Yes, there is something wrong, i have tried the same thing that u just do now before, and get into the same error.<br><br>The patch for 2.8.5 in the snortsam site, is not really for 2.8.5, but for 2.8.4.1 like u see in the header of the file:<br>
<br><pre>diff -ruN snort-2.8.4.1.orig/autojunk.sh snort-2.8.4.1/autojunk.sh<br>--- snort-2.8.4.1.orig/autojunk.sh        1970-01-01 03:30:00.000000000 +0330<br>+++ snort-2.8.4.1/autojunk.sh        2009-06-23 16:40:44.000000000 +0430<br>
</pre><br>Is just the same 2.8.4.1 patch. I think the snortsam team has not release the 2.8.5 patch yet.<br><br><br><div class="gmail_quote">On Thu, Oct 8, 2009 at 5:52 AM, Wouter de Jong <span dir="ltr"><<a href="mailto:maddog2k@maddog2k.net">maddog2k@maddog2k.net</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">Hi Rob,<br>
<br>
This is exactly what I did...<br>
That's why I posted the 'strings /usr/sbin/snort | grep -i fwsam' output as<br>
'proof',<br>
cause I knew I'd get a reaction like yours, but apparently it was still not<br>
clear :))<br>
<br>
In the mean time, I've downgraded to Snort 2.8.4.1,<br>
build it in exact the same way as 2.8.5 but with the 2.8.4.1 snortsam-patch<br>
and that works ok.<br>
<br>
So there seems to be something wrong with the patch for 2.8.5 ...<br>
<br>
Best regards,<br>
<font color="#888888"><br>
Wouter<br>
</font><div class="im"><br>
<br>
-----Original Message-----<br>
From: <a href="mailto:snortsam-discussion-bounces@snortsam.net">snortsam-discussion-bounces@snortsam.net</a><br>
[mailto:<a href="mailto:snortsam-discussion-bounces@snortsam.net">snortsam-discussion-bounces@snortsam.net</a>] On Behalf Of Rob Sly<br>
Sent: Wednesday, October 07, 2009 17:47<br>
To: <a href="mailto:snortsam-discussion@snortsam.net">snortsam-discussion@snortsam.net</a><br>
</div><div><div></div><div class="h5">Subject: Re: [Snortsam-discussion] Snort 2.8.5 + Snortsam : Unknown rule<br>
option:'fwsam'.<br>
<br>
You need to download the patch file from<br>
<a href="http://www.snortsam.net/download.html" target="_blank">http://www.snortsam.net/download.html</a> for the specific version of snort that<br>
<br>
you are using, and patch the sourcecode for snort, to add in snortsam. Then<br>
<br>
you need to configure and compile, and you should be able to get it working.<br>
<br>
Post back on your success or if you need further help.<br>
<br>
--------------------------------------------------<br>
From: "Wouter de Jong" <<a href="mailto:maddog2k@maddog2k.net">maddog2k@maddog2k.net</a>><br>
Sent: Wednesday, October 07, 2009 9:26 AM<br>
To: <<a href="mailto:snortsam-discussion@snortsam.net">snortsam-discussion@snortsam.net</a>><br>
Subject: [Snortsam-discussion] Snort 2.8.5 + Snortsam : Unknown rule<br>
option:'fwsam'.<br>
<br>
> Hi,<br>
><br>
> I can't get Snort 2.8.5 (patched with the Snortsam patch) to work ...<br>
> As soon as I want to load a test-rule like this :<br>
><br>
> alert icmp any any -> $HOME_NET any (msg:"ICMP test"; dsize:>1400;<br>
> sid:1000001; fwsam: src, 20 minutes;)<br>
><br>
> I get the following :<br>
><br>
> +++++++++++++++++++++++++++++++++++++++++++++++++++<br>
> Initializing rule chains...<br>
> ERROR: /etc/snort/rules/local.rules(7) Unknown rule option: 'fwsam'.<br>
> Fatal Error, Quitting..<br>
><br>
> Snort does have Snortsam compiled in, because a 'string /usr/sbin/snort |<br>
> grep -i fwsam' reveals lines like :<br>
><br>
> ERROR => [Alert_FWsam](FWsamCheckOut) Funky socket error (socket)!<br>
> ERROR => [Alert_FWsam](FWsamCheckOut) Could not bind socket!<br>
> INFO => [Alert_FWsam](FWsamCheckOut) Disconnecting from host %s.<br>
> INFO => [Alert_FWsam](FWsamCheckOut) Had to use initial key!<br>
><br>
> etc, etc.<br>
><br>
> Am I missing something here ?<br>
><br>
> Best regards,<br>
><br>
> Wouter de Jong<br>
><br>
> _______________________________________________<br>
> Snortsam-discussion mailing list<br>
> <a href="mailto:Snortsam-discussion@snortsam.net">Snortsam-discussion@snortsam.net</a><br>
> <a href="http://lists.snortsam.net/mailman/listinfo/snortsam-discussion" target="_blank">http://lists.snortsam.net/mailman/listinfo/snortsam-discussion</a><br>
><br>
_______________________________________________<br>
Snortsam-discussion mailing list<br>
<a href="mailto:Snortsam-discussion@snortsam.net">Snortsam-discussion@snortsam.net</a><br>
<a href="http://lists.snortsam.net/mailman/listinfo/snortsam-discussion" target="_blank">http://lists.snortsam.net/mailman/listinfo/snortsam-discussion</a><br>
<br>
_______________________________________________<br>
Snortsam-discussion mailing list<br>
<a href="mailto:Snortsam-discussion@snortsam.net">Snortsam-discussion@snortsam.net</a><br>
<a href="http://lists.snortsam.net/mailman/listinfo/snortsam-discussion" target="_blank">http://lists.snortsam.net/mailman/listinfo/snortsam-discussion</a><br>
</div></div></blockquote></div><br><br clear="all"><br>