Snort mailing list archives

Re: NIDS on large (>500MB) pcap dumps


From: "Jefferson, Shawn" <Shawn.Jefferson () bcferries com>
Date: Mon, 17 Dec 2012 11:29:50 -0700

Sorry, I used the wrong terminology... It downloads the already built so binary files, and builds the rule stubs, like 
you say.


From: Tony Robinson [mailto:deusexmachina667 () gmail com]
Sent: Friday, December 14, 2012 4:23 PM
To: Jefferson, Shawn
Cc: Steve Marotta; Balasubramaniam Natarajan; snort-users () lists sourceforge net
Subject: Re: [Snort-users] NIDS on large (>500MB) pcap dumps

Wait... Not to threadjack, but can pp actually *Rebuild* SO rules? I know it builds the unified SO rule stub file based 
on your rule policy... but don't recall an option to rebuild the actual SO rules. If it can do this, what manual did I 
not read? and/or what options do I need to be using?

-DA
On Fri, Dec 14, 2012 at 6:11 PM, Jefferson, Shawn <Shawn.Jefferson () bcferries com<mailto:Shawn.Jefferson () bcferries 
com>> wrote:
You need to rebuild your so rule files.  Pulled Pork can do this for you.


-----Original Message-----
From: Steve Marotta [mailto:smarotta () cra com<mailto:smarotta () cra com>]
Sent: Friday, December 14, 2012 2:07 PM
To: Balasubramaniam Natarajan
Cc: snort-users () lists sourceforge net<mailto:snort-users () lists sourceforge net>
Subject: Re: [Snort-users] NIDS on large (>500MB) pcap dumps

Thanks to everyone for the responses. I compiled Snort from source (I had originally installed using Ubuntu apt-get), 
configuring it with --enable-large-pcap. I downloaded rule set 2930 and set it up, configured the snort.conf file, and 
when I try to run it now, I get:

ERROR: The dynamic detection library "/usr/local/snort/lib/snort_dynamicrules/imap.so" version 1.0 compiled with 
dynamic engine library version 1.16 isn't compatible with the current dynamic engine library 
"/usr/local/snort/lib/snort_dynamicengine/libsf_engine.so" version 1.17.
Fatal Error, Quitting..

Both of these files are in the same rule set that I downloaded. I can understand a conflict between two different 
things that I've installed, but a conflict between two items in one package is puzzling.

So I'm figuring that the issue is that I installed Snort version 2.9.4 but could only get rulesets for 2.9.3.x. I'm 
looking around for an older version of Snort so I can use the only rules I can get access to, and I can't seem to find 
anywhere that lets me download 2.9.3.0 or 2.9.3.1. Am I missing something?







THIS MESSAGE IS INTENDED FOR THE USE OF THE PERSON TO WHOM IT IS ADDRESSED. IT MAY CONTAIN INFORMATION THAT IS 
PRIVILEGED, CONFIDENTIAL AND EXEMPT FROM DISCLOSURE UNDER APPLICABLE LAW. If you are not the intended recipient, your 
use of this message for any purpose is strictly prohibited. If you have received this communication in error, please 
delete the message and notify the sender so that we may correct our records.






------------------------------------------------------------------------------
LogMeIn Rescue: Anywhere, Anytime Remote support for IT. Free Trial Remotely access PCs and mobile devices and provide 
instant support Improve your efficiency, and focus on delivering more value-add services Discover what IT Professionals 
Know. Rescue delivers http://p.sf.net/sfu/logmein_12329d2d
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net<mailto:Snort-users () lists sourceforge net>
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

------------------------------------------------------------------------------
LogMeIn Rescue: Anywhere, Anytime Remote support for IT. Free Trial
Remotely access PCs and mobile devices and provide instant support
Improve your efficiency, and focus on delivering more value-add services
Discover what IT Professionals Know. Rescue delivers
http://p.sf.net/sfu/logmein_12329d2d
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net<mailto:Snort-users () lists sourceforge net>
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!



--
when does reality end? when does fantasy begin?
------------------------------------------------------------------------------
LogMeIn Rescue: Anywhere, Anytime Remote support for IT. Free Trial
Remotely access PCs and mobile devices and provide instant support
Improve your efficiency, and focus on delivering more value-add services
Discover what IT Professionals Know. Rescue delivers
http://p.sf.net/sfu/logmein_12329d2d
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: