Re: [sentinix-list] Snort work a bit ;-)
Michel Blomgren <[email protected]>
| Newsgroups | gmane.linux.sentinix |
|---|---|
| Message-ID | <[email protected]> |
On Thursday 18 December 2003 20:12, Thierry wrote: > On 18/12/03 19:50, Michel Blomgren wrote: > > Which browser are you using??! > > For this exemple, i am using IE ....But i have the samle results with opera > on unix box ... Yepp, I thought so... IE simply doesn't support SnortCenter's javascripts (or one could see it the other way around, I don't care). The db gets updated, it's just the javascript that doens't really work in IE. When you click "push", just wait until some page is being loaded (either the regular front page or perhaps the loading screen - I've seen both happen in IE 6.x). I think SnortCenter worked better in some previous IE, don't know for sure though. If you want to see SnortCenter the way the developer intended, use Mozilla or Netscape 6.x+. Those "unknown rule" messages can be ignored, you have the sid number there, check the rules listing, search for those sids, you (hopefully) find them in there. Michel > > > On Thursday 18 December 2003 19:47, Thierry wrote: > > > Hi, > > > I reinstall for the second time Sentinix, i change my nic, leave eth0 > > > as snort sensor (default) i did a permutation between my two NIC ... > > > But i still can not Push, and making any Update rules through internet. > > > For my push, nothing moving, i only can see Loading running ..... > > > For my update : > > > > > > Unknown Rule option: msg:"ATTACK-RESPONSES id check returned userid"; > > > content:"uid="; byte_test:5,<,65537,0,relative,string; content:" gid="; > > > distance:0; within:15; byte_test:5,<,65537,0,relative,string; > > > classtype:bad-unknown; sid:1882; rev:9; > > > -> byte_test > > > Unknown Rule option: msg:"ATTACK-RESPONSES id check returned userid"; > > > content:"uid="; byte_test:5,<,65537,0,relative,string; content:" gid="; > > > distance:0; within:15; byte_test:5,<,65537,0,relative,string; > > > classtype:bad-unknown; sid:1882; rev:9; > > > -> byte_test > > > Unknown Rule option: msg:"BACKDOOR typot trojan traffic"; flags:S,12; > > > window:55808; sid:2182; rev:1; > > > -> window > > > Unknown Rule option: msg:"RPC portmap tooltalk request TCP"; > > > flow:to_server,established; content:"|00 00 00 00|"; offset:8; depth:4; > > > content:"|00 01 86 A0|"; offset:16; depth:4; content:"|00 00 00 03|"; > > > distance:4; within:4; byte_jump:4,4,relative,align; > > > byte_jump:4,4,relative,align; content:"|00 01 86 F3|"; within:4; > > > reference:cve,CAN-2001-0717; reference:cve,CVE-1999-0003; > > > reference:cve,CVE-1999-0687; reference:cve,CAN-1999-1075; > > > reference:url,www.cert.org/advisories/CA-2001-05.html; > > > classtype:rpc-portmap-decode; sid:1298; rev:10; > > > > > > I do not know what does that mean .... > > > Can it be a problem between configuration of my two Nic ? different ip > > > number, network and default gateway ?? > > > > > > Thx > > > > _______________________________________________ > > SENTINIX mailing list > > [email protected] > > http://elevenprospect.com/mailman/listinfo/sentinix