Snort mailing list archives

Re: snortrules-snapshot not sustainable?


From: Matt Watchinski <mwatchinski () sourcefire com>
Date: Wed, 6 May 2009 18:03:42 -0400

Rule packages will be getting smaller in the next couple weeks, as we
drop some of the other versions.  Additionally after we switch
beta.snort.org over to snort.org we'll be investigating other ways to
distribute things.

Cheers,
-matt

On Wed, May 6, 2009 at 6:48 AM, Zultan <zultan () mad scientist com> wrote:

----- Original Message -----
From: "Jason Haar" <Jason.Haar () trimble co nz>
.........


Hi there

Has anyone looked at the size of that tar file? 94M! From New Zealand
it's taking 10-15 minutes to download, and I only want ~4M of it.

Surely this screams out for separation.
snortrules-snapshot-$VERSION-$DISTRO-$ARCH.tar.gz springs to mind?
Better yet, split the rules back into their original standalone tar, and
put the "binary" stuff in other per-distro containers?

Rsync would be better of course :-)


Rsync would be better, except for users like me.  Why?  Because politicians far above me with their lofty CISSP 
decided that rsync might be abused.  So they ordered port 873 blocked.

A simpler solution would be to reduce the size of the tarball.

Hello VRT rules folks!

Since the rules .tgz file for rules >= version 2.8.4 will not work on lessor versions, why are the precompiled rules 
for lessor still included in the tarball?

If the rules for < 2.8.4 will not be maintained, then why not fork off the 2.8.4 rules and only include the 
precompiled rules for 2.8.4+?

Z







--
Be Yourself @ mail.com!
Choose From 200+ Email Addresses
Get a Free Account at www.mail.com


------------------------------------------------------------------------------
The NEW KODAK i700 Series Scanners deliver under ANY circumstances! Your
production scanning environment may not be a perfect world - but thanks to
Kodak, there's a perfect scanner to get the job done! With the NEW KODAK i700
Series Scanner you'll get full speed at 300 dpi even with all image
processing features enabled. http://p.sf.net/sfu/kodak-com
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users




-- 
Matthew Watchinski
Sr. Director Vulnerability Research Team (VRT)
Sourcefire, Inc.
Office: 410-423-1928
http://vrt-sourcefire.blogspot.com && http://www.snort.org/vrt/

------------------------------------------------------------------------------
The NEW KODAK i700 Series Scanners deliver under ANY circumstances! Your
production scanning environment may not be a perfect world - but thanks to
Kodak, there's a perfect scanner to get the job done! With the NEW KODAK i700
Series Scanner you'll get full speed at 300 dpi even with all image 
processing features enabled. http://p.sf.net/sfu/kodak-com
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: