Snort mailing list archives

Re: Bad port number error??


From: Phil Wood <cpw () lanl gov>
Date: Thu, 14 Jun 2001 16:15:10 -0600

On Thu, Jun 14, 2001 at 05:02:49PM -0400, Darrin Powell wrote:





Why do I get this error on my exploit.rules ? 







# snort -Afull -c /etc/snort/snort.conf -v

        --== Initializing Snort ==--

Initializing Network Interface eth0
Kernel filter, protocol ALL, TURBO mode (63 frames), raw packet socket
Decoding Ethernet on interface eth0
Initializing Preprocessors!
Initializing Plug-ins!
Initializating Output Plugins!

+++++++++++++++++++++++++++++++++++++++++++++++++++
Initializing rule chains...
[!] ERROR /home/dpowell/exploit.rules(29) => Bad port number: "(msg:"EXPLOIT"


If you would also post the rule itself, I'd more likely have a good answer.
I suggest you check the rule for any variables you have not initialized
in your configuration file.



Thank in advance

Darrin

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

-- 
Phil Wood, cpw () lanl gov


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: