Re: Fialed to download registered rules (release 3.1.59.0)
Carlos Lopez via Snort-users <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <PRAP251MB0567D67373B1FC633665AEDFDB9B9@PRAP251MB0567.EURP251.PROD.OUTLOOK.COM> |
Many thanks David. It works if I use snort version 3.1.47.0 in pulledpork3 Regards, C. L. Martinez From: David Melczer <[email protected]> Sent: Wednesday, April 12, 2023 16:47 To: Carlos Lopez <[email protected]>; [email protected] Subject: RE: Fialed to download registered rules (release 3.1.59.0) There are many times when the snort rules aren’t published to match a specific snort version. You can override which rules get pulled in pulledpork.conf…uncomment and change snort_version to whatever is available (I’m using 3.1.35.0 currently, despite being on 3.1.59.0). I believe it is also advisable to use the LightSPD_ruleset instead of the community_ruleset when using pulledpork3. I hope this information helps. -Dave David Z. Melczer | Director of Information Technology Greenbaum, Rowe, Smith & Davis LLP Delivery: 99 Wood Avenue South | Iselin, NJ | 08830 Mailing: P.O. Box 5600 | Woodbridge, NJ | 07095 T: 732.476.3284 | F: 732.476.3285 | vCard<http://www.greenbaumlaw.com/vcard-1999.vcf> [cid:[email protected]] greenbaumlaw.com<http://www.greenbaumlaw.com/> [cid:[email protected]]<https://www.linkedin.com/company/greenbaum-rowe-smith-&-davis-llp?trk=top_nav_home> [cid:[email protected]]<https://twitter.com/greenbaumlaw> [cid:[email protected]]<https://www.facebook.com/greenbaumlaw?fref=ts&ref=br_tf> From: Snort-users <[email protected]<mailto:[email protected]>> On Behalf Of Carlos Lopez via Snort-users Sent: Wednesday, April 12, 2023 10:18 AM To: [email protected]<mailto:[email protected]> Subject: [Snort-users] Fialed to download registered rules (release 3.1.59.0) *** External Email Message *** Hi all, I have just setup a FreeBSD 13.2 with Snort 3.1.59.0 and when I try to download registered rules with pulledpork3, the following error appears: Entering: Config.validate() Exiting: Config.validate() Setting up the working directory structure in: /tmp/PulledPork-2023.04.12-14.12.25 - Successfully setup the working directory Working directory is: WorkingDirectory(path:/tmp/PulledPork-2023.04.12-14.12.25, cleanup_on_exit:True) Determining Snort version from executable - Running Snort using: snort -V - Output from Snort: b'\n ,,_ -*> Snort++ <*-\n o" )~ Version 3.1.59.0\n \'\'\'\' By Martin Roesch & The Snort Team\n http://snort.org/contact#team\n Copyright (C) 2014-2023 Cisco and/or its affiliates. All rights reserved.\n Copyright (C) 1998-2013 Sourcefire, Inc., et al.\n Using DAQ version 3.0.11\n Using LuaJIT version 2.1.0-beta3\n Using OpenSSL 1.1.1t-freebsd 7 Feb 2023\n Using libpcap version 1.9.1\n Using PCRE version 8.45 2021-06-15\n Using ZLIB version 1.2.13\n Using Hyperscan version 5.4.0 2023-02-19\n Using LZMA version 5.4.1\n\n' - Snort version is: 3.1.59.0 --------------------------------- After parsing the command line and configuration file, this is what I know: Program will terminate when encountering an error or warning. Oinkcode will be obfuscated in the output (this is a good thing). Temporary directory is: /tmp Temporary working directory will be deleted at the end. The Snort version number used for processing is: 3.1.59.0 The distro used for processing is: ubuntu-x64 The ips policy used for processing is: balanced Pre-compiled (.so) rules will not be processed. Rulesets will be downloaded from: Snort Registered Ruleset The following rules files will not be included in rulesets: includes.rules, snort3-deleted.rules Rule Output mode is: simple Rules from Local rules file will be included: /usr/local/etc/snort/rules/local.rules All Rules will be written to a single file: /usr/local/etc/snort/rules/pulledpork.rules Disabled rules will not be written to the rules file The rule_mode is: simple No Blocklists will be downloaded. The state_order is: ['enable', 'drop', 'disable'] Snort will NOT be reloaded with new configuration. --------------------------------- Loading rulesets Downloading Snort rulesets from Internet Loading rules archive: - Source: https://snort.org/rules/snortrules-snapshot-31590.tar.gz WARNING: Unable to load rules archive: 422 Client Error: Unprocessable Entity for url: https://snort.org/rules/snortrules-snapshot-31590.tar.gz?oinkcode=<hidden<https://snort.org/rules/snortrules-snapshot-31590.tar.gz?oinkcode=%3chidden>> --------------------------------- Attempting to delete working directory: /tmp/PulledPork-2023.04.12-14.12.25 - Successfully deleted working directory Which it is correct …. There is no rules for 3.1.59.0 release in Snort Rules and IDS Software Download<https://www.snort.org/downloads#rules> … Do I need to download community rules or rules for 3.1.47.0 version? Regards, C. L. Martinez Disclaimer This e-mail (including any attachments) is intended only for the exclusive use of the individual to whom it is addressed. The information contained hereinafter may be proprietary, confidential, privileged and exempt from disclosure under applicable law. If the reader of this e-mail is not the intended recipient or agent responsible for delivering the message to the intended recipient, the reader is hereby put on notice that any use, dissemination, distribution or copying of this communication is strictly prohibited. If the reader has received this communication in error, please immediately notify the sender by telephone (732-549-5600) or e-mail and delete all copies of this e-mail and any attachments. Thank you. _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
image001.jpg
(image/jpeg, 3.4 KB) - not displayed
image002.png
(image/png, 687 B) - not displayed
image003.png
(image/png, 670 B) - not displayed
image004.png
(image/png, 637 B) - not displayed