[Snort-users] Content-list rule option

Jeremy Hoel jthoel at ...11827...
Tue Aug 7 12:05:12 EDT 2012


Are you looking to make it a classification?  Or look for the word
'porn' in the content?

On Tue, Aug 7, 2012 at 3:57 PM, Jose Ortiz <cissp2k8 at ...11827...> wrote:
> I have this rule on 2.9.3 :
> alert tcp any any -> any any
> (content-list:"porn";msg:"test";rev:1;sid:99990000001001;)
>
> I get the following error:
>
> ERROR: /etc/snort/rules/local.rules(6) Unknown rule option: 'content-list'.
> Fatal Error, Quitting..
>
> What is the alternative to "content-list"?
>
>
> ------------------------------------------------------------------------------
> Live Security Virtual Conference
> Exclusive live event will cover all the ways today's security and
> threat landscape has changed and how IT managers can respond. Discussions
> will include endpoint security, mobile security and the latest in malware
> threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users
>
> Please visit http://blog.snort.org to stay current on all the latest Snort
> news!




More information about the Snort-users mailing list