Snort mailing list archives

Re: Snort 2.9.0.2 to be released


From: "Randal T. Rioux" <randy () procyonlabs com>
Date: Sun, 05 Dec 2010 01:02:23 -0500

On 12/01/2010 08:32 AM, Joel Esler wrote:
Randal,

Please refresh me with the problem with OpenBSD and I'll see if there
is a bug for it/create a bug for it.

If you want to email me onlist or off, either way.

*sigh*

I shall go over it again.

# snort -c /etc/snort/etc/snort.conf -i bge1
Running in IDS mode

        --== Initializing Snort ==--
Initializing Output Plugins!
Initializing Preprocessors!
Initializing Plug-ins!
Parsing Rules file "/etc/snort/etc/snort.conf"
PortVar 'HTTP_PORTS' defined :  [ 80 311 591 593 901 1220 1414 1830 2301
2381 2809 3128 3702 5250 7001 7777 7779 8000 8008 8028 8080 8088 8118
8123 8180 8243 8280 8888 9090:9091 9443 9999 11371 ]
PortVar 'SHELLCODE_PORTS' defined :  [ 0:79 81:65535 ]
PortVar 'ORACLE_PORTS' defined :  [ 1024:65535 ]
PortVar 'SSH_PORTS' defined :  [ 22 ]
Detection:
   Search-Method = AC-Full-Q
    Split Any/Any group = enabled
    Search-Method-Optimizations = enabled
    Maximum pattern length = 20
ERROR: parser.c(5244) Could not stat dynamic module path
"/usr/local/lib/snort_dynamicengine/libsf_engine.so": No such file or
directory.
Fatal Error, Quitting..

And...

# find / | grep libsf_engine
/usr/local/lib/snort_dynamicengine/libsf_engine.la
/usr/local/lib/snort_dynamicengine/libsf_engine.a
/usr/src/snort-2.9.0.2/src/dynamic-plugins/sf_engine/.libs/libsf_engine.a
/usr/src/snort-2.9.0.2/src/dynamic-plugins/sf_engine/.libs/libsf_engine.lai
/usr/src/snort-2.9.0.2/src/dynamic-plugins/sf_engine/.libs/libsf_engine.la
/usr/src/snort-2.9.0.2/src/dynamic-plugins/sf_engine/libsf_engine.la

Snort 2.9.0.2 built as follows:

# ./configure --enable-reload --enable-ppm --enable-zlib \
  --enable-dynamicplugin \
  --enable-perfprofiling \
  --with-libpcap-includes=/usr/local/include \
  --with-libpcap-libraries=/usr/local/lib \
  --with-dnet-includes=/usr/local/include \
  --with-dnet-libraries=/usr/local/lib \
  --with-daq-includes=/usr/local/include \
  --with-daq-libraries=/usr/local/lib
# make && make install

------------------------------------------------------------------------------
What happens now with your Lotus Notes apps - do you make another costly 
upgrade, or settle for being marooned without product support? Time to move
off Lotus Notes and onto the cloud with Force.com, apps are easier to build,
use, and manage than apps on traditional platforms. Sign up for the Lotus 
Notes Migration Kit to learn more. http://p.sf.net/sfu/salesforce-d2d
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: