Snort mailing list archives

Re: Run as user?


From: Chris Green <cmg () sourcefire com>
Date: Thu, 03 Apr 2003 08:41:42 -0500

Alberto Gonzalez <albertg () wwjh net> writes:

According to the FAQ, the snort tool is supposed to be run as root. Is there any
way to run it as a regular user, ie. giving myself permission to read 
the stream through eth0?


(root@cerebro)(~) snort -?
[..snip..]

    -g <gname> Run snort gid as <gname> group (or gid) after initialization
    -u <uname> Run snort uid as <uname> user (or uid) after initialization

[..snip..]

make sure the logging directory has the proper permissions. And take in 
mind you won't be able to send a HUP signal. Check the snort-users archive 
i believe this came up awhile ago.

In Snort 2.0, it will atleast tell you that HUP isn't supported with
chroot :)
-- 
Chris Green <cmg () sourcefire com>
Laugh and the world laughs with you, snore and you sleep alone.


-------------------------------------------------------
This SF.net email is sponsored by: ValueWeb: 
Dedicated Hosting for just $79/mo with 500 GB of bandwidth! 
No other company gives more support or power for your dedicated server
http://click.atdmt.com/AFF/go/sdnxxaff00300020aff/direct/01/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: