Snort mailing list archives
Re: Snortcenter
From: Roberto Bosticardo <roberto.bosticardo () csp it>
Date: Mon, 13 Oct 2003 18:19:13 +0200
Hi Shawni had the same problem so i disabled the rule at the line indicated in the error. Check the /etc/snort/snort.eth1.conf at line 88 (in your case) and disable that rule in snortcenter. You get this error because of the lack of parameters in byte_test rule option.
I hope I helped you! Bye Shawn Cannon ha scritto:
I have an issue with Snortcenter v1.0 RC1 and I was wondering if someone on this list could help. I selected some of the Snort rules and tried to push out the config file and I get an error. Here is the entire sensor message. Please help! Thanks.Reload: Current config file error: Running in IDS mode Log directory = /var/log/snort Initializing Network Interface eth1OpenPcap() device eth1 network lookup: eth1: no IPv4 address assigned--== Initializing Snort ==-- Rule application order changed to Pass->Alert->Log Initializing Output Plugins! Decoding Ethernet on interface eth1 Parsing Rules file /etc/snort/snort.eth1.conf +++++++++++++++++++++++++++++++++++++++++++++++++++ Initializing rule chains... Initializing Preprocessors! Initializing Plug-ins! No arguments to frag2 directive, setting defaults to: Fragment timeout: 60 seconds Fragment memory cap: 4194304 bytes Fragment min_ttl: 0 Fragment ttl_limit: 5 Fragment Problems: 0 Self preservation threshold: 500 Self preservation period: 90 Suspend threshold: 1000 Suspend period: 30 Stream4 config: Stateful inspection: ACTIVE Session statistics: INACTIVE Session timeout: 30 seconds Session memory cap: 8388608 bytes State alerts: INACTIVE Evasion alerts: INACTIVE Scan alerts: ACTIVE Log Flushed Streams: INACTIVE MinTTL: 1 TTL Limit: 5 Async Link: 0 State Protection: 0 Self preservation threshold: 50 Self preservation period: 90 Suspend threshold: 200 Suspend period: 30 Stream4_reassemble config: Server reassembly: INACTIVE Client reassembly: ACTIVE Reassembler alerts: ACTIVE Zero out flushed packets: INACTIVE flush_data_diff_size: 500Ports: 21 23 25 53 80 110 111 143 513 1433 Emergency Ports: 21 23 25 53 80 110 111 143 513 1433 http_decode arguments:Unicode decoding IIS alternate Unicode decoding IIS double encoding vuln Flip backslash to slash Include additional whitespace separatorsPorts to decode http on: 80 rpc_decode arguments: Ports to decode RPC on: 111 32771 alert_fragments: INACTIVEalert_large_fragments: ACTIVE alert_incomplete: ACTIVE alert_multiple_requests: ACTIVE telnet_decode arguments:Ports to decode telnet on: 21 23 25 119 database: compiled support for ( mysql )database: configured to use mysql database: user = snort database: password is set database: database name = snort database: host = 10.255.255.95 database: sensor name = unknown:eth1 database: sensor id = 1 database: schema version = 106 database: using the "log" facilityERROR: ERROR /etc/snort/snort.eth1.conf (88): Bad arguments to byte_test: Fatal Error, Quitting..Reload: SIGHUP has not been sent to snort pid!
-- ------------------------------------- Roberto Bosticardo Intrusion Detection Systems --------------------------- SecureLAB - CSP Innovazione nelle ICT Viale Settimio Severo 63 10133 Torino Phone: +39 011 4815120 ICQ: 15260939 Email: roberto.bosticardo () csp it Web: www.securelab.it ------------------------------------- ------------------------------------------------------- This SF.net email is sponsored by: SF.net Giveback Program. SourceForge.net hosts over 70,000 Open Source Projects. See the people who have HELPED US provide better services: Click here: http://sourceforge.net/supporters.php _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Snortcenter Shawn Cannon (Oct 13)
- Re: Snortcenter Roberto Bosticardo (Oct 13)
- <Possible follow-ups>
- snortcenter SWIT (Nov 19)