Snort mailing list archives

Re: "Bad range" error


From: Joel Esler <jesler () sourcefire com>
Date: Wed, 25 Apr 2012 08:59:54 -0400

We're taking a look at this as we speak. 

--
Joel Esler
Sent from Space

On Apr 25, 2012, at 4:07 AM, Peter Bates <peter.bates () ucl ac uk> wrote:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Hello all

In the output from my daily restart of Snort,
this morning I saw the following:

Starting snort service: Bad range: 3038303030303030
Bad range: 3038303030303030
Bad range: 3038303030303030
Bad range: 3038303030303030
Bad range: 3038303030303030
Spawning daemon child...

A quick grep for the number shows it in 5 rules in the 'FILE-OFFICE'
category, SIDS 21902-21906:

alert tcp $EXTERNAL_NET $FILE_DATA_PORTS -> $HOME_NET any
<snip>
byte_test:8,>,3038303030303030,-8,relative,little,string,hex;
<snip>
sid:21906; rev:1;)

Is this an error, or a sign I should move to 2.9.2.x?

- -- 
Peter Bates
Senior Computer Security Officer    Phone: +44(0)2076792049
Information Services Division        Internal Ext: 32049
University College London
London WC1E 6BT
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.17 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQEcBAEBAgAGBQJPl7DXAAoJELhVoVpEMS6RaCwH/1Bcy04NvWDHnJr7o+9rYYe7
qjY1b3ZpS9Nw9if6pM5uV4A40bIgLsLTYpZ991/Ex+FoNM01UZlIRYTPKRF9UkPE
xHFdGPsIbWNZOVo9C5BHo05PE0bDja7+H41YBodNHEEyKzH/bmLBYBNdUta/E0NQ
dNBj2k7U0TYjX5BkS4xnQGzpV2jxfL6RoX2rl/lEoi60BXS5pwfbko6vziWCMaMh
fsC12LTWjF5Dkyy83l/d7H1QfCgBj8fZx2D2iVud7vUj7cxoekp5ms5BpU6iMxxK
EaNPDK5U5xNButL5y6p7DftJn6ggP0d8enV/1l9Yc/v8OqxwEqQT/dy4D7PbazM=
=5/O/
-----END PGP SIGNATURE-----


------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: