Snort mailing list archives

Re: HTTP 422 when trying to download rulesets with pulledpork


From: Anshuman Anil Deshmukh <anshuman () cybage com>
Date: Fri, 11 Jul 2014 14:02:21 +0000

Hi Joel,



Here is where I am downloading from-



rule_url=https://www.snort.org/reg-rules/|opensource.gz|e5454e32094dd017be5907b5cacb387eb55d2152

rule_url=https://rules.emergingthreats.net/|emerging.rules.tar.gz|open

rule_url=https://s3.amazonaws.com/snort-org/www/rules/community/|community-rules.tar.gz|Community

rule_url=http://labs.snort.org/feeds/ip-filter.blf|IPBLACKLIST|open



Just to let you know I was able to download the rules till day before yesterday.





Regards,

Anshuman



From: Joel Esler (jesler) [mailto:jesler () cisco com]
Sent: Friday, July 11, 2014 5:42 PM
To: Anshuman Anil Deshmukh
Cc: snort-users mailinglist
Subject: Re: [Snort-users] HTTP 422 when trying to download rulesets with pulledpork



What file are you trying to download?

--

Joel Esler

Sent from my iPhone


On Jul 11, 2014, at 3:21, "Anshuman Anil Deshmukh" <anshuman () cybage com<mailto:anshuman () cybage com>> wrote:

   Hi,



   We are still having issues downloading the rules. Is this going to take some more time to fix?





   Regards,

   Anshuman



   From: Joel Esler (jesler) [mailto:jesler () cisco com]
   Sent: Friday, July 11, 2014 12:10 AM
   To: Starner, Mark
   Cc: snort-users mailinglist
   Subject: Re: [Snort-users] HTTP 422 when trying to download rulesets with pulledpork



   It's an error on our side, you shouldn't have to change a thing.





   On Jul 10, 2014, at 2:15 PM, Starner, Mark <mark.starner () unisys com<mailto:mark.starner () unisys com>> wrote:






   So, once it is working on the snort.org<http://snort.org/> website, the new rule_url line should be as you specified 
below, with no |, ignoring the rules specified?

   # note that the url, rule file, and oinkcode itself are separated by a pipe |

   # i.e. url|tarball|123456789



   Very confused!



   Thanks

   Mark





   From: Shirkdog [mailto:shirkdog () gmail com]
   Sent: Thursday, July 10, 2014 8:46 AM
   To: Anshuman Anil Deshmukh
   Cc: snort-users mailinglist
   Subject: Re: [Snort-users] HTTP 422 when trying to download rulesets with pulledpork



   I will work on updating the default for pulled pork, but use the following URL, per the new website:

   https://www.snort.org/rules/snortrules-snapshot-29xx-tar.gz?<oinkcode>

   On Jul 10, 2014 8:40 AM, "Anshuman Anil Deshmukh" <anshuman () cybage com<mailto:anshuman () cybage com>> wrote:

   Hi,



   Even I am getting such error. in my case the only difference is that I am on the older version. Is it something to 
do with the recent changes that happened on the website?



   Base URL is: 
https://www.snort.org/reg-rules/|snortrules-snapshot.tar.gz|<https://www.snort.org/reg-rules/%7Csnortrules-snapshot.tar.gz%7C><my
 oinkcode>https://www.snort.org/reg-rules/|opensource.gz|<https://www.snort.org/reg-rules/%7Copensource.gz%7C><my 
oinkcode>https://rules.emergingthreats.net/|emerging.rules.tar.gz|open<https://rules.emergingthreats.net/%7Cemerging.rules.tar.gz%7Copen>
 
https://s3.amazonaws.com/snort-org/www/rules/community/|community-rules.tar.gz|Community<https://s3.amazonaws.com/snort-org/www/rules/community/%7Ccommunity-rules.tar.gz%7CCommunity>
 
http://labs.snort.org/feeds/ip-filter.blf|IPBLACKLIST|open<http://labs.snort.org/feeds/ip-filter.blf%7CIPBLACKLIST%7Copen>

   Checking latest MD5 for snortrules-snapshot-2950.tar.gz....

                   Fetching md5sum for: snortrules-snapshot-2950.tar.gz.md5

   ** GET https://www.snort.org/reg-rules/snortrules-snapshot-2950.tar.gz.md5/<my oinkcode> ==> 422 Unprocessable 
Entity (2s)

                   Error 422 when fetching https://www.snort.org/reg-rules/snortrules-snapshot-2950.tar.gz.md5 
atpulledpork.pl<http://pulledpork.pl/> line 463

                   main::md5file('<my oinkcode>', 'snortrules-snapshot-2950.tar.gz', '/etc/snort/tmp/', 
'https://www.snort.org/reg-rules/&apos;) called at pulledpork.pl<http://pulledpork.pl/> line 1847





   Regards,

   Anshuman





   -----Original Message-----
   From: Laszlo Toth [mailto:laszlo.toth () linguamatics com<mailto:laszlo.toth () linguamatics com>]
   Sent: Thursday, July 10, 2014 5:00 PM
   To: snort-users () lists sourceforge net<mailto:snort-users () lists sourceforge net>
   Subject: [Snort-users] HTTP 422 when trying to download rulesets with pulledpork



   Hi,



   I'm trying to download the registered rules with pulledpork but I'm getting the following error message:



   Rules tarball download of snortrules-snapshot-2961.tar.gz....

            Error 422 when fetching snortrules-snapshot-2961.tar.gz at ./pulledpork.pl<http://pulledpork.pl/> line 408

            main::rulefetch('oinkcode', 'snortrules-snapshot-2961.tar.gz',

   '/tmp/', 'https://www.snort.org/reg-rules/&apos;) called at ./pulledpork.pl<http://pulledpork.pl/> line 1856



   Pulledpork rule config:

   
rule_url=https://www.snort.org/reg-rules/|snortrules-snapshot.tar.gz|oinkcode<https://www.snort.org/reg-rules/%7Csnortrules-snapshot.tar.gz%7Coinkcode>





   I get the same HTTP response code when I try to manually download the rules 
fromhttps://www.snort.org/reg-rules/snortrules-snapshot-2961.tar.gz/oinkcode



   Am I missing something?

   Thanks,

   Laszlo



   --

   Laszlo Toth

   Systems administrator

   Linguamatics

   324 Cambridge Science Park

   Milton Road

   Cambridge

   CB4 0WG

   UK

   Telephone number:

   +44 (0)1223 651910<tel:%2B44%20%280%291223%20651910>

   www.linguamatics.com<http://www.linguamatics.com/>





   ------------------------------------------------------------------------------

   Open source business process management suite built on Java and Eclipse Turn processes into business applications 
with Bonita BPM Community Edition Quickly connect people, data, and systems into organized workflows Winner of BOSSIE, 
CODIE, OW2 and Gartner awards http://p.sf.net/sfu/Bonitasoft_______________________________________________

   Snort-users mailing list

   Snort-users () lists sourceforge net<mailto:Snort-users () lists sourceforge net>

   Go to this URL to change user options or unsubscribe:

   https://lists.sourceforge.net/lists/listinfo/snort-users

   Snort-users list archive:

   http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users



   Please visit http://blog.snort.org<http://blog.snort.org/> to stay current on all the latest Snort news!






   "Legal Disclaimer: This electronic message and all contents contain information from Cybage Software Private Limited 
which may be privileged, confidential, or otherwise protected from disclosure. The information is intended to be for 
the addressee(s) only. If you are not an addressee, any disclosure, copy, distribution, or use of the contents of this 
message is strictly prohibited. If you have received this electronic message in error please notify the sender by reply 
e-mail to and destroy the original message and all copies. Cybage has taken every reasonable precaution to minimize the 
risk of malicious content in the mail, but is not liable for any damage you may sustain as a result of any malicious 
content in this e-mail. You should carry out your own malicious content checks before opening the e-mail or 
attachment." www.cybage.com<http://www.cybage.com/>


   ------------------------------------------------------------------------------
   Open source business process management suite built on Java and Eclipse
   Turn processes into business applications with Bonita BPM Community Edition
   Quickly connect people, data, and systems into organized workflows
   Winner of BOSSIE, CODIE, OW2 and Gartner awards
   http://p.sf.net/sfu/Bonitasoft
   _______________________________________________
   Snort-users mailing list
   Snort-users () lists sourceforge net<mailto:Snort-users () lists sourceforge net>
   Go to this URL to change user options or unsubscribe:
   https://lists.sourceforge.net/lists/listinfo/snort-users
   Snort-users list archive:
   http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

   Please visit http://blog.snort.org<http://blog.snort.org/> to stay current on all the latest Snort news!

   ------------------------------------------------------------------------------
   Open source business process management suite built on Java and Eclipse
   Turn processes into business applications with Bonita BPM Community Edition
   Quickly connect people, data, and systems into organized workflows
   Winner of BOSSIE, CODIE, OW2 and Gartner awards
   http://p.sf.net/sfu/Bonitasoft_______________________________________________
   Snort-users mailing list
   Snort-users () lists sourceforge net<mailto:Snort-users () lists sourceforge net>
   Go to this URL to change user options or unsubscribe:
   https://lists.sourceforge.net/lists/listinfo/snort-users
   Snort-users list archive:
   http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

   Please visit http://blog.snort.org to stay current on all the latest Snort news!






   "Legal Disclaimer: This electronic message and all contents contain information from Cybage Software Private Limited 
which may be privileged, confidential, or otherwise protected from disclosure. The information is intended to be for 
the addressee(s) only. If you are not an addressee, any disclosure, copy, distribution, or use of the contents of this 
message is strictly prohibited. If you have received this electronic message in error please notify the sender by reply 
e-mail to and destroy the original message and all copies. Cybage has taken every reasonable precaution to minimize the 
risk of malicious content in the mail, but is not liable for any damage you may sustain as a result of any malicious 
content in this e-mail. You should carry out your own malicious content checks before opening the e-mail or 
attachment." www.cybage.com<http://www.cybage.com>

   ------------------------------------------------------------------------------
   Open source business process management suite built on Java and Eclipse
   Turn processes into business applications with Bonita BPM Community Edition
   Quickly connect people, data, and systems into organized workflows
   Winner of BOSSIE, CODIE, OW2 and Gartner awards
   http://p.sf.net/sfu/Bonitasoft

   _______________________________________________
   Snort-users mailing list
   Snort-users () lists sourceforge net<mailto:Snort-users () lists sourceforge net>
   Go to this URL to change user options or unsubscribe:
   https://lists.sourceforge.net/lists/listinfo/snort-users
   Snort-users list archive:
   http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

   Please visit http://blog.snort.org to stay current on all the latest Snort news!



"Legal Disclaimer: This electronic message and all contents contain information from Cybage Software Private Limited 
which may be privileged, confidential, or otherwise protected from disclosure. The information is intended to be for 
the addressee(s) only. If you are not an addressee, any disclosure, copy, distribution, or use of the contents of this 
message is strictly prohibited. If you have received this electronic message in error please notify the sender by reply 
e-mail to and destroy the original message and all copies. Cybage has taken every reasonable precaution to minimize the 
risk of malicious content in the mail, but is not liable for any damage you may sustain as a result of any malicious 
content in this e-mail. You should carry out your own malicious content checks before opening the e-mail or 
attachment." 
www.cybage.com

------------------------------------------------------------------------------
Open source business process management suite built on Java and Eclipse
Turn processes into business applications with Bonita BPM Community Edition
Quickly connect people, data, and systems into organized workflows
Winner of BOSSIE, CODIE, OW2 and Gartner awards
http://p.sf.net/sfu/Bonitasoft
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: