You Are Here : Forums Sunday, September 07, 2008
     
Activeworx.org Forums
 
  Forum  IDS Policy Mana...  IDS Policy Mana...  Update Policies
Previous Previous
 
Next Next
New Post 5/29/2008 7:54 PM
  paulr
21 posts
9th Level Poster


Update Policies 

Hi,

I've been a bit concerned because there have been no updates from Snort 2.8, Snort Community Current, and BleedingSnort in a few weeks.  (I was expecting at least a signature update by now).  Can anyone confirm if there have been no signature changes for a while?

When I go to 'Update Policies' it downloads, checks the policy, then is finished and I close out.  Typically after a few weeks there are some changes I can enable or disable.

Maybe this is normal...but we have another snort-based device that has received updated rules a few times since then.  25 rules on the 28th it looks like.  I'm not certain the source on tha one though.

Thanks.

 

 

 
New Post 5/29/2008 8:58 PM
  Jeff Dell
233 posts
www.activeworx.com
1st Level Poster


Re: Update Policies 

You might want to check your update locations. This is done under settings.

 I know that Bleeding Snort has changed it's name a couple of times in the last year or so. The new name is emerging threats http://www.emergingthreats.net/ none of the other locations are updated as far as I know.

Cheers,

Jeff

 
New Post 5/29/2008 11:49 PM
  paulr
21 posts
9th Level Poster


Re: Update Policies 

Yeah...I recall changing that at some point: http://www.emergingthreats.net/bleeding.rules.tar.gz

There are no errors downloading that I can see...I just would have thought an update to something such as RBN or malware would have happened in the last few weeks.  Normally my Stillsecure updates are close to the emergingthreats updates and I know it downloaded a bunch recently.

Thanks.

 

 
New Post 5/30/2008 1:03 AM
  Jeff Dell
233 posts
www.activeworx.com
1st Level Poster


Re: Update Policies 

You might want to check that file.. I just checked the location on emerging threats and it looks like it is:

http://www.emergingthreats.net/rules/emerging.rules.tar.gz

Jeff

 
New Post 6/2/2008 6:44 PM
  paulr
21 posts
9th Level Poster


Re: Update Policies 

Well, that's interesting.  The domain doesn't even return in a lookup from our DNS or a web-based DNS lookup.

I'm not sure that's been the case previously but it seems emergingthreats doesn't currently exist (or has DNS issues).

 

 
New Post 6/2/2008 9:26 PM
  paulr
21 posts
9th Level Poster


Re: Update Policies 
Never mind... OrgName: ThePlanet.com Internet Services, Inc. OrgID: TPCM Address: 315 Capitol Address: Suite 205 City: Houston StateProv: TX PostalCode: 77002 Country: US I guess something blew up at ThePlanet (literally) and emergingthreats is hosted there...I'll wait and try the new URL later...though IDS PM didn't return any errors with my old URL...but maybe it's picking up old data.
 
New Post 6/3/2008 2:51 PM
  Ray
55 posts
6th Level Poster


Re: Update Policies 

I had the same ET path as you did and I also noticed the updates stopped awhile ago. I had to add in /rules/ as well. I guess they changed something.

 

Yes, the are hosted on ThePlanet. According to incidents.org, they had two servers in different data centers, but when ThePlanet bought EV1, ThePlanet moved their second server into the same data center. <sigh>

 

Ray

 
Previous Previous
 
Next Next
  Forum  IDS Policy Mana...  IDS Policy Mana...  Update Policies
 
 
Copyright 2000-2007 by Activeworx, Inc.
All trademarks and copyrights on this page are owned by their respective owners.