Re: [sentinix-list] Snort work a bit ;-)
Michel Blomgren <[email protected]>
| Newsgroups | gmane.linux.sentinix |
|---|---|
| Message-ID | <[email protected]> |
Which browser are you using??! On Thursday 18 December 2003 19:47, Thierry wrote: > Hi, > I reinstall for the second time Sentinix, i change my nic, leave eth0 as > snort sensor (default) i did a permutation between my two NIC ... But i > still can not Push, and making any Update rules through internet. For my > push, nothing moving, i only can see Loading running ..... > For my update : > > Unknown Rule option: msg:"ATTACK-RESPONSES id check returned userid"; > content:"uid="; byte_test:5,<,65537,0,relative,string; content:" gid="; > distance:0; within:15; byte_test:5,<,65537,0,relative,string; > classtype:bad-unknown; sid:1882; rev:9; > -> byte_test > Unknown Rule option: msg:"ATTACK-RESPONSES id check returned userid"; > content:"uid="; byte_test:5,<,65537,0,relative,string; content:" gid="; > distance:0; within:15; byte_test:5,<,65537,0,relative,string; > classtype:bad-unknown; sid:1882; rev:9; > -> byte_test > Unknown Rule option: msg:"BACKDOOR typot trojan traffic"; flags:S,12; > window:55808; sid:2182; rev:1; > -> window > Unknown Rule option: msg:"RPC portmap tooltalk request TCP"; > flow:to_server,established; content:"|00 00 00 00|"; offset:8; depth:4; > content:"|00 01 86 A0|"; offset:16; depth:4; content:"|00 00 00 03|"; > distance:4; within:4; byte_jump:4,4,relative,align; > byte_jump:4,4,relative,align; content:"|00 01 86 F3|"; within:4; > reference:cve,CAN-2001-0717; reference:cve,CVE-1999-0003; > reference:cve,CVE-1999-0687; reference:cve,CAN-1999-1075; > reference:url,www.cert.org/advisories/CA-2001-05.html; > classtype:rpc-portmap-decode; sid:1298; rev:10; > > I do not know what does that mean .... > Can it be a problem between configuration of my two Nic ? different ip > number, network and default gateway ?? > > Thx