Snort mailing list archives

Re: Broken snort rule


From: Matt Jonkman <jonkman () jonkmans com>
Date: Tue, 07 Oct 2008 11:11:40 -0400

Yes, it would. But we used to rely on an error report from snort. Now it
just ignores and goes on....

So no real good automated way to do so. There was talk about a switch to
have snort exit on an error. Any traction with that?

If you have a good automated way we can use I'd love to hear it.

Matt

Brian Caswell wrote:
On Tue, Oct 7, 2008 at 9:37 AM, Matt Jonkman <jonkman () jonkmans com
<mailto:jonkman () jonkmans com>> wrote:

    Thats an issue for emerging-sigs, but thanks for reporting it.

    Script error not watching for an even number of IPs. Fixed up, can you
    pull again and retest for me?


Perhaps it would be a good idea to ... I donno, test the rules before
releasing them?

Brian 

-- 
--------------------------------------------
Matthew Jonkman
Emerging Threats
Phone 765-429-0398
Fax 312-264-0205
http://www.emergingthreats.net
--------------------------------------------

PGP: http://www.jonkmans.com/mattjonkman.asc



-------------------------------------------------------------------------
This SF.Net email is sponsored by the Moblin Your Move Developer's challenge
Build the coolest Linux based applications with Moblin SDK & win great prizes
Grand prize is a trip for two to an Open Source event anywhere in the world
http://moblin-contest.org/redirect.php?banner_id=100&url=/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: