Snort mailing list archives

RE: Snort 2.1.0 rules won't update in SnortCenter


From: "Jeff Evenson" <Jeff.Evenson () midwestwireless com>
Date: Tue, 27 Jan 2004 11:19:31 -0600

Jason,
Have you thought of downgrading to Snort 2.0 until you get time? Didn't
know if you lived the pain of doing that or if it's no big deal.

jeff

-----Original Message-----
From: Jason Alexander [mailto:lists () itsecurity3 its uiowa edu] 
Sent: Monday, January 26, 2004 4:37 PM
To: Jeff Evenson
Subject: Re: [Snort-users] Snort 2.1.0 rules won't update in SnortCenter

I'm not the best programer in the world either. I'm just trying to make 
it work for myself in my free time. If I get it working I'll set it free
but I don't have a time line for a fix as I'm doing this in my limited
free time.

Jason


Jeff Evenson wrote:
Great,
I'd love to assist, but I'm not a programmer by trade.  Thanks for the
info.
jeff

-----Original Message-----
From: Jason Alexander [mailto:lists () itsecurity3 its uiowa edu] 
Sent: Friday, January 23, 2004 9:25 AM
To: Jeff Evenson
Cc: snort-users () lists sourceforge net
Subject: Re: [Snort-users] Snort 2.1.0 rules won't update in
SnortCenter

Jeff,

That's becasue SnortCenter doesn't know about all the rules changes in
Snort 2.1.  When you try to import some of the rules thare aren't
fields
in the database that are needed and you get the SQL Error.  It also 
doesn't know anything about some of the preprocessors.

  I'm currently working on trying to addapt Snort Center to work with
2.1 but my schedule has kept me away for the last couple of days 
(Beagle).  If I get it working I'll post my revised code here

Jason Alexander
IT Security
University of Iowa

Jeff Evenson wrote:

I have been attempting to use SnortCenter to update rules via the 
internet or file upload. I've changed the path in the config.php to 
point to the snortrules-current file.  It is now downloading to the 
SnortCenter, but I find the following errors:



Database ERROR:Database ERROR:You have an error in your SQL syntax. 
Check the manual that corresponds to your MySQL server version for the


right syntax to use near 'yes' )' at line 1



Also, each rule it errors out on is preceded by "Unknown Rule option:

..."



Has anyone seen this?

tks,



Jeff



Jeff Evenson CISSP, MCSE, GSEC











-------------------------------------------------------
The SF.Net email is sponsored by EclipseCon 2004
Premiere Conference on Open Tools Development and Integration
See the breadth of Eclipse activity. February 3-5 in Anaheim, CA.
http://www.eclipsecon.org/osdn
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: