Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Snort-users] Snort 2.3.0 Final released! |
|---|---|
| Date: | Wed, 26 Jan 2005 10:45:59 -0600 |
On Wed, 2005-01-26 at 11:04 +0200, Nerijus Krukauskas wrote:
Well, fixes for these two (I'm just guessing) broke the way the comments are handled in threshold/suppress configs. I'm used to put a short comment after threshold/suppress command in threshold.conf. That way I know why I've put it there. E.g. suppress gen_id 1, sig_id 3003, track by_src, ip x.y.z.w # hostname (MBSA/AV scans) snort-2.3.0 now barfs on me because of the slash (/) in comment. If I change it to dash (-), then it parses the command without errors. Am I not supposed to put comments this way or is this a small bug?
Same thing happened to me. I send in a patch which apparently didn't make it into the release. It's attached to this email. With it, you can patch sfthreshold.c and continue using slashes in comments in threshold.conf. Note: Slashes elsewhere may still break things. This issue should be fixed centrally in the parser. My patch only addresses the parsing for threshold.conf. Regards, Frank
comment-patch
Description: Text document
signature.asc
Description: This is a digitally signed message part
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Snort-users] Windows Logon Failures, kimhick |
|---|---|
| Next by Date: | Re: [Snort-users] Alerts, Bill Parker |
| Previous by Thread: | Re: [Snort-users] Snort 2.3.0 Final released!, Nerijus Krukauskas |
| Next by Thread: | [Snort-users] A New White Paper - Baseline Analysis of Security Data, Orit Vidas |
| Indexes: | [Date] [Thread] [Top] [All Lists] |