[Snort-sigs] newby quistin
whitevamp47 at ...12...
Wed Apr 16 00:29:10 EDT 2003
i have d/l snort 2.x and i was doing the conf file and noticed this section
in the conf file
# This example will create a type that will log to just tcpdump.
output log_tcpdump: suspicious.log
# EXAMPLE RULE FOR SUSPICIOUS RULETYPE:
#suspicious $HOME_NET any -> $HOME_NET 6667 (msg:"Internal IRC Server";)
well my quistion is when i place suspicious $HOME_NET any -> $HOME_NET
6667 (msg:"Internal IRC in a rules file it say's
Bad protocol: any
any ideas on this and how to correct this issue ?
and thankx in advance
STOP MORE SPAM with the new MSN 8 and get 2 months FREE*
More information about the Snort-sigs