Bug 10614 - Snort VRT rules don't work
Summary: Snort VRT rules don't work
Status: CLOSED DUPLICATE of bug 10273
Alias: None
Product: IPFire
Classification: Unclassified
Component: oinkmaster (show other bugs)
Version: 2
Hardware: unspecified Unspecified
: - Unknown - - Unknown -
Assignee: Assigned to nobody - feel free to grab it and work on it
QA Contact:
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-09-08 09:57 UTC by Lucifer Cipher
Modified: 2017-11-08 16:10 UTC (History)
3 users (show)

See Also:
michael.tremer: needinfo+


Attachments
screenshot (66.90 KB, image/png)
2014-09-08 20:45 UTC, Lucifer Cipher
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Lucifer Cipher 2014-09-08 09:57:56 UTC
My tests show that the checked rules do not work for VRT against subscription. Emerging threats work fine. There is no alert or indication generated by the IDS.
Comment 1 Michael Tremer 2014-09-08 20:33:08 UTC
Please provide an error message about what went wrong there.
Comment 2 Lucifer Cipher 2014-09-08 20:45:57 UTC
Created attachment 219 [details]
screenshot
Comment 3 Lucifer Cipher 2014-09-09 22:47:22 UTC
Further bug:

Snort when enabled does not intercept traffic on Orange interface at all.
Comment 4 Stefan Schantl 2015-04-13 10:15:55 UTC
Comment 3 is a duplicate of #10273.

Does the main issue still exists in the latest available version of IPFire 2 - Core 88 or the testing release Core 89 ?

Best regards,

-Stefan
Comment 5 Lucifer Cipher 2015-05-08 21:23:04 UTC
Yes Stefan. Tested and the problem is still there. VRT rules are successfully loaded but my testing shows that IDS can't even detect portscans and advanced XSS and SQL injection attacks.
Comment 6 Lucifer Cipher 2015-05-08 21:23:41 UTC
(In reply to Lucifer Cipher from comment #5)
> Yes Stefan. Tested and the problem is still there. VRT rules are
> successfully loaded but my testing shows that IDS can't even detect
> portscans and advanced XSS and SQL injection attacks.

Core89 tested. Problem not resolved.
Comment 7 Lucifer Cipher 2015-05-13 21:13:58 UTC
(In reply to Stefan Schantl from comment #4)
> Comment 3 is a duplicate of #10273.
> 
> Does the main issue still exists in the latest available version of IPFire 2
> - Core 88 or the testing release Core 89 ?
> 
> Best regards,
> 
> -Stefan

Tested again. Problem still exists. Please tell me what should i try at my end and I will try to help you guys out too for problem eradication.

best regards.
Comment 8 Peter Müller 2017-11-08 16:10:49 UTC
I can confirm that snort does not detect internal attacks from i.e. GREEN to i.e. ORANGE. If an attack is running against the firewall itself, the detection works.

However, that is a duplicate of #10273. Currently working to find these snort bugs and fix them (see https://wiki.ipfire.org/devel/telco/2017-11-06).

*** This bug has been marked as a duplicate of bug 10273 ***