| Main Archive Page > Month Archives > snort-users archives |
On 12/21/07, Timothy Ding <iolabs@gmail.com> wrote:
> many thanks for the reply Paul, i still don't get any results from the rule,
> could it possibly be the version of snort (ver 2.3.3) that i am using?
Yes, I think it could. I second Joel's suggestion that you upgrade to Snort 2.8. I don't subscribe to the notion that you should automatically run the latest version of anything, but 2.8(.0.1) is a big improvement in performance and functionality from 2.7, let alone 2.3. And 2.3 is old enough that you are bound to run into problems with rules being published by Sourcefire or others.
If you are unable to upgrade from 2.3 for some reason, I recommend removing the flow: tag from my suggested rule as a first troubleshooting step.
PaulM