Snort mailing list archives
Re: Changing the Community sid-msg.map
From: Richard Harman <snort () richardharman com>
Date: Thu, 17 Nov 2005 22:10:27 -0500
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I vote in favor. Also, if people are just running something akin to 'find /path/to/rules - -type f -iname \*sig-msg.map -exec cat {} > /path/to/sid-msg.map', I would strongly suggest not doing so. Instead, use the utility scripts that come with oinkmaster (create-sidmap.pl, addsid.pl) that will actually parse the rules, and generate a sid-msg.map/fix things for you. It's much safer that way, especially if you use barnyard. Otherwise, you run the chance of rules missing from the sidmaps, or malformed rules w/o sids or msgs causing you headaches. Can you tell I've been bitten by this in the past? *grin* Richard Harman Alex Kirk wrote:
In response to multiple requests from users, we here at Sourcefire are considering making a small change to the format of Community rulepacks: we'd like to change the name of sid-msg.map to community-sid-msg.map. This would eliminate the naming conflict with sid-msg.map from the VRT rule set. Before we do so, though, we wanted to check with the community at large, to ensure that this change won't break anyone's scripts/tools/etc. If you know of any problems this would cause, please let us know now, so that we can work with you to prevent such problems while still eliminating this conflict. Alex Kirk Community Rules Maintainer Sourcefire, Inc. ------------------------------------------------------- This SF.Net email is sponsored by the JBoss Inc. Get Certified Today Register for a JBoss Training Course. Free Certification Exam for All Training Attendees Through End of 2005. For more info visit: http://ads.osdn.com/?ad_id=7628&alloc_id=16845&op=click _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
- -- - ----------------------------------------------------------- "Looks like there'll be no money for you, Crazy Round Man." - Samurai Jack Richard G Harman Jr <me+nospam () richardharman com> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.7 (GNU/Linux) Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org iD8DBQFDfUYi3rKdb192Vz8RAkvWAJ9abRwAACIQ5pBhazs4eiI4MkSMEACePUZN UejjaRV9Bfu7kE/JwekMkSQ= =3CnK -----END PGP SIGNATURE----- ------------------------------------------------------- This SF.Net email is sponsored by the JBoss Inc. Get Certified Today Register for a JBoss Training Course. Free Certification Exam for All Training Attendees Through End of 2005. For more info visit: http://ads.osdn.com/?ad_id=7628&alloc_id=16845&op=click _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Changing the Community sid-msg.map Alex Kirk (Nov 17)
- Re: Changing the Community sid-msg.map Richard Harman (Nov 17)