• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Snort and Backdoor Rules not working

Scheduled Pinned Locked Moved pfSense Packages
6 Posts 4 Posters 9.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A
    AhnHEL
    last edited by Sep 16, 2007, 7:13 AM Sep 15, 2007, 10:25 PM

    Ruleset was updated yesterday and I noticed Snort wasnt blocking spyware from newegg.com anymore, looked in the logs and confirmed snort showed up as not starting successfully, promiscuous mode disabled, and some other complaint about backdoor rules

    Sep-13-2007.5:17:18 PM.Daemon.Error.10.33.40.1.UDP.Sep 13 17:17:21 snort[4709]: FATAL ERROR: Unable to open rules file: /usr/local/etc/snort/rules/backdoor.rules or /usr/local/etc/snort//usr/local/etc/snort/rules/backdoor.rules….............

    Unchecked this rule and snort is working again, can anyone else confirm this.

    Using ac performance method with 2 gigs of RAM/full install on white box

    AhnHEL (Angel)

    1 Reply Last reply Reply Quote 0
    • A
      AhnHEL
      last edited by Sep 16, 2007, 7:13 AM Sep 16, 2007, 7:11 AM

      Ok, tracked it all down to Backdoor rules, Netbios, and Misc. rules.  These 3 categories are not allowing Snort to initialize.  Are any of these 3 problematic for anyone else or is it something within my own setup that causes this?

      I have all other rules enabled and snort is successfully working, alerting and blocking.

      Latest snort update 9/11/07

      AhnHEL (Angel)

      1 Reply Last reply Reply Quote 0
      • W
        welliott
        last edited by Sep 20, 2007, 12:18 PM

        Have had the issue with only the Netbios rules myself. As soon as I check it and save snort crashes and won't restart.

        1 Reply Last reply Reply Quote 0
        • C
          coolcat1975
          last edited by Oct 26, 2007, 11:45 PM

          the following rules are not working here:

          pfsense in ac mode

          backdoor
          content-replace
          misc
          netbios
          web-php

          in lowmem mode snort works fine

          regards

          cc

          1 Reply Last reply Reply Quote 0
          • A
            AhnHEL
            last edited by Nov 6, 2007, 10:57 PM

            I got Netbios to work if I disable Exploit and Chat.  Rule Categories are so finicky with Snort.

            Just noticed too that the recent update 11/6/07 doesnt  reflect my own ruleset when i compare it to the changelog.  For example SPYWARE-PUT Adware adblaster 2.0 runtime detection is not listed in the Deleted category.  According to the 11/6 changelog this rule was moved to Deleted but my ruleset still shows the rule in Spyware-Put.  I am a Premium member and I'm referring to the 2.6 changelog.

            http://www.snort.org/vrt/docs/ruleset_changelogs/2_6/changes-2007-11-06.html

            AhnHEL (Angel)

            1 Reply Last reply Reply Quote 0
            • T
              trendchiller
              last edited by Nov 8, 2007, 8:43 PM

              sql rules also are a problem…

              in lowmem mode it works fine without sql...

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received