Snort mailing list archives

non-root user cannot run snort


From: Robert Storey <y2kbug () ms25 hinet net>
Date: Tue, 27 Jan 2004 00:08:43 +0800

I'm very new at using Snort, so forgive the ignorance :-(

I want to run Snort as some other user than root. Unfortunately, I only
have success as root. As a normal user "bob", this is what happens:

  bob@sonic:~> snort -dev -l ./log
  Running in packet logging mode
  Log directory = ./log

  Initializing Network Interface eth0
  ERROR: OpenPcap() device eth0 open: 
        socket: Operation not permitted
  Fatal Error, Quitting..

The "log" file does indeed belong to user bob, so the error can't be
that.

If I repeat the operation as root, I have success:

  root@sonic:~# snort -dev -l ./log
  Running in packet logging mode
  Log directory = ./log

  Initializing Network Interface eth0

        --== Initializing Snort ==--
  Initializing Output Plugins!
  Decoding Ethernet on interface eth0

        --== Initialization Complete ==--

  -*> Snort! <*-
  Version 2.1.0 (Build 9)
  By Martin Roesch (roesch () sourcefire com, www.snort.org)



I'd be very happy to hear any suggestions.

Thanks in advance,
Robert


-------------------------------------------------------
The SF.Net email is sponsored by EclipseCon 2004
Premiere Conference on Open Tools Development and Integration
See the breadth of Eclipse activity. February 3-5 in Anaheim, CA.
http://www.eclipsecon.org/osdn
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: