FW: [nmap/nmap] Npcap 0.9982 Failing! (#1677)

"Michael Steele" <[email protected]> Wed, 4 Sep 2019 19:41:00 -0400
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <[email protected]>
This is a multipart message in MIME format.

--===============7306215473017037433==
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_0001_01D56358.AEB50B30"
Content-Language: en-us

This is a multipart message in MIME format.

------=_NextPart_000_0001_01D56358.AEB50B30
Content-Type: text/plain;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable

It appears WinPcap is no longer being developed and Npcap is. Once snort =
start it fails because of the issue below.

=20

Seems there should be a better way to link Snort to the .DLL=E2=80=99s =
in memory weather using either program?

=20

Not real sure of the solution but WinPcap or Npcap should be installed =
and running prior to installing Snort.=20

=20

From: Daniel Miller <[email protected]>=20
Sent: Wednesday, September 4, 2019 6:27 PM
To: nmap/nmap <[email protected]>
Cc: mesteele101 <[email protected]>; Mention =
<[email protected]>
Subject: Re: [nmap/nmap] Npcap 0.9982 Failing! (#1677)

=20

In the final analysis, the issue is caused by a version mismatch between =
the WinPcap version of Packet.DLL that is shipped with Snort and the =
Npcap driver API that is implemented by Npcap's own Packet.DLL. The =
solution is to remove wpcap.dll and Packet.dll from the executable path =
of Snort and either install Npcap in WinPcap API-compatible mode or =
modify Snort to call SetDllDirectory appropriately to find the Npcap =
DLLs as described in the Npcap Developers' Guide =
<https://nmap.org/npcap/guide/npcap-devguide.html#npcap-feature-native> =
.

=E2=80=94
You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub =
<https://github.com/nmap/nmap/issues/1677?email_source=3Dnotifications&em=
ail_token=3DAAJWQ6RDWIX7QIQIPD2FCH3QIAYZ3A5CNFSM4IJGWHM2YY3PNVWWK3TUL52HS=
4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOD55GY7Y#issuecomment-528116863=
> , or mute the thread =
<https://github.com/notifications/unsubscribe-auth/AAJWQ6TDF5ZDAQ24CMINGM=
TQIAYZ3ANCNFSM4IJGWHMQ> .  =
<https://github.com/notifications/beacon/AAJWQ6VKGWT5PHCU642RFVDQIAYZ3A5C=
NFSM4IJGWHM2YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOD=
55GY7Y.gif>=20


------=_NextPart_000_0001_01D56358.AEB50B30
Content-Type: text/html;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta =
http-equiv=3DContent-Type content=3D"text/html; charset=3Dutf-8"><meta =
name=3DGenerator content=3D"Microsoft Word 15 (filtered medium)"><!--[if =
!mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman",serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p
	{mso-style-priority:99;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:12.0pt;
	font-family:"Times New Roman",serif;}
code
	{mso-style-priority:99;
	font-family:"Courier New";}
p.msonormal0, li.msonormal0, div.msonormal0
	{mso-style-name:msonormal;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:12.0pt;
	font-family:"Times New Roman",serif;}
span.EmailStyle20
	{mso-style-type:personal-reply;
	font-family:"Calibri",sans-serif;
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri",sans-serif;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue =
vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'=
>It appears WinPcap is no longer being developed and Npcap is. Once =
snort start it fails because of the issue below.<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'=
><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'=
>Seems there should be a better way to link Snort to the .DLL=E2=80=99s =
in memory weather using either program?<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'=
><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'=
>Not real sure of the solution but WinPcap or Npcap should be installed =
and running prior to installing Snort. <o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'=
><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><b><span =
style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif'>From:</span><=
/b><span style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif'> =
Daniel Miller &lt;[email protected]&gt; <br><b>Sent:</b> =
Wednesday, September 4, 2019 6:27 PM<br><b>To:</b> nmap/nmap =
&lt;[email protected]&gt;<br><b>Cc:</b> mesteele101 =
&lt;[email protected]&gt;; Mention =
&lt;[email protected]&gt;<br><b>Subject:</b> Re: [nmap/nmap] =
Npcap 0.9982 Failing! (#1677)<o:p></o:p></span></p><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><p>In the final analysis, the =
issue is caused by a version mismatch between the WinPcap version of =
Packet.DLL that is shipped with Snort and the Npcap driver API that is =
implemented by Npcap's own Packet.DLL. The solution is to remove =
wpcap.dll and Packet.dll from the executable path of Snort and either =
install Npcap in WinPcap API-compatible mode or modify Snort to call =
<code><span style=3D'font-size:10.0pt'>SetDllDirectory</span></code> =
appropriately to find the Npcap DLLs <a =
href=3D"https://nmap.org/npcap/guide/npcap-devguide.html#npcap-feature-na=
tive">as described in the Npcap Developers' Guide</a>.<o:p></o:p></p><p =
style=3D'-webkit-text-size-adjust:none'><span =
style=3D'color:#666666'>=E2=80=94<br>You are receiving this because you =
were mentioned.<br>Reply to this email directly, <a =
href=3D"https://github.com/nmap/nmap/issues/1677?email_source=3Dnotificat=
ions&amp;email_token=3DAAJWQ6RDWIX7QIQIPD2FCH3QIAYZ3A5CNFSM4IJGWHM2YY3PNV=
WWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOD55GY7Y#issuecommen=
t-528116863">view it on GitHub</a>, or <a =
href=3D"https://github.com/notifications/unsubscribe-auth/AAJWQ6TDF5ZDAQ2=
4CMINGMTQIAYZ3ANCNFSM4IJGWHMQ">mute the thread</a>.<img border=3D0 =
width=3D1 height=3D1 style=3D'width:.0104in;height:.0104in' =
id=3D"_x0000_i1025" =
src=3D"https://github.com/notifications/beacon/AAJWQ6VKGWT5PHCU642RFVDQIA=
YZ3A5CNFSM4IJGWHM2YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORP=
WSZGOD55GY7Y.gif"><o:p></o:p></span></p></div></body></html>
------=_NextPart_000_0001_01D56358.AEB50B30--


--===============7306215473017037433==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-devel

Please visit http://blog.snort.org for the latest news about Snort!

--===============7306215473017037433==--