Vulnerability Development mailing list archives

Re: [Snort-users] Re: snort crash ...


From: Fyodor <fygrave () TIGERTEAM NET>
Date: Thu, 3 Aug 2000 04:48:58 +0700

~ :> Marty  has fixed some issues  with icmp handling as well and these have
~ :> been integrated into version 1.6.3. I am currently trying to integrate
~ :> those fixes into current version as well, and it should show up in cvs
~ :> tree as soon as I am done.
~ :>
~ :
~ :sorry for the crosspost... i am still unclear as to why snort 1.6.3 needs
~ :to open a raw socket at all... regardless of its lack of igm usage...
~ :

 Raw socket? it's only needed if you use flexresp feature (which is not
enabled by default) and is used to spoof `rst' or `icmp portunreach'
packets, otherwise we use lipcap routines to read the data from datalink.


if that helps..


Current thread: