Problem with SID Management in Snort



  • Has anyone ever encountered a problem using SID Management that some of the rules are not "properly" enabled?

    efa47645-aa79-4c7b-bc6a-07d0a45b3883-image.png

    I help myself through SID Management by turning on enablesid-sample.conf

    0acd3055-9703-4eb1-b4ca-0f4e978538b5-image.png

    with the following rules:

    What am I doing wrong?



  • 1b8b413d-5d3d-4edd-a144-d769111e2e54-image.png
    cc6e40c4-e5b5-4159-ab08-8cd3d3de3e11-image.png
    b2e3190d-b9ba-427f-b60c-9657487fdd41-image.png
    1f65e427-c058-49ca-95a5-103b2ffd8aaf-image.png



  • I'm quite confused by the four different enablesid-sample.conf file screencaps you posted. Are those all in the same file, or did you actually post four different versions?

    The SID MGMT logic is not meant to work the way you are doing it. It is not designed to enable every single rule in every category. It's never been tested for that -- might work, or might not.

    Why are you doing this anyway? That most definitely is not the correct way to configure an IDS.


Log in to reply