[Snort-users] URL to download VRT rules

Weir, Jason jason.weir at ...14916...
Fri Oct 29 16:09:31 EDT 2010


This is the oinkmaster url I use to get the ET ruleset
 
url=http://rules.emergingthreats.net/open/snort-2.8.6/emerging.rules.tar
.gz

No oinkcode needed....  I can't answer you on the 2.9 compatibility you
might as over on the et list..
 
http://lists.emergingthreats.net/mailman/listinfo/emerging-sigs
 
-J
 

	-----Original Message-----
	From: Alejandro Cabrera Obed [mailto:aco1967 at ...11827...] 
	Sent: Friday, October 29, 2010 3:56 PM
	To: Kevin Ross; snort-users at lists.sourceforge.net
	Subject: Re: [Snort-users] URL to download VRT rules
	
	
	OK, just two questions: 

	1) Are ET ruleset suitable for Snort 2.9 ??? Because I can't see
the download link for this Snort version at
http://rules.emergingthreats.net/

	2) How can I download ET ruleset automatically similar to
oinkmaster usage (with cron)???

	Thanks a lot
	



	2010/10/28 Kevin Ross <kevross33 at ...14012...>
	

		I think you may also find use in the emergingthreats
rules www.emergingthreats.net. Latest rulesets are here:
		
	
http://rules.emergingthreats.net/open-nogpl/snort-2.8.4/emerging.rules.t
ar.gz
		
		I would recommend you upgrade though to at least snort
2.8.6.1 so you can make use of the improvements and http_modifiers.
		
	
http://rules.emergingthreats.net/open/snort-2.8.6/emerging.rules.tar.gz
		
		In ET a lot of focus on malware command and control,
malware, viruses and current things going on. A worthwhile ruleset to
include to detect stuff within your network. 
		
		Regards, Kevin
		
		
		On 28 October 2010 16:09, Alejandro Cabrera Obed
<aco1967 at ...11827...> wrote:
		

			Dear all, I've registered in snort.org to
download the VRT rules....I have Snort 2.8.5.3. 

			I use oinkmaster to download the rules, but what
is the new URL I have to use:

			

			*	
				
				
				This:
	
http://www.snort.org/reg-rules/snortrules-snapshot-2853.tar.gz/<
<http://www.snort.org/reg-rules/snortrules-snapshot-2853.tar.gz/a9e009e9
8b55441d6aeb6983048178df82d721b9> oinkcode>

			
			
			
			
			
			or this:
	
http://www.snort.org/pub-bin/oinkmaster.cgi/<oinkcode>/snortrules-snapsh
ot-2853.tar.gz
			    
			
			
			
			Thanks a lot.

_____________________________________________________________________________________________

Please visit www.nhrs.org to subscribe to NHRS email announcements and updates.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20101029/a2af6d8e/attachment.html>


More information about the Snort-users mailing list