Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SNORT - 2.9.1 pkg v. 2.0 - (http_inspect) - SID - 120:3:1

    Scheduled Pinned Locked Moved pfSense Packages
    13 Posts 9 Posters 15.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      th3r3isnospoon
      last edited by

      Hey Guys,

      Has anyone been seeing this error on pfsense 2.0 RELEASE AMD64 with SNORT 2.9.1 pkg v. 2.0:
      (http_inspect) NO CONTENT-LENGTH OR TRANSFER-ENCODING IN HTTP RESPONSE

      FWIW, this error happened after I upgraded the SNORT package.
      If you browse to (almost) any website, this SID pops up and blocks the site.  I've tried suppressing this under the 'Suppress' tab.  I've tried disabling HTTP inspect, changing it from a 0 to a -1, nothing seems to work.

      Here's a sample log:
      snort[8714]: [120:3:1] (http_inspect) NO CONTENT-LENGTH OR TRANSFER-ENCODING IN HTTP RESPONSE [Classification: Unknown Traffic] [Priority: 3] {TCP} ...:80 -> ...:17105

      I've tried a bunch of different things in order to get this error to go away and no luck.

      Any idea on how to fix this?

      Thanks!

      -th3r3isnospoon

      1 Reply Last reply Reply Quote 0
      • RonpfSR
        RonpfS
        last edited by

        http://forum.pfsense.org/index.php/topic,41533.msg220890.html#msg220890

        2.4.5-RELEASE-p1 (amd64)
        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

        1 Reply Last reply Reply Quote 0
        • T
          th3r3isnospoon
          last edited by

          @RonpfS:

          http://forum.pfsense.org/index.php/topic,41533.msg220890.html#msg220890

          Thanks for the link.

          I actually saw that thread and read through it.  I was just able to get the -1 to work.  However, I would like this to be at 0.  I had it at 0 on the last version of the SNORT package and I never had this error before.  Just curious why this happened after the upgrade.  Was this not fully working before?

          Thanks,

          -th3r3isnospoon

          1 Reply Last reply Reply Quote 0
          • C
            Cino
            last edited by

            its not an error but an alert

            1 Reply Last reply Reply Quote 0
            • B
              bdwyer
              last edited by

              Did you try this?  suppress gen_id 120, sig_id 3

              Make sure you add your suppression list to the snort interface settings.  Change it from default to the list that has that rule.  Works fine for me, I have http_inspect set to 300

              CCNP, MCITP

              Intel Atom N550 - 2gb DDR3
              Jetway NC9C-550-LF
              Antec ISK 300-150
              HP ProCurve 1810-24
              Cisco 1841 & 2821, Cisco 3550 x3

              1 Reply Last reply Reply Quote 0
              • T
                th3r3isnospoon
                last edited by

                @Cino:

                its not an error but an alert

                Yes, that is true.  However, about 80% of websites generate this alert.

                @bdwyer:

                Did you try this?  suppress gen_id 120, sig_id 3

                Make sure you add your suppression list to the snort interface settings.  Change it from default to the list that has that rule.  Works fine for me, I have http_inspect set to 300

                Hrmm… I just disabled HTTP inspect.  I then restarted the SNORT service and all is well.  I will try this and report back.

                At this point I am just wondering why exactly this is being triggered on almost every website I visit.

                Thanks,

                -th3r3isnospoon

                1 Reply Last reply Reply Quote 0
                • N
                  NightHawk007
                  last edited by

                  @th3r3isnospoon:

                  @Cino:

                  its not an error but an alert

                  Yes, that is true.  However, about 80% of websites generate this alert.

                  @bdwyer:

                  Did you try this?  suppress gen_id 120, sig_id 3

                  Make sure you add your suppression list to the snort interface settings.  Change it from default to the list that has that rule.  Works fine for me, I have http_inspect set to 300

                  I have the same problem and it is a big problem with web surfing blocks everything

                  Hrmm… I just disabled HTTP inspect.  I then restarted the SNORT service and all is well.  I will try this and report back.

                  At this point I am just wondering why exactly this is being triggered on almost every website I visit.

                  Thanks,

                  -th3r3isnospoon

                  1 Reply Last reply Reply Quote 0
                  • I
                    ipv6kid
                    last edited by

                    I've created a video:
                    http://www.youtube.com/watch?v=uQ7OrxtiAes

                    1 Reply Last reply Reply Quote 0
                    • B
                      bdwyer
                      last edited by

                      @ipv6kid:

                      I've created a video:
                      http://www.youtube.com/watch?v=uQ7OrxtiAes

                      Nice job.  Its kind of difficult to put into words that the interface must have the suppression list added to it and that simply creating the suppression list is not enough.

                      CCNP, MCITP

                      Intel Atom N550 - 2gb DDR3
                      Jetway NC9C-550-LF
                      Antec ISK 300-150
                      HP ProCurve 1810-24
                      Cisco 1841 & 2821, Cisco 3550 x3

                      1 Reply Last reply Reply Quote 0
                      • I
                        ipv6kid
                        last edited by

                        Thanks – Can we get a SOLVED tag put in the Subject?

                        1 Reply Last reply Reply Quote 0
                        • T
                          tim.mcmanus
                          last edited by

                          @ipv6kid:

                          I've created a video:
                          http://www.youtube.com/watch?v=uQ7OrxtiAes

                          Thank you!

                          1 Reply Last reply Reply Quote 0
                          • ?
                            A Former User
                            last edited by

                            @ipv6kid:

                            I've created a video:
                            http://www.youtube.com/watch?v=uQ7OrxtiAes

                            Thank You so Far so good !!!!! ^_^

                            1 Reply Last reply Reply Quote 0
                            • Y
                              yakupm
                              last edited by

                              @ipv6kid:

                              I've created a video:
                              http://www.youtube.com/watch?v=uQ7OrxtiAes

                              Well done - little good documentation exists for pfSense.  Your video explains one small but vital aspect of pfsense/snort.

                              Yak

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.