components/snort/patches/snort.conf.patch
author Danek Duvall <danek.duvall@oracle.com>
Mon, 05 Aug 2013 13:37:57 -0700
changeset 1420 597ecfc1f6c0
parent 1345 ee87318d9935
child 2198 168b8acace5f
permissions -rw-r--r--
17237605 TPNOs required for cherrypy coverage ldtp m2crpyto mako ply pybonjour and pycurl (fix build)
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
     1
--- snort-2.9.2/etc/snort.conf.orig	2013-05-15 07:26:24.138736340 -0700
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
     2
+++ snort-2.9.2/etc/snort.conf	2013-05-15 07:36:06.628399989 -0700
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
     3
@@ -143,7 +143,7 @@
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
     4
 # Configure DAQ related options for inline operation. For more information, see README.daq
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
     5
 #
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
     6
 # config daq: <type>
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
     7
-# config daq_dir: <dir>
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
     8
+config daq_dir: /usr/lib/64/daq/
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
     9
 # config daq_mode: <mode>
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    10
 # config daq_var: <var>
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
    11
 #
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    12
@@ -217,13 +217,13 @@
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    13
 ###################################################
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    14
 
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    15
 # path to dynamic preprocessor libraries
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    16
-dynamicpreprocessor directory /usr/local/lib/snort_dynamicpreprocessor/
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    17
+dynamicpreprocessor directory /usr/lib/64/snort_dynamicpreprocessor/
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    18
 
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    19
 # path to base preprocessor engine
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
    20
-dynamicengine /usr/local/lib/snort_dynamicengine/libsf_engine.so
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    21
+dynamicengine /usr/lib/64/snort_dynamicengine/libsf_engine.so
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    22
 
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    23
 # path to dynamic rules libraries
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    24
-dynamicdetection directory /usr/local/lib/snort_dynamicrules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    25
+dynamicdetection directory /usr/lib/64/snort_dynamicrules
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
    26
 
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
    27
 ###################################################
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    28
 # Step #5: Configure preprocessors
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    29
@@ -264,34 +264,34 @@
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    30
 # preprocessor perfmonitor: time 300 file /var/snort/snort.stats pktcnt 10000
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
    31
 
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    32
 # HTTP normalization and anomaly detection.  For more information, see README.http_inspect
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    33
-preprocessor http_inspect: global iis_unicode_map unicode.map 1252 compress_depth 65535 decompress_depth 65535
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
    34
-preprocessor http_inspect_server: server default \
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    35
-    chunk_length 500000 \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    36
-    server_flow_depth 0 \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    37
-    client_flow_depth 0 \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    38
-    post_depth 65495 \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    39
-    oversize_dir_length 500 \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    40
-    max_header_length 750 \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    41
-    max_headers 100 \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    42
-    ports { 80 81 311 591 593 901 1220 1414 1830 2301 2381 2809 3128 3702 5250 7001 7777 7779 8000 8008 8028 8080 8088 8118 8123 8180 8181 8243 8280 8888 9090 9091 9443 9999 11371 } \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    43
-    non_rfc_char { 0x00 0x01 0x02 0x03 0x04 0x05 0x06 0x07 } \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    44
-    enable_cookie \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    45
-    extended_response_inspection \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    46
-    inspect_gzip \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    47
-    normalize_utf \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    48
-    unlimited_decompress \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    49
-    apache_whitespace no \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    50
-    ascii no \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    51
-    bare_byte no \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    52
-    directory no \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    53
-    double_decode no \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    54
-    iis_backslash no \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    55
-    iis_delimiter no \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    56
-    iis_unicode no \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    57
-    multi_slash no \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    58
-   utf_8 no \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    59
-    u_encode yes \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    60
-    webroot no
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    61
+#preprocessor http_inspect: global iis_unicode_map unicode.map 1252 compress_depth 65535 decompress_depth 65535
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
    62
+#preprocessor http_inspect_server: server default \
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    63
+#    chunk_length 500000 \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    64
+#    server_flow_depth 0 \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    65
+#    client_flow_depth 0 \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    66
+#    post_depth 65495 \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    67
+#    oversize_dir_length 500 \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    68
+#    max_header_length 750 \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    69
+#    max_headers 100 \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    70
+#    ports { 80 81 311 591 593 901 1220 1414 1830 2301 2381 2809 3128 3702 5250 7001 7777 7779 8000 8008 8028 8080 8088 8118 8123 8180 8181 8243 8280 8888 9090 9091 9443 9999 11371 } \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    71
+#    non_rfc_char { 0x00 0x01 0x02 0x03 0x04 0x05 0x06 0x07 } \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    72
+#    enable_cookie \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    73
+#    extended_response_inspection \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    74
+#    inspect_gzip \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    75
+#    normalize_utf \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    76
+#    unlimited_decompress \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    77
+#    apache_whitespace no \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    78
+#    ascii no \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    79
+#    bare_byte no \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    80
+#    directory no \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    81
+#    double_decode no \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    82
+#    iis_backslash no \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    83
+#    iis_delimiter no \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    84
+#    iis_unicode no \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    85
+#    multi_slash no \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    86
+#   utf_8 no \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    87
+#    u_encode yes \
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    88
+#    webroot no
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
    89
 
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    90
 # ONC-RPC normalization and anomaly detection.  For more information, see the Snort Manual, Configuring Snort - Preprocessors - RPC Decode
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    91
 preprocessor rpc_decode: 111 32770 32771 32772 32773 32774 32775 32776 32777 32778 32779 no_alert_multiple_requests no_alert_large_fragments no_alert_incomplete
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    92
@@ -487,8 +487,8 @@
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    93
 # output alert_prelude
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
    94
 
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    95
 # metadata reference data.  do not modify these lines
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
    96
-include classification.config
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    97
-include reference.config
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    98
+# include classification.config
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
    99
+# include reference.config
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
   100
 
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
   101
 
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   102
 ###################################################
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   103
@@ -499,61 +499,61 @@
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   104
 ###################################################
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
   105
 
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   106
 # site specific rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   107
-include $RULE_PATH/local.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   108
+# include $RULE_PATH/local.rules
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
   109
 
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   110
-include $RULE_PATH/attack-responses.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   111
-include $RULE_PATH/backdoor.rules
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
   112
-include $RULE_PATH/bad-traffic.rules
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   113
-include $RULE_PATH/blacklist.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   114
-include $RULE_PATH/botnet-cnc.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   115
-include $RULE_PATH/chat.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   116
-include $RULE_PATH/content-replace.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   117
-include $RULE_PATH/ddos.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   118
-include $RULE_PATH/dns.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   119
-include $RULE_PATH/dos.rules
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
   120
-include $RULE_PATH/exploit.rules
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
   121
-include $RULE_PATH/finger.rules
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
   122
-include $RULE_PATH/ftp.rules
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   123
-include $RULE_PATH/icmp.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   124
-include $RULE_PATH/icmp-info.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   125
-include $RULE_PATH/imap.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   126
-include $RULE_PATH/info.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   127
-include $RULE_PATH/misc.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   128
-include $RULE_PATH/multimedia.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   129
-include $RULE_PATH/mysql.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   130
-include $RULE_PATH/netbios.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   131
-include $RULE_PATH/nntp.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   132
-include $RULE_PATH/oracle.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   133
-include $RULE_PATH/other-ids.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   134
-include $RULE_PATH/p2p.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   135
-include $RULE_PATH/phishing-spam.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   136
-include $RULE_PATH/policy.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   137
-include $RULE_PATH/pop2.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   138
-include $RULE_PATH/pop3.rules
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
   139
-include $RULE_PATH/rpc.rules
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
   140
-include $RULE_PATH/rservices.rules
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   141
-include $RULE_PATH/scada.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   142
-include $RULE_PATH/scan.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   143
-include $RULE_PATH/shellcode.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   144
-include $RULE_PATH/smtp.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   145
-include $RULE_PATH/snmp.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   146
-include $RULE_PATH/specific-threats.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   147
-include $RULE_PATH/spyware-put.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   148
-include $RULE_PATH/sql.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   149
-include $RULE_PATH/telnet.rules
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
   150
-include $RULE_PATH/tftp.rules
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   151
-include $RULE_PATH/virus.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   152
-include $RULE_PATH/voip.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   153
-include $RULE_PATH/web-activex.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   154
-include $RULE_PATH/web-attacks.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   155
-include $RULE_PATH/web-cgi.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   156
-include $RULE_PATH/web-client.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   157
-include $RULE_PATH/web-coldfusion.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   158
-include $RULE_PATH/web-frontpage.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   159
-include $RULE_PATH/web-iis.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   160
-include $RULE_PATH/web-misc.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   161
-include $RULE_PATH/web-php.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   162
-include $RULE_PATH/x11.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   163
+# include $RULE_PATH/attack-responses.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   164
+# include $RULE_PATH/backdoor.rules
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
   165
+# include $RULE_PATH/bad-traffic.rules
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   166
+# include $RULE_PATH/blacklist.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   167
+# include $RULE_PATH/botnet-cnc.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   168
+# include $RULE_PATH/chat.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   169
+# include $RULE_PATH/content-replace.rules
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
   170
+# include $RULE_PATH/ddos.rules
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
   171
+# include $RULE_PATH/dns.rules
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   172
+# include $RULE_PATH/dos.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   173
+# include $RULE_PATH/exploit.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   174
+# include $RULE_PATH/finger.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   175
+# include $RULE_PATH/ftp.rules
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
   176
+# include $RULE_PATH/icmp.rules
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   177
+# include $RULE_PATH/icmp-info.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   178
+# include $RULE_PATH/imap.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   179
+# include $RULE_PATH/info.rules
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
   180
+# include $RULE_PATH/misc.rules
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   181
+# include $RULE_PATH/multimedia.rules
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
   182
+# include $RULE_PATH/mysql.rules
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   183
+# include $RULE_PATH/netbios.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   184
+# include $RULE_PATH/nntp.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   185
+# include $RULE_PATH/oracle.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   186
+# include $RULE_PATH/other-ids.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   187
+# include $RULE_PATH/p2p.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   188
+# include $RULE_PATH/phishing-spam.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   189
+# include $RULE_PATH/policy.rules
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
   190
+# include $RULE_PATH/pop2.rules
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
   191
+# include $RULE_PATH/pop3.rules
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   192
+# include $RULE_PATH/rpc.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   193
+# include $RULE_PATH/rservices.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   194
+# include $RULE_PATH/scada.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   195
+# include $RULE_PATH/scan.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   196
+# include $RULE_PATH/shellcode.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   197
+# include $RULE_PATH/smtp.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   198
+# include $RULE_PATH/snmp.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   199
+# include $RULE_PATH/specific-threats.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   200
+# include $RULE_PATH/spyware-put.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   201
+# include $RULE_PATH/sql.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   202
+# include $RULE_PATH/telnet.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   203
+# include $RULE_PATH/tftp.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   204
+# include $RULE_PATH/virus.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   205
+# include $RULE_PATH/voip.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   206
+# include $RULE_PATH/web-activex.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   207
+# include $RULE_PATH/web-attacks.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   208
+# include $RULE_PATH/web-cgi.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   209
+# include $RULE_PATH/web-client.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   210
+# include $RULE_PATH/web-coldfusion.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   211
+# include $RULE_PATH/web-frontpage.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   212
+# include $RULE_PATH/web-iis.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   213
+# include $RULE_PATH/web-misc.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   214
+# include $RULE_PATH/web-php.rules
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   215
+# include $RULE_PATH/x11.rules
213
7d4229dba5ed 7041863 move snort to userland
Mike Sullivan <Mike.Sullivan@Oracle.COM>
parents:
diff changeset
   216
 
1345
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   217
 ###################################################
ee87318d9935 PSARC 2013/113 snort 2.9.2
Rich Burridge <rich.burridge@oracle.com>
parents: 213
diff changeset
   218
 # Step #8: Customize your preprocessor and decoder alerts