[Snort-users] More WinPcap 2.3 and Win2k

Chris Reid chris.reid at ...3029...
Tue Jun 18 12:05:05 EDT 2002

The reason you're seeing nothing in the interface list is also a WinPcap
problem.  In previous versions of WinPcap there is a 1K buffer, which
overflows if you have many interfaces (ie. 10+).  This has been replaced
with an 8K buffer in more recent versions of WinPcap.  The current snort
distribution should already be linking against the newer WinPcap libraries,
which should resolve this problem.  Try obtaining a more recent build of

Chris Reid

----- Original Message -----
From: "Madziarczyk, Jonathan" <than at ...3657...>
Cc: <snort-users at lists.sourceforge.net>
Sent: Tuesday, June 18, 2002 10:25 AM
Subject: [Snort-users] More WinPcap 2.3 and Win2k

> I've done a little digging and from what I can see this appears to be a
> WinPcap problem, I tried windump -D and I get the same error, so it's not
> snort specific.  Also one thing I didn't mention previously was that my
> snort -W shows what I think is nothing.  There are 4 nics in my machine
> all I see is this:
> C:\Snort>snort -W
> -*> Snort! <*-
> Version 1.8.7-MySQL-WIN32 (Build 121)
> By Martin Roesch (roesch at ...1935..., www.snort.org)
> 1.7-WIN32 Port By Michael Davis (mike at ...92...,
> www.datanerds.net/~mike)
> 1.8-WIN32 Port By Chris Reid (chris.reid at ...3029...)
> 1.8-WIN32 Compiled By Michael Steele (michaels at ...155...,
> www.siliconde
> fense.com)
>           (based on code from 1.7 port)
> Interface       Device          Description
> -------------------------------------------
> 1
> C:\Snort>
> For some reason I think this interface 1 is a loopback.
> Hope this info is of some use.
> Peace,
> Jon M
> "(Anakin) Why do I get the feeling you'll be the death of me someday"
> --ObiWan
> -----Original Message-----
> From: snort-users-admin at lists.sourceforge.net
> [mailto:snort-users-admin at lists.sourceforge.net] On Behalf Of Madziarczyk,
> Jonathan
> Sent: June 17, 2002 2:39 PM
> To: 'snort-users at lists.sourceforge.net'
> Subject: [Snort-users] WinPcap 2.3 and Win2k
> I'm setting up a new install of Snort on Win2k and I'm getting the "ERROR:
> OpenPcap( ) device open: Error opening adapter: Overlapped I/O operation
> in progress.  Fatal Error, Quitting.."
> The FAQ says this can be due to an old incompatible, or uninstalled
> of WinPcap.  I'm using 2.3 and the install appears to be running
> successfully. Is there any way I can check to make sure it is, or is this
> already a known issue?
> Thanks,
> JonM

More information about the Snort-users mailing list