Snort mailing list archives
Snort 2.0.6 - Error with a working rule under Snort-2.0.2
From: <CGhercoias () TWEC COM>
Date: Wed, 14 Jan 2004 12:13:59 -0500
Hi guys, I upgraded snort-2.0.2 to snort-2.0.6 and I'm getting the following error from a rule which was perfectly valid under previous version of snort. Below is the message I'm getting from snort: Current config file error: Running in IDS mode Log directory = /var/log/snort Initializing Network Interface eth1 OpenPcap() device eth1 network lookup: eth1: no IPv4 address assigned --== Initializing Snort ==-- Rule application order changed to Pass->Alert->Log Initializing Output Plugins! Decoding Ethernet on interface eth1 Parsing Rules file /etc/snort/snort.eth1.conf +++++++++++++++++++++++++++++++++++++++++++++++++++ Initializing rule chains... Initializing Preprocessors! Initializing Plug-ins! No arguments to frag2 directive, setting defaults to: Fragment timeout: 60 seconds Fragment memory cap: 4194304 bytes Fragment min_ttl: 0 Fragment ttl_limit: 5 Fragment Problems: 0 Self preservation threshold: 500 Self preservation period: 90 Suspend threshold: 1000 Suspend period: 30 Stream4 config: Stateful inspection: ACTIVE Session statistics: INACTIVE Session timeout: 30 seconds Session memory cap: 8388608 bytes State alerts: INACTIVE Evasion alerts: INACTIVE Scan alerts: ACTIVE Log Flushed Streams: INACTIVE MinTTL: 1 TTL Limit: 5 Async Link: 0 State Protection: 0 Self preservation threshold: 50 Self preservation period: 90 Suspend threshold: 200 Suspend period: 30 Stream4_reassemble config: Server reassembly: INACTIVE Client reassembly: ACTIVE Reassembler alerts: ACTIVE Zero out flushed packets: INACTIVE flush_data_diff_size: 500 Ports: 21 23 25 53 80 110 111 143 513 1433 Emergency Ports: 21 23 25 53 80 110 111 143 513 1433 http_decode arguments: Unicode decoding IIS alternate Unicode decoding IIS double encoding vuln Flip backslash to slash Include additional whitespace separators Ports to decode http on: 80 rpc_decode arguments: Ports to decode RPC on: 111 32771 alert_fragments: INACTIVE alert_large_fragments: ACTIVE alert_incomplete: ACTIVE alert_multiple_requests: ACTIVE telnet_decode arguments: Ports to decode telnet on: 21 23 25 119 database: compiled support for ( mysql ) database: configured to use mysql database: user = snort database: password is set database: database name = snort database: host = 177.1.0.94 database: port = 3306 database: sensor name = internal database: detail level = full database: sensor id = 3 database: schema version = 106 database: using the "log" facility ERROR: /etc/snort/snort.eth1.conf(311) => ParsePattern Got Null enclosed in quotation marks (")! Fatal Error, Quitting.. And this is the content of the line 311..... <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<DATA SKIPS -- snort.conf>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> 311 alert icmp $EXTERNAL_NET any -> $HOME_NET any ( sid: 1000029; rev: 3; msg: "WELCHIA Virus scanning"; content: "|aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa|"; depth: 32; itype: 8; reference: arachnids,154; classtype: misc -activity;) 312 # 313 #----------------------------------------------------------------------- -------- 314 # $Id: misc.rules, Wednesday 14th of January 2004 09:44:08 AM 315 #----------------------------------------------------------------------- -------- <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<DATA SKIPS -- snort.conf>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> Thank you, _________________ Catalin, Tart words make no friends; a spoonful of honey will catch more flies than a gallon of vinegar. -- B. Franklin ------------------------------------------------------- This SF.net email is sponsored by: Perforce Software. Perforce is the Fast Software Configuration Management System offering advanced branching capabilities and atomic changes on 50+ platforms. Free Eval! http://www.perforce.com/perforce/loadprog.html _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Snort 2.0.6 - Error with a working rule under Snort-2.0.2 CGhercoias (Jan 14)
- <Possible follow-ups>
- Snort 2.0.6 - Error with a working rule under Snort-2.0.2 CGhercoias (Jan 15)