Hi list,

IDS is running with several rulesets, no seen problems, but one set
always throws this error:

***SNIP***
[1433] <Error> -- error parsing signature "drop tcp $EXTERNAL_NET
$HTTP_PORTS -> $HOME_NET any (msg:"MALWARE-OTHER Win.Trojan.Zeus Spam
2013 dated zip/exe HTTP Response - potential malware download";
flow:to_client,established; content:"-2013.zip|0D 0A|";
fast_pattern:only; content:"-2013.zip|0D 0A|"; http_header; content:"-";
within:1; distance:-14; http_header; file_data; content:"-2013.exe";
content:"-"; within:1; distance:-14; metadata:impact_flag red, policy
balanced-ips drop, policy max-detect-ips drop, policy security-ips drop,
ruleset community, service http;
reference:url,www.virustotal.com/en/file/2eff3ee6ac7f5bf85e4ebcbe51974d0708cef666581ef1385c628233614b22c0/analysis/;
classtype:trojan-activity; sid:26470; rev:2;)" from file
/var/lib/suricata/community-community.rules at line 2581
***SNAP***

Everything is working fine - except for this error message.

So I tried to deactivate this rule - but I can't. Every time I uncheck
this rule, it gets checked again. No chance. There are others —
apparently not every rule — who also refuse to get unchecked.

Can anyone confirm?

Best
Matthias


Reply via email to