Re: [Snort-users] does not work local.rules

This is a discussion on Re: [Snort-users] does not work local.rules within the Snort forums, part of the System Security and Security Related category; Also make sure your snort.conf is actually looking at your local.rules. This is commented out by default. Cheers, ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 08-09-2006
info+lucretia.ca
 
Posts: n/a
Default Re: [Snort-users] does not work local.rules

Also make sure your snort.conf is actually looking at your local.rules.

This is commented out by default.

Cheers,

James Friesen, CIO
Lucretia Enterprises
Our World Is Here
info at lucretia dot ca
http://lucretia.ca


> -----Original Message-----
> From: snort-users-bounces@lists.sourceforge.net
> [mailto:snort-users-bounces@lists.sourceforge.net] On Behalf
> Of Lorine Ruotolo
> Sent: Tuesday, August 08, 2006 1:54 PM
> To: repniksz@aviva.co.hu; snort-users@lists.sourceforge.net
> Subject: Re: [Snort-users] does not work local.rules
>
>
> I think ! may not be allowed in regular text within the rule
> because it is the NOT character. You can use escape or hex
> forms of it, not sure what they are off the top of my head though.
>
> >From: repniksz@aviva.co.hu
> >To: snort-users@lists.sourceforge.net
> >Subject: [Snort-users] does not work local.rules
> >Date: Tue, 8 Aug 2006 15:34:09 +0200
> >
> >Hi,
> >I've made a very simple rule in my local.rules:
> >alert tcp any any -> any 8080 ( msg: "Own"; content:

> "Hello!!!!"; ) and
> >after that i've watched a file in my browser on 8080 port, and i did
> >not get any alert.
> >The local.rules is in my snort.conf .
> >What is wrong?

>
>
> >-------------------------------------------------------------

> ----------
> >-- Using Tomcat but need to do more? Need to support web services,
> >security?
> >Get stuff done quickly with pre-integrated technology to

> make your job
> >easier Download IBM WebSphere Application Server v.1.0.1 based on
> >Apache Geronimo
> >http://sel.as-us.falkag.net/sel?cmd=...709&bid=263057

> &dat=12164
> >2

>
>
> >_______________________________________________
> >Snort-users mailing list
> >Snort-users@lists.sourceforge.net
> >Go to this URL to change user options or unsubscribe:
> >https://lists.sourceforge.net/lists/...fo/snort-users
> >Snort-users list archive:
> >http://www.geocrawler.com/redir-sf.p...st=snort-users

>
> __________________________________________________ _______________
> Express yourself instantly with MSN Messenger! Download today
> - it's FREE!
> http://messenger.msn.click-url.com/g...ave/direct/01/
>
>
> --------------------------------------------------------------
> -----------
> Using Tomcat but need to do more? Need to support web
> services, security?
> Get stuff done quickly with pre-integrated technology to make
> your job easier Download IBM WebSphere Application Server
> v.1.0.1 based on Apache Geronimo
> http://sel.as-us.falkag.net/sel?cmd=...09&bid=263057&

dat=121642
> _______________________________________________
> Snort-users mailing list
> Snort-users@lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/...fo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.p...st=snort-users
>
>




-------------------------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=...057&dat=121642
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 05:54 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0