[Snort-users] Content-list rule option

Joel Esler jesler at ...1935...
Tue Aug 7 16:38:45 EDT 2012


On Aug 7, 2012, at 11:57 AM, Jose Ortiz <cissp2k8 at ...11827...> wrote:

> I have this rule on 2.9.3 :
> alert tcp any any -> any any (content-list:"porn";msg:"test";rev:1;sid:99990000001001;)
> 
> I get the following error:
> 
> ERROR: /etc/snort/rules/local.rules(6) Unknown rule option: 'content-list'.
> Fatal Error, Quitting..
> 
> What is the alternative to "content-list"?

There is no such rule option.  Are you just looking for "content"?

--
Joel Esler
Senior Research Engineer, VRT
OpenSource Community Manager
Sourcefire



More information about the Snort-users mailing list