Hi, Using ids.cgi (Services -> Intrusion Detection) breaks the rule file by splitting some lines in 2 lines, and therefore the snort fails to start. Actions to recreate the error: expand one rule group (emerging-current_events for example), uncheck the rules containing POODLE, save. In /var/log/messages I saw snort generating a FATAL ERROR FATAL ERROR: /etc/snort/rules/emerging-current_events.rules(1943) Bad pattern length! At line 1943 in /etc/snort/rules/emerging-current_events.rules is this: alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"ET CURRENT_EVENTS Flash Action Script Invalid Regex CVE-2013-0634";flow:established,to_client; file_data; flowbits:isset,OLE.WithFlash; content:"RegExp"; distance:0; content:""; distance:0;pcre:"/^[\x20-\x7f]*\(\?[sxXmUJ]*i[sxXmUJ]*(\-[sxXmUJ]*)?\)[\x20-\x7f]*\(\?[sxXmUJ]*\-[sxXmUJ]*i[sxXmUJ]*\)[\x20-\x7f]*\|\|/R";reference:cve,2013-0364; classtype:trojan-activity; sid:2016401; rev:3;) Clearly the line 1943 is not the one I've unchecked in the Web Interface - the ones I've unchecked are containing POODLE! The above line 1943 is actually part of the rule, the last part of a rule. The rule was split in 2 lines after using ids.cgi. Also, other rules were split in 2, not only the one I gave as example. More details in the forum: http://forum.ipfire.org/viewtopic.php?f=52&t=12475 Best regards, H&M
Stefan, could you please confirm if this is a bug?
Could be related to: https://bugzilla.ipfire.org/show_bug.cgi?id=10770
Could be related to: https://bugzilla.ipfire.org/show_bug.cgi?id=10791
Has this been confirmed as a bug?
Several bugs were reported with snort / ids before update 89. Feedback has been provided and feedback needs to be received back if needed. Any plans to move away from snort to something like suricata ? http://suricata-ids.org/features/all-features/
Any update to this and the other snort/ids bugs? Was hoping it would be fixed in Core Update 90.
Is this still up to date? Experiencing some issues with Snort here, but I am not sure if this might be related.
Fixed during the movement from snort to suricata.