Snort mailing list archives

Re: Re: [Snort-sigs] Oinkmaster questions


From: Andreas Östling <andreaso () it su se>
Date: Wed, 11 Jun 2003 11:20:53 +0200


On Tuesday 10 June 2003 15.05, Philip Davidson wrote:
Yeah, I would like to see something that would check for updates against an
md5 checksum.  That would be pretty keen.

Philip Davidson

I don't really see how checking the md5 checksum would be much help
in this case. Just because the tarball's md5 checksum matches, it doesn't
really say anything whether its content will screw things up or not.

I think the most common reason that things break when you do it fully
automated with oinkmaster is when new variables are added to snort.conf and 
used in the rules (since your local snort.conf does not get updated).
So far, this has happened very rarely though, but it's something to be
aware of. It would be easy to add an option to oinkmaster that makes it
look for variables in the distribution snort.conf and add possible missing
ones to the local snort.conf though, if people think this is a good idea.

If you really want to do the updating automatically but don't want to screw
things up because of syntax errors, simply run snort -T before possibly 
reloading the rules and have the script call for help when required.
(This of course still assumes that you automatically approve all rule changes, 
which may cause other problems even though they actually load without 
problems...)

/Andreas



-------------------------------------------------------
This SF.net email is sponsored by:  Etnus, makers of TotalView, The best
thread debugger on the planet. Designed with thread debugging features
you've never dreamed of, try TotalView 6 free at www.etnus.com.
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: