Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - bmail

#16
Hello,

Try to deactivate Snort VRT rules.
I was using the 29120 version, and it seems suricata does not love it.
Since giving up snort rules, no more ERRCODE: SC_WARN_FLOWBIT(306) and suricata just works well.

Bertrand

#17
Bonjour,

Personnellement, je n'ai pas eu de soucis pour upgrader depuis la dernière 18.
Proc Intel
Cartes Intel et Broadcom.
Dpinger fonctionne normalement.

Bonne journée à tout le monde.
#18
Hello,

Not a real answer neither an explanation for your issue, but , try Hyperscan  for pattern research (for suricata).

It could work better with Intel NIC and claim  less ram (at least for my system).
Hope it could help you.
#19
Hello,

Using OPNsense 19.1, with Suricata 4.1.2_1, I noticed a new message in log (within dasboard):
Lots (more or less 45 for the same date and hour) of .....

Feb 5 18:18:45    rule-updater.py: version response for https://rules.emergingthreats.net/open/suricata-4.0/version.txt : 9115

With a version.txt incrementing each day.

It seems correctly downloading and installing new versions of rules, but do you know why rule-updater.py returns so numerous identical messages ?

Thanks a lot for teaching me ...
#20
18.7 Legacy Series / Difference between alias type
November 28, 2018, 12:08:20 PM
Hello,

Could someone explain to me the difference between the type "URL (IPs)" and "URL Table (IPs)" when creating a new alias for the firewall ?

thanks a lot !
Have a good day.
#21
Hello Mimugmail,

Well, That's what I was thinking about this ... Too bad ....
So I will try the DOMBL.

Thanks for your answer.

Best regards

#22
Hello,

Did someone succed in downloading and using this list with squid ?

https://ransomwaretracker.abuse.ch/downloads/RW_URLBL.txt

This list is downloadable with a browser but, when I create an external acl with it, it does not work:

Warning: empty ACL: acl remoteblacklist_URL.Ransomware dstdomain "/usr/local/etc/squid/acl/URL.ransomware"

Permissions are same as others remote acl which work fine.
Is it because squid waits for domains and not url ?

Thanks for any advice !
#23
No. Other rulesets are downloading fine.
Just an issue with abuse.ch on specific subdomain.

#24
Hello,

Not the same issue. I was talking about downloading rules from feodotracker.abuse.ch or sslbl.abuse.ch.
Issue with URLhaus seems to be related to hypersan method.

#25
Hello,

Thanks for this news.  So no issue coming from OPNsense.
Have a good we.
best regards

#26
Hello,

Since 18.7.7, I've been noticed that suricata does'nt download rules coming from abuse.ch.

For example:
rule-updater.py: download failed for https://feodotracker.abuse.ch/blocklist/?download=suricata
rule-updater.py: download failed for https://sslbl.abuse.ch/blacklist/dyre_sslipblacklist.rules
rule-updater.py: download failed for https://sslbl.abuse.ch/blacklist/sslipblacklist.rules
rule-updater.py: download failed for https://sslbl.abuse.ch/blacklist/sslblacklist.rules

Into the rules section, we can see that no new download had been completed for some days:

abuse.ch/Dyre SSL IPBL                          2018/11/09 10:18                                   drop   
abuse.ch/Feodo Tracker                          2018/11/06 22:18                                   drop   
abuse.ch/SSL Fingerprint Blacklist          2018/11/09 10:18                                   drop   
abuse.ch/SSL IP Blacklist                          2018/11/09 10:18                                   drop

Have you the same issue with 18.7.7  and suricata 4.0.6 ?

Thanks fo any idea !
Regards
#27
Hello,

Perhaps, you should flush ssl cache of all your PC or ipad.
SSL cache of each browser can create issues, sometimes quite persistent ...

have a good day.
#28
Hello,

You don't need rules from wan to lan if you only have clients on lan side.

bmail
#29
Hello,

I just see that user defined rules are no more applied ...
I also use squid. And, in order to filter website with its ssl fingerprint, I put the website in the "SSL no bump sites" list in the squid config.

After this, I use the SSL fingerprint of this website in order to create a new "user defined" rule (with a "reject" argument), in the suricata config section.

This one is no longer applied ... I can access to this website.

I use:
OPNsense 18.7.4-amd64
FreeBSD 11.1-RELEASE-p14
OpenSSL 1.0.2p 14 Aug 2018

And Hyperscan for "pattern matcher". But "default" does'nt work anymore.

Did someone notice this ?

Thanks a lot for any idea.
Best regards
#30
Hello,

If I can allow myself to answer for my part ...

Yes the issue is still here with 18.1.9 and an exemple  with special characters : ^https?:\/\/([a-zA-Z]+)\.youtube\.

I don't use whitelist but it seems to be the same issue with blacklist.

Thanks to all for any advice