[Snort-users] snort 1.87beta5 still holds some fds on HUP(fixed)

Michael Scheidell scheidell at ...5171...
Sat Jun 1 09:15:41 EDT 2002


not in snort1.87beta6 yet.

it DOES stop opening additional bpf's, but it still keeps the tcp FILTER
file opened:
 lsof | grep bpf
snort     166      root    3r  VREG 116,262149         19  476837
/usr/local/share/snort/snort.bpf
snort     166      root    4r  VCHR       23,0  0t1289300    7187 /dev/bpf0
scanner# killall -HUP snort
scanner# lsof | grep bpf
snort     166      root    3r  VREG 116,262149         19  476837
/usr/local/share/snort/snort.bpf
snort     166      root    4r  VREG 116,262149         19  476837
/usr/local/share/snort/snort.bpf
snort     166      root    5r  VCHR       23,0     0t5416    7187 /dev/bpf0
scanner# snort -V

-*> Snort! <*-
Version 1.8.7beta6 (Build 121)

Michael Scheidell
SECNAP Network Security, LLC
(561) 368-9561 scheidell at ...5171...

http://www.secnap.net





More information about the Snort-users mailing list