# alert icmp any any -> any any (msg:"ICMP Destination Unreachable 
(Communication Administratively Prohibited)"; itype: 3; icode: 13; sid:485; 
classtype:misc-activity; rev:2;)
-------------------------
disablesid 485
-------------------------
# oinkmaster.pl -o /etc/snort/rules
/oinkmaster.pl -o /usr/local/etc/snort/rules
Loading /usr/local/etc/oinkmaster.conf
Downloading file from http://www.snort.org/pub-bin/downloads.cgi/Download/comm_rules/Community-Rules-2.4.tar.gz... done.
Archive successfully downloaded, unpacking... done.
Downloading file from http://www.bleedingsnort.com/bleeding.rules.tar.gz... done.
Archive successfully downloaded, unpacking... done.
Setting up rules structures... done.
Processing downloaded rules... disabled 0, enabled 0, modified 0, total=1912
Setting up rules structures... done.
Comparing new files to the old ones... done.
Updating local rules files... done.

[***] Results from Oinkmaster started 20060511 20:21:18 [***]

[*] Rules modifications: [*]
    None.

[*] Non-rule line modifications: [*]
    None.

[+] Added files (consider updating your snort.conf to include them if needed): [+]

    -> bleeding-attack_response.rules
    -> bleeding-dos.rules
    -> bleeding-drop-BLOCK.rules
    -> bleeding-drop.rules
    -> bleeding-dshield-BLOCK.rules
    -> bleeding-dshield.rules
    -> bleeding-exploit.rules
    -> bleeding-game.rules
    -> bleeding-inappropriate.rules
    -> bleeding-malware.rules
    -> bleeding-p2p.rules
    -> bleeding-policy.rules
    -> bleeding-scan.rules
    -> bleeding-sid-msg.map
    -> bleeding-virus.rules
    -> bleeding-web.rules
    -> bleeding.conf
    -> bleeding.rules
    -> community-bot.rules
    -> community-dos.rules
    -> community-exploit.rules
    -> community-ftp.rules
    -> community-game.rules
    -> community-icmp.rules
    -> community-imap.rules
    -> community-inappropriate.rules
    -> community-mail-client.rules
    -> community-misc.rules
    -> community-nntp.rules
    -> community-oracle.rules
    -> community-sid-msg.map
    -> community-sip.rules
    -> community-smtp.rules
    -> community-sql-injection.rules
    -> community-virus.rules
    -> community-web-attacks.rules
    -> community-web-cgi.rules
    -> community-web-client.rules
    -> community-web-dos.rules
    -> community-web-iis.rules
    -> community-web-misc.rules
    -> community-web-php.rules
-------------------------
url = http://www.snort.org/pub-bin/oinkmaster.cgi/ 5f6e64e16258a2f94dd7e7b0ef4e5c59cf4216a3/snortrules-snapshot-2.4.tar.gz
