LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 10-06-2011, 05:17 AM   #1
nkd
Member
 
Registered: Oct 2006
Location: india
Distribution: fedora 8, ubuntu 10.10
Posts: 318

Rep: Reputation: 34
Snort install on Ubuntu: no preproc rules folder?


hi everyone,
I am trying out a snort installation on my ubuntu (10.10)machine. I checked out the rules in the directory /etc/snort/rules , they seem to be all there. But I donot have a preproc_rules directory or a so_rules directory. Aren't these needed ? Becoz, my snort.conf file has the relevant entries for both of them.

BTW the rules directory and the rules in it were part of the apt-get install of the snort. I didnot download them from the snort website separately and install them.

I am wondering if the pre-processor is working at all without the rules in the preproc directory ?!?!?

Thanks in advance for any help or suggestions.

nishith
 
Old 10-06-2011, 07:00 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by nkd View Post
But I donot have a preproc_rules directory or a so_rules directory.
Preprocs are in the "snort-common-libraries" package.


Quote:
Originally Posted by nkd View Post
BTW the rules directory and the rules in it were part of the apt-get install of the snort.
Dependencies may get installed automagically but rules are in the "snort-rules-default" package.


Quote:
Originally Posted by nkd View Post
I didnot download them from the snort website separately and install them.
You should update them. If you use Snort rules use Oinkmaster or else see the Emerging Threats site for details.


Quote:
Originally Posted by nkd View Post
I am wondering if the pre-processor is working at all without the rules in the preproc directory ?!?!?
Snort comes with multiple preprocessors (see the "snort-doc" package). Some, like http_inspect or sfportscan may work but others like SSH/SSL may not w/o preloading dynamic preprocessor libraries.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[snort] Understanding Snort Rules Fracker Linux - Security 3 04-13-2009 09:34 AM
snort-2.8.2.1 Rules shahz Linux - Software 3 06-28-2008 08:21 AM
How to write two snort detection rules to alert on packets to those rules romafiel *BSD 0 06-08-2007 07:00 PM
Snort, Rules Tredo Linux - Security 1 12-20-2004 12:36 AM
Snort Rules Canadian_2k2 Linux - Security 5 11-01-2002 10:24 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 07:46 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration