[sentinix-list] Snort work a bit ;-)

Thierry <[email protected]>
Newsgroups gmane.linux.sentinix
Message-ID <20031218184703.GA53212@urania>
Hi,
I reinstall for the second time Sentinix, i change my nic, leave eth0 as snort sensor (default) i did a permutation between my two NIC ... But i still can not Push, and making any Update rules through internet.
For my push, nothing moving, i only can see Loading running .....
For my update :

Unknown Rule option: msg:"ATTACK-RESPONSES id check returned userid";
content:"uid="; byte_test:5,<,65537,0,relative,string; content:" gid=";
distance:0; within:15; byte_test:5,<,65537,0,relative,string;
classtype:bad-unknown; sid:1882; rev:9;
-> byte_test
Unknown Rule option: msg:"ATTACK-RESPONSES id check returned userid";
content:"uid="; byte_test:5,<,65537,0,relative,string; content:" gid=";
distance:0; within:15; byte_test:5,<,65537,0,relative,string;
classtype:bad-unknown; sid:1882; rev:9;
-> byte_test
Unknown Rule option: msg:"BACKDOOR typot trojan traffic"; flags:S,12;
window:55808; sid:2182; rev:1;
-> window
Unknown Rule option: msg:"RPC portmap tooltalk request TCP";
flow:to_server,established; content:"|00 00 00 00|"; offset:8; depth:4;
content:"|00 01 86 A0|"; offset:16; depth:4; content:"|00 00 00 03|";
distance:4; within:4; byte_jump:4,4,relative,align;
byte_jump:4,4,relative,align; content:"|00 01 86 F3|"; within:4;
reference:cve,CAN-2001-0717; reference:cve,CVE-1999-0003;
reference:cve,CVE-1999-0687; reference:cve,CAN-1999-1075;
reference:url,www.cert.org/advisories/CA-2001-05.html;
classtype:rpc-portmap-decode; sid:1298; rev:10;

I do not know what does that mean ....
Can it be a problem between configuration of my two Nic ? different ip number, network and default gateway ??

Thx 

-- 
Thierry
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.