[Snort-users] Run SNORT as different user

Sat Mar 2 04:52:03 EST 2002

According to Ralf Hildebrandt:
> On Fri, Mar 01, 2002 at 11:17:19AM -0800, spyguy703 wrote:
> > Is there a way to run snort as a user other than root?
> Yes. Check "man snort" (-u and -g option)
> Chroot is -t

There is also another way.  If you can make the device that pcap reads
from readable by a user or group other than root, then you should be 
able to run snort as that user or group.

For example, in openbsd I set my bpf device to g+rw.  This change
allows any user in the wheel group to sniff.

crw-rw----  1 root  wheel   23,   0 Mar  2 01:31 /dev/bpf0

The student help desk at my old college had the internal motto of:
"Tech Services - We Aim To Please, We Shoot To Kill" -- H. Wade Minter

