[Fwd: Re: FWD: Re: [Snort-users] Snort complains about rules file]

Josh Oshiro josh at ...155...
Thu Apr 19 15:34:36 EDT 2001


-------- Original Message --------
From: Josh Oshiro <josh at ...155...>
Subject: Re: FWD: Re: [Snort-users] Snort complains about rules file
To: lists at ...297...

If you are using the rules that come with the 1.7 release then you
shouldn't have problems but if you update
the rules then you need to add some things to your snort.conf file.

There are new variables to define in snort.conf for the new rules.
var SMTP x.x.x.x/32
var HTTP_SERVERS x.x.x.x/32
var SQL_SERVERS x.x.x.x/32


Joe Magee wrote:

> I have the snort.conf that comes with the 1.7 package... I didn't change anything... hmmmm...
>
> I'm plagued by old rules... help! ; >
>
> People are trying to dot dot me and cross-site-script me.. I can feel it... ; >
>
> ---------- Original Message ----------------------------------
> From: Joe McAlerney <joey at ...155...>
> Date: Mon, 02 Apr 2001 10:52:31 -0700
>
> >lists wrote:
> >>
> >> I'm also having this problem with the new rulesets... I have my EXTERNAL_NET defined in snort.conf as:
> >>
> >> var EXTERNAL_NET any
> >>
> >> This is no good with the new rules?
> >>
> >> Joe
> >
> >Joe,
> >
> >There were a few other variables added to the recent snort.conf file
> >(SMTP, SQL_SERVERS).  My guess is that you are using an older snort.conf
> >with new snort rulesets.  You may want to check to see if those
> >variables are defined.
> >
> >Hope this helps,
> >
> >-Joe M.
> >
> >--
> >|   Joe McAlerney     joey at ...155...   |
> >| Silicon Defense - Technical Support for Snort |
> >|       http://www.silicondefense.com/          |
> >+--                                           --+
> >
>
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> http://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users

--
josh at ...155...
Snort Support
Silicon Defense




More information about the Snort-users mailing list