-
Notifications
You must be signed in to change notification settings - Fork 133
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Modifysid doesn't modify rules #357
Comments
For the first three, you should remove "1:" so your line in your modifysid.conf looks like this: |
Also, you say you are running 2.9.9.0 (which is EOL), but you are downloading 2.9.8.3 rules. 2.9.9.0 don't exist anymore, so I would suggest that you upgrade your version of Snort & your ruleset. |
Thanks for the information provided. |
It seems the modifying file is skipped for some reason by Pulledpork even using the suggested rule: pulledpork output
modifysid.conf
Snort rule
Any idea about what's wrong? |
what user is running pulledpork (maybe perms, but probably not an issue)? you have modifysid.conf in your pulledpork.conf from before, but you are using dropsid.conf to set everything to drop, then only changing this one signature to alert? Run again with -vvv, and see if anything states modifysid.conf is being used. Another test is to remove dropsid.conf, and change the modifysid.conf to go from "alert" to "drop" just to test. This may point to an order of operation issue, where pulledpork is only processing the drops, and not processing the modification. |
Hi guys,
I'm trying to modify a rule from "drop" to "alert" action, but for some reason, pulledpork is skipping any configuration in the modifysid.conf file.
my setup:
OS: Ubuntu 16.04
Snort version: 2.9.9
Pulledpork version: 0.8.0
Pulledpork config file:
Modifysid.conf file:
Rule:
Running pulledpork, basically, it is doing nothing:
I've tried the below configurations in the modifysid.conf file:
Any idea about what is wrong?
Thanks in advance,
Kind regards
The text was updated successfully, but these errors were encountered: