-
Notifications
You must be signed in to change notification settings - Fork 133
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Unable to process shared object rules for a previous version of snort3 #361
Comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Hey Hey, Swine people.
I'm having a problem with pulledpork, and pulling down rules for snort 3.
I'm using the latest release of snort on github (3.1.3.0)
I discovered quickly that there is not a snortrules-snapshot for version 3.1.3.0 available via snort.org
So I suppose my first question/problem is:
Are "releases" on github.com for snort 3 considered "stable"?
Should they be used in a production environment?
If so, that there aren't any snortrules-snapshots available for them is problematic.
If not, problem solved, I'll just download the version of snort3 specified on snort.org.
That brings me to my primary issue: if I run pulledpork.pl with the "-S" argument to specify a previous version of snort3 (e.g. -S 3.1.0.0) in order to download rules, it expects there to be a snort.conf file.
Here is my pulledpork.conf:
Here are the arguments that I run for pulledpork.pl:
pulledpork.pl -W -vv -c /usr/local/etc/pulledpork/pulledpork.conf -S 3.1.0.0 -l -P -E
Here is the error I get from the verbose output:
"Why don't you get rid of the config_path argument, then?"
Here's what happens when I remove the config_path option from my pulledpork.conf file:
Note: I was able to get pulledpork to work by adding in the -T (text-only rules) option:
pulledpork.pl -W -vv -c /usr/local/etc/pulledpork/pulledpork.conf -S 3.1.0.0 -l -P -E -T
My problem with that is that means I don't get any SO rules. That's somewhat annoying.
The text was updated successfully, but these errors were encountered: