Re: Snort Rules - Version Not Listed
Justin Chin-You via Snort-users <[email protected]> Wed, 31 Jul 2024 21:22:29 +0000
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <010201910aac4de1-dab239f1-2445-48df-bdc5-ad76a2c49940-000000@eu-west-1.amazonses.com> |
Thanks Michael! That’s the path I decided on trying, I adjusted pull pork and manually pulled the 3200 ruleset figuring it was the closest, I haven’t had a chance today to test but will add it to my homework tonight! On Jul 31, 2024, at 5:14 PM, Michael Steele <[email protected]> wrote: Snort Rules - Version Not Listed The below works for me but you are running 3310 which does not work. This was a chronic problem with 2.9 as it took forever for Sourcefire to make sure the latest Snort release had a matching rule release. I’m guessing that 3200 is the latest in the Registered side. There is not a version 3200 listed in the Subscription side. It looks like Sourcefire is having some issues? https://www.snort.org/rules/snortrules-snapshot-3200.tar.gz?oinkcode=<oinkcode> Be sure to replace <oinkcode> with your actual oinkcode. Those rules should work with 3310? If you are running pulledpork it should be configured to whatever version of snort you are running and should pull the correct rules set? WINSNORT.com Management… -- ******************** Established ~ 2003 ********************** * FREE Windows Intrusion Detection System (WinIDS) Tutorials * * ~~ FREE Windows Support Forums ~~ * * Visit @ http://winsnort.com * * Snort: Open Source Network IDS - http://snort.org * ************************************************************** Best regards, Michael... From: Snort-users <[email protected]> On Behalf Of Justin Chin-You via Snort-users Sent: Tuesday, July 30, 2024 11:28 PM To: [email protected] Subject: [Snort-users] Snort Rules - Version Not Listed Hi All, Hoping someone might be able to guide me a little. I just built Snort and pulled version 3.3.1.0 from Git. I've gotten to the part where I get to pull my updates, per the rules download page my URL should be formatted: https://www.snort.org/rules/snortrules-snapshot-<version>.tar.gz.md5?oinkcode=<oinkcode> <https://www.snort.org/rules/snortrules-snapshot-%3cversion%3e.tar.gz.md5?oinkcode=%3coinkcode%3e> I was expecting this to work: https://www.snort.org/rules/snortrules-snapshot-3310.tar.gz.md5?oinkcode= <https://www.snort.org/rules/snortrules-snapshot-3310.tar.gz.md5?oinkcode=%3ccode%3e> However, this definitely doesn't work. Anyway I can determine what version of the rulesets I need for my specific version of Snort? Thanks! _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette