FW: [nmap/nmap] Npcap 0.9982 Failing! (#1677)
"Michael Steele" <[email protected]> Wed, 4 Sep 2019 19:41:00 -0400
| Newsgroups | gmane.comp.security.ids.snort.devel |
|---|---|
| Message-ID | <[email protected]> |
This is a multipart message in MIME format. --===============7306215473017037433== Content-Type: multipart/alternative; boundary="----=_NextPart_000_0001_01D56358.AEB50B30" Content-Language: en-us This is a multipart message in MIME format. ------=_NextPart_000_0001_01D56358.AEB50B30 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable It appears WinPcap is no longer being developed and Npcap is. Once snort = start it fails because of the issue below. =20 Seems there should be a better way to link Snort to the .DLL=E2=80=99s = in memory weather using either program? =20 Not real sure of the solution but WinPcap or Npcap should be installed = and running prior to installing Snort.=20 =20 From: Daniel Miller <[email protected]>=20 Sent: Wednesday, September 4, 2019 6:27 PM To: nmap/nmap <[email protected]> Cc: mesteele101 <[email protected]>; Mention = <[email protected]> Subject: Re: [nmap/nmap] Npcap 0.9982 Failing! (#1677) =20 In the final analysis, the issue is caused by a version mismatch between = the WinPcap version of Packet.DLL that is shipped with Snort and the = Npcap driver API that is implemented by Npcap's own Packet.DLL. The = solution is to remove wpcap.dll and Packet.dll from the executable path = of Snort and either install Npcap in WinPcap API-compatible mode or = modify Snort to call SetDllDirectory appropriately to find the Npcap = DLLs as described in the Npcap Developers' Guide = <https://nmap.org/npcap/guide/npcap-devguide.html#npcap-feature-native> = . =E2=80=94 You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub = <https://github.com/nmap/nmap/issues/1677?email_source=3Dnotifications&em= ail_token=3DAAJWQ6RDWIX7QIQIPD2FCH3QIAYZ3A5CNFSM4IJGWHM2YY3PNVWWK3TUL52HS= 4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOD55GY7Y#issuecomment-528116863= > , or mute the thread = <https://github.com/notifications/unsubscribe-auth/AAJWQ6TDF5ZDAQ24CMINGM= TQIAYZ3ANCNFSM4IJGWHMQ> . = <https://github.com/notifications/beacon/AAJWQ6VKGWT5PHCU642RFVDQIAYZ3A5C= NFSM4IJGWHM2YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOD= 55GY7Y.gif>=20 ------=_NextPart_000_0001_01D56358.AEB50B30 Content-Type: text/html; charset="utf-8" Content-Transfer-Encoding: quoted-printable <html xmlns:v=3D"urn:schemas-microsoft-com:vml" = xmlns:o=3D"urn:schemas-microsoft-com:office:office" = xmlns:w=3D"urn:schemas-microsoft-com:office:word" = xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" = xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta = http-equiv=3DContent-Type content=3D"text/html; charset=3Dutf-8"><meta = name=3DGenerator content=3D"Microsoft Word 15 (filtered medium)"><!--[if = !mso]><style>v\:* {behavior:url(#default#VML);} o\:* {behavior:url(#default#VML);} w\:* {behavior:url(#default#VML);} .shape {behavior:url(#default#VML);} </style><![endif]--><style><!-- /* Font Definitions */ @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0in; margin-bottom:.0001pt; font-size:12.0pt; font-family:"Times New Roman",serif;} a:link, span.MsoHyperlink {mso-style-priority:99; color:blue; text-decoration:underline;} a:visited, span.MsoHyperlinkFollowed {mso-style-priority:99; color:purple; text-decoration:underline;} p {mso-style-priority:99; mso-margin-top-alt:auto; margin-right:0in; mso-margin-bottom-alt:auto; margin-left:0in; font-size:12.0pt; font-family:"Times New Roman",serif;} code {mso-style-priority:99; font-family:"Courier New";} p.msonormal0, li.msonormal0, div.msonormal0 {mso-style-name:msonormal; mso-margin-top-alt:auto; margin-right:0in; mso-margin-bottom-alt:auto; margin-left:0in; font-size:12.0pt; font-family:"Times New Roman",serif;} span.EmailStyle20 {mso-style-type:personal-reply; font-family:"Calibri",sans-serif; color:#1F497D;} .MsoChpDefault {mso-style-type:export-only; font-family:"Calibri",sans-serif;} @page WordSection1 {size:8.5in 11.0in; margin:1.0in 1.0in 1.0in 1.0in;} div.WordSection1 {page:WordSection1;} --></style><!--[if gte mso 9]><xml> <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" /> </xml><![endif]--><!--[if gte mso 9]><xml> <o:shapelayout v:ext=3D"edit"> <o:idmap v:ext=3D"edit" data=3D"1" /> </o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue = vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span = style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'= >It appears WinPcap is no longer being developed and Npcap is. Once = snort start it fails because of the issue below.<o:p></o:p></span></p><p = class=3DMsoNormal><span = style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'= ><o:p> </o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'= >Seems there should be a better way to link Snort to the .DLL=E2=80=99s = in memory weather using either program?<o:p></o:p></span></p><p = class=3DMsoNormal><span = style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'= ><o:p> </o:p></span></p><p class=3DMsoNormal><span = style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'= >Not real sure of the solution but WinPcap or Npcap should be installed = and running prior to installing Snort. <o:p></o:p></span></p><p = class=3DMsoNormal><span = style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'= ><o:p> </o:p></span></p><p class=3DMsoNormal><b><span = style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif'>From:</span><= /b><span style=3D'font-size:11.0pt;font-family:"Calibri",sans-serif'> = Daniel Miller <[email protected]> <br><b>Sent:</b> = Wednesday, September 4, 2019 6:27 PM<br><b>To:</b> nmap/nmap = <[email protected]><br><b>Cc:</b> mesteele101 = <[email protected]>; Mention = <[email protected]><br><b>Subject:</b> Re: [nmap/nmap] = Npcap 0.9982 Failing! (#1677)<o:p></o:p></span></p><p = class=3DMsoNormal><o:p> </o:p></p><p>In the final analysis, the = issue is caused by a version mismatch between the WinPcap version of = Packet.DLL that is shipped with Snort and the Npcap driver API that is = implemented by Npcap's own Packet.DLL. The solution is to remove = wpcap.dll and Packet.dll from the executable path of Snort and either = install Npcap in WinPcap API-compatible mode or modify Snort to call = <code><span style=3D'font-size:10.0pt'>SetDllDirectory</span></code> = appropriately to find the Npcap DLLs <a = href=3D"https://nmap.org/npcap/guide/npcap-devguide.html#npcap-feature-na= tive">as described in the Npcap Developers' Guide</a>.<o:p></o:p></p><p = style=3D'-webkit-text-size-adjust:none'><span = style=3D'color:#666666'>=E2=80=94<br>You are receiving this because you = were mentioned.<br>Reply to this email directly, <a = href=3D"https://github.com/nmap/nmap/issues/1677?email_source=3Dnotificat= ions&email_token=3DAAJWQ6RDWIX7QIQIPD2FCH3QIAYZ3A5CNFSM4IJGWHM2YY3PNV= WWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOD55GY7Y#issuecommen= t-528116863">view it on GitHub</a>, or <a = href=3D"https://github.com/notifications/unsubscribe-auth/AAJWQ6TDF5ZDAQ2= 4CMINGMTQIAYZ3ANCNFSM4IJGWHMQ">mute the thread</a>.<img border=3D0 = width=3D1 height=3D1 style=3D'width:.0104in;height:.0104in' = id=3D"_x0000_i1025" = src=3D"https://github.com/notifications/beacon/AAJWQ6VKGWT5PHCU642RFVDQIA= YZ3A5CNFSM4IJGWHM2YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORP= WSZGOD55GY7Y.gif"><o:p></o:p></span></p></div></body></html> ------=_NextPart_000_0001_01D56358.AEB50B30-- --===============7306215473017037433== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Snort-devel mailing list [email protected] https://lists.snort.org/mailman/listinfo/snort-devel Please visit http://blog.snort.org for the latest news about Snort! --===============7306215473017037433==--