Snort 2.9.4.1 pkg v.2.5.8
-
I did some further testing. Deinstalled snort without saving configuration and configured it from scratch: same problems.
Then I installed a fresh pfSense RC0 Fri May 31 from memorystick to hard disk and restored configuration file and rebooted: same problems
An alert and then "check_reload_status" as I mentioned before.Just so I'm clear, does the 2.5.8 package start and run fine until the first Alert, and then it starts going haywire? And one more question. Does it go haywire on the first Alert, or the first Alert with a Block? I'm wondering if something is weird with Spoink, the snort2c table, and the check_reload_status() tool.
You could help me test this by configuring a VM and not checking the "Block Offenders" option. Let it record Alerts, but tell it not to block on them. Let's see if that keeps it stable. Trying to isolate if the problem is with Snort itself, or if it might be related to Spoink.
Bill
-
Try the status_dhcpv6_leases.php, it outgrows the border to fit in information.
Thanks for the tip, but I wound up finding a different trick using a zero-width space character after each colon in an IPv6 address. That seems to fix the column overrun on my test systems using IE10, Chrome and Firefox as browsers.
This fix has been submitted via a Pull Request to the Core Team for review and approval. The Snort Package Version number will not increment, though. I will post back when the update has been pushed to the Packages repository.
Bill
-
I did some further testing. Deinstalled snort without saving configuration and configured it from scratch: same problems.
Then I installed a fresh pfSense RC0 Fri May 31 from memorystick to hard disk and restored configuration file and rebooted: same problems
An alert and then "check_reload_status" as I mentioned before.Just so I'm clear, does the 2.5.8 package start and run fine until the first Alert, and then it starts going haywire? And one more question. Does it go haywire on the first Alert, or the first Alert with a Block? I'm wondering if something is weird with Spoink, the snort2c table, and the check_reload_status() tool.
You could help me test this by configuring a VM and not checking the "Block Offenders" option. Let it record Alerts, but tell it not to block on them. Let's see if that keeps it stable. Trying to isolate if the problem is with Snort itself, or if it might be related to Spoink.
Bill
I found it!
This bug #2555 describes also what I discovered and this topic made me also think. I have Intel NICs (82574L) and I switched my WAN interface to an Realtek one. Problem gone!
It must be a driver issue although the Intel NICs are recommended and were stable.Fingers crossed!!!!
-
I found it!
This bug #2555 describes also what I discovered and this topic made me also think. I have Intel NICs (82574L) and I switched my WAN interface to an Realtek one. Problem gone!
It must be a driver issue although the Intel NICs are recommended and were stable.Fingers crossed!!!!
Great news! Another user in the thread topic you linked was also having a problem with a newer Intel NIC (using the fxp0) driver. He swapped out his card and his problems also went away.
Bill
-
Yes I referred to that post but mangled my link. Corrected that now.
Just wanted 2.5.8 so badly that I spent a day looking for solutions ;D
But I can't change the driver for my Virtual Machine >:(
-
Another user in the thread topic you linked was also having a problem with a newer Intel NIC (using the fxp0) driver.
He swapped out his card and his problems also went away.Unless something changed very recently, the fxp(4) FreeBSD driver is used for ancient (mid-1990s) 100Mbps Intel NICs.
For best results it is recommended to use relatively recent (less than 10 years old) Intel GbE NICs such as those supported by the em(4) driver, and IMHO avoid wasting developers' time troubleshooting 20 year old hardware …
PS: bmeeks keep up your fine work !!!
-
But I can't change the driver for my Virtual Machine >:(
If it's VMware, yes you can. Simply choose e1000 in the NIC options (for ESXi). For Workstation you can manually edit the vmx file. Do a quick Google search. VMware will usually by default configure the e1000 NIC driver for virtual machines. This driver will show up in pfSense as "em0".
Bill
-
We are going off-topic but I have a Mac and Parallels Desktop. Too bad :'(
-
We are going off-topic but I have a Mac and Parallels Desktop. Too bad :'(
Oh…there is VMware Fusion for the Mac ... :D
-
Only security gives me the blank page, as previously stated. I'm using iceweasel (for all intents and purposes it's identical to firefox).
/usr/pbi/snort_i386/etc/snort/snort_xxxx_em1/snort.rules does not exist
/usr/local/etc/snort/snort_7104_em1/rules/snort.rules on the other hand exists and contains:
#some comments
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"EXPLOIT-KIT Nuclear exploit kit Spoofed Host Header .com- requests"; flow:to_server,established; content:".com-"; http_header; pcre:"/\r\nHost\x3a\x20[a-z0-9\x2d\x2e]+.com\x2d[a-z0-9\x2d\x2e]+(\x3a\d{1,5})?\r\n/Hi"; content:"|0D 0A|Accept|3A 20|text/html, image/gif, image/jpeg, *|3B| q=.2, /|3B| q=.2|0D 0A|"; fast_pattern:only; http_header; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, ruleset community, service http; classtype:trojan-activity; sid:26562; rev:1;)
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"MALWARE-CNC Harakit botnet traffic"; flow:to_server,established; urilen:10; content:"sousi.extasix.com|0D 0A|"; fast_pattern:only; http_header; content:"/genst.htm"; http_uri; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, ruleset community, service http; reference:url,www.symantec.com/security_response/attacksignatures/detail.jsp?asid=23239; reference:url,www.virustotal.com/en/file/3df72fe102fddc74de2da518ea16948bd2c8c0e910c28c4358367e10723ba21f/analysis/; classtype:trojan-activity; sid:26563; rev:1;)
and so on and so forth…
As you can see it shows security-ips. It's not that security is not used, it's just not displayed properly. As I said above it was working fine just before the update, updated and now both systems show that behaviour (security selected, enabled,used, but rule edit page is completely blank). Is that the only file that gets parsed to display the results on the IPS Policy Security rule edit page (the one that comes up blank)?
I can't remember if system B (slave) displayed this behaviour before the first post-update sync. But system B definitely shows blank page now, maybe something got messed up on system A (master) and got replicated to B. -
I also see the behavior of a blank screen when IPS Security is enabled, but also a crash report:
[02-Jun-2013 11:33:13 Europe/Amsterdam] PHP Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 12488260 bytes) in /usr/local/www/csrf/csrf-magic.php on line 157
This should give a clou I guess?
-
I also see the behavior of a blank screen when IPS Security is enabled, but also a crash report:
[02-Jun-2013 11:33:13 Europe/Amsterdam] PHP Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 12488260 bytes) in /usr/local/www/csrf/csrf-magic.php on line 157
This should give a clou I guess?
Yep, the box is running out of memory to hold the rules from the IPS Security policy as it loads them into an array for manipulation. Can you give the amount of RAM configured in your box and whether you are running 32-bit or 64-bit pfSense kernel.
Bill
-
@jflsakfja:
Only security gives me the blank page, as previously stated. I'm using iceweasel (for all intents and purposes it's identical to firefox).
/usr/pbi/snort_i386/etc/snort/snort_xxxx_em1/snort.rules does not exist
/usr/local/etc/snort/snort_7104_em1/rules/snort.rules on the other hand exists and contains:
#some comments
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"EXPLOIT-KIT Nuclear exploit kit Spoofed Host Header .com- requests"; flow:to_server,established; content:".com-"; http_header; pcre:"/\r\nHost\x3a\x20[a-z0-9\x2d\x2e]+.com\x2d[a-z0-9\x2d\x2e]+(\x3a\d{1,5})?\r\n/Hi"; content:"|0D 0A|Accept|3A 20|text/html, image/gif, image/jpeg, *|3B| q=.2, /|3B| q=.2|0D 0A|"; fast_pattern:only; http_header; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, ruleset community, service http; classtype:trojan-activity; sid:26562; rev:1;)
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"MALWARE-CNC Harakit botnet traffic"; flow:to_server,established; urilen:10; content:"sousi.extasix.com|0D 0A|"; fast_pattern:only; http_header; content:"/genst.htm"; http_uri; metadata:impact_flag red, policy balanced-ips drop, policy security-ips drop, ruleset community, service http; reference:url,www.symantec.com/security_response/attacksignatures/detail.jsp?asid=23239; reference:url,www.virustotal.com/en/file/3df72fe102fddc74de2da518ea16948bd2c8c0e910c28c4358367e10723ba21f/analysis/; classtype:trojan-activity; sid:26563; rev:1;)
and so on and so forth…
As you can see it shows security-ips. It's not that security is not used, it's just not displayed properly. As I said above it was working fine just before the update, updated and now both systems show that behaviour (security selected, enabled,used, but rule edit page is completely blank). Is that the only file that gets parsed to display the results on the IPS Policy Security rule edit page (the one that comes up blank)?
I can't remember if system B (slave) displayed this behaviour before the first post-update sync. But system B definitely shows blank page now, maybe something got messed up on system A (master) and got replicated to B.Same question for you as for gogol:
How much RAM is installed in your firewall and are you running 32-bit or 64-bit pfSense?
Can you list for me the exact sequence of steps you go through to get the blank page? Where do you click and in what order? I want to try and reproduce this by configuring a VM with the same specs and then duplicating your steps precisely.
Oh, and the "xxxx" in my previous post was referring to that "7104" number. That is an unique identifier (UUID) generated by the system for each configured Snort interface. Each one will be different, hence I just said "xxxx" in my post.
Bill
-
I needed 4GB to run Snort in a stable state. 2GB was not enough to load all the rules and it pulled a Swap file error on me.
Did a lot of searching together with Bill to come to that conclusion :)
-
I also see the behavior of a blank screen when IPS Security is enabled, but also a crash report:
[02-Jun-2013 11:33:13 Europe/Amsterdam] PHP Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 12488260 bytes) in /usr/local/www/csrf/csrf-magic.php on line 157
This should give a clou I guess?
Yep, the box is running out of memory to hold the rules from the IPS Security policy as it loads them into an array for manipulation. Can you give the amount of RAM configured in your box and whether you are running 32-bit or 64-bit pfSense kernel.
Bill
I have 2 GB Ram on a 32bit system. I have 1 snort sensor and Dashboard says that I use 67% Ram. I tested on a VM and upped it to 4 GB of Ram. Dashboard says 49% of Ram used, but I get the same crash report.
-
If I load some ET rules + IPS Security, Snort is using +2 GB RAM on my system with AC as memory performance option. So it could be that your system is running out of memory. Either for Snort process or PHP possibly.
-
I run AC-Sparsebands. Try that and see if it makes a difference.
-
In my case it doesn't matter how much memory Snort uses, I just thought of mentioning it to remind that Snort is a resource hog with a lot of rules loaded up. My box has 8 GB RAM and I run AMD64 version of Snort, so memory usage isn't really a problem :)
-
Thanks for all of the hard work on this. I just updated today. All went well so far and i am loving the new features! Just gotta wait and see if auto updates run ok. ;)
-
I have 2 GB Ram on a 32bit system. I have 1 snort sensor and Dashboard says that I use 67% Ram. I tested on a VM and upped it to 4 GB of Ram. Dashboard says 49% of Ram used, but I get the same crash report.
Sorry to continue with questions, but I need one more answered to help me reproduce. Besides the Snort VRT rules, what others are you running?
Emerging Threats (if yes, how many categories are selected)?
Snort GPLv2 Community Rules?
I will send you a PM with my e-mail address, and if you don't mind I would like for you to send me a copy of your config.xml (or at least the sections for Snort). I want to reproduce your setup and see if I can force the same problem.
Bill