From 153970064d1c93c42499a19d05dbb69fd6f78e68 Mon Sep 17 00:00:00 2001 From: MDLeom <2809763-curben@users.noreply.gitlab.com> Date: Sat, 20 Mar 2021 00:56:59 +0000 Subject: [PATCH] fix: unique sid - resolve conflict with urlhaus-filter --- src/script.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/script.sh b/src/script.sh index d250b16d..ec6c1a44 100644 --- a/src/script.sh +++ b/src/script.sh @@ -231,7 +231,7 @@ rm -f "../dist/phishing-filter-snort2.rules" \ "../dist/phishing-filter-snort3.rules" \ "../dist/phishing-filter-suricata.rules" -SID="100000001" +SID="200000001" while read DOMAIN; do SN_RULE="alert tcp \$HOME_NET any -> \$EXTERNAL_NET [80,443] (msg:\"phishing-filter phishing website detected\"; flow:established,from_client; content:\"GET\"; http_method; content:\"$DOMAIN\"; content:\"Host\"; http_header; classtype:attempted-recon; sid:$SID; rev:1;)"