ClearFoundation Tracker - ClearOS
View Issue Details
0000318ClearOSsnortpublic2011-07-12 14:182019-03-04 09:31
NickH 
 
normalminorN/A
closedfixed 
5.2-SP1 
6.2.0 
0000318: Malformed rules in default rule set
1 - malware-user-agents.rules lines 899/900. This should be one line. Delete the <cr> at the end of 899 and replace it with an "r" to correctly spell the word "reference"

2 - virus.rules lines 91/92 should be one line. Delete the <cr> at the end of 91 and replace it with a "/" or just delete the two lines as the rule is disabled anyway
No tags attached.
Issue History
2011-07-12 14:18NickHNew Issue
2011-08-16 10:31user2Statusnew => acknowledged
2012-12-14 11:53user2Note Added: 0000616
2012-12-14 11:53user2Statusacknowledged => resolved
2012-12-14 11:53user2Fixed in Version => 6.2.0
2012-12-14 11:53user2Resolutionopen => won't fix
2012-12-14 11:53user2Assigned To => user2
2012-12-14 11:53user2Statusresolved => closed
2012-12-14 12:23NickHNote Added: 0000617
2012-12-14 12:23NickHStatusclosed => feedback
2012-12-14 12:23NickHResolutionwon't fix => reopened
2018-12-14 12:11user2Statusfeedback => assigned
2018-12-14 12:11user2Assigned Touser2 => tracker
2019-03-04 09:31NickHNote Added: 0010351
2019-03-04 09:31NickHStatusassigned => closed
2019-03-04 09:31NickHAssigned Totracker =>
2019-03-04 09:31NickHResolutionreopened => fixed

Notes
(0000616)
user2   
2012-12-14 11:53   
These broken rules do not exist in ClearOS 6 or in version 5.x with the "Intrusion Protection Updates" service. Since the rules do not cause snort to fail, closing without a fix.
(0000617)
NickH   
2012-12-14 12:23   
I believe the two rules do cause snort to fail if the rule sets are enabled. They are disabled by default so you do not normally see the failure. There was a forum post http://www.clearfoundation.com/component/option,com_kunena/Itemid,232/catid,40/func,view/id,18341/limit,10/limitstart,20/#29945 [^] going onto the next page for diagnonis with this as an issue.

Those two rule sets do not exist in 6.3
(0010351)
NickH   
2019-03-04 09:31   
Problem disappeared in 6.3 where the two rules were removed upstream.