[Snort-users] Broken snort rule

Matt Jonkman jonkman at ...4024...
Tue Oct 7 11:11:40 EDT 2008


Yes, it would. But we used to rely on an error report from snort. Now it
just ignores and goes on....

So no real good automated way to do so. There was talk about a switch to
have snort exit on an error. Any traction with that?

If you have a good automated way we can use I'd love to hear it.

Matt

Brian Caswell wrote:
> On Tue, Oct 7, 2008 at 9:37 AM, Matt Jonkman <jonkman at ...4024...
> <mailto:jonkman at ...4024...>> wrote:
> 
>     Thats an issue for emerging-sigs, but thanks for reporting it.
> 
>     Script error not watching for an even number of IPs. Fixed up, can you
>     pull again and retest for me?
> 
> 
> Perhaps it would be a good idea to ... I donno, test the rules before
> releasing them?
> 
> Brian 

-- 
--------------------------------------------
Matthew Jonkman
Emerging Threats
Phone 765-429-0398
Fax 312-264-0205
http://www.emergingthreats.net
--------------------------------------------

PGP: http://www.jonkmans.com/mattjonkman.asc






More information about the Snort-users mailing list