<feed xmlns='http://www.w3.org/2005/Atom'>
<title>packages/net/snort3/files/snort-rules, branch master</title>
<subtitle>Mirror of packages feed</subtitle>
<id>https://git.openwrt.org/feed/packages/atom?h=master</id>
<link rel='self' href='https://git.openwrt.org/feed/packages/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/'/>
<updated>2024-02-07T22:01:11Z</updated>
<entry>
<title>snort3: improve script reliability</title>
<updated>2024-02-07T22:01:11Z</updated>
<author>
<name>Eric Fahlgren</name>
</author>
<published>2024-02-05T15:07:38Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=b94c6dd37df76aa7f6b6813135228b82cd5d8886'/>
<id>urn:sha1:b94c6dd37df76aa7f6b6813135228b82cd5d8886</id>
<content type='text'>
 - Enable missing variable checking by default
 - Explicitly check variables are defined in all 'rm' commands

Signed-off-by: Eric Fahlgren &lt;ericfahlgren@gmail.com&gt;
</content>
</entry>
<entry>
<title>snort3: finish up several incomplete capabilities</title>
<updated>2024-02-05T00:21:11Z</updated>
<author>
<name>Eric Fahlgren</name>
</author>
<published>2024-01-10T16:10:05Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=203e9413e28defd62e376406b523eb7d9ac05d58'/>
<id>urn:sha1:203e9413e28defd62e376406b523eb7d9ac05d58</id>
<content type='text'>
Reporting
 - Use json alert data for 10x speed improvement in report generation
 - Include both gid and sid, plus packet direction in report output
 - Add by-date incident filtering
 - Add verbose mode which displays actual rules triggered and their source
 - Attempt to look up host names from IPs in verbose mode
 - Clean up display of port number involved in incidents

Rules
 - Complete downloader for subscription rules using oinkcode (only tested
   with snort.org's "free" tier subscription)
 - Auto-detect multiple rules files and include them in lua 'ips.rules'
 - Add '--backup' option to copy out current rules before installing new
 - Add '--persistent' option to 'snort-rules', storing in persistent location

CLI interface
 - Completely rework command line option parsing in all user scripts
 - Allow options and commands to be in any order on command line
 - Add long-form names for all options ('--help' for '-h' and so on)
 - Detect errors properly in options, enhance help pages

Bug fixes
 - Use 'mkdir -p' on all directory creation
 - Use proper tmp directory from 'snort.snort.temp_dir' everywhere

Signed-off-by: Eric Fahlgren &lt;ericfahlgren@gmail.com&gt;
</content>
</entry>
<entry>
<title>snort3: complete rework</title>
<updated>2023-12-03T21:53:58Z</updated>
<author>
<name>Eric Fahlgren</name>
</author>
<published>2023-11-27T16:21:43Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=f21dffc2a306ad97cefa03dac8bcee0552da556f'/>
<id>urn:sha1:f21dffc2a306ad97cefa03dac8bcee0552da556f</id>
<content type='text'>
  - Add many options to config file.
  - Move rules and generated snort.lua to /tmp.
  - Add script for downloading rules.
  - Add preliminary reporting capabilites.

Signed-off-by: Eric Fahlgren &lt;ericfahlgren@gmail.com&gt;
</content>
</entry>
</feed>
