Login  Register

Re: Hotfix 160210

Posted by user8446 on Mar 14, 2016; 1:39pm
URL: https://itus.accessinnov.com/Hotfix-160210-tp8p440.html

Open snort.rules and do a search for 2405000 which will bring up this rule:

drop tcp $HOME_NET any -> 50.116.1.225 22 (msg:"ET CNC Shadowserver Reported CnC Server Port 22 Group 1"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/BotCC; reference:url,www.shadowserver.org; threshold: type limit, track by_src, seconds 360, count 1; classtype:trojan-activity; flowbits:set,ET.Evil; flowbits:set,ET.BotccIP; sid:2405000; rev:4159;)

You have this rule more than once in your rulefile which is causing your error.. delete them all but one.
Running the latest OpenWrt stable release