Errata

Snort Cookbook

Errata for Snort Cookbook

Submit your own errata for this product.

The errata list is a list of errors and their corrections that were found after the product was released. If the error was corrected in a later version or reprint the date of the correction will be displayed in the column titled "Date Corrected".

The following errata were submitted by our customers and approved as valid errors by the author or editor.

Color key: Serious technical mistake Minor technical mistake Language or formatting error Typo Question Note Update

Version Location Description Submitted By Date submitted Date corrected
Printed
Page 19
In "DISCUSSION" first paragraph

And solder in a 23pF capacitor...
Should read:
And solder in a 22pF capacitor...

Anonymous    May 22, 2015
Printed
Page 23
bottom, AirSnort entry

This is available from , but despite...
should read:
This is available from the above link, but despite...

Anonymous    May 22, 2015
Printed
Page 91
2nd-last code sample

var IRC_PORTS 6667:70001
should be:
var IRC_PORTS 6667:7001

Anonymous    May 22, 2015
Printed
Page 109
2nd-last paragraph

Immediately mark out known server, and...
should read:
Immediately mark out known servers and...

Anonymous    May 22, 2015
Printed
Page 109
2nd-last paragraph

...you can determine with what ports and to whom your talk workstation has been communicating.
should read:
...you can determine with what ports and to whom your workstation has been communicating.

Anonymous    May 22, 2015
Printed
Page 117
2nd paragraph

Replace
"Then make the payload a little more accurate, ssing the keyword within"
with
"Then make the payload a little more accurate, using the keyword within"
^

Anonymous    May 22, 2015
Printed
Page 235
first paragraph under Solution

If you want to reset any illegitimate connection attempts, use the resp keyword
from Recipe 2.n.

should read:

If you want to reset any illegitimate connection attempts, use the resp keyword
from Recipe 2.27.

Anonymous    May 22, 2015
Printed
Page 235
second paragraph under Solution

If you want to call on an external program to perform some action, use the
unixsock output plug-in from Recipe 2.n.

should read:

If you want to call on an external program to perform some action, use the
unixsock output plug-in from Recipe 2.23.

Anonymous    May 22, 2015
Printed
Page 241
6th paragraph (last)

"The unixsock alerting program from Recipe 2.n has ..."
should read
"The unixsock alerting program from Recipe 2.23 has ..."
^^

Anonymous    May 22, 2015
Printed
Page 251
middle of page, list entry for "sdrop"

Drops the packet using Iptables but does not log itreplace
should read:
Drops the packet using Iptables but does not log it

Anonymous    May 22, 2015