From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4gDM1y13FMz2xp0 for ; Mon, 11 May 2026 01:04:22 +0000 (UTC) Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "R12" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4gDM1t5gSjz2xgk for ; Mon, 11 May 2026 01:04:18 +0000 (UTC) Received: from mail-pg1-x536.google.com (mail-pg1-x536.google.com [IPv6:2607:f8b0:4864:20::536]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "WR4" (verified OK)) by mail01.ipfire.org (Postfix) with ESMTPS id 4gDM1s45Ywz2TL for ; Mon, 11 May 2026 01:04:17 +0000 (UTC) Authentication-Results: mail01.ipfire.org; dkim=pass header.d=gmail.com header.s=20251104 header.b=YugIU4N2; dmarc=pass (policy=none) header.from=gmail.com; spf=pass (mail01.ipfire.org: domain of jaylubo@gmail.com designates 2607:f8b0:4864:20::536 as permitted sender) smtp.mailfrom=jaylubo@gmail.com; arc=pass ("google.com:s=arc-20240605:i=1") ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=lists.ipfire.org; s=202003rsa; t=1778461457; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references:dkim-signature; bh=mqecy2B1udHV4ymMKXW3fUzgGR253WrGtTYFstRp6mE=; b=QmBGXsrIssLrc36r6tcVilUf3sHZxQ+GtRkM2JTuDbZCEjTjj+6tYrL8GWFLDodllXCZ2d NUgHJGeNS5oeKHKaoRruLBB3g8G391g3WuUowNxtyTNMAb6TDV5xTHYYIjId7wETjQyP4D UyLGaTyvs2AoRtfb9QlRwT3UYiJIscHfvJStDc7tee9/J88ybsnF4L/3KN/5GQ1G1L/M7V z0f5O6KVkzhqKjE0DE2IFZDh6AAvbVQXB+B3puidMgh8dUFR1gG6Qeu6OSVlEaXPJ96Bc+ cE0lx7RvG7jKNEXUpXa5RgLC7jrtMCEKDOgM7PbkZqnSQydMtERoufDcYVap+Q== ARC-Authentication-Results: i=2; mail01.ipfire.org; dkim=pass header.d=gmail.com header.s=20251104 header.b=YugIU4N2; dmarc=pass (policy=none) header.from=gmail.com; spf=pass (mail01.ipfire.org: domain of jaylubo@gmail.com designates 2607:f8b0:4864:20::536 as permitted sender) smtp.mailfrom=jaylubo@gmail.com; arc=pass ("google.com:s=arc-20240605:i=1") ARC-Seal: i=2; a=rsa-sha256; d=lists.ipfire.org; s=202003rsa; cv=pass; t=1778461457; b=A19YQOR0HUesFcpy6/NVKAktrk8w3W2sYm7WjvCD9RZVGeO0BDdgFpeaaO6bu1Ckrq8x2v 5J0RQGCv0fRGh8KWxU9fXJh8o00/2RPij9hA9a8kFuaLJcAZomI9O7RpdQpVjycIl+01PX DOXvO2mD/HsmGdXLrs/Rm9QAU7+r5op17qAnK7kNeH3dqJ7d6qogKkFXNYLwRVxVuFXg93 IVkInmzQbb2hTgfmHS2F/iUcvLIqOt4rQxMabZ/nNJAQ+oA1KDuiviayRgzDm4vcpd97X4 Xi/WaewT/Kad3ZPM1ZsUucJGugDMSvSWjJdsUIzBv5fNkz2eKUQ5J+G+lTjLwQ== Received: by mail-pg1-x536.google.com with SMTP id 41be03b00d2f7-c82471904fcso1518379a12.2 for ; Sun, 10 May 2026 18:04:17 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1778461455; cv=none; d=google.com; s=arc-20240605; b=FQjVYocUFx4KZZzLzwoGagjeOpCPiqOl94YstixF0Q+CHgDg5Yw3aUYgbZKm1gD6xC cJAxgv13GeHb08lKsoXlss24sNMbUFZ+nJtDEHit4lpzTx2/gYuus2coDqwCnd7HjRV2 lU0xkr0qAhX0U35OSLKsW4BuAUOxDa5lAIfCR9IOx48tTvw1jOvtkEAUGRv6l41ngxG4 SSiubRR0Y2trdCUgEh/TJ53dbxSdn8Zza/HWDQ6PwpL578l3qCgCC8z55Sshmx9zFptV sJNLVxjqpoNxAJYMnjVGFQgcBepDjxqJ1TRouW20HK9SmiwiQed4vv7dtXlozvg2VuER jFxg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :dkim-signature; bh=mqecy2B1udHV4ymMKXW3fUzgGR253WrGtTYFstRp6mE=; fh=369tWsaCUZja16x6LI2MpI8b4TA4szvaPx87xomhnvw=; b=RHQ17dpUCj2fd0dkNzrEhVDn+viwIZ6yNTim0bJ8zh6DV7tr8WUjhnlHe5e7SA+ha4 0ZvoWXBy0Hr6qUAhYxIdW+Eo/le7okwEGGW6QxnQxSEoyYuAvTZY8wf8KrHcF4Ec3N3T lgHBWLkq9vIma8pGh8OuDGHe8sdj8m+spC/q41aNvlxx6iXBiILGp1oKLJzD/oKUWcIT ll/73Uc0pf0XGdaX8bk7t2QB+8BGUnP7jKpTdrruJZaQy1quW/lq1dvd96hc3wRK3vsE bEhQbXB7+psPYPHHReuBjX45vvZmt/aA4t9KON0w4F5IxOdaYifs5fpwkHqS+essQdDQ I4vw==; darn=lists.ipfire.org ARC-Authentication-Results: i=1; mx.google.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1778461455; x=1779066255; darn=lists.ipfire.org; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :from:to:cc:subject:date:message-id:reply-to; bh=mqecy2B1udHV4ymMKXW3fUzgGR253WrGtTYFstRp6mE=; b=YugIU4N27LXwwJBF38wFjMGetuRJ7mdXyIJhN3e8nkM7FicCOrEn88x/FAdY/Bz/t7 cSX8zMEIr/vD6mAGudv+5q2+w4vjaOZh/skktQcHAtxNWAsiBi4xeDYfeOL9FxFraqCA E0zmGvN+E+rNqdiJP5gSSLThbchXPSp1kx2pFl/i1jmlOdhxIOQGjM0cwMsHNEDgYD4Y wjEw8aRMbh1SfHTEHugPL8fU6oTq42ZjnoN5oFNmq5trtPCTtG2cfRIcsh+qJKB3AkMg N5rGrtKQ22EaIqp0H2J+6dMYgQCk5X7ZWwvxthL0nlAvTu+s6bPbjU6XSK/wOX6LNN0X lemg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1778461455; x=1779066255; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=mqecy2B1udHV4ymMKXW3fUzgGR253WrGtTYFstRp6mE=; b=D2RktglxjEjQ+TvV1IDmYbcpnYulyUMomeoz77IoReD4sGLBD2cmxDhEpmgnd+5Uyo lk6n7nfBUxcdujljlGWrBl8xEr3+7OsnJlYklrLn72Znv47HDBu+fSfy9XI8e4DSi4It 8GJkvvMQBOh/hCAzGbZApWFQGp0sI3YSyMoCQmdUKH2QleRKxeZEnWZygLWY7IOkRIY8 KB5BiFRKPnfT6A60Pcjx3M/FUbukMsJyWwVjYrhcq0UndAaaFGXJ7EqUK9Man9rUKjL1 t7L2VcVCm0hGO+PkbXzRIteBXq8OxM3biP6ouMkn/eetrya3u+nHk438fI4Zhv/g7ZCx IoRA== X-Gm-Message-State: AOJu0Yzh4IQLAvmOgkJqeyjtsECntpX9DEhSBhjDP4TD11ZU/WQWd1OT nUV1qiA/BJhhGWv3o7rPKdclnwiLN8iF69eyh8MSK5dXN4ZRhrhSgIfR7D903Z4eNrNSMwRlPno 7vWrRlPgni+8md/r7OuPCvJ9LU57K0r/UB5gZ X-Gm-Gg: Acq92OFvDzyfbNxyjaCI+hWn0OX+pxpTZ5hYa9xljjdWAzrWa+Svxf7RxFxhdGS9B7f NTr0FlELwQhT3kOwJuGgzhUfEpP7Qn/lFUENxfdTiLLdVCTGp/THSS52MxGm7LUpL4bM1f7xpeE sQygYmaqOYGuKV04X/2/v5e11qbE1DCxHruGLpO0q33I3hWxd50/UiU7eOONN4n4kXPLOXpbxpT e5ACr96U3wJbIQd18ooNHpwDshTRysa8IDEixKoJgeGWel5ttjP+YFzzQNRlO7OvE4D0mfJU7+N jHG8k/w= X-Received: by 2002:a05:6a20:3ca5:b0:39b:f8d1:a603 with SMTP id adf61e73a8af0-3aa5a931e3emr25048382637.22.1778461454550; Sun, 10 May 2026 18:04:14 -0700 (PDT) Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 References: In-Reply-To: From: Jay Lubomirski Date: Sun, 10 May 2026 21:04:03 -0400 X-Gm-Features: AVHnY4LLMh1h214deM_KejdD3K-N5k116Fl3b9tkO5lvzGhImz0ONOYqdNSEJKM Message-ID: Subject: Re: IDS / Snort/VRT GPLv2 Community-Rules : Error parsing signature... - but I can't deactivate specific rule(s) To: development@lists.ipfire.org Content-Type: multipart/alternative; boundary="0000000000003eca050651805307" X-Rspamd-Action: no action X-Spamd-Result: default: False [-8.82 / 11.00]; BAYES_HAM(-3.00)[100.00%]; R_DKIM_ALLOW(-1.68)[gmail.com:s=20251104]; IP_REPUTATION_HAM(-1.14)[asn: 15169(-0.29), country: US(-0.01), ip: 2607:f8b0:4864:20::(-0.85)]; NEURAL_HAM(-1.00)[-1.000]; ARC_ALLOW(-1.00)[google.com:s=arc-20240605:i=1]; URI_COUNT_ODD(1.00)[7]; DKIM_REPUTATION(-0.95)[-0.95250725362629]; DMARC_POLICY_ALLOW(-0.50)[gmail.com,none]; SPF_REPUTATION_HAM(-0.23)[-0.2327521473419]; R_SPF_ALLOW(-0.20)[+ip6:2607:f8b0:4864::/56]; MIME_GOOD(-0.10)[multipart/alternative,text/plain]; MX_GOOD(-0.01)[]; FROM_HAS_DN(0.00)[]; MIME_TRACE(0.00)[0:+,1:+,2:~]; ARC_SIGNED(0.00)[lists.ipfire.org:s=202003rsa:i=2]; RCPT_COUNT_ONE(0.00)[1]; FREEMAIL_ENVFROM(0.00)[gmail.com]; FREEMAIL_FROM(0.00)[gmail.com]; RCVD_TLS_LAST(0.00)[]; DKIM_TRACE(0.00)[gmail.com:+]; RCVD_IN_DNSWL_NONE(0.00)[2607:f8b0:4864:20::536:from]; PREVIOUSLY_DELIVERED(0.00)[development@lists.ipfire.org]; TO_DN_NONE(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; MID_RHS_MATCH_FROMTLD(0.00)[]; RCVD_COUNT_ONE(0.00)[1]; ASN(0.00)[asn:15169, ipnet:2607:f8b0::/32, country:US]; MISSING_XM_UA(0.00)[]; DWL_DNSWL_NONE(0.00)[gmail.com:dkim] X-Rspamd-Server: mail01.haj.ipfire.org X-Rspamd-Queue-Id: 4gDM1s45Ywz2TL --0000000000003eca050651805307 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hi Matthias, I've been using this patch to fix the can't uncheck a rule problem: # /var/ipfire/ids-functions.pl # --- ids-functions.pl.old +++ ids-functions.pl.new @@ -614,8 +614,8 @@ # Check if the Provider is set so IPS mode. if ($providers_mode{$provider} eq "IPS") { # Replacements for sourcefire rules= . - $line =3D~ s/^#\s*(?:alert|drop)(.+policy balanced-ips alert)/alert${1}/; - $line =3D~ s/^#\s*(?:alert|drop)(.+policy balanced-ips drop)/drop${1}/; + $line =3D~ s/^(?:alert|drop)(.+poli= cy balanced-ips alert)/alert${1}/; + $line =3D~ s/^(?:alert|drop)(.+poli= cy balanced-ips drop)/drop${1}/; # Replacements for generic rules. $line =3D~ s/^(#?)\s*(?:alert|drop)/${1}drop/; Can you see if that helps in your situation? Jay Lubomirski On Sat, May 9, 2026 at 12:12=E2=80=AFPM Matthias Fischer < matthias.fischer@ipfire.org> wrote: > Hi list, > > IDS is running with several rulesets, no seen problems, but one set > always throws this error: > > ***SNIP*** > [1433] -- error parsing signature "drop tcp $EXTERNAL_NET > $HTTP_PORTS -> $HOME_NET any (msg:"MALWARE-OTHER Win.Trojan.Zeus Spam > 2013 dated zip/exe HTTP Response - potential malware download"; > flow:to_client,established; content:"-2013.zip|0D 0A|"; > fast_pattern:only; content:"-2013.zip|0D 0A|"; http_header; content:"-"; > within:1; distance:-14; http_header; file_data; content:"-2013.exe"; > content:"-"; within:1; distance:-14; metadata:impact_flag red, policy > balanced-ips drop, policy max-detect-ips drop, policy security-ips drop, > ruleset community, service http; > reference:url, > www.virustotal.com/en/file/2eff3ee6ac7f5bf85e4ebcbe51974d0708cef666581ef1= 385c628233614b22c0/analysis/ > ; > classtype:trojan-activity; sid:26470; rev:2;)" from file > /var/lib/suricata/community-community.rules at line 2581 > ***SNAP*** > > Everything is working fine - except for this error message. > > So I tried to deactivate this rule - but I can't. Every time I uncheck > this rule, it gets checked again. No chance. There are others =E2=80=94 > apparently not every rule =E2=80=94 who also refuse to get unchecked. > > Can anyone confirm? > > Best > Matthias > > > --0000000000003eca050651805307 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
Hi Matthias,=C2=A0

I've = been using this patch to fix the can't uncheck a rule problem:

#= /var/ipfire/ids-functions.pl
#<= br>--- ids-functions.pl.old
+++ = ids-functions.pl.new
@@ -614,8 +614,8 @@
=C2=A0 =C2=A0 =C2=A0 =C2= =A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0 # Check if the Provider is set so IPS mode.
=C2=A0 =C2=A0 = =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0 =C2=A0 =C2=A0 =C2=A0 if ($providers_mode{$provider} eq "IPS")= {
=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0= =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 # Re= placements for sourcefire rules.
- =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0 =C2=A0 =C2=A0 =C2=A0 $line =3D~ s/^#\s*(?:alert|drop)(.+policy balanced= -ips alert)/alert${1}/;
- =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0 $line =3D~ s/^#\s*(?:alert|drop)(.+policy balanced-ips drop)/= drop${1}/;
+ =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 $= line =3D~ s/^(?:alert|drop)(.+policy balanced-ips alert)/alert${1}/;
+ = =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 $line =3D~ s/^(= ?:alert|drop)(.+policy balanced-ips drop)/drop${1}/;
=C2=A0
=C2=A0 = =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 # Replacements = for generic rules.
=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0 $line =3D~ s/^(#?)\s*(?:alert|drop)/${1}drop/;

<= div>Can you see if that helps in your situation?=C2=A0

=
Jay Lubomirski

On Sat, May 9, 2026 at 12:12= =E2=80=AFPM Matthias Fischer <matthias.fischer@ipfire.org> wrote:
Hi list,

IDS is running with several rulesets, no seen problems, but one set
always throws this error:

***SNIP***
[1433] <Error> -- error parsing signature "drop tcp $EXTERNAL_NE= T
$HTTP_PORTS -> $HOME_NET any (msg:"MALWARE-OTHER Win.Trojan.Zeus Sp= am
2013 dated zip/exe HTTP Response - potential malware download";
flow:to_client,established; content:"-2013.zip|0D 0A|";
fast_pattern:only; content:"-2013.zip|0D 0A|"; http_header; conte= nt:"-";
within:1; distance:-14; http_header; file_data; content:"-2013.exe&quo= t;;
content:"-"; within:1; distance:-14; metadata:impact_flag red, po= licy
balanced-ips drop, policy max-detect-ips drop, policy security-ips drop, ruleset community, service http;
reference:url,www.virustotal.com/en/file/2eff3ee6ac7f5bf85e4ebcbe51= 974d0708cef666581ef1385c628233614b22c0/analysis/;
classtype:trojan-activity; sid:26470; rev:2;)" from file
/var/lib/suricata/community-community.rules at line 2581
***SNAP***

Everything is working fine - except for this error message.

So I tried to deactivate this rule - but I can't. Every time I uncheck<= br> this rule, it gets checked again. No chance. There are others =E2=80=94
apparently not every rule =E2=80=94 who also refuse to get unchecked.

Can anyone confirm?

Best
Matthias


--0000000000003eca050651805307--