[Snort-users] enable to open file

William K. Hardeman wont-i at ...1878...
Mon Apr 23 12:19:20 EDT 2001


Filippo,

I had the same problems this weekend when I was setting mine up for the 
first time. What I discovered is that, if the rules file(s) don't live in 
the same directory as the snort.conf file, you have to use the full path to 
the rules file when you 'include' them. For example, include 
/etc/snort/exploits.rules to get the exploits file, assuming it lives in 
the /etc/snort directory.

Hope this helps,
Will

--On Monday, 23 April, 2001 17:32 +0200 Puppy <balyfix at ...1877...> wrote:

> Hello all,
> I'm a beginnner and i have a little problem, i can 't run snort as ids.
> i have redhat 6.2 and when i thrown this command
> ./snort -d -h 10.1.1.0/24 -l ./log -c snort.conf
> it say to me that it is enable to open rules file : webcgi-lib.
> Later i try with scan-lib and so on, i download exploits.rules and i put
> it in snort.conf but nothing...
> The ownership of those files are ok, because i can read and write.
> Thanks for help
> bye
> --Filippo
>
>
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> http://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users
>



----------------------------------------------------------------------------
William K. Hardeman
wont-i at ...1878...
http://www.wkh.org

Always listen to experts. They'll tell you what can't be done and why. Then
do it.
--Robert A. Heinlein




More information about the Snort-users mailing list