Welcome, Guest. Please login or register.
Did you miss your activation email?
Friday 15 November 2024, 05:09:54 pm

Login with username, password and session length

Visit the Official Endian Reference Manual  HERE
14255 Posts in 4377 Topics by 6515 Members
Latest Member: hulteends
Search:     Advanced search
+  EFW Support
|-+  Support
| |-+  General Support
| | |-+  How to find specific snort rule? > Solved
0 Members and 0 Guests are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: How to find specific snort rule? > Solved  (Read 7499 times)
seh2000
Full Member
***
Offline Offline

Posts: 16


« on: Wednesday 01 February 2012, 07:03:04 am »

Hi all,

I have been away from the forum on few for a long period due to .

Upgraded to the EFW 2.5.1 thanks to the team for a great job.

Now, I need to deactivate a few of the SNORT rules, but how do I find the actual rule in the rule files?
Lets say I want to deactivate this rule "[1:2002157:9] ET POLICY Skype User-Agent detected..." the in which of the files do I find this rule? Like it is not in the files 'auto/emerging-virus.rules' or in 'auto/emerging-policy.rules' 
I know 2002157 is the SNORT ID and I know I find the rule in one of the rule files, but which one?
Is there somewhere a list showing each rule in each file?

Your input is much appreciated.

BR// Steen

Oops!!!
Solved, in the example did not check the 'auto/emerging-policy.rules' file properly!
Sorry about!
Steen
Logged
Pages: [1] Go Up Print 
« previous next »
Jump to:  

Page created in 0.031 seconds with 19 queries.
Powered by SMF 1.1 RC2 | SMF © 2001-2005, Lewis Media Design by 7dana.com