OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Snort-users] snort 2.9.2 & Razorback

From: Matt Olney (molneysourcefire.com)
Date: Tue Feb 07 2012 - 08:35:35 CST


Umm...not certain if these answer your question, but I think they do:

The custom build is a stand-alone nugget that connects to the Razorback
system. The nugget is included as part of the tarball for the Razorback
system as a whole. The custom tarball has been modified to the point that
it should only be used for integrating with Razorback, not as a platform
for standard detection.

If you are trying to configure standard Snort, use the Snort tarball from
snort.org and you shouldn't have to use any switches related to Razorback.

Matt

On Mon, Feb 6, 2012 at 10:45 PM, Jonathan S. Abrams <
jonathansabramsgmail.com> wrote:

> Does this custom build wrap Snort and Razorback into one package? Would
> it put an end to errors I am getting about Snort not being able to find
> Razorback AND ignoring my --without-razorback option during ./configure?
>
>
> On Tue, Jan 31, 2012 at 10:14 AM, Matt Olney <molneysourcefire.com>wrote:
>
>> There is a specific, custom build of Snort in the Razorback trunk. Use
>> this version, as the production version has not yet been integrated with
>> Razorback. Also, do not combine Snort detection with Snort-as-a-collector.
>>
>> Matt
>>
>> On Mon, Jan 30, 2012 at 8:10 PM, Joel Esler <jeslersourcefire.com>wrote:
>>
>>> Actually my answer sucks. Head over to the Razorback list. Answer would
>>> be better there by the Razorback team.
>>>
>>> Thanks.
>>>
>>>
>>> --
>>> Joel Esler
>>> Senior Research Engineer, VRT
>>> OpenSource Community Manager
>>> Sourcefire
>>>
>>> On Jan 30, 2012, at 6:11 PM, "Lawrence R. Hughes, Sr." <
>>> lhughessafemedia.com> wrote:
>>>
>>> Hi,
>>> Little confused, I have a linux box running snort 2.9.2.0 as a bridge
>>> (br0) how would I add razorback to the same machine?
>>>
>>> Thanks,
>>> Larry
>>>
>>>
>>>
>>> ------------------------------------------------------------------------------
>>>
>>> Try before you buy = See our experts in action!
>>> The most comprehensive online learning library for Microsoft developers
>>> is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3,
>>> Metro Style Apps, more. Free future releases when you subscribe now!
>>> http://p.sf.net/sfu/learndevnow-dev2
>>>
>>> _______________________________________________
>>> Snort-users mailing list
>>> Snort-userslists.sourceforge.net
>>> Go to this URL to change user options or unsubscribe:
>>> https://lists.sourceforge.net/lists/listinfo/snort-users
>>> Snort-users list archive:
>>> http://www.geocrawler.com/redir-sf.php3?list=snort-users
>>>
>>> Please visit http://blog.snort.org to stay current on all the latest
>>> Snort news!
>>>
>>>
>>>
>>> ------------------------------------------------------------------------------
>>> Keep Your Developer Skills Current with LearnDevNow!
>>>
>>> The most comprehensive online learning library for Microsoft developers
>>> is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3,
>>> Metro Style Apps, more. Free future releases when you subscribe now!
>>> http://p.sf.net/sfu/learndevnow-d2d
>>>
>>> _______________________________________________
>>> Snort-users mailing list
>>> Snort-userslists.sourceforge.net
>>> Go to this URL to change user options or unsubscribe:
>>> https://lists.sourceforge.net/lists/listinfo/snort-users
>>> Snort-users list archive:
>>> http://www.geocrawler.com/redir-sf.php3?list=snort-users
>>>
>>> Please visit http://blog.snort.org to stay current on all the latest
>>> Snort news!
>>>
>>
>>
>>
>> ------------------------------------------------------------------------------
>> Keep Your Developer Skills Current with LearnDevNow!
>> The most comprehensive online learning library for Microsoft developers
>> is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3,
>> Metro Style Apps, more. Free future releases when you subscribe now!
>> http://p.sf.net/sfu/learndevnow-d2d
>> _______________________________________________
>> Snort-users mailing list
>> Snort-userslists.sourceforge.net
>> Go to this URL to change user options or unsubscribe:
>> https://lists.sourceforge.net/lists/listinfo/snort-users
>> Snort-users list archive:
>> http://www.geocrawler.com/redir-sf.php3?list=snort-users
>>
>> Please visit http://blog.snort.org to stay current on all the latest
>> Snort news!
>
>

------------------------------------------------------------------------------
Keep Your Developer Skills Current with LearnDevNow!
The most comprehensive online learning library for Microsoft developers
is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3,
Metro Style Apps, more. Free future releases when you subscribe now!
http://p.sf.net/sfu/learndevnow-d2d

_______________________________________________
Snort-users mailing list
Snort-userslists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!