[Snort-sigs] receiving an error msg on a signature

Matt Kettler mkettler at ...189...
Tue Feb 4 17:33:27 EST 2003

from the output of the error message it sounds like theres some non-ascii 
bytes, namely a null byte, in your configfile. Check it closely with 
hexdump or something.. you should not find any hex 00's in it.

At 07:25 PM 2/4/2003 -0500, nick nelson wrote:
>Greetings everyone..
>The signature is used (or hopefully will be used..) to detect
>incoming xdcc send requests.
>Can anyone offer suggestions on the following error :
>I'm using snort 1.9,
>ERROR snort.conf Line 593 => ParsePattern Got Null enclosed in
>marks (")!
>Fatal Error, Quitting..
>alert tcp $EXTERNAL_NET 6660:7000 -> $HOME_NET any (msg:"Incoming
>XDCC Send Request Detected"; flow:to_server,established; content:"
>:^AXDCC *[Ss][Ee][Nn][Dd] *#[0-9]" ; nocase; offset:0; classtype:misc-
>Thanks in advance..

More information about the Snort-sigs mailing list