Re: [Cooker-firewall] snort
[EMAIL PROTECTED] writes: Hello, It appears that the file /etc/snort/snort.conf generated by naat is buggy. We must add the definition of 3 new variables HTTP_PORTS, ORACLE_PORTS and SHELLCODE_PORTS to allow snort to compile correctly the rule files (resp. web_cgi.rules (and associates), misc.rules and shellcode.rules). Re. package : snort-1.8.7-1mdk ok, I have updated this on the CVS. cheers, -- Florin http://www.mandrakesoft.com http://people.mandrakesoft.com/~florin/
Re: [Cooker-firewall] snort
[EMAIL PROTECTED] writes: Hello, It appears that the file /etc/snort/snort.conf generated by naat is buggy. We must add the definition of 3 new variables HTTP_PORTS, ORACLE_PORTS and SHELLCODE_PORTS to allow snort to compile correctly the rule files (resp. web_cgi.rules (and associates), misc.rules and shellcode.rules). Re. package : snort-1.8.7-1mdk Regards Marc Bethenod what version of the firewall are we talking about ? cheers, -- Florin http://www.mandrakesoft.com http://people.mandrakesoft.com/~florin/
Re: [Cooker-firewall] snort
Sorry, package snf-fr-8.2-11mdk Regards Marc Bethenod Florin [EMAIL PROTECTED] wrote: [EMAIL PROTECTED] writes: Hello, It appears that the file /etc/snort/snort.conf generated by naat is buggy. We must add the definition of 3 new variables HTTP_PORTS, ORACLE_PORTS and SHELLCODE_PORTS to allow snort to compile correctly the rule files (resp. web_cgi.rules (and associates), misc.rules and shellcode.rules). Re. package : snort-1.8.7-1mdk Regards Marc Bethenod what version of the firewall are we talking about ? cheers, -- Florin http://www.mandrakesoft.com http://people.mandrakesoft.com/~florin/ __ Your favorite stores, helpful shopping tools and great gift ideas. Experience the convenience of buying online with Shop@Netscape! http://shopnow.netscape.com/ Get your own FREE, personal Netscape Mail account today at http://webmail.netscape.com/
[Cooker-firewall] snort
Hello, It appears that the file /etc/snort/snort.conf generated by naat is buggy. We must add the definition of 3 new variables HTTP_PORTS, ORACLE_PORTS and SHELLCODE_PORTS to allow snort to compile correctly the rule files (resp. web_cgi.rules (and associates), misc.rules and shellcode.rules). Re. package : snort-1.8.7-1mdk Regards Marc Bethenod __ Your favorite stores, helpful shopping tools and great gift ideas. Experience the convenience of buying online with Shop@Netscape! http://shopnow.netscape.com/ Get your own FREE, personal Netscape Mail account today at http://webmail.netscape.com/
Re: [Cooker-firewall] SNORT STILL DOESN'T WORK
I am really upset. I sent this bug/fix in for RC1 and again for RC2, and then for the last test version and you still haven't fixed it. When installing the Firewall by default snort DOES NOT HAVE the proper permissions to the /var/log/snort directory. I was told by the Mandrake team each time that it would be fixed in the next version and I find that in the Final version the bug is still there. Once again, here is the problem. The directory /var/log/snort has permissions: drw--- and should have drwx--. Also snort needs to be the owner for /var/log/snort and the sub-files/directories. If the permissions above are not correct, snortd will abort as soon as it's started. If I sound upset it's because I am. I reported this bug and the fix for it at least three times and three times I was told it would be fixed in the next release. It never was. My company is looking at setting up our clients with this excellent firewall/intrusion detection system. How can we recommend that they buy it if it DOESN'T WORK. Hello there, you are upset ? This is understandable. Now, what version are we talking about ? I thought we've fixed that already, ages ago... make sure you have the latest version, and I'll check here too... cheers, -- Florin http://www.mandrakesoft.com
RE: [Cooker-firewall] SNORT STILL DOESN'T WORK
This is the final version that I downloaded the ISO about a week ago. When I install it on the system I am doing a complete format of the drives so I can make sure it will work for our clients. Stephen W. Thomas Network Engineer Technical Software Services [EMAIL PROTECTED] mailto:[EMAIL PROTECTED] -Original Message- From: Florin [mailto:[EMAIL PROTECTED]] Sent: Tuesday, June 19, 2001 7:26 PM To: [EMAIL PROTECTED] Subject: Re: [Cooker-firewall] SNORT STILL DOESN'T WORK I am really upset. I sent this bug/fix in for RC1 and again for RC2, and then for the last test version and you still haven't fixed it. When installing the Firewall by default snort DOES NOT HAVE the proper permissions to the /var/log/snort directory. I was told by the Mandrake team each time that it would be fixed in the next version and I find that in the Final version the bug is still there. Once again, here is the problem. The directory /var/log/snort has permissions: drw--- and should have drwx--. Also snort needs to be the owner for /var/log/snort and the sub-files/directories. If the permissions above are not correct, snortd will abort as soon as it's started. If I sound upset it's because I am. I reported this bug and the fix for it at least three times and three times I was told it would be fixed in the next release. It never was. My company is looking at setting up our clients with this excellent firewall/intrusion detection system. How can we recommend that they buy it if it DOESN'T WORK. Hello there, you are upset ? This is understandable. Now, what version are we talking about ? I thought we've fixed that already, ages ago... make sure you have the latest version, and I'll check here too... cheers, -- Florin http://www.mandrakesoft.com
RE: [Cooker-firewall] snort?
cool, thanks. -Original Message- From: philippe Libat [mailto:[EMAIL PROTECTED]] Sent: March 16, 2001 4:02 AM To: [EMAIL PROTECTED] Cc: Cooker-Firewall (E-mail) Subject: Re: [Cooker-firewall] snort? "R.I.P. Deaddog" a crit : 1. rpm -e --nodeps snort 2. install your MySQL 3. recompile snort source rpm to use newest mysql 4. install the generated snort binary rpm Abel Cheung On Thu, 15 Mar 2001, Gene Moreau wrote: What ever version shipped with Beta 4. I think Snort is 1.7.1mdk-i386 It looked like a MySQL related problem, so I installed that from the cookfire beta 4 cd 3.23.31-1 RPM's directory and it put libmysqlclient.so.10 instead on 9. looks like the Snort RPM was installed to start with. I removed it for some reason or other, but now it won't reinstall due to the same problem. what gives? do I need to go back to an older version of MySQL? it'a mistake in our spec files. if you want snort to work with new update of MySQL. you can make : [root@fire]# ln -s /usr/lib/libmysqlclient.so.10 /usr/lib/libmysqlclient.so.9 [root@fire]# ldconfig it should work! -- Philippe Libat [EMAIL PROTECTED] Linux-Mandrake http://www.linux-mandrake.com _ Think Different, Think Linux
[Cooker-firewall] snort?
what happened to snort in this version? it gives me the error snort: error in loading shared libraries: libmysqlclient.so.9: cannot open share d object file: No such file or directory what library is that from? I've tried loading a bunch, but can't seem to find the right one. Gene Moreau IT Specialist Arrista Technologies - http://www.arrista.com v: 204.489.3200 f: 204.489.8300 e: [EMAIL PROTECTED] PGP pub key: http://www3.mb.sympatico.ca/~moreaug/pgp.html
Re: [Cooker-firewall] snort?
You failed to tell us what version you are running, also you migth just have to get the srpm buecause the rpm you have might have been compiled agenst another set of librarys. -John what happened to snort in this version? it gives me the error snort: error in loading shared libraries: libmysqlclient.so.9: cannot open share d object file: No such file or directory what library is that from? I've tried loading a bunch, but can't seem to find the right one. Gene Moreau IT Specialist Arrista Technologies - http://www.arrista.com v: 204.489.3200 f: 204.489.8300 e: [EMAIL PROTECTED] PGP pub key: http://www3.mb.sympatico.ca/~moreaug/pgp.html