Snort mailing list archives

Re: error meant


From: Matt Kettler <mkettler () evi-inc com>
Date: Wed, 11 Jun 2003 18:32:27 -0400

At 05:12 PM 6/11/2003 -0500, msmythe () armada cl wrote:
Hi everyone. I found the snort.conf file and uncomenten some things, but i
have other problem. What that means the following error when i run:
snort -dev -l log -h xxx.xxx.xxx.xxx/24 -c /etc/sonrt.conf command?
ERROR. OpenPcap( )device eth0 open:
               socket: Operation not permitted

That means you're trying to run snort while logged in as a user who is not root, and does not have extended permissions to grant him raw IO privleges.

Only root users (system administrators) can open pcap sockets on most systems.

If you want to run snort as non-root for security reasons, start it up as root and use the setuid and chroot features to drop it's privleges.




-------------------------------------------------------
This SF.NET email is sponsored by: eBay
Great deals on office technology -- on eBay now! Click here:
http://adfarm.mediaplex.com/ad/ck/711-11697-6916-5
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: