[sentinix-list] Snort work a bit ;-)
Thierry <[email protected]>
| Newsgroups | gmane.linux.sentinix |
|---|---|
| Message-ID | <20031218184703.GA53212@urania> |
Hi, I reinstall for the second time Sentinix, i change my nic, leave eth0 as snort sensor (default) i did a permutation between my two NIC ... But i still can not Push, and making any Update rules through internet. For my push, nothing moving, i only can see Loading running ..... For my update : Unknown Rule option: msg:"ATTACK-RESPONSES id check returned userid"; content:"uid="; byte_test:5,<,65537,0,relative,string; content:" gid="; distance:0; within:15; byte_test:5,<,65537,0,relative,string; classtype:bad-unknown; sid:1882; rev:9; -> byte_test Unknown Rule option: msg:"ATTACK-RESPONSES id check returned userid"; content:"uid="; byte_test:5,<,65537,0,relative,string; content:" gid="; distance:0; within:15; byte_test:5,<,65537,0,relative,string; classtype:bad-unknown; sid:1882; rev:9; -> byte_test Unknown Rule option: msg:"BACKDOOR typot trojan traffic"; flags:S,12; window:55808; sid:2182; rev:1; -> window Unknown Rule option: msg:"RPC portmap tooltalk request TCP"; flow:to_server,established; content:"|00 00 00 00|"; offset:8; depth:4; content:"|00 01 86 A0|"; offset:16; depth:4; content:"|00 00 00 03|"; distance:4; within:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:"|00 01 86 F3|"; within:4; reference:cve,CAN-2001-0717; reference:cve,CVE-1999-0003; reference:cve,CVE-1999-0687; reference:cve,CAN-1999-1075; reference:url,www.cert.org/advisories/CA-2001-05.html; classtype:rpc-portmap-decode; sid:1298; rev:10; I do not know what does that mean .... Can it be a problem between configuration of my two Nic ? different ip number, network and default gateway ?? Thx -- Thierry