PulledPork Updates

Issue 111 created: "Sagan Support / Write unknown filetypes to output directory"

PulledPork Issue Tracker - Mon, 2012-05-07 05:31
Sagan support for pulledpork is limited only by the explicit file extension matching in pulledpork's sub rule_extract Pulledpork does work to download, extract, and parse the .rule files. What does not work is that pulledpork drops the other files that are not matched in the rule_extract subroutine. Pulledpork also does not warn that unknown file types were not examined, or saved. Sagan and other similar snort based rulesets were supported by oinkmaster's "update_files" directive. update_files = \.rulebase$|\.rules$|\.config$|\.conf$|\.txt$|\.map$ Pulledpork could be updated to include a similar know file directive, or a unknown filetype write directive to directory. pullpork options: -x Keep unknown filetypes in the archive? -U Where do you want me to put unknown filetypes in the archive that are not processed by pulledpork? FYI: Sagan was supported in oinkmaster for awhile. https://wiki.softwink.com/bin/view/Main/SaganOinkmaster http://sagan.quadrantsec.com/rules/
Categories: PulledPork Updates

Update 2 to issue 110 ("default distro doesn't exist for shared object directory")

PulledPork Issue Tracker - Sat, 2012-03-10 13:14
fix for the committed version fix. -distro=FreeBSD-8.1 +distro=FreeBSD-8-1
Categories: PulledPork Updates

Revision 241: Bug #110 - it's fixed, shirk

PulledPork Subversion Changes - Fri, 2012-03-09 09:07
Changed Paths:
    Modify    /trunk/etc/pulledpork.conf

Bug #110 - it's fixed, shirk
Categories: PulledPork Updates

Issue 110 created: "default distro doesn't exist for shared object directory"

PulledPork Issue Tracker - Fri, 2012-03-09 00:33
Easy to handle, but FreeBSD-8.0 is not a default shared object directory. This just needs to be changed to FreeBSD-8-1 so people have no right to hate on FreeBSD.
Categories: PulledPork Updates

Update 1 to issue 109 ("bug when using etpro rules")

PulledPork Issue Tracker - Mon, 2012-03-05 12:51
I need a full debug (-vv) debug output to be pasted here, also need to know what command you used to run pp etc...
Categories: PulledPork Updates

Issue 109 created: "bug when using etpro rules"

PulledPork Issue Tracker - Fri, 2012-03-02 13:01
When using the form: rule_url=https://rules.emergingthreatspro.com/|etpro.rules.tar.gz|<et pro oinkcode> I get: Use of uninitialized value $getrules_md5 in numeric eq (==) at /usr/local/bin/pulledpork.pl line 444. Use of uninitialized value $getrules_md5 in numeric eq (==) at /usr/local/bin/pulledpork.pl line 449. Use of uninitialized value $getrules_md5 in concatenation (.) or string at /usr/local/bin/pulledpork.pl line 453. Error when fetching https://rules.emergingthreatspro.com/etpro.rules.tar.gz.md5 at /usr/local/bin/pulledpork.pl line 453 using 0.6.1
Categories: PulledPork Updates

Issue 109 created: "bug when using etpro rules"

PulledPork Issue Tracker - Fri, 2012-03-02 13:01
When using the form: rule_url=https://rules.emergingthreatspro.com/|etpro.rules.tar.gz|<et pro oinkcode> I get: Use of uninitialized value $getrules_md5 in numeric eq (==) at /usr/local/bin/pulledpork.pl line 444. Use of uninitialized value $getrules_md5 in numeric eq (==) at /usr/local/bin/pulledpork.pl line 449. Use of uninitialized value $getrules_md5 in concatenation (.) or string at /usr/local/bin/pulledpork.pl line 453. Error when fetching https://rules.emergingthreatspro.com/etpro.rules.tar.gz.md5 at /usr/local/bin/pulledpork.pl line 453 using 0.6.1
Categories: PulledPork Updates

Update 1 to issue 108 ("Allow pid_path to accept wildcards for multicore deployments")

PulledPork Issue Tracker - Fri, 2012-02-24 19:15
Changing to a feature request.. will review.. maybe even allow for a pcre type option in here
Labels: -Type-Defect Type-Enhancement
Categories: PulledPork Updates

Update 1 to issue 108 ("Allow pid_path to accept wildcards for multicore deployments")

PulledPork Issue Tracker - Fri, 2012-02-24 19:15
Changing to a feature request.. will review.. maybe even allow for a pcre type option in here
Labels: -Type-Defect Type-Enhancement
Categories: PulledPork Updates

Update 7 to issue 97 ("HTTPS ET open rules download error")

PulledPork Issue Tracker - Thu, 2012-02-23 16:29
You should hit the mail lists with this for the fastest response... http://groups.google.com/group/pulledpork-users I would also remove my oinkcode from the output
Categories: PulledPork Updates

Update 7 to issue 97 ("HTTPS ET open rules download error")

PulledPork Issue Tracker - Thu, 2012-02-23 16:29
You should hit the mail lists with this for the fastest response... http://groups.google.com/group/pulledpork-users I would also remove my oinkcode from the output
Categories: PulledPork Updates

Update 6 to issue 97 ("HTTPS ET open rules download error")

PulledPork Issue Tracker - Thu, 2012-02-23 16:20
I am getting the following error using pulledpork-0.6.1: Checking latest MD5 for snortrules-snapshot-2921.tar.gz.... Error 501 when fetching http://www.snort.org/sub-rules/snortrules-snapshot-2921.tar.gz.md5 at /usr/local/pulledpork-0.6.1/pulledpork.pl line 453 main::md5file('<displays oikncode here>', 'snortrules-snapshot-2921.tar.gz', '/tmp/', 'http://www.snort.org/sub-rules/') called at /usr/local/pulledpork-0.6.1/pulledpork.pl line 1758 [root@copier etc]# Can't seem to get past this one. My pulledpork.conf file contains this: rule_url=http://www.snort.org/sub-rules/|snortrules-snapshot-2921.tar.gz|<with oinkcode here> Please advise.
Categories: PulledPork Updates

Update 6 to issue 97 ("HTTPS ET open rules download error")

PulledPork Issue Tracker - Thu, 2012-02-23 16:20
I am getting the following error using pulledpork-0.6.1: Checking latest MD5 for snortrules-snapshot-2921.tar.gz.... Error 501 when fetching http://www.snort.org/sub-rules/snortrules-snapshot-2921.tar.gz.md5 at /usr/local/pulledpork-0.6.1/pulledpork.pl line 453 main::md5file('<displays oikncode here>', 'snortrules-snapshot-2921.tar.gz', '/tmp/', 'http://www.snort.org/sub-rules/') called at /usr/local/pulledpork-0.6.1/pulledpork.pl line 1758 [root@copier etc]# Can't seem to get past this one. My pulledpork.conf file contains this: rule_url=http://www.snort.org/sub-rules/|snortrules-snapshot-2921.tar.gz|<with oinkcode here> Please advise.
Categories: PulledPork Updates

Update 5 to issue 97 ("HTTPS ET open rules download error")

PulledPork Issue Tracker - Thu, 2012-02-23 16:18
I am getting the following error using pulledpork-0.6.1: Checking latest MD5 for snortrules-snapshot-2921.tar.gz.... Error 501 when fetching http://www.snort.org/sub-rules/snortrules-snapshot-2921.tar.gz.md5 at /usr/local/pulledpork-0.6.1/pulledpork.pl line 453 main::md5file('ca476fa88d8150ec69ad4d68a8bc7d772e42cb30', 'snortrules-snapshot-2921.tar.gz', '/tmp/', 'http://www.snort.org/sub-rules/') called at /usr/local/pulledpork-0.6.1/pulledpork.pl line 1758 [root@copier etc]# Can't seem to get past this one. My pulledpork.conf file contains this: rule_url=http://www.snort.org/sub-rules/|snortrules-snapshot-2921.tar.gz|<with oinkcode here> Please advise.
Categories: PulledPork Updates

Update 5 to issue 97 ("HTTPS ET open rules download error")

PulledPork Issue Tracker - Thu, 2012-02-23 16:18
I am getting the following error using pulledpork-0.6.1: Checking latest MD5 for snortrules-snapshot-2921.tar.gz.... Error 501 when fetching http://www.snort.org/sub-rules/snortrules-snapshot-2921.tar.gz.md5 at /usr/local/pulledpork-0.6.1/pulledpork.pl line 453 main::md5file('ca476fa88d8150ec69ad4d68a8bc7d772e42cb30', 'snortrules-snapshot-2921.tar.gz', '/tmp/', 'http://www.snort.org/sub-rules/') called at /usr/local/pulledpork-0.6.1/pulledpork.pl line 1758 [root@copier etc]# Can't seem to get past this one. My pulledpork.conf file contains this: rule_url=http://www.snort.org/sub-rules/|snortrules-snapshot-2921.tar.gz|<with oinkcode here> Please advise.
Categories: PulledPork Updates

Update 7 to issue 107 ("Can't use an undefined value as an ARRAY reference at ./pulledpork.pl line 1516.")

PulledPork Issue Tracker - Thu, 2012-02-23 11:24
JJ - I think I've figured it out. Had to massage the configuration file but it seems OK now. Thanks for your help
Categories: PulledPork Updates

Update 7 to issue 107 ("Can't use an undefined value as an ARRAY reference at ./pulledpork.pl line 1516.")

PulledPork Issue Tracker - Thu, 2012-02-23 11:24
JJ - I think I've figured it out. Had to massage the configuration file but it seems OK now. Thanks for your help
Categories: PulledPork Updates
Syndicate content