Snort SID Management bug?
-
I mentioned this in another thread but it does not seem to be getting much traction.
https://forum.pfsense.org/index.php?topic=56267.msg688454#msg688454I'm using snort package 3.2.9.2_15 on pfsense 2.3.2_1.
I'm running into a strange issue when using a disablesid.conf file where the SIDs are not being disabled, I still see them triggering alerts, and when I check the rules in the snort interface I see "{$textse}"; " preceding SIDs that were specified in servers-disablesid.conf. See attachment
I've tried removing all of the comments in the conf file and rebuilding without luck. I've also tried limiting the file to just a couple of preprocessor rules only to see the same behavior. There are no hints in sid_changes.log. Has anyone else run into this? I apologize if if I've missed this being reported in another thread.