solunatec
asked on
Installed Snort; engine working well but errors with downloaded rules;
I installed the snort package form the ports directory and everything is fine but when I downloaded the 'rules' from the website as a 'registered user' and ran the engine I get the following error for separate rules in different files; if I delete the rule another 'bad' rule shows up;???
ERROR: Warning: ./rules/web-misc.rules(533 ) => Unknown keyworkd ' http_header' in rule!
Fatal Error, Quitting...
#
there are other errors for example in the netbios.rules file ....I donwloaded and tried both the Current snapshot and the SnortV2.8 snapshot..thanks
ERROR: Warning: ./rules/web-misc.rules(533
Fatal Error, Quitting...
#
there are other errors for example in the netbios.rules file ....I donwloaded and tried both the Current snapshot and the SnortV2.8 snapshot..thanks
Which part of Snort gives error you mention?
ASKER
when Initializing and gets to the 'rule chain'
#Initializing rule chain...
(then iget the error message I originally posted)
it finds the rules/ directory and goes through each file in the rules/ directory and its some of these files that have 'keywords' which the engine does not understand?
(by the way do you know if I can output the read-out of the initialzation process to a file so that I could post it here..)
#Initializing rule chain...
(then iget the error message I originally posted)
it finds the rules/ directory and goes through each file in the rules/ directory and its some of these files that have 'keywords' which the engine does not understand?
(by the way do you know if I can output the read-out of the initialzation process to a file so that I could post it here..)
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
i just # (comment out) the two rules giving me problems;