Re: [Cooker-firewall] snort

2002-08-29 Thread Florin
[EMAIL PROTECTED] writes: > Hello, > > It appears that the file /etc/snort/snort.conf generated by naat is buggy. > We must add the definition of 3 new variables HTTP_PORTS, ORACLE_PORTS and >SHELLCODE_PORTS to allow snort to compile correctly the rule files (resp. >web_cgi.rules (and associat

Re: [Cooker-firewall] snort

2002-08-20 Thread Marcbb6
Sorry, package snf-fr-8.2-11mdk Regards Marc Bethenod Florin <[EMAIL PROTECTED]> wrote: >[EMAIL PROTECTED] writes: > >> Hello, >> >> It appears that the file /etc/snort/snort.conf generated by naat is buggy. >> We must add the definition of 3 new variables HTTP_PORTS, ORACLE_PORTS and >SHELLC

Re: [Cooker-firewall] snort

2002-08-20 Thread Florin
[EMAIL PROTECTED] writes: > Hello, > > It appears that the file /etc/snort/snort.conf generated by naat is buggy. > We must add the definition of 3 new variables HTTP_PORTS, ORACLE_PORTS and >SHELLCODE_PORTS to allow snort to compile correctly the rule files (resp. >web_cgi.rules (and associat

[Cooker-firewall] snort

2002-08-19 Thread Marcbb6
Hello, It appears that the file /etc/snort/snort.conf generated by naat is buggy. We must add the definition of 3 new variables HTTP_PORTS, ORACLE_PORTS and SHELLCODE_PORTS to allow snort to compile correctly the rule files (resp. web_cgi.rules (and associates), misc.rules and shellcode.rules).

RE: [Cooker-firewall] SNORT STILL DOESN'T WORK

2001-06-19 Thread Thomas, Stephen W-CONT
AIL PROTECTED]> -Original Message- From: Florin [mailto:[EMAIL PROTECTED]] Sent: Tuesday, June 19, 2001 7:26 PM To: [EMAIL PROTECTED] Subject: Re: [Cooker-firewall] SNORT STILL DOESN'T WORK > I am really upset. I sent this bug/fix in for RC1 and again for RC2, and > then

Re: [Cooker-firewall] SNORT STILL DOESN'T WORK

2001-06-19 Thread Florin
> I am really upset. I sent this bug/fix in for RC1 and again for RC2, and > then for the last test version and you still haven't fixed it. When > installing the Firewall by default snort DOES NOT HAVE the proper > permissions to the /var/log/snort directory. I was told by the Mandrake team > e

[Cooker-firewall] SNORT STILL DOESN'T WORK

2001-06-19 Thread Thomas, Stephen W-CONT
I am really upset. I sent this bug/fix in for RC1 and again for RC2, and then for the last test version and you still haven't fixed it. When installing the Firewall by default snort DOES NOT HAVE the proper permissions to the /var/log/snort directory. I was told by the Mandrake team each tim

Re: [Cooker-firewall] Snort dies when modem redials

2001-05-09 Thread Florin Grad
Stephen Thomas <[EMAIL PROTECTED]> writes: > When running on a system with a dial up connection and the modem drops sync > and has to redial snort needs to be restarted. My ISP drops sync every 12 > hours and the modem redials. When I connect again it gives me a new IP > address. Since snort

[Cooker-firewall] Snort dies when modem redials

2001-04-26 Thread Stephen Thomas
When running on a system with a dial up connection and the modem drops sync and has to redial snort needs to be restarted. My ISP drops sync every 12 hours and the modem redials. When I connect again it gives me a new IP address. Since snort doesn't seem to reinitialize, it dies. There is so

RE: [Cooker-firewall] snort?

2001-03-16 Thread Gene Moreau
cool, thanks. -Original Message- From: philippe Libat [mailto:[EMAIL PROTECTED]] Sent: March 16, 2001 4:02 AM To: [EMAIL PROTECTED] Cc: Cooker-Firewall (E-mail) Subject: Re: [Cooker-firewall] snort? "R.I.P. Deaddog" a écrit : > > 1. rpm -e --nodeps snort >

Re: [Cooker-firewall] snort?

2001-03-16 Thread philippe Libat
"R.I.P. Deaddog" a écrit : > > 1. rpm -e --nodeps snort > > 2. install your MySQL > 3. recompile snort source rpm to use newest mysql > 4. install the generated snort binary rpm > > Abel Cheung > > On Thu, 15 Mar 2001, Gene Moreau wrote: > > > What ever version shipped with

RE: [Cooker-firewall] snort?

2001-03-16 Thread R.I.P. Deaddog
1. rpm -e --nodeps snort 2. install your MySQL 3. recompile snort source rpm to use newest mysql 4. install the generated snort binary rpm Abel Cheung On Thu, 15 Mar 2001, Gene Moreau wrote: > What ever version shipped with Beta 4. I think Snort is 1.7.1mdk-i386 > > It loo

RE: [Cooker-firewall] snort?

2001-03-15 Thread Gene Moreau
e: [Cooker-firewall] snort? You failed to tell us what version you are running, also you migth just have to get the srpm buecause the rpm you have might have been compiled agenst another set of librarys. -John > what happened to snort in this version? > > it gives me the error > >

Re: [Cooker-firewall] snort?

2001-03-15 Thread John Johnson
You failed to tell us what version you are running, also you migth just have to get the srpm buecause the rpm you have might have been compiled agenst another set of librarys. -John > what happened to snort in this version? > > it gives me the error > > snort: error in loading shared librarie

[Cooker-firewall] snort?

2001-03-15 Thread Gene Moreau
what happened to snort in this version? it gives me the error snort: error in loading shared libraries: libmysqlclient.so.9: cannot open share d object file: No such file or directory what library is that from? I've tried loading a bunch, but can't seem to find the right one. Gene Moreau I

Re: [Cooker-firewall] Snort

2001-03-09 Thread Stephen Thomas
As I said in the original message, it is working. I did go into snortd and set the ethernet port to the one I want to monitor. 1.6.3 is what came with beta 3. snort.conf does not exist in /etc or /etc/snort. The RPM that came with beta 3 uses a file that's called rules.something and calls an i

Re: [Cooker-firewall] Snort

2001-03-09 Thread John Johnson
Snort 1.7 was put into contribs if I recall.. I made the rpm for it. as for the config I would look in /etc/snort/snort.conf Also there are docs in /usr/share/doc/snort-1.7 if I recall. As for the Network card you want it to listen on go to /etc/rc.d/init.d/snortd and edit that file there is a

[Cooker-firewall] Snort

2001-03-09 Thread Stephen Thomas
OK, I've got Snort installed and I think it is runnig. It is generating logs. I have a few questions questions. 1. How can I test it? I've tried running a port scanner against it and IDSwakeup but neither one of them gernerate any log entries. 2. How do I configure it? I did go in and change

Re: [Cooker-firewall] Snort

2001-03-05 Thread philippe Libat
t; work to monitor our Internet Servers and WAN. > > -John > > - Original Message - > From: <[EMAIL PROTECTED]> > To: <[EMAIL PROTECTED]> > Sent: Friday, March 02, 2001 5:38 AM > Subject: [Cooker-firewall] Snort > > > I understand that snort is in

Re: [Cooker-firewall] Snort

2001-03-04 Thread John Johnson
gt; To: <[EMAIL PROTECTED]> Sent: Saturday, March 03, 2001 3:42 PM Subject: [Cooker-firewall] Snort > Did someone answer my question on how to configure Snort in Mandrake > Firewall? I posted it from work and won't be back there until Monday. > > Thanks, > Steve > >

Re: [Cooker-firewall] Snort

2001-03-03 Thread r j
yep. John Johnson. repeated for FYI: Reply-to:"John Johnson" <[EMAIL PROTECTED]> From:"John Johnson" <[EMAIL PROTECTED]> To:<[EMAIL PROTECTED]> Subject:Re: [Cooker-firewall] Snort Date:Fri, 2 Mar 2001 08:24:03 -0800 /etc/snort/snort

[Cooker-firewall] Snort

2001-03-03 Thread Stephen Thomas
Did someone answer my question on how to configure Snort in Mandrake Firewall? I posted it from work and won't be back there until Monday. Thanks, Steve