[Snort-sigs] receiving an error msg on a signature

Matt Kettler mkettler at ...189...
Tue Feb 4 17:33:27 EST 2003


from the output of the error message it sounds like theres some non-ascii 
bytes, namely a null byte, in your configfile. Check it closely with 
hexdump or something.. you should not find any hex 00's in it.

At 07:25 PM 2/4/2003 -0500, nick nelson wrote:
>Greetings everyone..
>
>The signature is used (or hopefully will be used..) to detect
>incoming xdcc send requests.
>
>Can anyone offer suggestions on the following error :
>
>I'm using snort 1.9,
>
>ERROR snort.conf Line 593 => ParsePattern Got Null enclosed in
>quotation
>marks (")!
>Fatal Error, Quitting..
>
>
>alert tcp $EXTERNAL_NET 6660:7000 -> $HOME_NET any (msg:"Incoming
>XDCC Send Request Detected"; flow:to_server,established; content:"
>:^AXDCC *[Ss][Ee][Nn][Dd] *#[0-9]" ; nocase; offset:0; classtype:misc-
>activity;)
>
>Thanks in advance..
>
>-nick





More information about the Snort-sigs mailing list