Home page logo

snort logo Snort mailing list archives

Re: Assistance with Blacklist
From: waldo kitty <wkitty42 () windstream net>
Date: Tue, 09 Apr 2013 12:44:41 -0400

On 4/9/2013 10:30, Hannibal S. Jackson wrote:
I'm getting ERROR: c:\snort\rules\black_list.rules (4) Invalid configuration

The only thing I have in my black_list.rules file is this:

# This is my black_list.rules file for www.facebook.com

this is not a valid network address or CIDR mask... the address is a 
workstation/server address, though... you need to use a proper network address 
and CIDR mask...

in this case, the facebook network range is - so the 
proper mask would be

IP Address        :
Address Class     : Classless /18
Network Address   :

Subnet Address    :
Subnet Mask       :
Subnet bit mask   : nnnnnnnn.nnnnnnnn.nnhhhhhh.hhhhhhhh
Subnet Bits       : 18
Host Bits         : 14
Number of Subnets : 1
Hosts per Subnet  : 16382

Subnet            :
Mask              :
Subnet Size       : 16382 Hosts
Host Range        :  to
Broadcast         :

Precog is a next-generation analytics platform capable of advanced
analytics on semi-structured data. The platform includes APIs for building
apps and a phenomenal toolset for data science. Developers can use
our toolset for easy data analysis & visualization. Get a free account!
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:

Please visit http://blog.snort.org to stay current on all the latest Snort news!

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]