1 Solaris specific changes to the snort configuration file that will be
2 installed under /etc/snort/.
4 These changes will not be submitted upstream.
6 --- snort-2.9.9.0/etc/snort.conf.~1~ 2016-11-29 09:12:42.000000000 +0300
7 +++ snort-2.9.9.0/etc/snort.conf 2017-01-31 17:20:16.515472440 +0300
9 # Path to your rules files (this can be a relative path)
10 # Note for Windows users: You are advised to make this an absolute path,
11 # such as: c:\snort\rules
12 -var RULE_PATH ../rules
13 -var SO_RULE_PATH ../so_rules
14 -var PREPROC_RULE_PATH ../preproc_rules
16 +var SO_RULE_PATH so_rules
17 +var PREPROC_RULE_PATH preproc_rules
19 # If you are using reputation preprocessor set these
20 # Currently there is a bug with relative paths, they are relative to where snort is
21 # not relative to snort.conf like the above variables
22 # This is completely inconsistent with how other vars work, BUG 89986
23 # Set the absolute path appropriately
24 -var WHITE_LIST_PATH ../rules
25 -var BLACK_LIST_PATH ../rules
26 +var WHITE_LIST_PATH rules
27 +var BLACK_LIST_PATH rules
29 ###################################################
30 # Step #2: Configure the decoder. For more information, see README.decode
32 # Configure DAQ related options for inline operation. For more information, see README.daq
35 -# config daq_dir: <dir>
36 +config daq_dir: /usr/lib/daq/
37 # config daq_mode: <mode>
38 # config daq_var: <var>
41 ###################################################
43 # path to dynamic preprocessor libraries
44 -dynamicpreprocessor directory /usr/local/lib/snort_dynamicpreprocessor/
45 +dynamicpreprocessor directory /usr/lib/snort_dynamicpreprocessor/
47 # path to base preprocessor engine
48 -dynamicengine /usr/local/lib/snort_dynamicengine/libsf_engine.so
49 +dynamicengine /usr/lib/snort_dynamicengine/libsf_engine.so
51 # path to dynamic rules libraries
52 -dynamicdetection directory /usr/local/lib/snort_dynamicrules
53 +dynamicdetection directory /usr/lib/snort_dynamicrules
55 ###################################################
56 # Step #5: Configure preprocessors
60 # Reputation preprocessor. For more information see README.reputation
61 -preprocessor reputation: \
63 - priority whitelist, \
65 - whitelist $WHITE_LIST_PATH/white_list.rules, \
66 - blacklist $BLACK_LIST_PATH/black_list.rules
67 +#preprocessor reputation: \
69 +# priority whitelist, \
71 +# whitelist $WHITE_LIST_PATH/white_list.rules, \
72 +# blacklist $BLACK_LIST_PATH/black_list.rules
74 ###################################################
75 # Step #6: Configure output plugins
76 @@ -543,112 +543,112 @@
77 ###################################################
80 -include $RULE_PATH/local.rules
81 +#include $RULE_PATH/local.rules
83 -include $RULE_PATH/app-detect.rules
84 -include $RULE_PATH/attack-responses.rules
85 -include $RULE_PATH/backdoor.rules
86 -include $RULE_PATH/bad-traffic.rules
87 -include $RULE_PATH/blacklist.rules
88 -include $RULE_PATH/botnet-cnc.rules
89 -include $RULE_PATH/browser-chrome.rules
90 -include $RULE_PATH/browser-firefox.rules
91 -include $RULE_PATH/browser-ie.rules
92 -include $RULE_PATH/browser-other.rules
93 -include $RULE_PATH/browser-plugins.rules
94 -include $RULE_PATH/browser-webkit.rules
95 -include $RULE_PATH/chat.rules
96 -include $RULE_PATH/content-replace.rules
97 -include $RULE_PATH/ddos.rules
98 -include $RULE_PATH/dns.rules
99 -include $RULE_PATH/dos.rules
100 -include $RULE_PATH/experimental.rules
101 -include $RULE_PATH/exploit-kit.rules
102 -include $RULE_PATH/exploit.rules
103 -include $RULE_PATH/file-executable.rules
104 -include $RULE_PATH/file-flash.rules
105 -include $RULE_PATH/file-identify.rules
106 -include $RULE_PATH/file-image.rules
107 -include $RULE_PATH/file-multimedia.rules
108 -include $RULE_PATH/file-office.rules
109 -include $RULE_PATH/file-other.rules
110 -include $RULE_PATH/file-pdf.rules
111 -include $RULE_PATH/finger.rules
112 -include $RULE_PATH/ftp.rules
113 -include $RULE_PATH/icmp-info.rules
114 -include $RULE_PATH/icmp.rules
115 -include $RULE_PATH/imap.rules
116 -include $RULE_PATH/indicator-compromise.rules
117 -include $RULE_PATH/indicator-obfuscation.rules
118 -include $RULE_PATH/indicator-shellcode.rules
119 -include $RULE_PATH/info.rules
120 -include $RULE_PATH/malware-backdoor.rules
121 -include $RULE_PATH/malware-cnc.rules
122 -include $RULE_PATH/malware-other.rules
123 -include $RULE_PATH/malware-tools.rules
124 -include $RULE_PATH/misc.rules
125 -include $RULE_PATH/multimedia.rules
126 -include $RULE_PATH/mysql.rules
127 -include $RULE_PATH/netbios.rules
128 -include $RULE_PATH/nntp.rules
129 -include $RULE_PATH/oracle.rules
130 -include $RULE_PATH/os-linux.rules
131 -include $RULE_PATH/os-other.rules
132 -include $RULE_PATH/os-solaris.rules
133 -include $RULE_PATH/os-windows.rules
134 -include $RULE_PATH/other-ids.rules
135 -include $RULE_PATH/p2p.rules
136 -include $RULE_PATH/phishing-spam.rules
137 -include $RULE_PATH/policy-multimedia.rules
138 -include $RULE_PATH/policy-other.rules
139 -include $RULE_PATH/policy.rules
140 -include $RULE_PATH/policy-social.rules
141 -include $RULE_PATH/policy-spam.rules
142 -include $RULE_PATH/pop2.rules
143 -include $RULE_PATH/pop3.rules
144 -include $RULE_PATH/protocol-finger.rules
145 -include $RULE_PATH/protocol-ftp.rules
146 -include $RULE_PATH/protocol-icmp.rules
147 -include $RULE_PATH/protocol-imap.rules
148 -include $RULE_PATH/protocol-pop.rules
149 -include $RULE_PATH/protocol-services.rules
150 -include $RULE_PATH/protocol-voip.rules
151 -include $RULE_PATH/pua-adware.rules
152 -include $RULE_PATH/pua-other.rules
153 -include $RULE_PATH/pua-p2p.rules
154 -include $RULE_PATH/pua-toolbars.rules
155 -include $RULE_PATH/rpc.rules
156 -include $RULE_PATH/rservices.rules
157 -include $RULE_PATH/scada.rules
158 -include $RULE_PATH/scan.rules
159 -include $RULE_PATH/server-apache.rules
160 -include $RULE_PATH/server-iis.rules
161 -include $RULE_PATH/server-mail.rules
162 -include $RULE_PATH/server-mssql.rules
163 -include $RULE_PATH/server-mysql.rules
164 -include $RULE_PATH/server-oracle.rules
165 -include $RULE_PATH/server-other.rules
166 -include $RULE_PATH/server-webapp.rules
167 -include $RULE_PATH/shellcode.rules
168 -include $RULE_PATH/smtp.rules
169 -include $RULE_PATH/snmp.rules
170 -include $RULE_PATH/specific-threats.rules
171 -include $RULE_PATH/spyware-put.rules
172 -include $RULE_PATH/sql.rules
173 -include $RULE_PATH/telnet.rules
174 -include $RULE_PATH/tftp.rules
175 -include $RULE_PATH/virus.rules
176 -include $RULE_PATH/voip.rules
177 -include $RULE_PATH/web-activex.rules
178 -include $RULE_PATH/web-attacks.rules
179 -include $RULE_PATH/web-cgi.rules
180 -include $RULE_PATH/web-client.rules
181 -include $RULE_PATH/web-coldfusion.rules
182 -include $RULE_PATH/web-frontpage.rules
183 -include $RULE_PATH/web-iis.rules
184 -include $RULE_PATH/web-misc.rules
185 -include $RULE_PATH/web-php.rules
186 -include $RULE_PATH/x11.rules
187 +#include $RULE_PATH/app-detect.rules
188 +#include $RULE_PATH/attack-responses.rules
189 +#include $RULE_PATH/backdoor.rules
190 +#include $RULE_PATH/bad-traffic.rules
191 +#include $RULE_PATH/blacklist.rules
192 +#include $RULE_PATH/botnet-cnc.rules
193 +#include $RULE_PATH/browser-chrome.rules
194 +#include $RULE_PATH/browser-firefox.rules
195 +#include $RULE_PATH/browser-ie.rules
196 +#include $RULE_PATH/browser-other.rules
197 +#include $RULE_PATH/browser-plugins.rules
198 +#include $RULE_PATH/browser-webkit.rules
199 +#include $RULE_PATH/chat.rules
200 +#include $RULE_PATH/content-replace.rules
201 +#include $RULE_PATH/ddos.rules
202 +#include $RULE_PATH/dns.rules
203 +#include $RULE_PATH/dos.rules
204 +#include $RULE_PATH/experimental.rules
205 +#include $RULE_PATH/exploit-kit.rules
206 +#include $RULE_PATH/exploit.rules
207 +#include $RULE_PATH/file-executable.rules
208 +#include $RULE_PATH/file-flash.rules
209 +#include $RULE_PATH/file-identify.rules
210 +#include $RULE_PATH/file-image.rules
211 +#include $RULE_PATH/file-multimedia.rules
212 +#include $RULE_PATH/file-office.rules
213 +#include $RULE_PATH/file-other.rules
214 +#include $RULE_PATH/file-pdf.rules
215 +#include $RULE_PATH/finger.rules
216 +#include $RULE_PATH/ftp.rules
217 +#include $RULE_PATH/icmp-info.rules
218 +#include $RULE_PATH/icmp.rules
219 +#include $RULE_PATH/imap.rules
220 +#include $RULE_PATH/indicator-compromise.rules
221 +#include $RULE_PATH/indicator-obfuscation.rules
222 +#include $RULE_PATH/indicator-shellcode.rules
223 +#include $RULE_PATH/info.rules
224 +#include $RULE_PATH/malware-backdoor.rules
225 +#include $RULE_PATH/malware-cnc.rules
226 +#include $RULE_PATH/malware-other.rules
227 +#include $RULE_PATH/malware-tools.rules
228 +#include $RULE_PATH/misc.rules
229 +#include $RULE_PATH/multimedia.rules
230 +#include $RULE_PATH/mysql.rules
231 +#include $RULE_PATH/netbios.rules
232 +#include $RULE_PATH/nntp.rules
233 +#include $RULE_PATH/oracle.rules
234 +#include $RULE_PATH/os-linux.rules
235 +#include $RULE_PATH/os-other.rules
236 +#include $RULE_PATH/os-solaris.rules
237 +#include $RULE_PATH/os-windows.rules
238 +#include $RULE_PATH/other-ids.rules
239 +#include $RULE_PATH/p2p.rules
240 +#include $RULE_PATH/phishing-spam.rules
241 +#include $RULE_PATH/policy-multimedia.rules
242 +#include $RULE_PATH/policy-other.rules
243 +#include $RULE_PATH/policy.rules
244 +#include $RULE_PATH/policy-social.rules
245 +#include $RULE_PATH/policy-spam.rules
246 +#include $RULE_PATH/pop2.rules
247 +#include $RULE_PATH/pop3.rules
248 +#include $RULE_PATH/protocol-finger.rules
249 +#include $RULE_PATH/protocol-ftp.rules
250 +#include $RULE_PATH/protocol-icmp.rules
251 +#include $RULE_PATH/protocol-imap.rules
252 +#include $RULE_PATH/protocol-pop.rules
253 +#include $RULE_PATH/protocol-services.rules
254 +#include $RULE_PATH/protocol-voip.rules
255 +#include $RULE_PATH/pua-adware.rules
256 +#include $RULE_PATH/pua-other.rules
257 +#include $RULE_PATH/pua-p2p.rules
258 +#include $RULE_PATH/pua-toolbars.rules
259 +#include $RULE_PATH/rpc.rules
260 +#include $RULE_PATH/rservices.rules
261 +#include $RULE_PATH/scada.rules
262 +#include $RULE_PATH/scan.rules
263 +#include $RULE_PATH/server-apache.rules
264 +#include $RULE_PATH/server-iis.rules
265 +#include $RULE_PATH/server-mail.rules
266 +#include $RULE_PATH/server-mssql.rules
267 +#include $RULE_PATH/server-mysql.rules
268 +#include $RULE_PATH/server-oracle.rules
269 +#include $RULE_PATH/server-other.rules
270 +#include $RULE_PATH/server-webapp.rules
271 +#include $RULE_PATH/shellcode.rules
272 +#include $RULE_PATH/smtp.rules
273 +#include $RULE_PATH/snmp.rules
274 +#include $RULE_PATH/specific-threats.rules
275 +#include $RULE_PATH/spyware-put.rules
276 +#include $RULE_PATH/sql.rules
277 +#include $RULE_PATH/telnet.rules
278 +#include $RULE_PATH/tftp.rules
279 +#include $RULE_PATH/virus.rules
280 +#include $RULE_PATH/voip.rules
281 +#include $RULE_PATH/web-activex.rules
282 +#include $RULE_PATH/web-attacks.rules
283 +#include $RULE_PATH/web-cgi.rules
284 +#include $RULE_PATH/web-client.rules
285 +#include $RULE_PATH/web-coldfusion.rules
286 +#include $RULE_PATH/web-frontpage.rules
287 +#include $RULE_PATH/web-iis.rules
288 +#include $RULE_PATH/web-misc.rules
289 +#include $RULE_PATH/web-php.rules
290 +#include $RULE_PATH/x11.rules
292 ###################################################
293 # Step #8: Customize your preprocessor and decoder alerts