Project

General

Profile

Actions

Bug #14480

closed

Faulty IDS rules can prevent Snort from starting

Added by Jonathan Lee almost 2 years ago. Updated almost 2 years ago.

Status:
Not a Bug
Priority:
Normal
Assignee:
-
Category:
Snort
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Affected Version:
All
Affected Plus Version:
23.05
Affected Architecture:
All

Description

FATAL ERROR: /usr/local/etc/snort/snort_4851_ix0/rules/snort.rules:19567: Can't use flow: stateless option with other options

Hello can you please help? This error condition and others like it have the ability to offline the Snort package and disable the IPS/IDS.

https://forum.netgate.com/topic/180867/snort-fatal-error-after-emerging-rules-update/28

One can say as experimental Layer 2 ethernet filtering advances this error could be a bigger issue within stateless filtering.

I am aware the the updated rules fixed this, is there anything that can be done to catch this error in the future to keep Snort from auto disabling. Maybe it could default to the old ruleset prior.

To quote bmeeks,

" _I am the package developer/maintainer for both Snort and Suricata on pfSense. I maintain both packages, not Netgate. A Redmine ticket makes no sense for this issue.

This is not a "bug" in the package. It is an error in the Emerging Threats rule package produced by other parties (in this case Proofpoint, who bought Emerging Threats a few years ago). The creators of the rules package will fix this problem. This is not the first time an error has been introduced by a rules package update from a vendor._ "

As quoted this is not the first time a rule update disabled all of the IPS/IDS security system. Such a error offlined the IPS on all systems using ET rules in the early morning. Most admins are sleeping at this time.


Files

Screenshot 2023-06-18 at 9.38.19 PM.png (383 KB) Screenshot 2023-06-18 at 9.38.19 PM.png Simple Array Try Catch Jonathan Lee, 06/19/2023 04:58 AM
Screenshot 2023-06-18 at 10.08.34 PM.png (118 KB) Screenshot 2023-06-18 at 10.08.34 PM.png Professors Java Throws error simple example you could make it as long as you wanted Jonathan Lee, 06/19/2023 05:08 AM
Screenshot 2023-06-18 at 10.15.18 PM.png (210 KB) Screenshot 2023-06-18 at 10.15.18 PM.png Professors throw in use Jonathan Lee, 06/19/2023 05:15 AM
Actions

Also available in: Atom PDF