[Snort-users] Problem Starting Snort

Kaplan, Andrew H. AHKAPLAN at ...10063...
Thu Sep 18 08:41:05 EDT 2003

I was trying to start Snort 2.0.2, recently upgraded from version 2.0.1, and I
was confronted with the error message shown below. What configuration changes do
I need to implement?

-----Original Message-----
From: root at ...10111...
[mailto:root at ...10111...]
Sent: Thursday, September 18, 2003 11:37 AM
To: Kaplan, Andrew H.

Error starting Snort

Running in IDS mode Log directory = /var/log/snort Initializing Network
Interface eth0 --== Initializing Snort ==-- Initializing Output Plugins!
Decoding Ethernet on interface eth0 Parsing Rules file /etc/snort/snort.conf
+++++++++++++++++++++++++++++++++++++++++++++++++++ Initializing rule chains...
Initializing Preprocessors! Initializing Plug-ins! No arguments to frag2
directive, setting defaults to: Fragment timeout: 60 seconds Fragment memory
cap: 4194304 bytes Fragment min_ttl: 0 Fragment ttl_limit: 5 Fragment Problems:
0 Self preservation threshold: 500 Self preservation period: 90 Suspend
threshold: 1000 Suspend period: 30 Stream4 config: Stateful inspection: ACTIVE
Session statistics: INACTIVE Session timeout: 30 seconds Session memory cap:
8388608 bytes State alerts: INACTIVE Evasion alerts: INACTIVE Scan alerts:
ACTIVE Log Flushed Streams: INACTIVE MinTTL: 1 TTL Limit: 5 Async Link: 0 State
Protection: 0 Self preservation threshold: 50 Self preservation period: 90 
 Suspend threshold: 200 Suspend period: 30 Stream4_reassemble config: Server
reassembly: INACTIVE Client reassembly: ACTIVE Reassembler alerts: ACTIVE Zero
out flushed packets: INACTIVE flush_data_diff_size: 500 Ports: 21 23 25 53 80
110 111 143 513 1433 Emergency Ports: 21 23 25 53 80 110 111 143 513 1433
http_decode arguments: Unicode decoding IIS alternate Unicode decoding IIS
double encoding vuln Flip backslash to slash Include additional whitespace
separators Ports to decode http on: 80 rpc_decode arguments: Ports to decode RPC
on: 111 32771 alert_fragments: INACTIVE alert_large_fragments: ACTIVE
alert_incomplete: ACTIVE alert_multiple_requests: ACTIVE telnet_decode
arguments: Ports to decode telnet on: 21 23 25 119 command line overrides rules
file alert plugin! ERROR: Undefined variable name: (/etc/snort/misc.rules:28):
AIM_SERVERS Fatal Error, Quitting.. 256

More information about the Snort-users mailing list