Snort mailing list archives
Re: Persistent problems with rule updates for Registerd Users
From: "Michael Steele" <michaels () winsnort com>
Date: Thu, 3 Jan 2013 23:20:42 -0500
Here is the problem. 1) The snort binary contains a snort.conf , classification.config, reference.config, and a threshold.conf 2) The rules tarball contain a snort.conf , classification.config, reference.config, and a threshold.conf 3) The snort.org site has a downloadable snort.conf and also a classification.config The snort.conf in in all three location above ALL different. The classification.config in location 1 and 2 above are different. However, the classification.config in location 1 matches location 3. The reference.config in location 1 and 2 above are different. The threshold.conf in location 1 and 2 above are different. Why is it that both groups are having the rules tarball updated on a daily basis, but they are not having the configuration files update to be current for that day? It really doesn't matter what files are in the Snort binaries, as long as all the files in the rule sets are current for the day. As a new Registered User, shouldn't the they be able to download the latest snort binary, download the latest rule set, extract the latest ruleset right into the snort folder and get the very latest in rules (30 days old), and the most current configurations on any single day. I'm not sure what's being distributed in the Subscribers rule set as they may be getting current configuration files along with the current zero day rule releases. The best guess I can come to is to download the current rule set. Then download the current snort.conf, then download the current classification.config, and then over write those two files in the current rule set. This looks like the only way to get a complete set of current rules and configurations? Best regards, Michael... From: Joel Esler [mailto:jesler () sourcefire com] Sent: Thursday, January 03, 2013 3:05 PM To: Michael Steele Cc: snort-users () lists sourceforge net Subject: Re: [Snort-users] Persistent problems with rule updates for Registerd Users On Jan 2, 2013, at 9:23 PM, Michael Steele <michaels () winsnort com <mailto:michaels () winsnort com> > wrote: I just downloaded the latest rule set for the 'Registered Users' titled <https://www.snort.org/downloads/2117> snortrules-snapshot-2940.tar.gz. It STILL contains an OLD snort.conf. It's missing port assignments, and it still includes the 'output database' option. The registered users file is 30 days behind the subscribers. It has an older snort.conf. This was a previous problem and there were assurances it was taken care of. Looks like someone is not doing their job? That's my job, and yes, it was done. You are 30 days behind. Can someone pull the Registered Users tarball ( <https://www.snort.org/downloads/2117> snortrules-snapshot-2940.tar.gz) and verify all the rules and configuration files are up-to-date? No. They are 30 days behind. -- Joel Esler Senior Research Engineer, VRT OpenSource Community Manager Sourcefire
------------------------------------------------------------------------------ Master HTML5, CSS3, ASP.NET, MVC, AJAX, Knockout.js, Web API and much more. Get web development skills now with LearnDevNow - 350+ hours of step-by-step video tutorials by Microsoft MVPs and experts. SALE $99.99 this month only -- learn more at: http://p.sf.net/sfu/learnmore_122812
_______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- Persistent problems with rule updates for Registerd Users Michael Steele (Jan 02)
- Re: Persistent problems with rule updates for Registerd Users Russ Combs (Jan 03)
- Re: Persistent problems with rule updates for Registerd Users Michael Steele (Jan 03)
- Re: Persistent problems with rule updates for Registerd Users Joel Esler (Jan 03)
- Re: Persistent problems with rule updates for Registerd Users Michael Steele (Jan 03)
- Re: Persistent problems with rule updates for Registerd Users Joel Esler (Jan 03)
- Re: Persistent problems with rule updates for Registerd Users Jeff Kell (Jan 03)
- Re: Persistent problems with rule updates for Registerd Users Michael Steele (Jan 03)
- Re: Persistent problems with rule updates for Registerd Users Joel Esler (Jan 04)
- Re: Persistent problems with rule updates for Registerd Users Michael Steele (Jan 04)
- Re: Persistent problems with rule updates for Registerd Users Joel Esler (Jan 04)
- Re: Persistent problems with rule updates for Registerd Users Michael Steele (Jan 04)
- Re: Persistent problems with rule updates for Registerd Users Jeff Kell (Jan 04)
- Re: Persistent problems with rule updates for Registerd Users Michael Steele (Jan 04)
- Re: Persistent problems with rule updates for Registerd Users Joel Esler (Jan 04)
- Re: Persistent problems with rule updates for Registerd Users Michael Steele (Jan 03)
- Re: Persistent problems with rule updates for Registerd Users Russ Combs (Jan 03)