Snort mailing list archives

Re: Run SNORT as different user


From: Fyodor <fygrave () tigerteam net>
Date: Sat, 2 Mar 2002 20:29:31 +0700

Brian <bmc () snort org> spoke:
Chroot is -t

There is also another way.  If you can make the device that pcap reads
from readable by a user or group other than root, then you should be 
able to run snort as that user or group.

For example, in openbsd I set my bpf device to g+rw.  This change
allows any user in the wheel group to sniff.

crw-rw----  1 root  wheel   23,   0 Mar  2 01:31 /dev/bpf0


Although for the moment such features as 'flexresp' and the similar
(which require root access to initialize) will not work. I believe these
will be fixed with snort2x design, as for now... ;-) (it could be
patched but won't look nice, and could cause some other probs with file
perms and stuff)


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: