Re: [sentinix-list] Snort work a bit ;-)

Michel Blomgren <[email protected]>
Newsgroups gmane.linux.sentinix
Message-ID <[email protected]>
On Thursday 18 December 2003 20:12, Thierry wrote:
> On 18/12/03   19:50, Michel Blomgren wrote:
> > Which browser are you using??!
>
> For this exemple, i am using IE ....But i have the samle results with opera
> on unix box ...

Yepp, I thought so...  IE simply doesn't support SnortCenter's javascripts (or 
one could see it the other way around, I don't care).

The db gets updated, it's just the javascript that doens't really work in IE.  
When you click "push", just wait until some page is being loaded (either the 
regular front page or perhaps the loading screen - I've seen both happen in 
IE 6.x).  I think SnortCenter worked better in some previous IE, don't know 
for sure though.

If you want to see SnortCenter the way the developer intended, use Mozilla or 
Netscape 6.x+.

Those "unknown rule" messages can be ignored, you have the sid number there, 
check the rules listing, search for those sids, you (hopefully) find them in 
there.

	Michel

>
> > On Thursday 18 December 2003 19:47, Thierry wrote:
> > > Hi,
> > > I reinstall for the second time Sentinix, i change my nic, leave eth0
> > > as snort sensor (default) i did a permutation between my two NIC ...
> > > But i still can not Push, and making any Update rules through internet.
> > > For my push, nothing moving, i only can see Loading running .....
> > > For my update :
> > >
> > > Unknown Rule option: msg:"ATTACK-RESPONSES id check returned userid";
> > > content:"uid="; byte_test:5,<,65537,0,relative,string; content:" gid=";
> > > distance:0; within:15; byte_test:5,<,65537,0,relative,string;
> > > classtype:bad-unknown; sid:1882; rev:9;
> > > -> byte_test
> > > Unknown Rule option: msg:"ATTACK-RESPONSES id check returned userid";
> > > content:"uid="; byte_test:5,<,65537,0,relative,string; content:" gid=";
> > > distance:0; within:15; byte_test:5,<,65537,0,relative,string;
> > > classtype:bad-unknown; sid:1882; rev:9;
> > > -> byte_test
> > > Unknown Rule option: msg:"BACKDOOR typot trojan traffic"; flags:S,12;
> > > window:55808; sid:2182; rev:1;
> > > -> window
> > > Unknown Rule option: msg:"RPC portmap tooltalk request TCP";
> > > flow:to_server,established; content:"|00 00 00 00|"; offset:8; depth:4;
> > > content:"|00 01 86 A0|"; offset:16; depth:4; content:"|00 00 00 03|";
> > > distance:4; within:4; byte_jump:4,4,relative,align;
> > > byte_jump:4,4,relative,align; content:"|00 01 86 F3|"; within:4;
> > > reference:cve,CAN-2001-0717; reference:cve,CVE-1999-0003;
> > > reference:cve,CVE-1999-0687; reference:cve,CAN-1999-1075;
> > > reference:url,www.cert.org/advisories/CA-2001-05.html;
> > > classtype:rpc-portmap-decode; sid:1298; rev:10;
> > >
> > > I do not know what does that mean ....
> > > Can it be a problem between configuration of my two Nic ? different ip
> > > number, network and default gateway ??
> > >
> > > Thx
> >
> > _______________________________________________
> > SENTINIX mailing list
> > [email protected]
> > http://elevenprospect.com/mailman/listinfo/sentinix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.