Bonjour à tous, snort me donne encore du fil à retordre ! Quand je démarre le MNF il est en echec :
Mar 17 01:20:14 mnf snort: FATAL ERROR: OpenPcap() device ppp0 open: ^Iioctl: No such device
mar 17 01:20:14 mnf snortd: snort startup failed
Un service snortd status me donne toujours ce message à la c.... : snort mort mais le ss-système reste vérouillé ( à vos traductions )
Si je rédémarre le service tout se passse correctement :
Mar 17 00:21:51 mnf CROND[5105]: (root) CMD ( /usr/share/msec/promisc_check.sh)
Mar 17 00:22:00 mnf CROND[5445]: (root) CMD ( /usr/share/msec/promisc_check.sh)
mar 17 00:22:04 mnf snortd: snort shutdown failed
Mar 17 00:22:05 mnf kernel: device ppp0 entered promiscuous mode
Mar 17 00:22:05 mnf snort: Initializing daemon mode
mar 17 00:22:05 mnf snortd: snort startup succeeded
Mar 17 00:22:05 mnf snort: PID path stat checked out ok, PID path set to /var/run/
Mar 17 00:22:05 mnf snort: Writing PID "5625" to file "/var/run//snort_ppp0.pid"
Mar 17 00:22:05 mnf snort: http_decode arguments:
Mar 17 00:22:05 mnf snort: Unicode decoding
Mar 17 00:22:05 mnf snort: IIS alternate Unicode decoding
Mar 17 00:22:05 mnf snort: IIS double encoding vuln
Mar 17 00:22:05 mnf snort: Flip backslash to slash
Mar 17 00:22:05 mnf snort: Include additional whitespace separators
Mar 17 00:22:05 mnf snort: Ports to decode http on: 80
Mar 17 00:22:05 mnf snort: rpc_decode arguments:
Mar 17 00:22:05 mnf snort: Ports to decode RPC on: 111 32771
Mar 17 00:22:05 mnf snort: alert_fragments: INACTIVE
Mar 17 00:22:05 mnf snort: alert_large_fragments: ACTIVE
Mar 17 00:22:05 mnf snort: alert_incomplete: ACTIVE
Mar 17 00:22:05 mnf snort: alert_multiple_requests: ACTIVE
Mar 17 00:22:05 mnf snort: telnet_decode arguments:
Mar 17 00:22:05 mnf snort: Ports to decode telnet on: 21 23 25 119
Mar 17 00:22:07 mnf snort: Snort initialization completed successfully
Je ne comprends plus bien ! Faut-il que je fasse un script qui relance snort une deuxième fois ?
Je suis preneur de toutes les idées, merci à vous !