort process the reload signal (PID 1223652).
Nov 30 16:04:43 example pulledpork.py[1223834]: WARNING: Error sending SIGHUP to Snort3 process: [Errno 3] No such process
Nov 30 16:04:43 example systemd[1]: pulledpork3.service: Main process exited, code=exited, status=255/EXCEPTION
Nov 30 16:04:43 example systemd[1]: pulledpork3.service: Failed with result 'exit-code'.
Nov 30 16:04:43 example systemd[1]: Failed to start Runs PulledPork3 to update Snort 3 Rulesets.
Nov 30 16:04:43 example systemd[1]: pulledpork3.service: Consumed 2.104s CPU time.
"

Journal logs from snort3:
"
Nov 30 16:04:42 example snort[1223652]: Snort (PID 1223652) caught fatal signal: SIGSEGV (11)
Nov 30 16:04:42 example snort[1223652]: Version: 3.1.18.0
Nov 30 16:04:42 example snort[1223652]: Backtrace:
Nov 30 16:04:42 example snort[1223652]:   #0 0x7f6c6a085400 in _ZL4evalPvR6CursorPN5snort6PacketE+0xa0
Nov 30 16:04:42 example systemd[1]: snort3.service: Main process exited, code=killed, status=11/SEGV
Nov 30 16:04:42 example systemd[1]: snort3.service: Failed with result 'signal'.
Nov 30 16:04:42 example systemd[1]: snort3.service: Consumed 18.906s CPU time.
"

I tested it when snort3 is running in one process or using multithread with option "-z" but it behaves same and snort3 always stops.


Running installation at ubuntu20.04LTS server.
Snort3 Version: 3.1.18.0
PuledPork Version: v3.0.0.4

Thank you for any help.

--
S pozdravom
With kind regards,
jacomo77

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.