Home page logo

snort logo Snort mailing list archives

Re: Clarification on so_rules
From: James Lay <jlay () slave-tothe-box net>
Date: Fri, 09 Aug 2013 10:32:05 -0600

On 2013-08-09 10:21, Y M wrote:
Hi James,

 I will take a shot explaining what I understand, if I get it wrong,
someone please correct me.

 PulledPork should copy the .so rules from the distro/precompiled
directory based on the distro variable you setup in your
pulledpork.conf. If you use -T in your pulledpork command, it will
process only text based rules.

Thanks YM...here's what I have in pp.conf:


As Joel said, it looks like this is doing what it's supposed to 
do...the actual .so rules don't seem to be present however...I'm 
assuming they are supposed to be in /opt/lib/snort_dynamicrules/ yes?


Get 100% visibility into Java/.NET code with AppDynamics Lite!
It's a free troubleshooting tool designed for production.
Get down to code-level detail for bottlenecks, with <2% overhead. 
Download for free and get started troubleshooting in minutes. 
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:

Please visit http://blog.snort.org to stay current on all the latest Snort news!

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]