[Snort-users] Coupla typos in the latest ruleset

shawn . moyer shawn at ...1184...
Wed Jan 24 14:45:29 EST 2001


Dunno if anyone else already found these, but these were making snort
barf on load... 

[root at ...1202... /etc]# diff rules_results.asp\? snort.rules
910c910
< alert tcp $EXTERNAL_NET any -> $HOME_NET 23 (msg:"Linux Rootkit
probe";flags:PA; content:"d13hh["; nocase) 
---
> alert tcp $EXTERNAL_NET any -> $HOME_NET 23 (msg:"Linux Rootkit probe";flags:PA; content:"d13hh["; nocase;) 
1301c1301
< alert tcp any any -> $HOME_NET 80 (msg:"IIS Codebrowser access
attempt"; content :"/selector/showcode.asp"; flags: PA; nocase;) 
---
> alert tcp any any -> $HOME_NET 80 (msg:"IIS Codebrowser access attempt"; content:"/selector/showcode.asp"; flags: PA; nocase;) 




--shawn  

-- 
s h a w n   m o y e r
shawn at ...1184...




More information about the Snort-users mailing list