Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Snort-users] custom ruletype (to mysql DB) is broken in snort 2.8.0.1 |
|---|---|
| Date: | Fri, 04 Jan 2008 10:26:24 -0500 |
Thanks for bringing this to our attention. The segfault you spoke of initially will be fixed in the next release. The current issue you are experiencing apparently has been broken for quite some time. A bug has been created, but the fix will most likely not make it into the next release. Thanks, Todd Agent Smith wrote:
nope, still doesn't work. it does the same thing it did with snort 2.6 where 'redalerts' are not the only once that gets logged into its DB but other stuff goes in there too. I only have one rule that I changed from alert to redalert and I don't understand why others are logging into the DB meant for the redalert even on snort 2.7 == from snort.conf == output database: log, mysql, user=snort password=pass dbname=snort host=localhost .. .. .. ruletype redalert { type alert output alert_syslog: LOG_AUTH LOG_ALERT output database: log, mysql, user=snort dbname=redalert host=localhost password=pass } --- Agent Smith <news8080@yahoo.com> wrote:so it works in 2.7 then? I am sorry but I spend a good day fighting this and gave up. I went back to snort 2.6 and saw the same kind of things (little different in that the ruletype redalert DB was also accepting 'normal' alerts that are suppose to go to generic DB that stores everything else) and I ended up with two copies of same alert in two different DB instances. haven't tried 2.7 yet but will give it a shot now... --- Jason Brvenik <jasonb@sourcefire.com> wrote:It is a know issue. If you need custom alert type functionality you will either need to revert to 2.7.x or wait for it toberesolved in an upcoming 2.8.x release. Agent Smith wrote:OK: As I stare at these damn BASE screens I amgettingcrazy. I finally managed to get alerts in thetestdatabase (originally intended for customsignaturesonly) Now the problem is that it logs ALL alerts inbothtest DB AND snort DB. thats just weird. There islike6 lines of documentation all together infaq.pdf,nota word in any READMEs about ruletype (and now Iamposting a reply to myself in the group) Have NOONE else ran into this?? really??? The alertype crap doesn't work and I may justneedtowrite my on SQL statements to extract things Iwantstored seperately in another DB --- Agent Smith <news8080@yahoo.com> wrote:I've been at this all freaking day today andcan'tget anywhere so I am hoping that some snortprogrammerwill chime in and either point me to a doc or something. All I am trying to do is use 'ruletype' to logallof ssh hackers. I have the following in snort.confandthen in local.rules I have a custom alertdefinedwhich starts with 'redalert tcp blah blah...' I have two different mysql databases test(for redalerts) and snort (for the rest of them) onlocalmachine. If I change the redalert to alert and removetheredalert defination from snort.conf all worksfine,no segfaults there and I can read the DB usingBASE---- from snort.conf ----- output database: log, mysql, user=snort password=pass dbname=snort28 host=localhost .. .. ruletype redalert { type alert output output database: log, mysql, user=snortdbname=testhost=localhost password=pass } -------- ---------- and whenever I start snort with /usr/local/snort-2.8.0.1/bin/snort -v -c /etc/snort-2.8.0.1/etc/snort.conf --pid-path /var/run1 -i eth2 it segfaults. I read the snort2.0 book and found that youactuallyhave to do 'type alert output' and NOT 'typealert'only like documented in snort.conf.sample file I've tried changing type alert output to logoutput,output database to alert instead of log to noavail.I thought maybe this functionality is broken inthisrelease so I downgraded to 2.6 and it still segfaults so I moved the snort from fc6 to a freshinstalloffc7 on a new machine - same damn thing. so I am clueless, it seems like a simple thingthata lot of people would be using so I am hopingI'llgetsome pointers here. - Agent Smith.____________________________________________________________________________________Never miss a thing. Make Yahoo your home page. http://www.yahoo.com/r/hs-------------------------------------------------------------------------This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2005.http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/_______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe:https://lists.sourceforge.net/lists/listinfo/snort-usersSnort-users list archive:http://www.geocrawler.com/redir-sf.php3?list=snort-users____________________________________________________________________________________Looking for last minute shopping deals? Find them fast with Yahoo! Search.http://tools.search.yahoo.com/newsearch/category.php?category=shopping-------------------------------------------------------------------------This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio2005.http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/_______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options orunsubscribe:=== message truncated === ____________________________________________________________________________________ Never miss a thing. Make Yahoo your home page. http://www.yahoo.com/r/hs ------------------------------------------------------------------------- This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2005. http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/ _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
------------------------------------------------------------------------- This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2005. http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/ _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Snort-users] custom ruletype (to mysql DB) is broken in snort 2.8.0.1, Agent Smith |
|---|---|
| Next by Date: | [Snort-users] Get one specific attack dump from snort dump file., Jorge Luiz Corrêa |
| Previous by Thread: | Re: [Snort-users] custom ruletype (to mysql DB) is broken in snort 2.8.0.1, Agent Smith |
| Next by Thread: | [Full-disclosure] January 4th Chicago 2600 Meeting Information, Steven McGrath |
| Indexes: | [Date] [Thread] [Top] [All Lists] |