Snort mailing list archives

(no subject)


From: Mike Cohen <mike.cohen () gmail com>
Date: Sat, 5 Jun 2004 10:46:19 -0700

Hello , 

Im new to snort, and Im trying to create a snort box that runs as a
non root user.
I have a user    snort   which is in the group snort_group.
I have given the snort_group ownership to the /var/log/snort 
directory and the /etc/snort directory.

whenever I try to start snort as any non root user I get the
following.  If I use root, or sudo I can start the program fine.  Im
guessing I need access to the eth0 interface or some particular file
or directory somehwere that is associated with starting sniffing on
eth0

Can someone help me with this?

Suse 9
Snort 2.12


snort@Myserver:/etc/snort> snort -c /etc/snort/snort.conf -i eth0 -u
snort -g snort_group
Running in IDS mode
Log directory = /var/log/snort

Initializing Network Interface eth0
ERROR: OpenPcap() device eth0 open: 
        socket: Operation not permitted
Fatal Error, Quitting..



any help is appreciated.

M.C.


-------------------------------------------------------
This SF.Net email is sponsored by the new InstallShield X.
From Windows to Linux, servers to mobile, InstallShield X is the one
installation-authoring solution that does it all. Learn more and
evaluate today! http://www.installshield.com/Dev2Dev/0504
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: