[Snort-users] NIDS on large (>500MB) pcap dumps

Tony Robinson deusexmachina667 at ...11827...
Fri Dec 14 19:23:03 EST 2012


Wait... Not to threadjack, but can pp actually *Rebuild* SO rules? I know
it builds the unified SO rule stub file based on your rule policy... but
don't recall an option to rebuild the actual SO rules. If it can do this,
what manual did I not read? and/or what options do I need to be using?

-DA

On Fri, Dec 14, 2012 at 6:11 PM, Jefferson, Shawn <
Shawn.Jefferson at ...14448...> wrote:

> You need to rebuild your so rule files.  Pulled Pork can do this for you.
>
>
> -----Original Message-----
> From: Steve Marotta [mailto:smarotta at ...16014...]
> Sent: Friday, December 14, 2012 2:07 PM
> To: Balasubramaniam Natarajan
> Cc: snort-users at lists.sourceforge.net
> Subject: Re: [Snort-users] NIDS on large (>500MB) pcap dumps
>
> Thanks to everyone for the responses. I compiled Snort from source (I had
> originally installed using Ubuntu apt-get), configuring it with
> --enable-large-pcap. I downloaded rule set 2930 and set it up, configured
> the snort.conf file, and when I try to run it now, I get:
>
> ERROR: The dynamic detection library
> "/usr/local/snort/lib/snort_dynamicrules/imap.so" version 1.0 compiled with
> dynamic engine library version 1.16 isn't compatible with the current
> dynamic engine library
> "/usr/local/snort/lib/snort_dynamicengine/libsf_engine.so" version 1.17.
> Fatal Error, Quitting..
>
> Both of these files are in the same rule set that I downloaded. I can
> understand a conflict between two different things that I've installed, but
> a conflict between two items in one package is puzzling.
>
> So I'm figuring that the issue is that I installed Snort version 2.9.4 but
> could only get rulesets for 2.9.3.x. I'm looking around for an older
> version of Snort so I can use the only rules I can get access to, and I
> can't seem to find anywhere that lets me download 2.9.3.0 or 2.9.3.1. Am I
> missing something?
>
>
>
>
>
>
>
> THIS MESSAGE IS INTENDED FOR THE USE OF THE PERSON TO WHOM IT IS
> ADDRESSED. IT MAY CONTAIN INFORMATION THAT IS PRIVILEGED, CONFIDENTIAL AND
> EXEMPT FROM DISCLOSURE UNDER APPLICABLE LAW. If you are not the intended
> recipient, your use of this message for any purpose is strictly prohibited.
> If you have received this communication in error, please delete the message
> and notify the sender so that we may correct our records.
>
>
>
>
>
>
>
> ------------------------------------------------------------------------------
> LogMeIn Rescue: Anywhere, Anytime Remote support for IT. Free Trial
> Remotely access PCs and mobile devices and provide instant support Improve
> your efficiency, and focus on delivering more value-add services Discover
> what IT Professionals Know. Rescue delivers
> http://p.sf.net/sfu/logmein_12329d2d
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users
>
> Please visit http://blog.snort.org to stay current on all the latest
> Snort news!
>
>
> ------------------------------------------------------------------------------
> LogMeIn Rescue: Anywhere, Anytime Remote support for IT. Free Trial
> Remotely access PCs and mobile devices and provide instant support
> Improve your efficiency, and focus on delivering more value-add services
> Discover what IT Professionals Know. Rescue delivers
> http://p.sf.net/sfu/logmein_12329d2d
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users
>
> Please visit http://blog.snort.org to stay current on all the latest
> Snort news!
>



-- 
when does reality end? when does fantasy begin?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20121214/bdd7ae62/attachment.html>


More information about the Snort-users mailing list