• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Snort Updating problems !!!

Scheduled Pinned Locked Moved pfSense Packages
72 Posts 27 Posters 37.6k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • ?
    A Former User
    last edited by Jul 2, 2010, 12:25 AM Jul 1, 2010, 11:49 PM

    I have watched you insult users time and time again. I understand your frustred but that is no excuse to insult users.

    James

    removed

    1 Reply Last reply Reply Quote 0
    • J
      jamesdean
      last edited by Jul 2, 2010, 12:58 AM

      Taking longer than expected, seems they moved the files to https server.
      Have to figure out a way to do this.

      hxxps://s3.amazonaws.com/snort.org/rules/20100525/snortrules-snapshot-2860.tar.gz?AWSAccessKeyId

      Please be patient

      James

      1 Reply Last reply Reply Quote 0
      • X
        XIII
        last edited by Jul 2, 2010, 1:04 AM Jul 2, 2010, 1:01 AM

        Thanks for the update jamesdean, Take your time, no rush

        cdx304, which "other"  firewall do you keep referring to?
        also maybe the snort maintainer for that product fixed the problem before you even noticed there was one or shortly there after. who knows it may be there job, like I said before, most package maintainers donate their time, they have other lives and jobs. Dont like that its not working, and dont want to wait, fix it yourself, not hard to do or to learn how to do, just takes time and patience, thats the beauty of opensource.

        -Chris Stutzman
        Sys0:2.0.1: AMD Sempron 140 @2.7 1024M RAM 100GHD
        Sys1:2.0.1: Intel P4 @2.66 1024M RAM 40GHD
        freedns.afraid.org - Free DNS dynamic DNS subdomain and domain hosting.
        Check out the pfSense Wiki

        1 Reply Last reply Reply Quote 0
        • C
          chowtamah
          last edited by Jul 2, 2010, 6:18 AM

          I praise the James for his way of participating in this discussion.

          He is my Hero ::). Well done James.

          2.0.2-RELEASE (amd64)  &  2.2.2-RELEASE (amd64)

          Always trying to learn!!

          1 Reply Last reply Reply Quote 0
          • D
            darklogic
            last edited by Jul 2, 2010, 3:59 PM

            Same issue. As always, thanks James. I was looking at snorts website and they indicate under their VRT to change your oinkmaster.conf

            Oinkcode
            Downloading with your Oinkcode
            Important Note

            We are changing the way we publish rules. In June 2010 we stopped offering rules in the "snortrules-snapshot-CURRENT" format. Instead, rules are released for specific versions of Snort. You will be responsible for downloading the correct rules release for your version of Snort. The new versioning mechanism will require a four digit version in the file name. For the Subscriber and Registered releases of Snort 2.8.6.0 and Snort 2.8.5.3, the download links would look as follows:

            Configuring Oinkmaster
            In order to use Oinkmaster to update Snort with VRT rules you must edit oinkmaster.conf.

            In the oinkmaster.conf modify "url" to:

            url = http://www.snort.org/pub-bin/oinkmaster.cgi/<oinkcode here="">/<filename></filename></oinkcode>

            1 Reply Last reply Reply Quote 0
            • D
              darklogic
              last edited by Jul 2, 2010, 3:59 PM

              I hope my last post helps.

              1 Reply Last reply Reply Quote 0
              • J
                jamesdean
                last edited by Jul 2, 2010, 4:36 PM Jul 2, 2010, 4:26 PM

                I wish it was as easy as pointing to a url.

                url = http://www.snort.org/pub-bin/oinkmaster.cgi/<oinkcode here="">/ <filename>The file you get from that url you posted redirects to a https server.

                Users on the snort.org mail-lists are having trouble with that redirect.
                Suggested fix is to install a perl mod that understands https.
                I am trying to avoid using Oinkmaster perl script.

                I'm trying to do this in pure php script.

                While I am hear might as well rewrite the whole "update tab" to include snort GUI updates to.
                I been wanting to do this for a long time, I guess this is a good thing for us.

                James

                @darklogic:

                Same issue. As always, thanks James. I was looking at snorts website and they indicate under their VRT to change your oinkmaster.conf

                Oinkcode
                Downloading with your Oinkcode
                Important Note

                We are changing the way we publish rules. In June 2010 we stopped offering rules in the "snortrules-snapshot-CURRENT" format. Instead, rules are released for specific versions of Snort. You will be responsible for downloading the correct rules release for your version of Snort. The new versioning mechanism will require a four digit version in the file name. For the Subscriber and Registered releases of Snort 2.8.6.0 and Snort 2.8.5.3, the download links would look as follows:

                Configuring Oinkmaster
                In order to use Oinkmaster to update Snort with VRT rules you must edit oinkmaster.conf.

                In the oinkmaster.conf modify "url" to:

                url = http://www.snort.org/pub-bin/oinkmaster.cgi/<oinkcode here="">/ <filename></filename></oinkcode></filename></oinkcode>

                1 Reply Last reply Reply Quote 0
                • D
                  DigitalJer
                  last edited by Jul 2, 2010, 4:58 PM

                  Thanks JamesDean.

                  I appreciate your class-act approach!

                  –------------------------------------------------
                  2.4.3-RELEASE (amd64)
                  built on Mon Mar 26 18:02:04 CDT 2018
                  FreeBSD 11.1-RELEASE-p7
                  VM in ESXi 5.5
                  1 x 1000baseTX (WAN)
                  1 x 1000baseTX (LAN)

                  1 Reply Last reply Reply Quote 0
                  • D
                    darklogic
                    last edited by Jul 2, 2010, 7:08 PM

                    Same here, I appreciate everything as well. 8)

                    1 Reply Last reply Reply Quote 0
                    • R
                      Rune
                      last edited by Jul 3, 2010, 7:02 AM

                      I figured I'd post this here in case people want to update their definitions manually. I used this post but updated the instructions to the current version.
                      http://forum.pfsense.org/index.php/topic,15464.msg81197.html#msg81197

                      1- Download the rules manually by logging to the shell and type this
                      fetch http://www.snort.org/pub-bin/oinkmaster.cgi/Oinkcode/snortrules-snapshot-2860.tar.gz
                      2 - Make temp directory and copy rules
                      mkdir /tmp/temp
                      cp snortrules-snapshot-2860.tar.gz /tmp/temp
                      3- extract the file with this command
                      tar -zxvf /tmp/temp/snortrules-snapshot-2860.tar.gz
                      4- Find interface name - it will be in a snort_#_interface format
                      ls /usr/local/etc/snort/
                      5- copy rules to rules directory
                      cp tmp/temp/rules/. /usr/local/etc/snort/interfacename/rules
                      6- Remove temp directory
                      rm -r /tmp/temp
                      7 - Restart Snort. This did it for me on a clean install.

                      Hope this helps someone out.

                      1 Reply Last reply Reply Quote 0
                      • S
                        simby
                        last edited by Jul 3, 2010, 8:15 AM

                        Jammes, can you add options to manual update snort packet? :)

                        1 Reply Last reply Reply Quote 0
                        • ?
                          A Former User
                          last edited by Jul 4, 2010, 12:43 AM

                          Has the package been fixed .I had to do a reinstall because of drive faulty hard drive .I see in the packeage list the snort package has the same number ?

                          1 Reply Last reply Reply Quote 0
                          • ?
                            A Former User
                            last edited by Jul 4, 2010, 8:27 PM

                            @Rune:

                            I figured I'd post this here in case people want to update their definitions manually. I used this post but updated the instructions to the current version.
                            http://forum.pfsense.org/index.php/topic,15464.msg81197.html#msg81197

                            1- Download the rules manually by logging to the shell and type this
                            fetch http://www.snort.org/pub-bin/oinkmaster.cgi/Oinkcode/snortrules-snapshot-2860.tar.gz
                            2 - Make temp directory and copy rules
                            mkdir /tmp/temp
                            cp snortrules-snapshot-2860.tar.gz /tmp/temp
                            3- extract the file with this command
                            tar -zxvf /tmp/temp/snortrules-snapshot-2860.tar.gz
                            4- Find interface name - it will be in a snort_#_interface format
                            ls /usr/local/etc/snort/
                            5- copy rules to rules directory
                            cp tmp/temp/rules/. /usr/local/etc/snort/interfacename/rules
                            6- Remove temp directory
                            rm -r /tmp/temp
                            7 - Restart Snort. This did it for me on a clean install.

                            Hope this helps someone out.

                            I tried the copy comand and it does not work for me .Everything else worked .

                            thanks for the help

                            1 Reply Last reply Reply Quote 0
                            • L
                              LostInIgnorance
                              last edited by Jul 5, 2010, 5:25 AM Jul 5, 2010, 5:04 AM

                              @cdx304:

                              @Rune:

                              I figured I'd post this here in case people want to update their definitions manually. I used this post but updated the instructions to the current version.
                              http://forum.pfsense.org/index.php/topic,15464.msg81197.html#msg81197

                              1- Download the rules manually by logging to the shell and type this
                              fetch http://www.snort.org/pub-bin/oinkmaster.cgi/Oinkcode/snortrules-snapshot-2860.tar.gz
                              2 - Make temp directory and copy rules
                              mkdir /tmp/temp
                              cp snortrules-snapshot-2860.tar.gz /tmp/temp
                              3- extract the file with this command
                              tar -zxvf /tmp/temp/snortrules-snapshot-2860.tar.gz
                              4- Find interface name - it will be in a snort_#_interface format
                              ls /usr/local/etc/snort/
                              5- copy rules to rules directory
                              cp tmp/temp/rules/. /usr/local/etc/snort/interfacename/rules
                              6- Remove temp directory
                              rm -r /tmp/temp
                              7 - Restart Snort. This did it for me on a clean install.

                              Hope this helps someone out.

                              I tried the copy comand and it does not work for me .Everything else worked .

                              thanks for the help

                              I ended up having to use this line instead to copy the files.  Worked for me, but only an expert can tell me if I actually did it correctly. Still kinda new to all of this. ;)

                              cp rules/. /usr/local/etc/snort/interfacename/rules

                              Thanks again JamesDean for everything!! :D

                              1 Reply Last reply Reply Quote 0
                              • R
                                Rune
                                last edited by Jul 6, 2010, 6:27 AM

                                Yeah. You did it correctly. I was just looking back at what I had posted and realized I had put the wrong thing. Sorry. It was late when I posted this.

                                1 Reply Last reply Reply Quote 0
                                • J
                                  jnorell
                                  last edited by Jul 6, 2010, 2:43 PM

                                  James, if you're rewriting parts of the updating anyways, I'd like to +1 simby's request of adding a manual update feature (ie. http interface to upload and install a snort ruleset .tgz).  If that would get everyone by in a pinch if there are similar future changes to the download procedure.

                                  Big thanks for your work on this package!

                                  1 Reply Last reply Reply Quote 0
                                  • G
                                    g4m3c4ck
                                    last edited by Jul 6, 2010, 6:38 PM Jul 6, 2010, 6:30 PM

                                    Well I am glad they are releasing rules for specific versions of snort now instead of coming out with a new version of snort and breaking the rules for the old versions. That alone will solve most of the headaches when dealing with snort.

                                    That being said good job as always JD! And for those that continue to bitch about a FREE product that kicks ass of most alternatives you have to PAY for…...  Then go BUY something else!

                                    People who can't comprend how to navigate and manipulate file systems should not be messing around with ANYONES network let alone their firewall/router. But hey that is just my opinion….

                                    1 Reply Last reply Reply Quote 0
                                    • ?
                                      A Former User
                                      last edited by Jul 6, 2010, 11:44 PM

                                      @LostInIgnorance:

                                      @cdx304:

                                      @Rune:

                                      I figured I'd post this here in case people want to update their definitions manually. I used this post but updated the instructions to the current version.
                                      http://forum.pfsense.org/index.php/topic,15464.msg81197.html#msg81197

                                      1- Download the rules manually by logging to the shell and type this
                                      fetch http://www.snort.org/pub-bin/oinkmaster.cgi/Oinkcode/snortrules-snapshot-2860.tar.gz
                                      2 - Make temp directory and copy rules
                                      mkdir /tmp/temp
                                      cp snortrules-snapshot-2860.tar.gz /tmp/temp
                                      3- extract the file with this command
                                      tar -zxvf /tmp/temp/snortrules-snapshot-2860.tar.gz
                                      4- Find interface name - it will be in a snort_#_interface format
                                      ls /usr/local/etc/snort/
                                      5- copy rules to rules directory
                                      cp tmp/temp/rules/. /usr/local/etc/snort/interfacename/rules
                                      6- Remove temp directory
                                      rm -r /tmp/temp
                                      7 - Restart Snort. This did it for me on a clean install.

                                      Hope this helps someone out.

                                      I tried the copy comand and it does not work for me .Everything else worked .

                                      thanks for the help

                                      I ended up having to use this line instead to copy the files.  Worked for me, but only an expert can tell me if I actually did it correctly. Still kinda new to all of this. ;)

                                      cp rules/. /usr/local/etc/snort/interfacename/rules

                                      Thanks again JamesDean for everything!! :D

                                      I tried this method and still does not work I hope this package gets fixed beause running my cisco box is getting real old !!

                                      1 Reply Last reply Reply Quote 0
                                      • S
                                        simby
                                        last edited by Jul 7, 2010, 12:52 PM

                                        any news?

                                        1 Reply Last reply Reply Quote 0
                                        • D
                                          darklogic
                                          last edited by Jul 7, 2010, 1:55 PM

                                          When I discovered last week there were some issues with updating. I was doing everything I could to get SNORT to install updates. I even deinstalled an reinstalled the packaged before I checked the fourms and found that others were having issues as well. I am noticing that SNORT is not releasing blocked IP's after 1 hour, which is what I have it set to release blocked offenders. I never had the issue before until after the uninstall and reinstall of the package. I tried the uninstall and reinstall of the package again and get the same results.

                                          Any ideas on what this is about? Has anyone else notice this or have this issue?

                                          Thanks,

                                          Matt

                                          1 Reply Last reply Reply Quote 0
                                          18 out of 72
                                          • First post
                                            18/72
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received