SYSTEM WARNING: 'date_default_timezone_get(): It is not safe to rely on the system's timezone settings. You are *required* to use the date.timezone setting or the date_default_timezone_set() function. In case you used any of those methods and you are still getting this warning, you most likely misspelled the timezone identifier. We selected the timezone 'UTC' for now, but please set date.timezone to select your timezone.' in '/usr/share/mantis/www/core.php' line 264

0000583: Snort Rules Location Incorrect? - MantisBT Endian Bugtracker
Endian Issue Tracker





Please see now our new Bugtracker system: JIRA








View Issue Details Jump to Notes ] Issue History ] Print ]
IDProjectCategoryView StatusDate SubmittedLast Update
0000583Endian FirewallOther Servicespublic2008-03-03 11:292009-10-27 12:03
ReporterBKJ 
Assigned Topeter-endian 
PrioritynormalSeverityminorReproducibilityalways
StatusclosedResolutionfixed 
PlatformOSOS Version
Product Version2.2-beta3 
Target VersionFixed in Version2.2-rc1 
Summary0000583: Snort Rules Location Incorrect?
DescriptionIt could be me and my misunderstanding of snort so please forgive me if the issue is really not an actual issue. Looking at the /etc/snort/snort.conf.tmpl on line 29 "var RULE_PATH /etc/snort/rules" seems to be incorrect. Shouldn't it be "var RULE_PATH /etc/snort" as the current rules folder does exist but is completly empty. The snort rules are being downloaded to /etc/snort and are there and have a .rules extension. The rules were downloaded by EFW web interface (services-intrusion detection-download new ruleset). In addition, shouldn't the snort.conf.tmpl include a section similiar to this:

##Customize your rule set
include $RULE_PATH/local.rules
include $RULE_PATH/bad-traffic.rules
include $RULE_PATH/exploit.rules

Thanks for a great product once the bugs are worked out.
TagsNo tags attached.
Attached Files

- Relationships
related to 0000536closedpeter-endian Intrusion Detection System (Snort) does not retain setting it to "Sourcefire VRT rules for registered users" 
related to 0000732closedlukas-endian Snort kann nicht aktualisiert werden 

-  Notes
There are no notes attached to this issue.

- Issue History
Date Modified Username Field Change
2008-03-03 11:29 BKJ New Issue
2008-03-04 15:12 peter-endian Status new => confirmed
2008-03-04 15:13 peter-endian Relationship added related to 0000536
2008-05-09 17:50 peter-endian Relationship added related to 0000732
2008-05-09 17:50 peter-endian Status confirmed => resolved
2008-05-09 17:50 peter-endian Fixed in Version => 2.2-rc1
2008-05-09 17:50 peter-endian Resolution open => fixed
2008-05-09 17:50 peter-endian Assigned To => peter-endian
2009-10-27 12:03 peter-endian Status resolved => closed

Copyright © 2005-2008 Endian, SRL. All rights reserved.


Copyright © 2000 - 2012 MantisBT Group
Powered by Mantis Bugtracker