[Snort-users] Initialization Error

Saul Bosquez cygnus133 at ...125...
Tue Jan 7 13:06:02 EST 2003

When I try to get the snort running I type 'snort' and get the following

[root at ...274... snort]# snort
Initializing Output Plugins!
Log directory = /var/log/snort
Initializing Network Interface eth0
using config file ./snort.conf
Initializing Preprocessors!
Initializing Plug-ins!
Parsing Rules file ./snort.conf
Initializing rule chains...
No arguments to frag2 directive, setting defaults to:
        Fragment timeout: 60 seconds
        Fragment memory cap: 4194304 bytes
        Fragment min_ttl: 0
        Fragment ttl_limit: 5
        Fragment Problems: 0
Stream4 config:
        Stateful inspection: ACTIVE
        Session statistics: INACTIVE
        Session timeout: 30 seconds
        Session memory cap: 8388608 bytes
        State alerts: INACTIVE
        Evasion alerts: INACTIVE
        Scan alerts: ACTIVE
        Log Flushed Streams: INACTIVE
        MinTTL: 1
        TTL Limit: 5
        Async Link: 0
No arguments to stream4_reassemble, setting defaults:
        Reassemble client: ACTIVE
        Reassemble server: INACTIVE
        Reassemble ports: 21 23 25 53 80 143 110 111 513
        Reassembly alerts: ACTIVE
        Reassembly method: FAVOR_OLD
http_decode arguments:
        Unicode decoding
        IIS alternate Unicode decoding
        IIS double encoding vuln
        Flip backslash to slash
        Include additional whitespace separators
        Ports to decode http on: 80
rpc_decode arguments:
        Ports to decode RPC on: 111 32771
telnet_decode arguments:
        Ports to decode telnet on: 21 23 25 119
Conversation Config:
        KeepStats: 0
        Conv Count: 32000
        Timeout : 60
        Alert Odd?: 0
        Allowed IP Protocols: All

Portscan2 config:
        log: /var/log/snort/scan.log
        scanners_max: 3200
        targets_max: 5000
        target_limit: 5
        port_limit: 20
        timeout: 60
Can't open logfile: (null)Fatal Error, Quitting...

Could you please help?

More information about the Snort-users mailing list