Snort mailing list archives

Snort 2.0.6 - Error with a working rule under Snort-2.0.2


From: <CGhercoias () TWEC COM>
Date: Wed, 14 Jan 2004 12:13:59 -0500

Hi guys,

I upgraded snort-2.0.2 to snort-2.0.6 and I'm getting the following
error from a rule which was perfectly valid under previous version of
snort.
Below is the message I'm getting from snort:

Current config file error:
Running in IDS mode
Log directory = /var/log/snort

Initializing Network Interface eth1
OpenPcap() device eth1 network lookup: 
eth1: no IPv4 address assigned

--== Initializing Snort ==--
Rule application order changed to Pass->Alert->Log
Initializing Output Plugins!
Decoding Ethernet on interface eth1
Parsing Rules file /etc/snort/snort.eth1.conf

+++++++++++++++++++++++++++++++++++++++++++++++++++
Initializing rule chains...
Initializing Preprocessors!
Initializing Plug-ins!
No arguments to frag2 directive, setting defaults to:
Fragment timeout: 60 seconds
Fragment memory cap: 4194304 bytes
Fragment min_ttl: 0
Fragment ttl_limit: 5
Fragment Problems: 0
Self preservation threshold: 500
Self preservation period: 90
Suspend threshold: 1000
Suspend period: 30
Stream4 config:
Stateful inspection: ACTIVE
Session statistics: INACTIVE
Session timeout: 30 seconds
Session memory cap: 8388608 bytes
State alerts: INACTIVE
Evasion alerts: INACTIVE
Scan alerts: ACTIVE
Log Flushed Streams: INACTIVE
MinTTL: 1
TTL Limit: 5
Async Link: 0
State Protection: 0
Self preservation threshold: 50
Self preservation period: 90
Suspend threshold: 200
Suspend period: 30
Stream4_reassemble config:
Server reassembly: INACTIVE
Client reassembly: ACTIVE
Reassembler alerts: ACTIVE
Zero out flushed packets: INACTIVE
flush_data_diff_size: 500
Ports: 21 23 25 53 80 110 111 143 513 1433 
Emergency Ports: 21 23 25 53 80 110 111 143 513 1433 
http_decode arguments:
Unicode decoding
IIS alternate Unicode decoding
IIS double encoding vuln
Flip backslash to slash
Include additional whitespace separators
Ports to decode http on: 80 
rpc_decode arguments:
Ports to decode RPC on: 111 32771 
alert_fragments: INACTIVE
alert_large_fragments: ACTIVE
alert_incomplete: ACTIVE
alert_multiple_requests: ACTIVE
telnet_decode arguments:
Ports to decode telnet on: 21 23 25 119 
database: compiled support for ( mysql )
database: configured to use mysql
database: user = snort
database: password is set
database: database name = snort
database: host = 177.1.0.94
database: port = 3306
database: sensor name = internal
database: detail level = full
database: sensor id = 3
database: schema version = 106
database: using the "log" facility
ERROR: /etc/snort/snort.eth1.conf(311) => ParsePattern Got Null enclosed
in quotation marks (")!
Fatal Error, Quitting..

And this is the content of the line 311.....

<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<DATA SKIPS --
snort.conf>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
311 alert icmp $EXTERNAL_NET any -> $HOME_NET any ( sid: 1000029; rev:
3; msg: "WELCHIA Virus scanning"; content:
"|aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa|"; depth: 32; itype: 8; reference:
arachnids,154; classtype: misc        -activity;)
312 #
313
#-----------------------------------------------------------------------
--------
314 # $Id: misc.rules, Wednesday 14th of January 2004 09:44:08 AM
315
#-----------------------------------------------------------------------
--------
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<DATA SKIPS --
snort.conf>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

Thank you,
_________________
Catalin,

Tart words make no friends; a spoonful of honey will catch more flies
than
a gallon of vinegar.
-- B. Franklin


-------------------------------------------------------
This SF.net email is sponsored by: Perforce Software.
Perforce is the Fast Software Configuration Management System offering
advanced branching capabilities and atomic changes on 50+ platforms.
Free Eval! http://www.perforce.com/perforce/loadprog.html
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: