Snort mailing list archives
Re: gen-msg.map missing some SIDs for dcerpc2
From: Joel Esler <jesler () sourcefire com>
Date: Thu, 22 Nov 2012 08:28:34 -0500
Correct. -- Joel Esler Sent from my iPad On Nov 21, 2012, at 8:09 PM, "Jefferson, Shawn" <Shawn.Jefferson () bcferries com> wrote:
Well I could be wrong of course, but I didn't think the preprocessor rules changed because the preprocessors themselves don't change except with an upgrade of the main code base? ----- Original Message ----- From: Jeremy Hoel <jthoel () gmail com> To: Jefferson, Shawn Cc: snort-users () lists sourceforge net <snort-users () lists sourceforge net> Sent: Wed Nov 21 17:06:03 2012 Subject: Re: [Snort-users] gen-msg.map missing some SIDs for dcerpc2 Well when i look in the VRT ruleset I see it there, and the last upgrade to 2.9.3.1 was a while back . but that could be. Since the file is going to change with the preprocessor rules, I would have thought it came with the vrt rule file. And double checking, the snortrules-snapshot-2931.tar.gz does contain 'etc/gen-msg.map' with today's date (could be from the extraction) The one from the snort 2.9.3.1 tarball has a date of 4/27/12 and they do have different sizes and md5sums. On Thu, Nov 22, 2012 at 12:52 AM, Jefferson, Shawn <Shawn.Jefferson () bcferries com> wrote:Gen-msg.map is packaged with the snort tarball I think, it doesn't change with VRT updates. Maybe you didn't copy the new one into the right directory when you upgraded? -----Original Message----- From: Jeremy Hoel [mailto:jthoel () gmail com] Sent: Wednesday, November 21, 2012 4:08 PM To: snort-users () lists sourceforge net Subject: [Snort-users] gen-msg.map missing some SIDs for dcerpc2 the latest VRT ruleset has a gen-msg.map that is missing some SIDs; at least some from the dcerpc2 processor. We started getting some alerts for 133.52 and looking at the README.dcerpc2 shows events up to 56 but the gen-msg.map only goes up to 133:43 (with 44-47 commented out). pulledpork only updates the sid-msg.map correct? Is this something that should be fixed in the vrt ruleset? ------------------------------------------------------------------------------ Monitor your physical, virtual and cloud infrastructure from a single web console. Get in-depth insight into apps, servers, databases, vmware, SAP, cloud infrastructure, etc. Download 30-day Free Trial. Pricing starts from $795 for 25 servers or applications! http://p.sf.net/sfu/zoho_dev2dev_nov _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!------------------------------------------------------------------------------ Monitor your physical, virtual and cloud infrastructure from a single web console. Get in-depth insight into apps, servers, databases, vmware, SAP, cloud infrastructure, etc. Download 30-day Free Trial. Pricing starts from $795 for 25 servers or applications! http://p.sf.net/sfu/zoho_dev2dev_nov _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
------------------------------------------------------------------------------ Monitor your physical, virtual and cloud infrastructure from a single web console. Get in-depth insight into apps, servers, databases, vmware, SAP, cloud infrastructure, etc. Download 30-day Free Trial. Pricing starts from $795 for 25 servers or applications! http://p.sf.net/sfu/zoho_dev2dev_nov _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- gen-msg.map missing some SIDs for dcerpc2 Jeremy Hoel (Nov 21)
- Re: gen-msg.map missing some SIDs for dcerpc2 Jefferson, Shawn (Nov 21)
- Re: gen-msg.map missing some SIDs for dcerpc2 Jeremy Hoel (Nov 21)
- Re: gen-msg.map missing some SIDs for dcerpc2 waldo kitty (Nov 22)
- Re: gen-msg.map missing some SIDs for dcerpc2 Jeremy Hoel (Nov 21)
- <Possible follow-ups>
- Re: gen-msg.map missing some SIDs for dcerpc2 Jefferson, Shawn (Nov 21)
- Re: gen-msg.map missing some SIDs for dcerpc2 Joel Esler (Nov 22)
- Re: gen-msg.map missing some SIDs for dcerpc2 Jeremy Hoel (Nov 22)
- Re: gen-msg.map missing some SIDs for dcerpc2 beenph (Nov 22)
- Re: gen-msg.map missing some SIDs for dcerpc2 Joel Esler (Nov 22)
- Re: gen-msg.map missing some SIDs for dcerpc2 waldo kitty (Nov 22)
- Re: gen-msg.map missing some SIDs for dcerpc2 Joel Esler (Nov 22)
- Re: gen-msg.map missing some SIDs for dcerpc2 Jefferson, Shawn (Nov 21)