Your message dated Mon, 28 Jan 2008 00:17:10 +0000 with message-id <[EMAIL PROTECTED]> and subject line Bug#458823: fixed in snort 2.7.0-10 has caused the attached Bug report to be marked as done.
This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what I am talking about this indicates a serious mail system misconfiguration somewhere. Please contact me immediately.) Debian bug tracking system administrator (administrator, Debian Bugs database)
--- Begin Message ---Package: snort Version: 2.7.0-8 Severity: normal I have multiple interfaces lan0 and wlan0 (fixed and wireless) on my computer. It's a laptop, I only use one at a time depending on where I happen to be at the time. I want to be able to run snort as a simple security measure, so that it keeps watch over either interface, whichever one happens to be running at the time. So I configure the two, setting snort/interface as "lan0 wlan0". However, because only one of the interfaces is activated at one time, snort fails to process the configuration, saying for instance: Starting Network Intrusion Detection System : snort (lan0 no /etc/snort/snort.lan0.conf found, defaulting to snort.conf ...done) (wlan0 no /etc/snort/snort.wlan0.conf found, defaulting to snort.conf ...ERROR: failed (check /var/log/syslog and /var/log/snort)) failed! invoke-rc.d: initscript snort, action "start" failed. dpkg: error processing snort (--configure): subprocess post-installation script returned error exit status 1 Hence dpkg treats snort as unconfigured, and proper installation is not successful. Looking at /var/log/syslog, it suggests the failure is simply due to wlan0 being deactivated (this upgrade was done over lan0): Jan 3 15:36:58 pug snort[29018]: FATAL ERROR: OpenPcap() device wlan0 open: SIOCGIFHWADDR: No such device So snort does not appear to elegantly deal with a temporarily deactivated interface. The expected behaviour would be for snort to simply ignore (or perhaps record a warning against) a missing interface, and then switch over to monitor that interface, once it is later activated (perhaps some use of ifupdown's /etc/network/if-up.d/ scripts is needed to achieve this ? ) Thanks, Drew -- System Information: Debian Release: lenny/sid APT prefers unstable APT policy: (990, 'unstable'), (1, 'experimental') Architecture: i386 (i686) Kernel: Linux 2.6.23 Locale: LANG=en_AU.UTF-8, LC_CTYPE=en_AU.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Versions of packages snort depends on: ii adduser 3.105 add and remove users and groups ii debconf [debconf-2.0] 1.5.17 Debian configuration management sy ii libc6 2.7-5 GNU C Library: Shared libraries ii libgcrypt11 1.4.0-2 LGPL Crypto library - runtime libr ii libgnutls13 2.0.4-1 the GNU TLS library - runtime libr ii libgpg-error0 1.4-2 library for common error values an ii libltdl3 1.5.24-2 A system independent dlopen wrappe ii libpcap0.8 0.9.8-2 System interface for user-level pa ii libpcre3 7.3-2 Perl 5 Compatible Regular Expressi ii libprelude2 0.9.16.1-1 Hybrid Intrusion Detection System ii libtasn1-3 1.2-1 Manage ASN.1 structures (runtime) ii logrotate 3.7.1-3 Log rotation utility ii snort-common 2.7.0-8 Flexible Network Intrusion Detecti ii snort-common-libraries 2.7.0-8 Flexible Network Intrusion Detecti ii snort-rules-default 2.7.0-8 Flexible Network Intrusion Detecti ii sysklogd [system-log-da 1.5-1 System Logging Daemon ii zlib1g 1:1.2.3.3.dfsg-8 compression library - runtime Versions of packages snort recommends: ii snort-doc 2.7.0-8 Documentation for the Snort IDS [d -- debconf information: snort/startup: boot snort/please_restart_manually: snort/stats_treshold: 1 snort/options: * snort/invalid_interface: * snort/interface: lan0 wlan0 snort/stats_rcpt: root snort/send_stats: true snort/config_parameters: * snort/config_error: snort/reverse_order: false snort/disable_promiscuous: false
--- End Message ---
--- Begin Message ---Source: snort Source-Version: 2.7.0-10 We believe that the bug you reported is fixed in the latest version of snort, which is due to be installed in the Debian FTP archive: snort-common-libraries_2.7.0-10_i386.deb to pool/main/s/snort/snort-common-libraries_2.7.0-10_i386.deb snort-common_2.7.0-10_all.deb to pool/main/s/snort/snort-common_2.7.0-10_all.deb snort-doc_2.7.0-10_all.deb to pool/main/s/snort/snort-doc_2.7.0-10_all.deb snort-mysql_2.7.0-10_i386.deb to pool/main/s/snort/snort-mysql_2.7.0-10_i386.deb snort-pgsql_2.7.0-10_i386.deb to pool/main/s/snort/snort-pgsql_2.7.0-10_i386.deb snort-rules-default_2.7.0-10_all.deb to pool/main/s/snort/snort-rules-default_2.7.0-10_all.deb snort_2.7.0-10.diff.gz to pool/main/s/snort/snort_2.7.0-10.diff.gz snort_2.7.0-10.dsc to pool/main/s/snort/snort_2.7.0-10.dsc snort_2.7.0-10_i386.deb to pool/main/s/snort/snort_2.7.0-10_i386.deb A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to [EMAIL PROTECTED], and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Javier Fernandez-Sanguino Pen~a <[EMAIL PROTECTED]> (supplier of updated snort package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing [EMAIL PROTECTED]) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Sun, 27 Jan 2008 11:12:05 +0100 Source: snort Binary: snort-mysql snort-doc snort-rules-default snort-common snort-pgsql snort snort-common-libraries Architecture: source i386 all Version: 2.7.0-10 Distribution: unstable Urgency: low Maintainer: Javier Fernandez-Sanguino Pen~a <[EMAIL PROTECTED]> Changed-By: Javier Fernandez-Sanguino Pen~a <[EMAIL PROTECTED]> Description: snort - Flexible Network Intrusion Detection System snort-common - Flexible Network Intrusion Detection System [common files] snort-common-libraries - Flexible Network Intrusion Detection System ruleset snort-doc - Documentation for the Snort IDS [documentation] snort-mysql - Flexible Network Intrusion Detection System [MySQL] snort-pgsql - Flexible Network Intrusion Detection System [PostgreSQL] snort-rules-default - Flexible Network Intrusion Detection System ruleset Closes: 458823 460344 462674 462865 Changes: snort (2.7.0-10) unstable; urgency=low . * Add a new ALLOW_UNAVAILABLE definition in /etc/default/snort which makes the init.d not complain if a configured interface is not available. Also make the init.d script not break if no instances are configured through debconf (to make it possible to use snort using just if-up.d by providing a given interface instance as a 'start' parameter) (Closes: #458823) * Fix typo in templates, unfuzzy translations I can "understand" and which seem to have fixed the typo themselves. * Po-debconf updates: - Update German translation provided by Erik Schanze (Closes: #462674) - Updated Italian translation provided by Gianluca Cotr (Closes: #462865) - Romanian translation provided by Eddy Petrisor (Closes: #460344) Files: fc4dc9087e0db9f8cf0745a7da233d3c 923 net optional snort_2.7.0-10.dsc eceb891bd52d39b94f0054229934f302 1554152 net optional snort_2.7.0-10.diff.gz 386d3f6863b8fd48db4388d0a1f5e698 457746 net optional snort_2.7.0-10_i386.deb afa12f5dbd76ff1ac49f4c2cc49c0d3d 466444 net extra snort-mysql_2.7.0-10_i386.deb 4cb4563412eaf2f3ab30fa76ce47995a 466168 net optional snort-pgsql_2.7.0-10_i386.deb 931f8a72b2309fdaded351e8a7a49df5 255832 net optional snort-common-libraries_2.7.0-10_i386.deb d39ad3a5d47a6272d50e703743e45e46 134948 net optional snort-common_2.7.0-10_all.deb 2eb6fe07c0c703ad6b49b42ef141e4d2 2300340 doc optional snort-doc_2.7.0-10_all.deb 77d557d9e6866fbad7fee70a21bb5b98 397380 net optional snort-rules-default_2.7.0-10_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFHnRxLsandgtyBSwkRAjKeAJ93GFNl2QDRJgVr2b3QDQIA1npx6wCeP17r qATvvzAfRp6OBmKv2OqIq+k= =HRQf -----END PGP SIGNATURE-----
--- End Message ---

