[Snort-sigs] Local.Rules rule misfiring

Clint Conner conner at ...4151...
Tue Apr 26 10:05:34 EDT 2016


I have the following rule added to my local.rules file.  The rule it replaces is disabled in disabledsids.conf.  The rule is firing incorrectly, though.  It alerts on the first IP address, which is  If I understand he rule correctly, it should not be alerting on this IP address.

alert tcp $HOME_NET any -> [!,!,$EXTERNAL_NET] $HTTP_PORTS (msg:"ET MALWARE User-Agent (Mozilla/4.0 (compatible))";flow:to_server,established; content:"User-Agent|3a| Mozilla/4.0 (compatible|29 0d 0a|"; fast_pattern:18,20; http_header; content:!"citrixonline.com"; http_header; reference:url,doc.emergingthreats.net/bin/view/Main/2008974; classtype:Trojan-activity; sid:900000010;rev:1;)

There are more IP address ranges that are ! out, but I have omitted them.  I copied the rule directly from the pulledpork file and just added the first IP address to it.  I still have alerts pouring in when anything goes to that first IP address.

Thank you,


Clint J. Conner
Managed Services Manager
Plummer Slade, Inc.
"Computer Networking & IT Solutions"
428 Forbes Avenue, Suite 2450<x-apple-data-detectors://3/0>
Pittsburgh, PA 15219<x-apple-data-detectors://3/0>
Tel: 412.261.5600 x215<tel:412.261.5600;215>
Fax: 412.261.1528<tel:412.261.1528>
conner at ...4151...<mailto:conner at ...4151...>

"Exclusively endorsed for IT solutions by the Allegheny County Bar Association (ACBA)."

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20160426/36ce5301/attachment.html>

More information about the Snort-sigs mailing list