Re: Snort priv. drop and chroot before/after changing uid/gid

"Ed Borgoyn (eborgoyn)" <[email protected]>
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <D2188E71.33F1B%[email protected]>
Hello Bill,
  Thanks for the Snort improvement suggestion.  We will capture your feature request.
    Ed Borgoyn
    Cisco Snort Development Team


From: Bill Parker <[email protected]<mailto:[email protected]>>
Date: Thursday, September 10, 2015 at 5:09 PM
To: "[email protected]<mailto:[email protected]>" <[email protected]<mailto:[email protected]>>
Subject: [Snort-devel] Snort priv. drop and chroot before/after changing uid/gid

Hi All,

    I ran into an instance where having snort set it's UID/GID before dropping priv/chroot can lead to a problem creating a .PID in /var/run, due to user permissions.  I know this behavior was changed in reading the Snort Changelog, but perhaps a CLI switch could be added to write PID before changing to user/group, rather than afterwards?

Bill

p.s. - when this happens, the snort script daemon can't find the correct PID to kill is why I'm mentioning it :)

------------------------------------------------------------------------------

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/snort-devel
Archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-devel

Please visit http://blog.snort.org for the latest news about Snort!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.