|
Home > Archive > Snort > September 2004 > [Snort-users] Fatal error when starting snort on the sensor
You are viewing an archived Text-only version of the thread.
To view this thread in it's original format and/or if you want to reply to
this thread please [click here]
| Author |
[Snort-users] Fatal error when starting snort on the sensor
|
|
| Juan Fernandez 2004-09-22, 10:25 pm |
| This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.
------_=_NextPart_001_01C49D26.B033F610
Content-Type: text/plain;
charset="iso-8859-1"
Hi !!!
It seems that I just had to comment out this:
#preprocessor http_inspect_server: server 1.1.1.1 \
ports { 80 3128 8080 } \
flow_depth 0 \
ascii no \
but now I receive another fatal error !!! :-(
here is what I see now In /var/log/messeges:
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(30):
Duplicate classification "not-suspicious"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(31):
Duplicate classification "unknown"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(32):
Duplicate classification "bad-unknown"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(33):
Duplicate classification "attempted-recon"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(34):
Duplicate classification "successful-recon-limited"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(35):
Duplicate classification "successful-recon-largescale"found, ignoring this
line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(36):
Duplicate classification "attempted-dos"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(37):
Duplicate classification "successful-dos"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(38):
Duplicate classification "attempted-user"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(39):
Duplicate classification "unsuccessful-user"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(40):
Duplicate classification "successful-user"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(41):
Duplicate classification "attempted-admin"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(42):
Duplicate classification "successful-admin"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(46):
Duplicate classification "rpc-portmap-decode"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(47):
Duplicate classification "shellcode-detect"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(48):
Duplicate classification "string-detect"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(49):
Duplicate classification "suspicious-filename-detect"found, ignoring this
line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(50):
Duplicate classification "suspicious-login"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(51):
Duplicate classification "system-call-detect"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(52):
Duplicate classification "tcp-connection"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(53):
Duplicate classification "trojan-activity"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(54):
Duplicate classification "unusual-client-port-connection"found, ignoring
this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(55):
Duplicate classification "network-scan"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(56):
Duplicate classification "denial-of-service"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(57):
Duplicate classification "non-standard-protocol"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(58):
Duplicate classification "protocol-command-decode"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(59):
Duplicate classification "web-application-activity"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(60):
Duplicate classification "web-application-attack"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(61):
Duplicate classification "misc-activity"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(62):
Duplicate classification "misc-attack"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(63):
Duplicate classification "icmp-event"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(64):
Duplicate classification "kickass-porn"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(65):
Duplicate classification "policy-violation"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(66):
Duplicate classification "default-login-attempt"found, ignoring this line
Sep 18 00:50:17 sensjrlan snort: FATAL ERROR: Undefined variable name:
(/etc/snort/rules/bad-traffic.rules:12): EXTERNAL_NET
what to do ?
thanks very much !!!
Original Message-----
From: Esler, Joel - Contractor [mailto:joel.esler@rcert-s.XXXXXXXXX]
Sent: Friday, September 17, 2004 10:13 PM
To: Juan Fernandez
Subject: RE: [Snort-users] Fatal error when starting snort on the sensor
-----Original Message-----
From: snort-users-admin@lists.sourceforge.net
[mailto:snort-users-admin@lists.sourceforge.net] On Behalf Of Juan Fernandez
Sent: Friday, September 17, 2004 2:11 PM
To: 'snort-users@lists.sourceforge.net'
Subject: [Snort-users] Fatal error when starting snort on the sensor
Hi Guys!!
When I start snort manually from the command line /etc/init.d/snort start I
see that snort starts:
Starting Intrusion Database System: SNORT
SNORT is up and running!
On /var/log/messeges I see:
Sep 17 21:02:54 sensjrlan snort: FATAL ERROR: /etc/snort/snort.conf(458) =>
Unknown rule type: ports
In snort.conf the 458 line is this:
output database: alert, mysql, user=snort password=snort dbname=snort
host=208.170.171.199 sensor_name=sensjrlan
Mysql and acid are on another server (208.170.171.199) I checked that I can
telnet to port 3306 so what's wrong ?
Thanks very much!!!
------_=_NextPart_001_01C49D26.B033F610
Content-Type: text/html;
charset="iso-8859-1"
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML xmlns="http://www.w3.org/TR/REC-html40" xmlns:o =
"urn:schemas-microsoft-com:office:office" xmlns:w =
"urn:schemas-microsoft-com:office:word"><HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<TITLE>Message</TITLE>
<META content="MSHTML 6.00.2800.1458" name=GENERATOR>
<STYLE>@page Section1 {size: 595.3pt 841.9pt; margin: 1.0in 1.25in 1.0in 1.25in; }
P.MsoNormal {
FONT-SIZE: 12pt; MARGIN: 0in 0in 0pt; DIRECTION: rtl; FONT-FAMILY: "Times New Roman"; unicode-bidi: embed; TEXT-ALIGN: right
}
LI.MsoNormal {
FONT-SIZE: 12pt; MARGIN: 0in 0in 0pt; DIRECTION: rtl; FONT-FAMILY: "Times New Roman"; unicode-bidi: embed; TEXT-ALIGN: right
}
DIV.MsoNormal {
FONT-SIZE: 12pt; MARGIN: 0in 0in 0pt; DIRECTION: rtl; FONT-FAMILY: "Times New Roman"; unicode-bidi: embed; TEXT-ALIGN: right
}
A:link {
COLOR: blue; TEXT-DECORATION: underline
}
SPAN.MsoHyperlink {
COLOR: blue; TEXT-DECORATION: underline
}
A:visited {
COLOR: purple; TEXT-DECORATION: underline
}
SPAN.MsoHyperlinkFollowed {
COLOR: purple; TEXT-DECORATION: underline
}
SPAN.EmailStyle17 {
COLOR: windowtext; FONT-FAMILY: Arial; mso-style-type: personal-compose
}
DIV.Section1 {
page: Section1
}
</STYLE>
</HEAD>
<BODY lang=EN-US vLink=purple link=blue>
<DIV><FONT face=Arial color=#0000ff size=2></FONT> </DIV>
<DIV> </DIV>
<P dir=ltr><FONT face=Tahoma><FONT size=2><SPAN class=156252503-18092004><FONT
face=Arial color=#0000ff><FONT face=Tahoma color=#000000>Hi
!!!</FONT> </FONT></SPAN><BR></FONT></FONT></P>
<DIV><FONT face=Arial color=#0000ff size=2><SPAN class=343535922-17092004>It
seems that I just had to comment out this:</SPAN></FONT></DIV>
<DIV><FONT face=Arial color=#0000ff size=2><SPAN
class=343535922-17092004></SPAN></FONT> </DIV>
<DIV><FONT size=+0><SPAN class=343535922-17092004>
<P><FONT face=Arial color=#0000ff size=2>#preprocessor http_inspect_server:
server 1.1.1.1 \</FONT></P>
<P><FONT face=Arial color=#0000ff size=2>ports { 80 3128 8080 } \</FONT></P>
<P><FONT face=Arial color=#0000ff size=2>flow_depth 0 \</FONT></P>
<P><FONT face=Arial color=#0000ff size=2>ascii no \</FONT></P>
<P><FONT face=Arial color=#0000ff size=2></FONT> </P>
<P><SPAN class=343535922-17092004><FONT face=Arial color=#0000ff size=2>but now
I receive another fatal error !!!
:-(</FONT></SPAN></SPAN></FONT></P></DIV>
<DIV><FONT face=Arial color=#0000ff size=2><SPAN
class=343535922-17092004></SPAN></FONT> </DIV>
<DIV><FONT face=Arial color=#0000ff size=2><SPAN class=343535922-17092004>here
is what I see now In /var/log/messeges:</SPAN></FONT></DIV>
<DIV><FONT face=Arial color=#0000ff size=2><SPAN
class=343535922-17092004></SPAN></FONT> </DIV>
<DIV><FONT face=Arial color=#0000ff size=2><SPAN class=343535922-17092004>Sep 18
00:50:17 sensjrlan snort: /etc/snort/classification.config(30): Duplicate
classification "not-suspicious"found, ignoring this line <BR>Sep 18 00:50:17
sensjrlan snort: /etc/snort/classification.config(31): Duplicate classification
"unknown"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan snort:
/etc/snort/classification.config(32): Duplicate classification
"bad-unknown"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan snort:
/etc/snort/classification.config(33): Duplicate classification
"attempted-recon"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan snort:
/etc/snort/classification.config(34): Duplicate classification
"successful-recon-limited"found, ignoring this line <BR>Sep 18 00:50:17
sensjrlan snort: /etc/snort/classification.config(35): Duplicate classification
"successful-recon-largescale"found, ignoring this line <BR>Sep 18 00:50:17
sensjrlan snort: /etc/snort/classification.config(36): Duplicate classification
"attempted-dos"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan snort:
/etc/snort/classification.config(37): Duplicate classification
"successful-dos"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan snort:
/etc/snort/classification.config(38): Duplicate classification
"attempted-user"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan snort:
/etc/snort/classification.config(39): Duplicate classification
"unsuccessful-user"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan
snort: /etc/snort/classification.config(40): Duplicate classification
"successful-user"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan snort:
/etc/snort/classification.config(41): Duplicate classification
"attempted-admin"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan snort:
/etc/snort/classification.config(42): Duplicate classification
"successful-admin"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan snort:
/etc/snort/classification.config(46): Duplicate classification
"rpc-portmap-decode"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan
snort: /etc/snort/classification.config(47): Duplicate classification
"shellcode-detect"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan snort:
/etc/snort/classification.config(48): Duplicate classification
"string-detect"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan snort:
/etc/snort/classification.config(49): Duplicate classification
"suspicious-filename-detect"found, ignoring this line <BR>Sep 18 00:50:17
sensjrlan snort: /etc/snort/classification.config(50): Duplicate classification
"suspicious-login"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan snort:
/etc/snort/classification.config(51): Duplicate classification
"system-call-detect"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan
snort: /etc/snort/classification.config(52): Duplicate classification
"tcp-connection"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan snort:
/etc/snort/classification.config(53): Duplicate classification
"trojan-activity"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan snort:
/etc/snort/classification.config(54): Duplicate classification
"unusual-client-port-connection"found, ignoring this line <BR>Sep 18 00:50:17
sensjrlan snort: /etc/snort/classification.config(55): Duplicate classification
"network-scan"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan snort:
/etc/snort/classification.config(56): Duplicate classification
"denial-of-service"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan
snort: /etc/snort/classification.config(57): Duplicate classification
"non-standard-protocol"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan
snort: /etc/snort/classification.config(58): Duplicate classification
"protocol-command-decode"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan
snort: /etc/snort/classification.config(59): Duplicate classification
"web-application-activity"found, ignoring this line <BR>Sep 18 00:50:17
sensjrlan snort: /etc/snort/classification.config(60): Duplicate classification
"web-application-attack"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan
snort: /etc/snort/classification.config(61): Duplicate classification
"misc-activity"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan snort:
/etc/snort/classification.config(62): Duplicate classification
"misc-attack"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan snort:
/etc/snort/classification.config(63): Duplicate classification
"icmp-event"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan snort:
/etc/snort/classification.config(64): Duplicate classification
"kickass-porn"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan snort:
/etc/snort/classification.config(65): Duplicate classification
"policy-violation"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan snort:
/etc/snort/classification.config(66): Duplicate classification
"default-login-attempt"found, ignoring this line <BR>Sep 18 00:50:17 sensjrlan
snort: FATAL ERROR: Undefined variable name:
(/etc/snort/rules/bad-traffic.rules:12): EXTERNAL_NET</SPAN></FONT></DIV>
<DIV><FONT face=Arial color=#0000ff size=2><SPAN
class=343535922-17092004></SPAN></FONT> </DIV>
<DIV><FONT face=Arial color=#0000ff size=2><SPAN
class=343535922-17092004></SPAN></FONT> </DIV>
<DIV><FONT face=Arial color=#0000ff size=2><SPAN class=343535922-17092004>what
to do ?</SPAN></FONT></DIV>
<DIV><FONT face=Arial color=#0000ff size=2><SPAN
class=343535922-17092004></SPAN></FONT> </DIV>
<DIV><FONT face=Arial color=#0000ff size=2><SPAN class=343535922-17092004>thanks
very much !!!</SPAN></FONT></DIV>
<DIV> </DIV>
<P dir=ltr><FONT face=Tahoma size=2>Original Message-----<BR><B>From:</B> Esler,
Joel - Contractor [mailto:joel.esler@rcert-s.XXXXXXXXX]<BR><B>Sent:</B> Friday,
September 17, 2004 10:13 PM<BR><B>To:</B> Juan Fernandez<BR><B>Subject:</B> RE:
[Snort-users] Fatal error when starting snort on the sensor<BR><BR></FONT></P>
<BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px">
<DIV><SPAN class=292591220-17092004><FONT face=Arial color=#0000ff
size=2></FONT></SPAN> </DIV>
<BLOCKQUOTE style="MARGIN-RIGHT: 0px">
<DIV></DIV>
<DIV class=OutlookMessageHeader lang=en-us dir=ltr align=left><FONT
face=Tahoma size=2>-----Original Message-----<BR><B>From:</B>
snort-users-admin@lists.sourceforge.net
[mailto:snort-users-admin@lists.sourceforge.net] <B>On Behalf Of </B>Juan
Fernandez<BR><B>Sent:</B> Friday, September 17, 2004 2:11 PM<BR><B>To:</B>
'snort-users@lists.sourceforge.net'<BR><B>Subject:</B> [Snort-users] Fatal
error when starting snort on the sensor<BR><BR></FONT></DIV>
<DIV class=Section1 dir=rtl>
<P class=MsoNormal dir=ltr
style="DIRECTION: ltr; unicode-bidi: embed; TEXT-ALIGN: left"><FONT
face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Hi
Guys!! <o:p></o:p></SPAN></FONT></P>
<P class=MsoNormal dir=ltr
style="DIRECTION: ltr; unicode-bidi: embed; TEXT-ALIGN: left"><FONT
face=Arial size=2><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"><o:p> </o:p></SPAN></FONT></P>
<P class=MsoNormal dir=ltr
style="DIRECTION: ltr; unicode-bidi: embed; TEXT-ALIGN: left"><FONT
face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">When I
start snort manually from the command line /etc/init.d/snort start I see
that snort starts:<o:p></o:p></SPAN></FONT></P>
<P class=MsoNormal dir=ltr
style="DIRECTION: ltr; unicode-bidi: embed; TEXT-ALIGN: left"><FONT
face=Arial size=2><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"><o:p> </o:p></SPAN></FONT></P>
<P class=MsoNormal dir=ltr
style="DIRECTION: ltr; unicode-bidi: embed; TEXT-ALIGN: left"><FONT
face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Starting
Intrusion Database System: SNORT</SPAN></FONT><FONT face=Arial size=2><SPAN
lang=HE dir=rtl
style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"><o:p></o:p></SPAN></FONT></P>
<P class=MsoNormal dir=ltr
style="DIRECTION: ltr; unicode-bidi: embed; TEXT-ALIGN: left"><FONT
face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">SNORT is
up and running!<o:p></o:p></SPAN></FONT></P>
<P class=MsoNormal dir=ltr
style="DIRECTION: ltr; unicode-bidi: embed; TEXT-ALIGN: left"><FONT
face=Arial size=2><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"><o:p> </o:p></SPAN></FONT></P>
<P class=MsoNormal dir=ltr
style="DIRECTION: ltr; unicode-bidi: embed; TEXT-ALIGN: left"><FONT
face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">On
/var/log/messeges I see:<o:p></o:p></SPAN></FONT></P>
<P class=MsoNormal dir=ltr
style="DIRECTION: ltr; unicode-bidi: embed; TEXT-ALIGN: left"><FONT
face=Arial size=2><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"> <o:p></o:p></SPAN></FONT></P>
<P class=MsoNormal dir=ltr
style="DIRECTION: ltr; unicode-bidi: embed; TEXT-ALIGN: left"><FONT
face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Sep 17
21:02:54 sensjrlan snort: FATAL ERROR: /etc/snort/snort.conf(458) =>
Unknown rule type: ports<o:p></o:p></SPAN></FONT></P>
<P class=MsoNormal dir=ltr
style="DIRECTION: ltr; unicode-bidi: embed; TEXT-ALIGN: left"><FONT
face=Arial size=2><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"><o:p> </o:p></SPAN></FONT></P>
<P class=MsoNormal dir=ltr
style="DIRECTION: ltr; unicode-bidi: embed; TEXT-ALIGN: left"><FONT
face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">In
snort.conf the 458 line is this:<o:p></o:p></SPAN></FONT></P>
<P class=MsoNormal dir=ltr
style="DIRECTION: ltr; unicode-bidi: embed; TEXT-ALIGN: left"><FONT
face=Arial size=2><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"><o:p> </o:p></SPAN></FONT></P>
<P class=MsoNormal dir=ltr
style="DIRECTION: ltr; unicode-bidi: embed; TEXT-ALIGN: left"><FONT
face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">output
database: alert, mysql, user=snort password=snort dbname=snort
host=208.170.171.199 sensor_name=sensjrlan<o:p></o:p></SPAN></FONT></P>
<P class=MsoNormal dir=ltr
style="DIRECTION: ltr; unicode-bidi: embed; TEXT-ALIGN: left"><FONT
face=Arial size=2><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"><o:p> </o:p></SPAN></FONT></P>
<P class=MsoNormal dir=ltr
style="DIRECTION: ltr; unicode-bidi: embed; TEXT-ALIGN: left"><FONT
face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Mysql
and acid are on another server (208.170.171.199) I checked that I can telnet
to port 3306 so what's wrong ?<o:p></o:p></SPAN></FONT></P>
<P class=MsoNormal dir=ltr
style="DIRECTION: ltr; unicode-bidi: embed; TEXT-ALIGN: left"><FONT
face=Arial size=2><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"><o:p> </o:p></SPAN></FONT></P>
<P class=MsoNormal dir=ltr
style="DIRECTION: ltr; unicode-bidi: embed; TEXT-ALIGN: left"><FONT
face=Arial size=2><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Thanks
very much!!!<o:p></o:p></SPAN></FONT></P>
<P class=MsoNormal dir=rtl><FONT face=Arial size=2><SPAN dir=ltr
style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"><o:p> </o:p></SPAN></FONT></P>
<P class=MsoNormal dir=rtl><FONT face="Times New Roman" size=3><SPAN lang=HE
style="FONT-SIZE: 12pt"><o:p> </o:p></SPAN></FONT></P></DIV></BLOCKQUOTE></BLOCKQUOTE></BODY></HTML>
------_=_NextPart_001_01C49D26.B033F610--
-------------------------------------------------------
This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170
Project Admins to receive an Apple iPod Mini FREE for your judgement on
who ports your project to Linux PPC the best. Sponsored by IBM.
Deadline: Sept. 24. Go here: http://sf.net/ppc_contest.php
________________________________________
_______
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists...nfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf....ist=snort-users
| |
| Jason 2004-09-22, 10:25 pm |
| Jaun,
I suspect that your editor is inserting line breaks where they do not
belong... or some other mysterious condition exists...
Is it possible for you to use a fresh snort.conf and rules files without
having opened them in _any_ editor?
Juan Fernandez wrote:
>
>
>
> Hi !!!
>
>
> It seems that I just had to comment out this:
>
> #preprocessor http_inspect_server: server 1.1.1.1 \
>
> ports { 80 3128 8080 } \
>
> flow_depth 0 \
>
> ascii no \
>
>
>
> but now I receive another fatal error !!! :-(
>
>
> here is what I see now In /var/log/messeges:
>
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(30):
> Duplicate classification "not-suspicious"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(31):
> Duplicate classification "unknown"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(32):
> Duplicate classification "bad-unknown"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(33):
> Duplicate classification "attempted-recon"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(34):
> Duplicate classification "successful-recon-limited"found, ignoring this line
>
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(35):
> Duplicate classification "successful-recon-largescale"found, ignoring this
> line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(36):
> Duplicate classification "attempted-dos"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(37):
> Duplicate classification "successful-dos"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(38):
> Duplicate classification "attempted-user"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(39):
> Duplicate classification "unsuccessful-user"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(40):
> Duplicate classification "successful-user"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(41):
> Duplicate classification "attempted-admin"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(42):
> Duplicate classification "successful-admin"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(46):
> Duplicate classification "rpc-portmap-decode"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(47):
> Duplicate classification "shellcode-detect"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(48):
> Duplicate classification "string-detect"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(49):
> Duplicate classification "suspicious-filename-detect"found, ignoring this
> line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(50):
> Duplicate classification "suspicious-login"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(51):
> Duplicate classification "system-call-detect"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(52):
> Duplicate classification "tcp-connection"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(53):
> Duplicate classification "trojan-activity"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(54):
> Duplicate classification "unusual-client-port-connection"found, ignoring
> this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(55):
> Duplicate classification "network-scan"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(56):
> Duplicate classification "denial-of-service"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(57):
> Duplicate classification "non-standard-protocol"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(58):
> Duplicate classification "protocol-command-decode"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(59):
> Duplicate classification "web-application-activity"found, ignoring this line
>
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(60):
> Duplicate classification "web-application-attack"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(61):
> Duplicate classification "misc-activity"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(62):
> Duplicate classification "misc-attack"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(63):
> Duplicate classification "icmp-event"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(64):
> Duplicate classification "kickass-porn"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(65):
> Duplicate classification "policy-violation"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(66):
> Duplicate classification "default-login-attempt"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: FATAL ERROR: Undefined variable name:
> (/etc/snort/rules/bad-traffic.rules:12): EXTERNAL_NET
>
>
> what to do ?
>
> thanks very much !!!
>
>
> Original Message-----
> From: Esler, Joel - Contractor [mailto:joel.esler@rcert-s.XXXXXXXXX]
> Sent: Friday, September 17, 2004 10:13 PM
> To: Juan Fernandez
> Subject: RE: [Snort-users] Fatal error when starting snort on the sensor
>
>
>
>
>
> -----Original Message-----
> From: snort-users-admin@lists.sourceforge.net
> [mailto:snort-users-admin@lists.sourceforge.net] On Behalf Of Juan Fernandez
> Sent: Friday, September 17, 2004 2:11 PM
> To: 'snort-users@lists.sourceforge.net'
> Subject: [Snort-users] Fatal error when starting snort on the sensor
>
>
>
> Hi Guys!!
>
>
>
> When I start snort manually from the command line /etc/init.d/snort start I
> see that snort starts:
>
>
>
> Starting Intrusion Database System: SNORT
>
> SNORT is up and running!
>
>
>
> On /var/log/messeges I see:
>
>
>
> Sep 17 21:02:54 sensjrlan snort: FATAL ERROR: /etc/snort/snort.conf(458) =>
> Unknown rule type: ports
>
>
>
> In snort.conf the 458 line is this:
>
>
>
> output database: alert, mysql, user=snort password=snort dbname=snort
> host=208.170.171.199 sensor_name=sensjrlan
>
>
>
> mysql and acid are on another server (208.170.171.199) I checked that I can
> telnet to port 3306 so what's wrong ?
>
>
>
> Thanks very much!!!
>
>
>
>
>
>
-------------------------------------------------------
This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170
Project Admins to receive an Apple iPod Mini FREE for your judgement on
who ports your project to Linux PPC the best. Sponsored by IBM.
Deadline: Sept. 24. Go here: http://sf.net/ppc_contest.php
________________________________________
_______
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists...nfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf....ist=snort-users
| |
| sekure 2004-09-22, 10:25 pm |
| The duplicate classification is not a fatal error, but my guess is
that somewhere, somehow, you are including classification.config
twice. Look through your snort.conf and make sure it's only listed
once.
The fatal error is that your EXTERNAL_NET variable is not defined.
Defining HOME_NET and EXTERNAL_NET is one of the first things you are
supposed to do when editing snort.conf (have you read through the
comments???). Usually, you define HOME_NET as the networks you are
monitoring, and EXTERNAL_NET is defined as everything else
(!$HOME_NET)
HTH
On Sat, 18 Sep 2004 00:58:36 +0300, Juan Fernandez
<juan.fernandez@deltathree.com> wrote:
> you Were right !!!!!
>
> but know I recieve another FATAL ERROR:
>
> here is what I see in /var/log/messeges:
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(30):
> Duplicate classification "not-suspicious"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(31):
> Duplicate classification "unknown"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(32):
> Duplicate classification "bad-unknown"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(33):
> Duplicate classification "attempted-recon"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(34):
> Duplicate classification "successful-recon-limited"found, ignoring this line
>
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(35):
> Duplicate classification "successful-recon-largescale"found, ignoring this
> line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(36):
> Duplicate classification "attempted-dos"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(37):
> Duplicate classification "successful-dos"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(38):
> Duplicate classification "attempted-user"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(39):
> Duplicate classification "unsuccessful-user"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(40):
> Duplicate classification "successful-user"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(41):
> Duplicate classification "attempted-admin"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(42):
> Duplicate classification "successful-admin"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(46):
> Duplicate classification "rpc-portmap-decode"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(47):
> Duplicate classification "shellcode-detect"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(48):
> Duplicate classification "string-detect"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(49):
> Duplicate classification "suspicious-filename-detect"found, ignoring this
> line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(50):
> Duplicate classification "suspicious-login"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(51):
> Duplicate classification "system-call-detect"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(52):
> Duplicate classification "tcp-connection"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(53):
> Duplicate classification "trojan-activity"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(54):
> Duplicate classification "unusual-client-port-connection"found, ignoring
> this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(55):
> Duplicate classification "network-scan"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(56):
> Duplicate classification "denial-of-service"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(57):
> Duplicate classification "non-standard-protocol"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(58):
> Duplicate classification "protocol-command-decode"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(59):
> Duplicate classification "web-application-activity"found, ignoring this line
>
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(60):
> Duplicate classification "web-application-attack"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(61):
> Duplicate classification "misc-activity"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(62):
> Duplicate classification "misc-attack"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(63):
> Duplicate classification "icmp-event"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(64):
> Duplicate classification "kickass-porn"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(65):
> Duplicate classification "policy-violation"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(66):
> Duplicate classification "default-login-attempt"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: FATAL ERROR: Undefined variable name:
> (/etc/snort/rules/bad-traffic.rules:12): EXTERNAL_NET
>
> I really appreciate your help !!!
>
> Thanks !!!
-------------------------------------------------------
This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170
Project Admins to receive an Apple iPod Mini FREE for your judgement on
who ports your project to Linux PPC the best. Sponsored by IBM.
Deadline: Sept. 24. Go here: http://sf.net/ppc_contest.php
________________________________________
_______
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists...nfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf....ist=snort-users
| |
| Joel Esler 2004-09-22, 10:25 pm |
| You officially have the most messed up version of Snort I have ever=20
seen. You are obviously not reading any manuals or FAQ's. You are=20
just trying to get us to fix your problems. That does not help you=20
learn, and It's a good way to make alot of enemies. If I were you, I=20
would learn what you are doing and start asking intelligent questions.
J
On Sep 17, 2004, at 10:28 PM, Juan Fernandez wrote:
> =A0
> =A0
>
> Hi !!!=A0
> It seems that I just had to comment out this:
> =A0
>
> #preprocessor http_inspect_server: server 1.1.1.1 \
>
> ports { 80 3128 8080 } \
>
> flow_depth 0 \
>
> ascii no \
>
> =A0
>
> but now I receive another fatal error !!!=A0=A0 :-(
> =A0
> here is what I see now In /var/log/messeges:
> =A0
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(30):=20=
> Duplicate classification "not-suspicious"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(31):=20=
> Duplicate classification "unknown"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(32):=20=
> Duplicate classification "bad-unknown"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(33):=20=
> Duplicate classification "attempted-recon"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(34):=20=
> Duplicate classification "successful-recon-limited"found, ignoring=20
> this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(35):=20=
> Duplicate classification "successful-recon-largescale"found, ignoring=20=
> this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(36):=20=
> Duplicate classification "attempted-dos"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(37):=20=
> Duplicate classification "successful-dos"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(38):=20=
> Duplicate classification "attempted-user"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(39):=20=
> Duplicate classification "unsuccessful-user"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(40):=20=
> Duplicate classification "successful-user"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(41):=20=
> Duplicate classification "attempted-admin"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(42):=20=
> Duplicate classification "successful-admin"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(46):=20=
> Duplicate classification "rpc-portmap-decode"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(47):=20=
> Duplicate classification "shellcode-detect"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(48):=20=
> Duplicate classification "string-detect"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(49):=20=
> Duplicate classification "suspicious-filename-detect"found, ignoring=20=
> this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(50):=20=
> Duplicate classification "suspicious-login"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(51):=20=
> Duplicate classification "system-call-detect"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(52):=20=
> Duplicate classification "tcp-connection"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(53):=20=
> Duplicate classification "trojan-activity"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(54):=20=
> Duplicate classification "unusual-client-port-connection"found,=20
> ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(55):=20=
> Duplicate classification "network-scan"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(56):=20=
> Duplicate classification "denial-of-service"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(57):=20=
> Duplicate classification "non-standard-protocol"found, ignoring this=20=
> line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(58):=20=
> Duplicate classification "protocol-command-decode"found, ignoring this=20=
> line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(59):=20=
> Duplicate classification "web-application-activity"found, ignoring=20
> this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(60):=20=
> Duplicate classification "web-application-attack"found, ignoring this=20=
> line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(61):=20=
> Duplicate classification "misc-activity"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(62):=20=
> Duplicate classification "misc-attack"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(63):=20=
> Duplicate classification "icmp-event"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(64):=20=
> Duplicate classification "kickass-porn"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(65):=20=
> Duplicate classification "policy-violation"found, ignoring this line
> Sep 18 00:50:17 sensjrlan snort: /etc/snort/classification.config(66):=20=
> Duplicate classification "default-login-attempt"found, ignoring this=20=
> line
> Sep 18 00:50:17 sensjrlan snort: FATAL ERROR: Undefined variable name:=20=
> (/etc/snort/rules/bad-traffic.rules:12): EXTERNAL_NET
> =A0
> =A0
> what to do ?
> =A0
> thanks very much !!!
> =A0
>
> Original Message-----
> From: Esler, Joel - Contractor [mailto:joel.esler@rcert-s.XXXXXXXXX]
> Sent: Friday, September 17, 2004 10:13 PM
> To: Juan Fernandez
> Subject: RE: [Snort-users] Fatal error when starting snort on the=20
> sensor
>
> =A0
> -----Original Message-----
> From: snort-users-admin@lists.sourceforge.net=20
> [mailto:snort-users-admin@lists.sourceforge.net] On Behalf Of Juan=20
> Fernandez
> Sent: Friday, September 17, 2004 2:11 PM
> To: 'snort-users@lists.sourceforge.net'
> Subject: [Snort-users] Fatal error when starting snort on the sensor
>
>
> Hi Guys!!=A0=A0=A0
>
> =A0
>
> When I start snort manually from the command line /etc/init.d/snort=20
> start I see that snort starts:
>
> =A0
>
> Starting Intrusion Database System: SNORT
>
> SNORT is up and running!
>
> =A0
>
> On /var/log/messeges I see:
>
> =A0
>
> Sep 17 21:02:54 sensjrlan snort: FATAL ERROR:=20
> /etc/snort/snort.conf(458) =3D> Unknown rule type: ports
>
> =A0
>
> In snort.conf the 458 line is this:
>
> =A0
>
> output database: alert, mysql, user=3Dsnort password=3Dsnort =
dbname=3Dsnort=20
> host=3D208.170.171.199 sensor_name=3Dsensjrlan
>
> =A0
>
> mysql and acid are on another server (208.170.171.199) I checked that=20=
> I can telnet to port 3306 so what's wrong ?
>
> =A0
>
> Thanks very much!!!
>
> =A0
>
> =A0
-------------------------------------------------------
This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170
Project Admins to receive an Apple iPod Mini FREE for your judgement on
who ports your project to Linux PPC the best. Sponsored by IBM.
Deadline: Sept. 24. Go here: http://sf.net/ppc_contest.php
________________________________________
_______
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists...nfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf....ist=snort-users
|
|
|
|
|