Re: Fialed to download registered rules (release 3.1.59.0)

Carlos Lopez via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <PRAP251MB0567D67373B1FC633665AEDFDB9B9@PRAP251MB0567.EURP251.PROD.OUTLOOK.COM>
Many thanks David. It works if I use snort version 3.1.47.0 in pulledpork3

Regards,
C. L. Martinez

From: David Melczer <[email protected]>
Sent: Wednesday, April 12, 2023 16:47
To: Carlos Lopez <[email protected]>; [email protected]
Subject: RE: Fialed to download registered rules (release 3.1.59.0)

There are many times when the snort rules aren’t published to match a specific snort version.  You can override which rules get pulled in pulledpork.conf…uncomment and change snort_version to whatever is available (I’m using 3.1.35.0 currently, despite being on 3.1.59.0).  I believe it is also advisable to use the LightSPD_ruleset instead of the community_ruleset when using pulledpork3.

I hope this information helps.

-Dave

David Z. Melczer  | Director of Information Technology

Greenbaum, Rowe, Smith & Davis LLP
Delivery: 99 Wood Avenue South | Iselin, NJ | 08830
Mailing: P.O. Box 5600 | Woodbridge, NJ | 07095
T: 732.476.3284  |  F: 732.476.3285  |  vCard<http://www.greenbaumlaw.com/vcard-1999.vcf>

[cid:[email protected]]
greenbaumlaw.com<http://www.greenbaumlaw.com/>
[cid:[email protected]]<https://www.linkedin.com/company/greenbaum-rowe-smith-&-davis-llp?trk=top_nav_home>
[cid:[email protected]]<https://twitter.com/greenbaumlaw>
[cid:[email protected]]<https://www.facebook.com/greenbaumlaw?fref=ts&ref=br_tf>


From: Snort-users <[email protected]<mailto:[email protected]>> On Behalf Of Carlos Lopez via Snort-users
Sent: Wednesday, April 12, 2023 10:18 AM
To: [email protected]<mailto:[email protected]>
Subject: [Snort-users] Fialed to download registered rules (release 3.1.59.0)

*** External Email Message ***

Hi all,

I have just setup a FreeBSD 13.2 with Snort 3.1.59.0 and when I try to download registered rules with pulledpork3, the following error appears:

Entering: Config.validate()
Exiting: Config.validate()
Setting up the working directory structure in: /tmp/PulledPork-2023.04.12-14.12.25
- Successfully setup the working directory
Working directory is:  WorkingDirectory(path:/tmp/PulledPork-2023.04.12-14.12.25, cleanup_on_exit:True)
Determining Snort version from executable
- Running Snort using:  snort -V
- Output from Snort:
b'\n   ,,_     -*> Snort++ <*-\n  o"  )~   Version 3.1.59.0\n   \'\'\'\'    By Martin Roesch & The Snort Team\n           http://snort.org/contact#team\n           Copyright (C) 2014-2023 Cisco and/or its affiliates. All rights reserved.\n           Copyright (C) 1998-2013 Sourcefire, Inc., et al.\n           Using DAQ version 3.0.11\n           Using LuaJIT version 2.1.0-beta3\n           Using OpenSSL 1.1.1t-freebsd  7 Feb 2023\n           Using libpcap version 1.9.1\n           Using PCRE version 8.45 2021-06-15\n           Using ZLIB version 1.2.13\n           Using Hyperscan version 5.4.0 2023-02-19\n           Using LZMA version 5.4.1\n\n'
- Snort version is: 3.1.59.0
---------------------------------
After parsing the command line and configuration file, this is what I know:
Program will terminate when encountering an error or warning.
Oinkcode will be obfuscated in the output (this is a good thing).
Temporary directory is:  /tmp
Temporary working directory will be deleted at the end.
The Snort version number used for processing is:  3.1.59.0
The distro used for processing is:  ubuntu-x64
The ips policy used for processing is:  balanced
Pre-compiled (.so) rules will not be processed.
Rulesets will be downloaded from:
        Snort Registered Ruleset
The following rules files will not be included in rulesets:  includes.rules, snort3-deleted.rules
Rule Output mode is:  simple
Rules from Local rules file will be included:  /usr/local/etc/snort/rules/local.rules
All Rules will be written to a single file:  /usr/local/etc/snort/rules/pulledpork.rules
Disabled rules will not be written to the rules file
The rule_mode is:  simple
No Blocklists will be downloaded.
The state_order is: ['enable', 'drop', 'disable']
Snort will NOT be reloaded with new configuration.
---------------------------------
Loading rulesets
Downloading Snort rulesets from Internet
Loading rules archive:
- Source:  https://snort.org/rules/snortrules-snapshot-31590.tar.gz
WARNING: Unable to load rules archive:  422 Client Error: Unprocessable Entity for url: https://snort.org/rules/snortrules-snapshot-31590.tar.gz?oinkcode=<hidden<https://snort.org/rules/snortrules-snapshot-31590.tar.gz?oinkcode=%3chidden>>
---------------------------------
Attempting to delete working directory: /tmp/PulledPork-2023.04.12-14.12.25
- Successfully deleted working directory

Which it is correct …. There is no rules for 3.1.59.0 release in Snort Rules and IDS Software Download<https://www.snort.org/downloads#rules> … Do I need to download community rules or rules for 3.1.47.0 version?

Regards,
C. L. Martinez



Disclaimer

This e-mail (including any attachments) is intended only for the exclusive use of the individual to whom it is addressed. The information contained hereinafter may be proprietary, confidential, privileged and exempt from disclosure under applicable law. If the reader of this e-mail is not the intended recipient or agent responsible for delivering the message to the intended recipient, the reader is hereby put on notice that any use, dissemination, distribution or copying of this communication is strictly prohibited. If the reader has received this communication in error, please immediately notify the sender by telephone (732-549-5600) or e-mail and delete all copies of this e-mail and any attachments. Thank you.

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
image001.jpg (image/jpeg, 3.4 KB) - not displayed
image002.png (image/png, 687 B) - not displayed
image003.png (image/png, 670 B) - not displayed
image004.png (image/png, 637 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.