[Snort-sigs] newby quistin

David Davis whitevamp47 at ...12...
Wed Apr 16 00:29:10 EDT 2003


i have d/l snort 2.x and i was doing the conf file and noticed this section 
in the conf file

# This example will create a type that will log to just tcpdump.
ruletype suspicious
{
   type log
   output log_tcpdump: suspicious.log
}
#
# EXAMPLE RULE FOR SUSPICIOUS RULETYPE:
#suspicious $HOME_NET any -> $HOME_NET 6667 (msg:"Internal IRC Server";)
well my quistion is  when  i place suspicious $HOME_NET any -> $HOME_NET 
6667 (msg:"Internal IRC in a rules file it say's
Bad protocol: any
any ideas on this and how to correct this issue ?

and thankx in advance





_________________________________________________________________
STOP MORE SPAM with the new MSN 8 and get 2 months FREE*  
http://join.msn.com/?page=features/junkmail





More information about the Snort-sigs mailing list