Snort mailing list archives

Re: gen-msg.map missing some SIDs for dcerpc2


From: "Jefferson, Shawn" <Shawn.Jefferson () bcferries com>
Date: Wed, 21 Nov 2012 17:52:11 -0700

Gen-msg.map is packaged with the snort tarball I think, it doesn't change with VRT updates.  Maybe you didn't copy the 
new one into the right directory when you upgraded?

-----Original Message-----
From: Jeremy Hoel [mailto:jthoel () gmail com] 
Sent: Wednesday, November 21, 2012 4:08 PM
To: snort-users () lists sourceforge net
Subject: [Snort-users] gen-msg.map missing some SIDs for dcerpc2

the latest VRT ruleset has a gen-msg.map that is missing some SIDs; at least some from the dcerpc2 processor.  We 
started getting some alerts for 133.52 and looking at the README.dcerpc2 shows events up to 56 but the gen-msg.map only 
goes up to 133:43 (with 44-47 commented out).

pulledpork only updates the sid-msg.map correct?

Is this something that should be fixed in the vrt ruleset?

------------------------------------------------------------------------------
Monitor your physical, virtual and cloud infrastructure from a single web console. Get in-depth insight into apps, 
servers, databases, vmware, SAP, cloud infrastructure, etc. Download 30-day Free Trial.
Pricing starts from $795 for 25 servers or applications!
http://p.sf.net/sfu/zoho_dev2dev_nov
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

------------------------------------------------------------------------------
Monitor your physical, virtual and cloud infrastructure from a single
web console. Get in-depth insight into apps, servers, databases, vmware,
SAP, cloud infrastructure, etc. Download 30-day Free Trial.
Pricing starts from $795 for 25 servers or applications!
http://p.sf.net/sfu/zoho_dev2dev_nov
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: