From: Adriel T. D. <ad_...@ne...> - 2009-06-02 18:40:02
|
Guys, When will snort_inline be up to date with respect to snort's latest version? Its inability to work with flow control and the most recent rule-sets is a real pain in the ass. Anyone? Adriel T. Desautels ad_...@ne... -------------------------------------- Subscribe to our blog http://snosoft.blogspot.com |
From: Will M. <wil...@gm...> - 2009-06-09 01:29:19
|
We may update snort_inline to the latest 2.8 version but we have no plans on porting the stream4inline functionality to stream5. The reason for this is that both victor and I are busy working on a new IDP engine which you can read about at the link below. With all of that said have you tried to compile with --enable-stream4udp? I believe this will make your error go away... http://www.openinfosecfoundation.org/index.php/component/content/article/1-latest-news/43-founded Regards, Will On Tue, Jun 2, 2009 at 1:20 PM, Adriel T. Desautels<ad_...@ne...> wrote: > Guys, > When will snort_inline be up to date with respect to snort's latest > version? Its inability to work with flow control and the most recent > rule-sets is a real pain in the ass. Anyone? > > > Adriel T. Desautels > ad_...@ne... > -------------------------------------- > > Subscribe to our blog > http://snosoft.blogspot.com > > > ------------------------------------------------------------------------------ > OpenSolaris 2009.06 is a cutting edge operating system for enterprises > looking to deploy the next generation of Solaris that includes the latest > innovations from Sun and the OpenSource community. Download a copy and > enjoy capabilities such as Networking, Storage and Virtualization. > Go to: http://p.sf.net/sfu/opensolaris-get > _______________________________________________ > Snort-inline-users mailing list > Sno...@li... > https://lists.sourceforge.net/lists/listinfo/snort-inline-users > |
From: Adriel T. D. <ad_...@ne...> - 2009-06-09 17:09:47
|
Certainly haven't tried that yet, I'll give it a shot. By the way, do you remember me from Open Market? On Jun 8, 2009, at 9:29 PM, Will Metcalf wrote: > We may update snort_inline to the latest 2.8 version but we have no > plans on porting the stream4inline functionality to stream5. The > reason for this is that both victor and I are busy working on a new > IDP engine which you can read about at the link below. With all of > that said have you tried to compile with --enable-stream4udp? I > believe this will make your error go away... > > http://www.openinfosecfoundation.org/index.php/component/content/article/1-latest-news/43-founded > > Regards, > > Will > > On Tue, Jun 2, 2009 at 1:20 PM, Adriel T. > Desautels<ad_...@ne...> wrote: >> Guys, >> When will snort_inline be up to date with respect to snort's >> latest >> version? Its inability to work with flow control and the most recent >> rule-sets is a real pain in the ass. Anyone? >> >> >> Adriel T. Desautels >> ad_...@ne... >> -------------------------------------- >> >> Subscribe to our blog >> http://snosoft.blogspot.com >> >> >> ------------------------------------------------------------------------------ >> OpenSolaris 2009.06 is a cutting edge operating system for >> enterprises >> looking to deploy the next generation of Solaris that includes the >> latest >> innovations from Sun and the OpenSource community. Download a copy >> and >> enjoy capabilities such as Networking, Storage and Virtualization. >> Go to: http://p.sf.net/sfu/opensolaris-get >> _______________________________________________ >> Snort-inline-users mailing list >> Sno...@li... >> https://lists.sourceforge.net/lists/listinfo/snort-inline-users >> Adriel T. Desautels ad_...@ne... -------------------------------------- Subscribe to our blog http://snosoft.blogspot.com |
From: Adriel T. D. <ad_...@ne...> - 2009-06-12 18:39:31
|
And this error? ERROR: Warning: /usr/local/etc/snort_inline/rules/web-cgi.rules(24) => Unknown keyword ' metadata' in rule! Fatal Error, Quitting.. On Jun 8, 2009, at 9:29 PM, Will Metcalf wrote: > We may update snort_inline to the latest 2.8 version but we have no > plans on porting the stream4inline functionality to stream5. The > reason for this is that both victor and I are busy working on a new > IDP engine which you can read about at the link below. With all of > that said have you tried to compile with --enable-stream4udp? I > believe this will make your error go away... > > http://www.openinfosecfoundation.org/index.php/component/content/article/1-latest-news/43-founded > > Regards, > > Will > > On Tue, Jun 2, 2009 at 1:20 PM, Adriel T. > Desautels<ad_...@ne...> wrote: >> Guys, >> When will snort_inline be up to date with respect to snort's >> latest >> version? Its inability to work with flow control and the most recent >> rule-sets is a real pain in the ass. Anyone? >> >> >> Adriel T. Desautels >> ad_...@ne... >> -------------------------------------- >> >> Subscribe to our blog >> http://snosoft.blogspot.com >> >> >> ------------------------------------------------------------------------------ >> OpenSolaris 2009.06 is a cutting edge operating system for >> enterprises >> looking to deploy the next generation of Solaris that includes the >> latest >> innovations from Sun and the OpenSource community. Download a copy >> and >> enjoy capabilities such as Networking, Storage and Virtualization. >> Go to: http://p.sf.net/sfu/opensolaris-get >> _______________________________________________ >> Snort-inline-users mailing list >> Sno...@li... >> https://lists.sourceforge.net/lists/listinfo/snort-inline-users >> Adriel T. Desautels ad_...@ne... -------------------------------------- Subscribe to our blog http://snosoft.blogspot.com |
From: Will M. <wil...@gm...> - 2009-06-12 19:27:38
|
What version of snort_inline are you using? Regards, Will On Fri, Jun 12, 2009 at 1:37 PM, Adriel T. Desautels<ad_...@ne...> wrote: > And this error? > > ERROR: Warning: /usr/local/etc/snort_inline/rules/web-cgi.rules(24) => > Unknown keyword ' metadata' in rule! > Fatal Error, Quitting.. > > > > On Jun 8, 2009, at 9:29 PM, Will Metcalf wrote: > >> We may update snort_inline to the latest 2.8 version but we have no >> plans on porting the stream4inline functionality to stream5. The >> reason for this is that both victor and I are busy working on a new >> IDP engine which you can read about at the link below. With all of >> that said have you tried to compile with --enable-stream4udp? I >> believe this will make your error go away... >> >> >> http://www.openinfosecfoundation.org/index.php/component/content/article/1-latest-news/43-founded >> >> Regards, >> >> Will >> >> On Tue, Jun 2, 2009 at 1:20 PM, Adriel T. >> Desautels<ad_...@ne...> wrote: >>> >>> Guys, >>> When will snort_inline be up to date with respect to snort's latest >>> version? Its inability to work with flow control and the most recent >>> rule-sets is a real pain in the ass. Anyone? >>> >>> >>> Adriel T. Desautels >>> ad_...@ne... >>> -------------------------------------- >>> >>> Subscribe to our blog >>> http://snosoft.blogspot.com >>> >>> >>> >>> ------------------------------------------------------------------------------ >>> OpenSolaris 2009.06 is a cutting edge operating system for enterprises >>> looking to deploy the next generation of Solaris that includes the latest >>> innovations from Sun and the OpenSource community. Download a copy and >>> enjoy capabilities such as Networking, Storage and Virtualization. >>> Go to: http://p.sf.net/sfu/opensolaris-get >>> _______________________________________________ >>> Snort-inline-users mailing list >>> Sno...@li... >>> https://lists.sourceforge.net/lists/listinfo/snort-inline-users >>> > > > > Adriel T. Desautels > ad_...@ne... > -------------------------------------- > > Subscribe to our blog > http://snosoft.blogspot.com > > |
From: Adriel T. D. <ad_...@ne...> - 2009-06-12 19:48:34
|
,,_ -*> Snort_Inline! <*- o" )~ Version 2.4.5 (Build 29) FreeBSD '''' By Martin Roesch & The Snort Team: http://www.snort.org/team.html (C) Copyright 1998-2005 Sourcefire Inc., et al. Snort_Inline Mod by William Metcalf, Victor Julien, Nick Rogness, Dave Remien, Rob McMillen and Jed Haile NOTE: Snort's default output has changed in version 2.4.1! The default logging mode is now PCAP, use "-K ascii" to activate the old default logging mode. On Jun 12, 2009, at 3:24 PM, Will Metcalf wrote: > What version of snort_inline are you using? > > Regards, > > Will > > On Fri, Jun 12, 2009 at 1:37 PM, Adriel T. > Desautels<ad_...@ne...> wrote: >> And this error? >> >> ERROR: Warning: /usr/local/etc/snort_inline/rules/web-cgi.rules(24) >> => >> Unknown keyword ' metadata' in rule! >> Fatal Error, Quitting.. >> >> >> >> On Jun 8, 2009, at 9:29 PM, Will Metcalf wrote: >> >>> We may update snort_inline to the latest 2.8 version but we have no >>> plans on porting the stream4inline functionality to stream5. The >>> reason for this is that both victor and I are busy working on a new >>> IDP engine which you can read about at the link below. With all of >>> that said have you tried to compile with --enable-stream4udp? I >>> believe this will make your error go away... >>> >>> >>> http://www.openinfosecfoundation.org/index.php/component/content/article/1-latest-news/43-founded >>> >>> Regards, >>> >>> Will >>> >>> On Tue, Jun 2, 2009 at 1:20 PM, Adriel T. >>> Desautels<ad_...@ne...> wrote: >>>> >>>> Guys, >>>> When will snort_inline be up to date with respect to >>>> snort's latest >>>> version? Its inability to work with flow control and the most >>>> recent >>>> rule-sets is a real pain in the ass. Anyone? >>>> >>>> >>>> Adriel T. Desautels >>>> ad_...@ne... >>>> -------------------------------------- >>>> >>>> Subscribe to our blog >>>> http://snosoft.blogspot.com >>>> >>>> >>>> >>>> ------------------------------------------------------------------------------ >>>> OpenSolaris 2009.06 is a cutting edge operating system for >>>> enterprises >>>> looking to deploy the next generation of Solaris that includes >>>> the latest >>>> innovations from Sun and the OpenSource community. Download a >>>> copy and >>>> enjoy capabilities such as Networking, Storage and Virtualization. >>>> Go to: http://p.sf.net/sfu/opensolaris-get >>>> _______________________________________________ >>>> Snort-inline-users mailing list >>>> Sno...@li... >>>> https://lists.sourceforge.net/lists/listinfo/snort-inline-users >>>> >> >> >> >> Adriel T. Desautels >> ad_...@ne... >> -------------------------------------- >> >> Subscribe to our blog >> http://snosoft.blogspot.com >> >> Adriel T. Desautels ad_...@ne... -------------------------------------- Subscribe to our blog http://snosoft.blogspot.com |
From: Adriel T. D. <ad_...@ne...> - 2009-06-12 19:48:23
|
From the FreeBSD ports... On Jun 12, 2009, at 3:24 PM, Will Metcalf wrote: > What version of snort_inline are you using? > > Regards, > > Will > > On Fri, Jun 12, 2009 at 1:37 PM, Adriel T. > Desautels<ad_...@ne...> wrote: >> And this error? >> >> ERROR: Warning: /usr/local/etc/snort_inline/rules/web-cgi.rules(24) >> => >> Unknown keyword ' metadata' in rule! >> Fatal Error, Quitting.. >> >> >> >> On Jun 8, 2009, at 9:29 PM, Will Metcalf wrote: >> >>> We may update snort_inline to the latest 2.8 version but we have no >>> plans on porting the stream4inline functionality to stream5. The >>> reason for this is that both victor and I are busy working on a new >>> IDP engine which you can read about at the link below. With all of >>> that said have you tried to compile with --enable-stream4udp? I >>> believe this will make your error go away... >>> >>> >>> http://www.openinfosecfoundation.org/index.php/component/content/article/1-latest-news/43-founded >>> >>> Regards, >>> >>> Will >>> >>> On Tue, Jun 2, 2009 at 1:20 PM, Adriel T. >>> Desautels<ad_...@ne...> wrote: >>>> >>>> Guys, >>>> When will snort_inline be up to date with respect to >>>> snort's latest >>>> version? Its inability to work with flow control and the most >>>> recent >>>> rule-sets is a real pain in the ass. Anyone? >>>> >>>> >>>> Adriel T. Desautels >>>> ad_...@ne... >>>> -------------------------------------- >>>> >>>> Subscribe to our blog >>>> http://snosoft.blogspot.com >>>> >>>> >>>> >>>> ------------------------------------------------------------------------------ >>>> OpenSolaris 2009.06 is a cutting edge operating system for >>>> enterprises >>>> looking to deploy the next generation of Solaris that includes >>>> the latest >>>> innovations from Sun and the OpenSource community. Download a >>>> copy and >>>> enjoy capabilities such as Networking, Storage and Virtualization. >>>> Go to: http://p.sf.net/sfu/opensolaris-get >>>> _______________________________________________ >>>> Snort-inline-users mailing list >>>> Sno...@li... >>>> https://lists.sourceforge.net/lists/listinfo/snort-inline-users >>>> >> >> >> >> Adriel T. Desautels >> ad_...@ne... >> -------------------------------------- >> >> Subscribe to our blog >> http://snosoft.blogspot.com >> >> Adriel T. Desautels ad_...@ne... -------------------------------------- Subscribe to our blog http://snosoft.blogspot.com |
From: Will M. <wil...@gm...> - 2009-06-12 19:53:54
|
That version is really old. Try compiling a newer version from source... http://sourceforge.net/project/platformdownload.php?group_id=78497 Regards, Will On Fri, Jun 12, 2009 at 2:47 PM, Adriel T. Desautels<ad_...@ne...> wrote: > From the FreeBSD ports... > > > On Jun 12, 2009, at 3:24 PM, Will Metcalf wrote: > >> What version of snort_inline are you using? >> >> Regards, >> >> Will >> >> On Fri, Jun 12, 2009 at 1:37 PM, Adriel T. >> Desautels<ad_...@ne...> wrote: >>> >>> And this error? >>> >>> ERROR: Warning: /usr/local/etc/snort_inline/rules/web-cgi.rules(24) => >>> Unknown keyword ' metadata' in rule! >>> Fatal Error, Quitting.. >>> >>> >>> >>> On Jun 8, 2009, at 9:29 PM, Will Metcalf wrote: >>> >>>> We may update snort_inline to the latest 2.8 version but we have no >>>> plans on porting the stream4inline functionality to stream5. The >>>> reason for this is that both victor and I are busy working on a new >>>> IDP engine which you can read about at the link below. With all of >>>> that said have you tried to compile with --enable-stream4udp? I >>>> believe this will make your error go away... >>>> >>>> >>>> >>>> http://www.openinfosecfoundation.org/index.php/component/content/article/1-latest-news/43-founded >>>> >>>> Regards, >>>> >>>> Will >>>> >>>> On Tue, Jun 2, 2009 at 1:20 PM, Adriel T. >>>> Desautels<ad_...@ne...> wrote: >>>>> >>>>> Guys, >>>>> When will snort_inline be up to date with respect to snort's >>>>> latest >>>>> version? Its inability to work with flow control and the most recent >>>>> rule-sets is a real pain in the ass. Anyone? >>>>> >>>>> >>>>> Adriel T. Desautels >>>>> ad_...@ne... >>>>> -------------------------------------- >>>>> >>>>> Subscribe to our blog >>>>> http://snosoft.blogspot.com >>>>> >>>>> >>>>> >>>>> >>>>> ------------------------------------------------------------------------------ >>>>> OpenSolaris 2009.06 is a cutting edge operating system for enterprises >>>>> looking to deploy the next generation of Solaris that includes the >>>>> latest >>>>> innovations from Sun and the OpenSource community. Download a copy and >>>>> enjoy capabilities such as Networking, Storage and Virtualization. >>>>> Go to: http://p.sf.net/sfu/opensolaris-get >>>>> _______________________________________________ >>>>> Snort-inline-users mailing list >>>>> Sno...@li... >>>>> https://lists.sourceforge.net/lists/listinfo/snort-inline-users >>>>> >>> >>> >>> >>> Adriel T. Desautels >>> ad_...@ne... >>> -------------------------------------- >>> >>> Subscribe to our blog >>> http://snosoft.blogspot.com >>> >>> > > > > Adriel T. Desautels > ad_...@ne... > -------------------------------------- > > Subscribe to our blog > http://snosoft.blogspot.com > > |
From: Adriel T. D. <ad_...@ne...> - 2009-06-12 19:56:02
|
Indeed that might help... thanks much. On Jun 12, 2009, at 3:52 PM, Will Metcalf wrote: > That version is really old. Try compiling a newer version from > source... > > http://sourceforge.net/project/platformdownload.php?group_id=78497 > > Regards, > > Will > > On Fri, Jun 12, 2009 at 2:47 PM, Adriel T. > Desautels<ad_...@ne...> wrote: >> From the FreeBSD ports... >> >> >> On Jun 12, 2009, at 3:24 PM, Will Metcalf wrote: >> >>> What version of snort_inline are you using? >>> >>> Regards, >>> >>> Will >>> >>> On Fri, Jun 12, 2009 at 1:37 PM, Adriel T. >>> Desautels<ad_...@ne...> wrote: >>>> >>>> And this error? >>>> >>>> ERROR: Warning: /usr/local/etc/snort_inline/rules/web- >>>> cgi.rules(24) => >>>> Unknown keyword ' metadata' in rule! >>>> Fatal Error, Quitting.. >>>> >>>> >>>> >>>> On Jun 8, 2009, at 9:29 PM, Will Metcalf wrote: >>>> >>>>> We may update snort_inline to the latest 2.8 version but we have >>>>> no >>>>> plans on porting the stream4inline functionality to stream5. The >>>>> reason for this is that both victor and I are busy working on a >>>>> new >>>>> IDP engine which you can read about at the link below. With all of >>>>> that said have you tried to compile with --enable-stream4udp? I >>>>> believe this will make your error go away... >>>>> >>>>> >>>>> >>>>> http://www.openinfosecfoundation.org/index.php/component/content/article/1-latest-news/43-founded >>>>> >>>>> Regards, >>>>> >>>>> Will >>>>> >>>>> On Tue, Jun 2, 2009 at 1:20 PM, Adriel T. >>>>> Desautels<ad_...@ne...> wrote: >>>>>> >>>>>> Guys, >>>>>> When will snort_inline be up to date with respect to snort's >>>>>> latest >>>>>> version? Its inability to work with flow control and the most >>>>>> recent >>>>>> rule-sets is a real pain in the ass. Anyone? >>>>>> >>>>>> >>>>>> Adriel T. Desautels >>>>>> ad_...@ne... >>>>>> -------------------------------------- >>>>>> >>>>>> Subscribe to our blog >>>>>> http://snosoft.blogspot.com >>>>>> >>>>>> >>>>>> >>>>>> >>>>>> ------------------------------------------------------------------------------ >>>>>> OpenSolaris 2009.06 is a cutting edge operating system for >>>>>> enterprises >>>>>> looking to deploy the next generation of Solaris that includes >>>>>> the >>>>>> latest >>>>>> innovations from Sun and the OpenSource community. Download a >>>>>> copy and >>>>>> enjoy capabilities such as Networking, Storage and >>>>>> Virtualization. >>>>>> Go to: http://p.sf.net/sfu/opensolaris-get >>>>>> _______________________________________________ >>>>>> Snort-inline-users mailing list >>>>>> Sno...@li... >>>>>> https://lists.sourceforge.net/lists/listinfo/snort-inline-users >>>>>> >>>> >>>> >>>> >>>> Adriel T. Desautels >>>> ad_...@ne... >>>> -------------------------------------- >>>> >>>> Subscribe to our blog >>>> http://snosoft.blogspot.com >>>> >>>> >> >> >> >> Adriel T. Desautels >> ad_...@ne... >> -------------------------------------- >> >> Subscribe to our blog >> http://snosoft.blogspot.com >> >> Adriel T. Desautels ad_...@ne... -------------------------------------- Subscribe to our blog http://snosoft.blogspot.com |