Snort mailing list archives

Re: Interesting observation with with so rules


From: <wkitty42 () windstream net>
Date: Fri, 11 Oct 2013 22:23:19 -0400


On Friday, October 11, 2013 11:11 AM, James Lay <jlay () slave-tothe-box net> wrote: 
include $SORULE_PATH/bad-traffic.rules 
 
 
If I leave the bad-traffic.rules line and try to dump the stubs, here's 
what I get: 

does the /opt/etc/snort/so_rules directory exist? if, yes, what are its permissions? can snort and/or pulledpork access 
it with their user or group membership?

if the directory exists, then does bad-traffic.rules exist in that directory with the needed permissions??



------------------------------------------------------------------------------
October Webinars: Code for Performance
Free Intel webinars can help you accelerate application performance.
Explore tips for MPI, OpenMP, advanced profiling, and more. Get the most from 
the latest Intel processors and coprocessors. See abstracts and register >
http://pubads.g.doubleclick.net/gampad/clk?id=60134071&iu=/4140/ostg.clktrk
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: