Snort mailing list archives

pulled pork - snort dynamic rules on mac OS X


From: Andrew Shagayev <drewshg () gmail com>
Date: Tue, 17 Mar 2015 22:17:20 -0700

Snort 2.9.7.0
PP 0.7.1
OSX Yosemite 10.10.2

When I run Snort, getting warnings:

WARNING: No dynamic libraries found in directory
/usr/local/lib/snort_dynamicrules.

and

WARNING: ip4 normalizations disabled because not inline.
WARNING: tcp normalizations disabled because not inline.
WARNING: icmp4 normalizations disabled because not inline.
WARNING: ip6 normalizations disabled because not inline.
WARNING: icmp6 normalizations disabled because not inline.

I'm trying to find out how to setup dynamic rules for Snort on my mac.
Seems like Pulled Pork doesn't do the job on OS X.
So when I run it I get "Fly Piggy Fly", but my
/usr/local/lib/snort_dynamicrules/  is still empty.

*Shouldn't PulledPork copy the appropriate precompiled so-rules to there on
OSX?*
*Or should it compile them automatically for each OS (including OSX)?*
*Or should I copy them manually? And in this case which ones should I copy?*

There are rules for different os in so_rules/precompiled/  but there are no
directory which says Darwin or OSX.

Please give me a hint.
I'll really appreciate the help!

Thank you!
-- 
A.S.
------------------------------------------------------------------------------
Dive into the World of Parallel Programming The Go Parallel Website, sponsored
by Intel and developed in partnership with Slashdot Media, is your hub for all
things parallel software development, from weekly thought leadership blogs to
news, videos, case studies, tutorials and more. Take a look and join the 
conversation now. http://goparallel.sourceforge.net/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: