[Snort-users] Snort IP blacklist issue

ha dinhphu hadinhphu at ...11827...
Fri Aug 14 10:25:35 EDT 2015


Good morning,

I followed the post on this webpage to install Snort on my linux box.

http://sublimerobots.com/2014/12/installing-snort-part-1/

However, on step 5, installing PulledPork for snort.

http://sublimerobots.com/2014/12/installing-snort-part-5/

I got the following error while I tried to run this command: "sudo
/usr/local/bin/pulledpork.pl -c /etc/snort/pulledpork.conf -l"

--------------------------
Checking latest MD5 for snortrules-snapshot-2975.tar.gz....
Rules tarball download of snortrules-snapshot-2975.tar.gz....
    They Match
    Done!
Checking latest MD5 for community-rules.tar.gz....
Rules tarball download of community-rules.tar.gz....
    They Match
    Done!
IP Blacklist download of http://labs.snort.org/feeds/ip-filter.blf....
Reading IP List...
Couldn't read /tmp/621.416477111296-black_list.rules - No such file or
directory
 at /usr/local/bin/pulledpork.pl line 487.
    main::read_iplist('HASH(0x1dd8148)',
'/tmp/621.416477111296-black_list.rules') called at /usr/local/bin/
pulledpork.pl line 378
    main::rulefetch('open', 'IPBLACKLIST0', '/tmp/', '
http://labs.snort.org/feeds/ip-filter.blf') called at /usr/local/bin/
pulledpork.pl line 1856
------------------------------
I searched the internet for solution but did not find any. Any help would
be greatly appreciated!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20150814/d4c84b83/attachment.html>


More information about the Snort-users mailing list