public inbox for development@lists.ipfire.org
 help / color / mirror / Atom feed
* IDS / Snort/VRT GPLv2 Community-Rules : Error parsing signature... - but I can't deactivate specific rule(s)
@ 2026-05-09 16:12 Matthias Fischer
  2026-05-11  1:04 ` Jay Lubomirski
  0 siblings, 1 reply; 4+ messages in thread
From: Matthias Fischer @ 2026-05-09 16:12 UTC (permalink / raw)
  To: IPFire: Development-List

Hi list,

IDS is running with several rulesets, no seen problems, but one set
always throws this error:

***SNIP***
[1433] <Error> -- error parsing signature "drop tcp $EXTERNAL_NET
$HTTP_PORTS -> $HOME_NET any (msg:"MALWARE-OTHER Win.Trojan.Zeus Spam
2013 dated zip/exe HTTP Response - potential malware download";
flow:to_client,established; content:"-2013.zip|0D 0A|";
fast_pattern:only; content:"-2013.zip|0D 0A|"; http_header; content:"-";
within:1; distance:-14; http_header; file_data; content:"-2013.exe";
content:"-"; within:1; distance:-14; metadata:impact_flag red, policy
balanced-ips drop, policy max-detect-ips drop, policy security-ips drop,
ruleset community, service http;
reference:url,www.virustotal.com/en/file/2eff3ee6ac7f5bf85e4ebcbe51974d0708cef666581ef1385c628233614b22c0/analysis/;
classtype:trojan-activity; sid:26470; rev:2;)" from file
/var/lib/suricata/community-community.rules at line 2581
***SNAP***

Everything is working fine - except for this error message.

So I tried to deactivate this rule - but I can't. Every time I uncheck
this rule, it gets checked again. No chance. There are others —
apparently not every rule — who also refuse to get unchecked.

Can anyone confirm?

Best
Matthias



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-05-11  8:47 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-05-09 16:12 IDS / Snort/VRT GPLv2 Community-Rules : Error parsing signature... - but I can't deactivate specific rule(s) Matthias Fischer
2026-05-11  1:04 ` Jay Lubomirski
2026-05-11  7:32   ` Matthias Fischer
2026-05-11  8:47     ` Adolf Belka

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox