[Snort-users] Running as unprivileged

Borja Marcos borjamar at ...778...
Thu Apr 19 16:07:55 EDT 2001


On Thursday 19 April 2001 18:31, you wrote:
> I am running snort as an unprivileged user and have found that the logs are
> still owned by root with 600 privileges.
>
> Is there a way to change this in the config file?

	Whenever I compile Snort for FreeBSD, I edit main() so that Snort doesn't 
abort when it is not run as root. In FreeBSD Snort only needs to have access 
to /dev/bpf. Running it as a member of a group with access to /dev/bpf? is 
enough.



	Borja.




More information about the Snort-users mailing list