Snort mailing list archives

Re: snort.conf in 2.9.2 and VRT tarball


From: Joel Esler <jesler () sourcefire com>
Date: Fri, 30 Dec 2011 13:53:47 -0500

This has been corrected.  Please see
http://www.snort.org/vrt/snort-conf-configurations/ for a correct copy.

On Tue, Dec 27, 2011 at 6:54 PM, Miguel Alvarez <miguellvrz9 () gmail com>wrote:

I may have missed the communication about this so if that is the case,
I apologise.  I was just wanting to update my 2.9.1.2 snort.conf for
2.9.2 but I noticed the snort.conf that ships with the 2.9.2 tarball
doesn't appear to include the reputation preprocessor and have the
WHITE_LIST_PATH or BLACK_LIST_PATH variables.  So I downloaded the
current VRT rule update for 2.9.2 and the snort.conf that ships with
that appears to be from 2.9.1.2 and it does include the reputation
configurations?

$ tar -zxvf snortrules-snapshot-2920.tar.gz
$ grep -A1 "Compatible with Snort Versions" etc/snort.conf
#     Compatible with Snort Versions:
#     VERSIONS : 2.9.1.2

$ md5sum snortrules-snapshot-2920.tar.gz
90242c0edf92cb44e05185487c36440b  snortrules-snapshot-2920.tar.gz

Is that right?  I'm just a little confused at the moment :-(


------------------------------------------------------------------------------
Write once. Port to many.
Get the SDK and tools to simplify cross-platform app development. Create
new or port existing apps to sell to consumers worldwide. Explore the
Intel AppUpSM program developer opportunity. appdeveloper.intel.com/join
http://p.sf.net/sfu/intel-appdev
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest
Snort news!




-- 
Joel Esler | http://blog.snort.org | http://vrt-blog.snort.org |
http://blog.clamav.net
Twitter:  http://twitter.com/snort
------------------------------------------------------------------------------
Ridiculously easy VDI. With Citrix VDI-in-a-Box, you don't need a complex
infrastructure or vast IT resources to deliver seamless, secure access to
virtual desktops. With this all-in-one solution, easily deploy virtual 
desktops for less than the cost of PCs and save 60% on VDI infrastructure 
costs. Try it free! http://p.sf.net/sfu/Citrix-VDIinabox
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: