Snort mailing list archives

PulledPork 0.7.2 errors with ETPro rules


From: Andre DiMino <adimino () sempersecurus org>
Date: Sat, 21 Nov 2015 21:22:41 -0500

I've recently noted PulledPork errors when it attempts to download ETPro
rulesets.
I've been speaking to the developer, and have posted an issue on
PulledPork's Github.  However I wanted to put this out there in case anyone
else is experiencing similar issues.

Running PulledPork with ETPro enabled causes the following:
++++++++++++++++++++

 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Checking latest MD5 for snortrules-snapshot-2975.tar.gz....
They Match
Done!

Rules tarball download of community-rules.tar.gz....
Checking latest MD5 for opensource.gz....
They Match
Done!

Checking latest MD5 for emerging.rules.tar.gz....
No Match
Done

Rules tarball download of emerging.rules.tar.gz....
They Match
Done!

Checking latest MD5 for etpro.rules.tar.gz....

Use of uninitialized value $md5 in scalar chomp at
/home/snortscan/snort_src/pulledpork-read-only/pulledpork.pl line 522.

Use of uninitialized value $md5 in pattern match (m//) at
/home/snortscan/snort_src/pulledpork-read-only/pulledpork.pl line 524.

No Match
Done

Rules tarball download of etpro.rules.tar.gz....
No Match
Done

Rules tarball download of etpro.rules.tar.gz....
No Match
Done

Rules tarball download of etpro.rules.tar.gz....
No Match
Done

Rules tarball download of etpro.rules.tar.gz....
No Match
Done

Rules tarball download of etpro.rules.tar.gz....
No Match
Done

++++++++++++++++++++
This just loops until it crashes.
If I comment out the ETPro ruleset download. everything completes
successfully.

-- 

Andre' M. DiMino
DeepEnd Research
http://www.deependresearch.org <http://deependresearch.org>
http://sempersecurus.org

"Make sure that nobody pays back wrong for wrong, but always try to be
kind to each other and to everyone else" - 1 Thess 5:15 (NIV)
------------------------------------------------------------------------------
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: