Snort mailing list archives

Snort for Windows with FlexResp/FlexResp2


From: "Doug Potter" <dpotter () newportconsulting com>
Date: Thu, 15 Apr 2010 11:04:28 -0700


I cannot seem to make flexresp work. 

LibnetNT.dll is sitting in the Bin directory with Snort.exe. But the rule: 
alert tcp any any -> any any (react: block; msg: "Ping with TTL=100";
sid:1000001;) 



yields 


Unable to open the driver, Error Code : 14 
ERROR: Cannot open raw socket for libnet, exiting... 

but the rule: 
alert tcp any any -> any any (msg: "Ping with TTL=100"; sid:1000001;) 
seems to work (at least Snort runs without errors). 

Any help or ideas?

 

_______________________________________________

dougmarti

        

 

------------------------------------------------------------------------------
Download Intel&#174; Parallel Studio Eval
Try the new software tools for yourself. Speed compiling, find bugs
proactively, and fine-tune applications for parallel performance.
See why Intel Parallel Studio got high marks during beta.
http://p.sf.net/sfu/intel-sw-dev
_______________________________________________
Snort-devel mailing list
Snort-devel () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-devel

Current thread: