[Snort-users] Invalid rules

Fontenot, Paul Paul.Fontenot at ...4988...
Wed Feb 27 13:42:11 EST 2002


I am evaluating Demarc and have set it to auto_update. This snort sensor was
started up about 20 minutes ago with the auto_update set to 5 minutes. I
have gotten this below since i started running demarc. has anyone seen this
problem?

-Paul

Updating local rules
Fetching current snort.conf
Adding 1-classifications to current_ruleset
Adding ATTACK RESPONSES to current_ruleset
Adding BACKDOOR RULES to current_ruleset
Adding BAD TRAFFIC RULES to current_ruleset
Adding DDOS RULES to current_ruleset
Adding DNS RULES to current_ruleset
Adding DOS RULES to current_ruleset
Adding EXPERIMENTAL RULES to current_ruleset
Adding EXPLOIT RULES to current_ruleset
Adding FINGER RULES to current_ruleset
Adding FTP RULES to current_ruleset
Adding ICMP RULES to current_ruleset
Adding INFO RULES to current_ruleset
Adding LOCAL RULES to current_ruleset
Adding MISC RULES to current_ruleset
Adding NETBIOS RULES to current_ruleset
Adding POLICY RULES to current_ruleset
Adding PORN RULES to current_ruleset
Adding RPC RULES to current_ruleset
Adding RSERVICES RULES to current_ruleset
Adding SCAN RULES to current_ruleset
Adding SHELLCODE RULES to current_ruleset
Adding SMTP RULES to current_ruleset
Adding SQL RULES to current_ruleset
Adding TELNET RULES to current_ruleset
Adding TFTP RULES to current_ruleset
Adding VIRUS RULES to current_ruleset
Adding WEB ATTACKS to current_ruleset
Adding WEB-CGI RULES to current_ruleset
Adding WEB-COLDFUSION RULES to current_ruleset
Adding WEB-FRONTPAGE RULES to current_ruleset
Adding WEB-IIS RULES to current_ruleset
Adding WEB-MISC RULES to current_ruleset
Adding X11 RULES to current_ruleset
Appears to be an invalid ruleset / snort.conf
RULES INVALID... NOT UPDATING CURRENT RUNNING CONFIG/RULESET!




More information about the Snort-users mailing list