Snort mailing list archives

Problem Starting Snort


From: "Kaplan, Andrew H." <AHKAPLAN () PARTNERS ORG>
Date: Thu, 18 Sep 2003 11:39:53 -0400

I was trying to start Snort 2.0.2, recently upgraded from version 2.0.1, and I
was confronted with the error message shown below. What configuration changes do
I need to implement?

-----Original Message-----
From: root () w0085955 mgh harvard edu
[mailto:root () w0085955 mgh harvard edu]
Sent: Thursday, September 18, 2003 11:37 AM
To: Kaplan, Andrew H.
Subject: 


Error starting Snort

Running in IDS mode Log directory = /var/log/snort Initializing Network
Interface eth0 --== Initializing Snort ==-- Initializing Output Plugins!
Decoding Ethernet on interface eth0 Parsing Rules file /etc/snort/snort.conf
+++++++++++++++++++++++++++++++++++++++++++++++++++ Initializing rule chains...
Initializing Preprocessors! Initializing Plug-ins! No arguments to frag2
directive, setting defaults to: Fragment timeout: 60 seconds Fragment memory
cap: 4194304 bytes Fragment min_ttl: 0 Fragment ttl_limit: 5 Fragment Problems:
0 Self preservation threshold: 500 Self preservation period: 90 Suspend
threshold: 1000 Suspend period: 30 Stream4 config: Stateful inspection: ACTIVE
Session statistics: INACTIVE Session timeout: 30 seconds Session memory cap:
8388608 bytes State alerts: INACTIVE Evasion alerts: INACTIVE Scan alerts:
ACTIVE Log Flushed Streams: INACTIVE MinTTL: 1 TTL Limit: 5 Async Link: 0 State
Protection: 0 Self preservation threshold: 50 Self preservation period: 90 
 Suspend threshold: 200 Suspend period: 30 Stream4_reassemble config: Server
reassembly: INACTIVE Client reassembly: ACTIVE Reassembler alerts: ACTIVE Zero
out flushed packets: INACTIVE flush_data_diff_size: 500 Ports: 21 23 25 53 80
110 111 143 513 1433 Emergency Ports: 21 23 25 53 80 110 111 143 513 1433
http_decode arguments: Unicode decoding IIS alternate Unicode decoding IIS
double encoding vuln Flip backslash to slash Include additional whitespace
separators Ports to decode http on: 80 rpc_decode arguments: Ports to decode RPC
on: 111 32771 alert_fragments: INACTIVE alert_large_fragments: ACTIVE
alert_incomplete: ACTIVE alert_multiple_requests: ACTIVE telnet_decode
arguments: Ports to decode telnet on: 21 23 25 119 command line overrides rules
file alert plugin! ERROR: Undefined variable name: (/etc/snort/misc.rules:28):
AIM_SERVERS Fatal Error, Quitting.. 256


-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: