Forums

Resolved
0 votes
ClearOS release 7.8.1 Snort 2.9.6.2
Rules can be update from community rules - https://www.snort.org/downloads/community/community-rules.tar.gz?
If can how do this?
Friday, August 28 2020, 01:44 PM
Share this post:
Responses (9)
  • Accepted Answer

    Wednesday, September 02 2020, 07:46 AM - #Permalink
    Resolved
    0 votes
    Presumably you've done something wrong and disabled all the existing GPL rules. Note any additional rules you add yourself will not show in the webconfig. From memory, if you look at your logs, you will see what rules are being loaded.
    The reply is currently minimized Show
  • Accepted Answer

    Wednesday, September 02 2020, 06:49 AM - #Permalink
    Resolved
    0 votes
    Snort is starting. Bit in grpah interface there is no any rules, see attach. How can i testing snort is work?
    Attachments:
    The reply is currently minimized Show
  • Accepted Answer

    Tuesday, September 01 2020, 07:03 PM - #Permalink
    Resolved
    0 votes
    So try deleting the line.If doing it programatically, delete it by its sid.
    The reply is currently minimized Show
  • Accepted Answer

    Tuesday, September 01 2020, 06:04 PM - #Permalink
    Resolved
    0 votes
    I download https://rules.emergingthreats.net/open-nogpl/snort-2.9.0/ rules. Insert in snort.conf

    And have error
    WARNING: /etc/snort.d/rules/emerging-all.rules(627) threshold (in rule) is deprecated; use detection_filter instead.
    FATAL ERROR: /etc/snort.d/rules/emerging-all.rules(42918) Bad rule in rules file: tcp
    The reply is currently minimized Show
  • Accepted Answer

    Saturday, August 29 2020, 02:49 PM - #Permalink
    Resolved
    0 votes
    Search the forums for "Emerging Threats".
    The reply is currently minimized Show
  • Accepted Answer

    Saturday, August 29 2020, 02:32 PM - #Permalink
    Resolved
    0 votes
    Yes in rule conf is older version than i have. I install snort from marketplace(app ids). Check update, there are no update. How can i update snort without marketplace. And still it work ?
    The reply is currently minimized Show
  • Accepted Answer

    Saturday, August 29 2020, 01:08 PM - #Permalink
    Resolved
    0 votes
    So possibly there is a bad rule in the rule set or you need a later version of snort for that rule to work.
    The reply is currently minimized Show
  • Accepted Answer

    Saturday, August 29 2020, 12:33 PM - #Permalink
    Resolved
    2 votes
    I'm add line but have error FATAL ERROR: /etc/snort.d/rules/gpl/community.rules(3522): unknown modifier "bitmask 0x8000"
    The reply is currently minimized Show
  • Accepted Answer

    Friday, August 28 2020, 04:09 PM - #Permalink
    Resolved
    0 votes
    You'd need to add a line to /etc/snort.conf to reference the new rules. You also need to make sure there are no duplicates with the current rule set. There is a thread in the forums about integrating the Emerging Threats rules. You may want to see how that was scripted if this rule set gets regularly updated.

    I am not sure what to do with the sid-msg.map but I don't think it is important.
    The reply is currently minimized Show
Your Reply