Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-users] corrupt table problem with snort, mysql, acid and ssh setup |
|---|---|
| Date: | Thu, 27 Jan 2005 14:56:28 +0000 |
I'm remotely administering a fedora 2 snort box via ssh. running snort with snort -c /etc.snort/snort.conf is fine - that is everything is logged to tables and shows in acid. But if i leave it running for over about a minute it buggers up. I lose my ssh and acid/apache service. I then have to get a guy from down the road to go and restart the thing for me. When I restart it i get this error message in acid: database: mysql_error: Got error 127 from table handler But nothing in mysqld.log This box is checking quite alot of traffic and i have minimised the rules to check against. when i run it for about 30 seconds it will not crash ssh or acid and acid can read the tables but everytime i do myisamchk afterwards i get : myisamchk: warning: 1 clients is using or hasn't closed the table properly MyISAM-table '/var/lib/mysql/snort/acid_ip_cache.MYI' is usable but should be fixed myisamchk: error: Size of datafile is: 0 Should be: 4011 myisamchk: error: Found key at page 2048 that points to record outside datafile MyISAM-table '/var/lib/mysql/snort/event.MYI' is corrupted Fix it using switch "-r" or "-o" myisamchk: error: Size of datafile is: 0 Should be: 6112 myisamchk: error: Found key at page 2048 that points to record outside datafile MyISAM-table '/var/lib/mysql/snort/iphdr.MYI' is corrupted Fix it using switch "-r" or "-o" There are similar errors for most tables not just the 3 here. I don't think the guy up the road will go and restart it for me again so would appreciate any help. Could this be reaching maximum table cache or memory of some sort so not closing the tables properly? I can myisamchk recover tables and it will be fine but i'd like to run snort for longer and not have to worry about losing my remote connection. ------------------------------------------------------- This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting Tool for open source databases. Create drag-&-drop reports. Save time by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc. Download a FREE copy at http://www.intelliview.com/go/osdn_nl _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: [Snort-users] TCP Portsweep and TCP Portscan, Alex Butcher, ISC/ISYS |
|---|---|
| Next by Date: | [Snort-users] ACID Problems (here's your fix it), Joel Esler |
| Previous by Thread: | RE: [Snort-users] TCP Portsweep and TCP Portscan, Alex Butcher, ISC/ISYS |
| Next by Thread: | [Snort-users] corrupt table problem with snort, mysql, acid and ssh setup, VAUGHAN MOSELEY |
| Indexes: | [Date] [Thread] [Top] [All Lists] |