Snort mailing list archives

Re: need assistance - no so rules with pulled pork


From: "Joel Esler (jesler)" <jesler () cisco com>
Date: Thu, 5 Mar 2015 12:25:58 +0000

What OS do you have on the pi?

--
Joel Esler
Sent from my iPhone

On Mar 5, 2015, at 6:43 AM, Rata Pelua <intesnetmiosolo () gmail com<mailto:intesnetmiosolo () gmail com>> wrote:


Hi Everybody,


I'm having different issues when I have tried to configure pulledpork in my raspberry pi (Raspbian) ,
Firstly , it didn't generate the snort.rules , but I tried several times, tried to check the pulledpork.conf
rename the path file, and after it, It successfully generated the snort.rules but not the .so rules ...

please, Is there anybody that it can help me?

Also, I would like to activate the predecessor for port scan, I have tried to include a code in the snort.conf file 
(since 426-447) but when I ran snort -b

I got a warning:

WARNING: No preprocessors configured for policy 0.



Attached there are my pulledpork.conf and snort.conf files, and output in -verbose mode .

Thank you in advance,
Atai


<snort.conf>
<pulledpork.conf>
<rules!->
<verbosemode_noSOrules>
------------------------------------------------------------------------------
Dive into the World of Parallel Programming The Go Parallel Website, sponsored
by Intel and developed in partnership with Slashdot Media, is your hub for all
things parallel software development, from weekly thought leadership blogs to
news, videos, case studies, tutorials and more. Take a look and join the
conversation now. http://goparallel.sourceforge.net/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net<mailto:Snort-users () lists sourceforge net>
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!
------------------------------------------------------------------------------
Dive into the World of Parallel Programming The Go Parallel Website, sponsored
by Intel and developed in partnership with Slashdot Media, is your hub for all
things parallel software development, from weekly thought leadership blogs to
news, videos, case studies, tutorials and more. Take a look and join the 
conversation now. http://goparallel.sourceforge.net/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: