Snort Updating problems !!!
-
Dear James,
Dear rnowotny,
Being the newbie you are. If you already knew the time James and many others have already spent on the pfsense project as well as the complexity of doing so you would not have worded or made the statements in the way you did. pfSense is a great and very powerful project that you use for FREE. If you want to contribute to the project please do so but in the proper way. Basically, I am asking you to put up or shut up.
Sincerly,
Avid pfSense/Snort user and appeciator
-
James, do you have any news?
-
I'm just a newb to this form but not to pf. I have to say Thanks to everyone for all the work. That snort package Is wild. I dug through some of the scripts. All I could say Is AMAZING man. Of course I had a new chunk of hardware I just put in and snort will not update. Ill post the specs on the bottom. After looking through the update code I felt like my brain was stuck in a blinder. But I wrote an add in box for direct url placement. It failed to pick up the package. I'm sure the issue has to be the url that's not allowing the download. The same conclusion you have already come to.
Pretty much I threw a fit for an hour and had a cocktail and it popped into my head that a year or so ago I was using a copy of gallery2 on one of my servers. It had a piece of code that dealt with and took care of url redirect with a cache page. Tomorrow Ill look for that code and see If I could find It and post if you want.
Also It might be possible to post a second server that allows the update page to go fetch the url from and then download the package. Even a Proxy for the download but It would take resources. It might mess with your untar code but could be a final solution. Good luck James. Everyone Thanks for all the work. Its very appreciated.
Snort's on manual for now.
Supermicro X6DPL-4G2 board.
dule LV xeon 2ghz processors
sda/ hdd
2 gig's ram
quad supermicro gig Net card add on. -
Dear g4m3c4ck,
I dont wanted to be rude at all, just giving some input what might make sense.
So if my post seems to be unpolite, I apologize.
You may have noticed that I posted a tiny shellscript some posts before,
to make a manual update of snortrules via cronjob. Not a big deal - but some rookies might use it.
I might come up with a script that preserve the ON/OFF state for each IDS across updates,
because I need it myself ;-)Yours sincerely
RobertDear rnowotny,
Being the newbie you are. If you already knew the time James and many others have already spent on the pfsense project as well as the complexity of doing so you would not have worded or made the statements in the way you did. pfSense is a great and very powerful project that you use for FREE. If you want to contribute to the project please do so but in the proper way. Basically, I am asking you to put up or shut up.Sincerly,
Avid pfSense/Snort user and appeciator
-
Alright. I dug through my code folder and found this price. Its using fstockopen opt. to pull a redirected url. Its not what I was looking for but might do the job. Ill test it tonight and see if I can pull down the monster url from snort. If I have any luck Ill post my finished pages for inspection.
Take it EZ. -
rnowotny
I understand what you are saying on a lot of your post. I agree with most statements on the rules and there are better ways to make sure rules are enabled and disabled after updates. These are all the same issues that others are dealing with. James Dean picked up on the SNORT project when no one else did, he also has contributed endless hours to the programming and online fourms. SNORT is getting better and better. I realize you may mean no harm, but your wording is kind of blunt!!! Different people online are going to take your words differently from others. Statements like posting scripts online so some rookies may use it is not what I would call appropriate commits. The fact that anyone on these forums and using pfsense says to me that hey, no one here is really a rookie.
Take Care,
Matt
-
hello,
I use Pfsense V1.2.3-RC1 , a have install package : Snort : 2.8.6 pkg v. 1.27
i have find a bug , to update the rules the filename of the rules has change since : 10 junes 2010
the file name is now :
snortrules-snapshot-2860.tar.gzExample for snort 2.8.6.0:
url = http://www.snort.org/pub-bin/oinkmaster.cgi/XXXXXXXXXXXXXX/snortrules-snapshot-2860.tar.gzImportant Note from SNORT website:
We are changing the way we publish rules. In June 2010 we stopped offering rules in the "snortrules-snapshot-CURRENT" format. Instead, rules are released for specific versions of Snort. You will be responsible for downloading the correct rules release for your version of Snort. The new versioning mechanism will require a four digit version in the file name.Please James can you update the package ?
Best reagrds
-
Where is the file : oinkmaster.conf on pfsense vers: 1.2.21 ??
-
Please check this post, it is a quick and dirty workaround until the new version is avail :
http://forum.pfsense.org/index.php/topic,26382.msg139375.html#msg139375
hello,
I use Pfsense V1.2.3-RC1 , a have install package : Snort : 2.8.6 pkg v. 1.27
i have find a bug , to update the rules the filename of the rules has change since : 10 junes 2010
the file name is now :
snortrules-snapshot-2860.tar.gzExample for snort 2.8.6.0:
url = http://www.snort.org/pub-bin/oinkmaster.cgi/XXXXXXXXXXXXXX/snortrules-snapshot-2860.tar.gzImportant Note from SNORT website:
We are changing the way we publish rules. In June 2010 we stopped offering rules in the "snortrules-snapshot-CURRENT" format. Instead, rules are released for specific versions of Snort. You will be responsible for downloading the correct rules release for your version of Snort. The new versioning mechanism will require a four digit version in the file name.Please James can you update the package ?
Best reagrds
-
hi,
Ok thanck you, but i have already read this post, i would like know if an official update of this package will be done or not ?
best regards.
-
Well they're tricky guys there at Sourcefire. There were a couple things wrong with the rule downloads:
1. The URL changed.
2. They now redirect you to an Amazon s3 URL to get the actual rules
3. The Amazon url is HTTPS.So I fixed the URL, changed a redirect option, and I had to disable cURL's SSL validation, but now the rules download for me.
The new package version is up now, give it a try and see if it works.
-
Giving it a try now. Will post back soon!
Update:
Seems to be working just fine - Rules updated and Snort running. Thanks jimp!!! -
I tried it on all 3 of my pfSense boxes and is working fine. Thanks again Jim!
-Jason
-
Looking good here!
Many thanks…
-
I uninstalled the old package and installed the new one and updated it no problem did a port scan test and all is working (fingers crossed) . ;D
-
Question for those brave people that updated (no going back) :)
Premium rules or basic rules?Hoping people have tested both…
-
I used the subscribed rules and everything is working great over here
-
Basic working fine for me.
-
Thanks for the feedback! I'll give it a whirl…
-
Thanks Jimp.
Snort now updates and works fine. (with Basic rules)