Re: [Snort-users] snort -c /etc/snort/snort.conf fatal error

This is a discussion on Re: [Snort-users] snort -c /etc/snort/snort.conf fatal error within the Snort forums, part of the System Security and Security Related category; If he followed the latest documentation it is. But what most likely happened is that he used the doc off ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 04-18-2004
Patrick S. Harper
 
Posts: n/a
Default Re: [Snort-users] snort -c /etc/snort/snort.conf fatal error

If he followed the latest documentation it is. But what most likely
happened is that he used the doc off the snort site which is for 2.0.2
and installed 2.1.2 instead and did not look at the updated
documentation. I have a link to it in that document and the updates are
kept on my site.

Patrick S. Harper | CISSP RHCT MCSE
www.internetsecurityguru.com
www.ntsug.org

On Sat, 2004-04-17 at 07:30, VanZee, Timothy wrote:
> Can anyone help me out? I am not getting any alerts even after running=

CIS Scanner against the box.
> I installed according to Install Guide by Patrick S. Harper on snort.or=

g/docs.
> =20
> Here is the output from snort -c /etc/snort/snort.conf
> =20
>=20
> ################################################## ####
> =20
> # snort -c /etc/snort/snort.conf
> Running in IDS mode
> Log directory =3D /var/log/snort
> Initializing Network Interface eth0
> --=3D=3D Initializing Snort =3D=3D--
> Initializing Output Plugins!
> Decoding Ethernet on interface eth0
> Initializing Preprocessors!
> Initializing Plug-ins!
> Parsing Rules file /etc/snort/snort.conf
> ++++++++++++++++++++++++++++++++++++++++++++++++++ +
> Initializing rule chains...
> ,-----------[Flow Config]----------------------
> | Stats Interval: 0
> | Hash Method: 2
> | Memcap: 10485760
> | Rows : 4099
> | Overhead Bytes: 16400(%0.16)
> `----------------------------------------------
> No arguments to frag2 directive, setting defaults to:
> Fragment timeout: 60 seconds
> Fragment memory cap: 4194304 bytes
> Fragment min_ttl: 0
> Fragment ttl_limit: 5
> Fragment Problems: 0
> Self preservation threshold: 500
> Self preservation period: 90
> Suspend threshold: 1000
> Suspend period: 30
> Stream4 config:
> Stateful inspection: ACTIVE
> Session statistics: INACTIVE
> Session timeout: 30 seconds
> Session memory cap: 8388608 bytes
> State alerts: INACTIVE
> Evasion alerts: INACTIVE
> Scan alerts: INACTIVE
> Log Flushed Streams: INACTIVE
> MinTTL: 1
> TTL Limit: 5
> Async Link: 0
> State Protection: 0
> Self preservation threshold: 50
> Self preservation period: 90
> Suspend threshold: 200
> Suspend period: 30
> Stream4_reassemble config:
> Server reassembly: INACTIVE
> Client reassembly: ACTIVE
> Reassembler alerts: ACTIVE
> Zero out flushed packets: INACTIVE
> flush_data_diff_size: 500
> Ports: 21 23 25 53 80 110 111 143 513 1433
> Emergency Ports: 21 23 25 53 80 110 111 143 513 1433
> ERROR: /etc/snort/snort.conf(285) =3D> Invalid file name for IIS Unicod=

e Map file.
> Fatal Error, Quitting..
>=20
> =20
>=20
>=20
> ################################################## ####
> =20
>=20
> Here are lines 284 and 285 from my snort.conf
> =20
> ###############
> =20
> preprocessor http_inspect: global \
> iis_unicode_map unicode.map 1252
>=20
> ###############
> =20
>=20
>=20
> Thanks for your help as I'm new to snort.
> =20
>=20
> =D3=86+=12=17^=E9=9A=8AX'u =13=0B{Nh&Zx=1BnjZkz=C7=A7[6Q=CF=AD"ujwB=10=1F=

=19=D3=A2^r=19=E8=96=88"zyzb=07g=D6=A6z{Zh+-zf)=DA=B6*'=1Bmig&'=D7=8Ee?=C7=
=ABf)+-Jz+z+-(=1E~{=DE=B4j-bDK!jx=1E=C7=ABb{(=EC=B9=BB=1C&=1BmXy+zlX)=DF=A3=
'=C7=AB)+-j!i=0Fz+k ^(v*=E9=86=9D+-
--=20







-------------------------------------------------------
This SF.Net email is sponsored by: IBM Linux Tutorials
Free Linux tutorial presented by Daniel Robbins, President and CEO of
GenToo technologies. Learn everything from fundamentals to system
administration.http://ads.osdn.com/?ad_id=1470&alloc_id=3638&op=click
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 08:37 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0