Snort mailing list archives

Re: Snort 2.4.0 problem


From: Frank Knobbe <frank () knobbe us>
Date: Fri, 29 Jul 2005 11:06:31 -0500

On Fri, 2005-07-29 at 11:40 -0400, John Hally wrote:
I just compiled the 2.4 and when starting it up I get a huge amount of
errors like this in the messages file:

 

SNORT DETECTION ENGINE: Pure Not Rule 'BLEEDING-EDGE WEB-MISC cross
site scripting stealth attempt to access SHELL:' not added to
detection engine.  These rules are not supported at this time.

 

Any idea why and what 'Pure' is?  How can it not be supported at this
time if it's the latest version of snort? 2.3.3 seems to work fine.

Yeah, we screwed up yesterday. Sorry. We removed the silly content:"=";
from 6 six rule in order to speed up rule processing. But it seems that
it was put there in the first place because of the NOT-content match.

We'll fix shortly. Stay tuned.

Sorry,
Frank

Attachment: signature.asc
Description: This is a digitally signed message part


Current thread: