Re: Hotfix 160210
Posted by
user8446 on
Mar 14, 2016; 1:39pm
URL: https://itus.accessinnov.com/Hotfix-160210-tp8p440.html
Open snort.rules and do a search for 2405000 which will bring up this rule:
drop tcp $HOME_NET any -> 50.116.1.225 22 (msg:"ET CNC Shadowserver Reported CnC Server Port 22 Group 1"; flags:S; reference:url,doc.emergingthreats.net/bin/view/Main/BotCC; reference:url,www.shadowserver.org; threshold: type limit, track by_src, seconds 360, count 1; classtype:trojan-activity; flowbits:set,ET.Evil; flowbits:set,ET.BotccIP; sid:2405000; rev:4159;)
You have this rule more than once in your rulefile which is causing your error.. delete them all but one.
Running the latest OpenWrt stable release