Re: Fialed to download registered rules (release 3.1.59.0)
David Melczer via Snort-users <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <BLAPR10MB53774C1EAD35BF697551B655A19B9@BLAPR10MB5377.namprd10.prod.outlook.com> |
There are many times when the snort rules aren’t published to match a specific snort version. You can override which rules get pulled in pulledpork.conf…uncomment and change snort_version to whatever is available (I’m using 3.1.35.0 currently, despite being on 3.1.59.0). I believe it is also advisable to use the LightSPD_ruleset instead of the community_ruleset when using pulledpork3. I hope this information helps. -Dave David Z. Melczer | Director of Information Technology Greenbaum, Rowe, Smith & Davis LLP Delivery: 99 Wood Avenue South | Iselin, NJ | 08830 Mailing: P.O. Box 5600 | Woodbridge, NJ | 07095 T: 732.476.3284 | F: 732.476.3285 | vCard<http://www.greenbaumlaw.com/vcard-1999.vcf> [cid:[email protected]] greenbaumlaw.com<http://www.greenbaumlaw.com/> [cid:[email protected]]<https://www.linkedin.com/company/greenbaum-rowe-smith-&-davis-llp?trk=top_nav_home> [cid:[email protected]]<https://twitter.com/greenbaumlaw> [cid:[email protected]]<https://www.facebook.com/greenbaumlaw?fref=ts&ref=br_tf> From: Snort-users <[email protected]> On Behalf Of Carlos Lopez via Snort-users Sent: Wednesday, April 12, 2023 10:18 AM To: [email protected] Subject: [Snort-users] Fialed to download registered rules (release 3.1.59.0) *** External Email Message *** Hi all, I have just setup a FreeBSD 13.2 with Snort 3.1.59.0 and when I try to download registered rules with pulledpork3, the following error appears: Entering: Config.validate() Exiting: Config.validate() Setting up the working directory structure in: /tmp/PulledPork-2023.04.12-14.12.25 - Successfully setup the working directory Working directory is: WorkingDirectory(path:/tmp/PulledPork-2023.04.12-14.12.25, cleanup_on_exit:True) Determining Snort version from executable - Running Snort using: snort -V - Output from Snort: b'\n ,,_ -*> Snort++ <*-\n o" )~ Version 3.1.59.0\n \'\'\'\' By Martin Roesch & The Snort Team\n http://snort.org/contact#team\n Copyright (C) 2014-2023 Cisco and/or its affiliates. All rights reserved.\n Copyright (C) 1998-2013 Sourcefire, Inc., et al.\n Using DAQ version 3.0.11\n Using LuaJIT version 2.1.0-beta3\n Using OpenSSL 1.1.1t-freebsd 7 Feb 2023\n Using libpcap version 1.9.1\n Using PCRE version 8.45 2021-06-15\n Using ZLIB version 1.2.13\n Using Hyperscan version 5.4.0 2023-02-19\n Using LZMA version 5.4.1\n\n' - Snort version is: 3.1.59.0 --------------------------------- After parsing the command line and configuration file, this is what I know: Program will terminate when encountering an error or warning. Oinkcode will be obfuscated in the output (this is a good thing). Temporary directory is: /tmp Temporary working directory will be deleted at the end. The Snort version number used for processing is: 3.1.59.0 The distro used for processing is: ubuntu-x64 The ips policy used for processing is: balanced Pre-compiled (.so) rules will not be processed. Rulesets will be downloaded from: Snort Registered Ruleset The following rules files will not be included in rulesets: includes.rules, snort3-deleted.rules Rule Output mode is: simple Rules from Local rules file will be included: /usr/local/etc/snort/rules/local.rules All Rules will be written to a single file: /usr/local/etc/snort/rules/pulledpork.rules Disabled rules will not be written to the rules file The rule_mode is: simple No Blocklists will be downloaded. The state_order is: ['enable', 'drop', 'disable'] Snort will NOT be reloaded with new configuration. --------------------------------- Loading rulesets Downloading Snort rulesets from Internet Loading rules archive: - Source: https://snort.org/rules/snortrules-snapshot-31590.tar.gz WARNING: Unable to load rules archive: 422 Client Error: Unprocessable Entity for url: https://snort.org/rules/snortrules-snapshot-31590.tar.gz?oinkcode=<hidden<https://snort.org/rules/snortrules-snapshot-31590.tar.gz?oinkcode=%3chidden>> --------------------------------- Attempting to delete working directory: /tmp/PulledPork-2023.04.12-14.12.25 - Successfully deleted working directory Which it is correct …. There is no rules for 3.1.59.0 release in Snort Rules and IDS Software Download<https://www.snort.org/downloads#rules> … Do I need to download community rules or rules for 3.1.47.0 version? Regards, C. L. Martinez Disclaimer The information contained in this communication from the sender is confidential. It is intended solely for use by the recipient and others authorized to receive it. If you are not the recipient, you are hereby notified that any disclosure, copying, distribution or taking action in relation of the contents of this information is strictly prohibited and may be unlawful. This email has been scanned for viruses and malware, and may have been automatically archived by Mimecast Ltd, an innovator in Software as a Service (SaaS) for business. Providing a safer and more useful place for your human generated data. Specializing in; Security, archiving and compliance. To find out more visit the Mimecast website. _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
image001.jpg
(image/jpeg, 3.4 KB) - not displayed
image002.png
(image/png, 687 B) - not displayed
image003.png
(image/png, 670 B) - not displayed
image004.png
(image/png, 637 B) - not displayed