Snort mailing list archives

Re: Verify configuration as non root


From: Russ Combs <rcombs () sourcefire com>
Date: Fri, 17 Jun 2011 11:36:05 -0400

On Thu, Jun 16, 2011 at 7:37 PM, Gilad Benjamini <gbenjamini () juniper net>wrote:

After an upgrade from 2.8 to 2.9 I tried to verify my Snort configuration
with "snort -T".
The verification failed with the message: "ERROR: Active response: can't
open ip!"

After some digging into the code it seems like the code was trying to open
a raw socket, but failing since I was not running as root.

Using "--daq dump" as a workaround seems to work.

Are root permissions really needed to verify the configuration, or is that
a bug ?


A bit pedantic, perhaps, but by design.  With 2.9.0, Snort tries to verify
as much of the configuration as possible.


Is the workaround a reasonable one, or is there a better option ?


The workaround is fine.  You can also use --daq pcap.





------------------------------------------------------------------------------
EditLive Enterprise is the world's most technically advanced content
authoring tool. Experience the power of Track Changes, Inline Image
Editing and ensure content is compliant with Accessibility Checking.
http://p.sf.net/sfu/ephox-dev2dev
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please see http://www.snort.org/docs for documentation

------------------------------------------------------------------------------
EditLive Enterprise is the world's most technically advanced content
authoring tool. Experience the power of Track Changes, Inline Image
Editing and ensure content is compliant with Accessibility Checking.
http://p.sf.net/sfu/ephox-dev2dev
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please see http://www.snort.org/docs for documentation

Current thread: