Snort fails to start on rule initialization
-
Not sure if anyone else had this problem with starting snort.
ERROR: /usr/local/etc/snort/rules/ddos.rules(25) => Invalid port: [31335,35555]
Fatal Error, Quitting..Note that I havn't really gone into much detail yet on the cause of the problem (being related to the rule or snort itself).
In any case, it starts fine if I disable this rule. Just wanted to put this out there.
I've also disabled the automatic rule updates for the time being.
1.2-RELEASE
built on Sun Feb 24 17:04:58 EST 2008Snort v2.7.0.1_4
-
I had the same problem, and I've just been running without those rules. I'm guessing that this rule is responsible:
223 udp $EXTERNAL_NET any $HOME_NET [31335,35555] DDOS Trin00 Daemon to Master PONG message detected
Edit: I disabled that rule, and it starts up fine. I guess the syntax on the port specification is incorrect.