Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Snort-users] Quick questions about recieved packets |
|---|---|
| Date: | Wed, 26 Oct 2005 15:49:17 -0500 |
Well I got my head out of my butt and realized what my major issue was. I was running Snort from the command line for testing purposes before I set it up to run at boot as a Daemon. I was using the following command line: /usr/local/bin/snort -c /etc/snort/snort.conf -i eth1 -g snort -v I kinda forgot that verbose mode will cause a ton of dropped packets like I was getting. I am now after a 10 min run without the -v getting 10% loss instead of 90%. That is something I could live with or at least close the gap on easier. I installed the new pcap library as suggested above. I am using Fedora Core 3 (yeah I know, don't say it :-P) and I downloaded the lib, un-tarred it, did the configure, make, make install dance around the fire pit. I rebooted the server. Will that pcap lib actually be used or is there something I have to change somewhere to tell FC3 not to use the pcap lib that it came with and to use my new one? On 10/26/05, Joseph Nicholson <wjnicholson@gmail.com> wrote:
I went ahead and disabled all of the rulesets to see if that made any differece. Unfortunately it made no difference at all. My next question will be if I use the pcap library suggested above, when I install it will Snort know to use it automatically or will I have to change something so Snort will know?
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-users] Is this possible answer to the problem?, Peter Rodger |
|---|---|
| Next by Date: | Re: [Snort-users] BO preproc exploit published, byte_jump |
| Previous by Thread: | Re: [Snort-users] Quick questions about recieved packets, Joseph Nicholson |
| Next by Thread: | Re: [Snort-users] Quick questions about recieved packets, sekure |
| Indexes: | [Date] [Thread] [Top] [All Lists] |