Your message dated Mon, 28 Jan 2008 00:17:10 +0000
with message-id <[EMAIL PROTECTED]>
and subject line Bug#458823: fixed in snort 2.7.0-10
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--- Begin Message ---
Package: snort
Version: 2.7.0-8
Severity: normal

I have multiple interfaces lan0 and wlan0 (fixed and wireless) on my
computer.  It's a laptop, I only use one at a time depending on where
I happen to be at the time.

I want to be able to run snort as a simple security measure, so that it
keeps watch over either interface, whichever one happens to be running
at the time.  So I configure the two, setting snort/interface as 
"lan0 wlan0".

However, because only one of the interfaces is activated at one time,
snort fails to process the configuration, saying for instance:

Starting Network Intrusion Detection System : snort (lan0 no
/etc/snort/snort.lan0.conf found, defaulting to snort.conf ...done)
(wlan0 no /etc/snort/snort.wlan0.conf found, defaulting to snort.conf
...ERROR: failed (check /var/log/syslog and /var/log/snort)) failed!
invoke-rc.d: initscript snort, action "start" failed.
dpkg: error processing snort (--configure):
 subprocess post-installation script returned error exit status 1
 
Hence dpkg treats snort as unconfigured, and proper installation is
not successful.

Looking at /var/log/syslog, it suggests the failure is simply due to
wlan0 being deactivated (this upgrade was done over lan0):

Jan  3 15:36:58 pug snort[29018]: FATAL ERROR: OpenPcap() device wlan0
open:  
        SIOCGIFHWADDR: No such device 



So snort does not appear to elegantly deal with a temporarily
deactivated interface.  The expected behaviour would be for snort to
simply ignore (or perhaps record a warning against) a missing
interface, and then switch over to monitor that interface, once it is
later activated (perhaps some use of ifupdown's /etc/network/if-up.d/
scripts is needed to achieve this ? )

Thanks,
Drew

-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (990, 'unstable'), (1, 'experimental')
Architecture: i386 (i686)

Kernel: Linux 2.6.23
Locale: LANG=en_AU.UTF-8, LC_CTYPE=en_AU.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages snort depends on:
ii  adduser                 3.105            add and remove users and groups
ii  debconf [debconf-2.0]   1.5.17           Debian configuration management sy
ii  libc6                   2.7-5            GNU C Library: Shared libraries
ii  libgcrypt11             1.4.0-2          LGPL Crypto library - runtime libr
ii  libgnutls13             2.0.4-1          the GNU TLS library - runtime libr
ii  libgpg-error0           1.4-2            library for common error values an
ii  libltdl3                1.5.24-2         A system independent dlopen wrappe
ii  libpcap0.8              0.9.8-2          System interface for user-level pa
ii  libpcre3                7.3-2            Perl 5 Compatible Regular Expressi
ii  libprelude2             0.9.16.1-1       Hybrid Intrusion Detection System 
ii  libtasn1-3              1.2-1            Manage ASN.1 structures (runtime)
ii  logrotate               3.7.1-3          Log rotation utility
ii  snort-common            2.7.0-8          Flexible Network Intrusion Detecti
ii  snort-common-libraries  2.7.0-8          Flexible Network Intrusion Detecti
ii  snort-rules-default     2.7.0-8          Flexible Network Intrusion Detecti
ii  sysklogd [system-log-da 1.5-1            System Logging Daemon
ii  zlib1g                  1:1.2.3.3.dfsg-8 compression library - runtime

Versions of packages snort recommends:
ii  snort-doc                     2.7.0-8    Documentation for the Snort IDS [d

-- debconf information:
  snort/startup: boot
  snort/please_restart_manually:
  snort/stats_treshold: 1
  snort/options:
* snort/invalid_interface:
* snort/interface: lan0 wlan0
  snort/stats_rcpt: root
  snort/send_stats: true
  snort/config_parameters:
* snort/config_error:
  snort/reverse_order: false
  snort/disable_promiscuous: false



--- End Message ---
--- Begin Message ---
Source: snort
Source-Version: 2.7.0-10

We believe that the bug you reported is fixed in the latest version of
snort, which is due to be installed in the Debian FTP archive:

snort-common-libraries_2.7.0-10_i386.deb
  to pool/main/s/snort/snort-common-libraries_2.7.0-10_i386.deb
snort-common_2.7.0-10_all.deb
  to pool/main/s/snort/snort-common_2.7.0-10_all.deb
snort-doc_2.7.0-10_all.deb
  to pool/main/s/snort/snort-doc_2.7.0-10_all.deb
snort-mysql_2.7.0-10_i386.deb
  to pool/main/s/snort/snort-mysql_2.7.0-10_i386.deb
snort-pgsql_2.7.0-10_i386.deb
  to pool/main/s/snort/snort-pgsql_2.7.0-10_i386.deb
snort-rules-default_2.7.0-10_all.deb
  to pool/main/s/snort/snort-rules-default_2.7.0-10_all.deb
snort_2.7.0-10.diff.gz
  to pool/main/s/snort/snort_2.7.0-10.diff.gz
snort_2.7.0-10.dsc
  to pool/main/s/snort/snort_2.7.0-10.dsc
snort_2.7.0-10_i386.deb
  to pool/main/s/snort/snort_2.7.0-10_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Javier Fernandez-Sanguino Pen~a <[EMAIL PROTECTED]> (supplier of updated snort 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Sun, 27 Jan 2008 11:12:05 +0100
Source: snort
Binary: snort-mysql snort-doc snort-rules-default snort-common snort-pgsql 
snort snort-common-libraries
Architecture: source i386 all
Version: 2.7.0-10
Distribution: unstable
Urgency: low
Maintainer: Javier Fernandez-Sanguino Pen~a <[EMAIL PROTECTED]>
Changed-By: Javier Fernandez-Sanguino Pen~a <[EMAIL PROTECTED]>
Description: 
 snort      - Flexible Network Intrusion Detection System
 snort-common - Flexible Network Intrusion Detection System [common files]
 snort-common-libraries - Flexible Network Intrusion Detection System ruleset
 snort-doc  - Documentation for the Snort IDS [documentation]
 snort-mysql - Flexible Network Intrusion Detection System [MySQL]
 snort-pgsql - Flexible Network Intrusion Detection System [PostgreSQL]
 snort-rules-default - Flexible Network Intrusion Detection System ruleset
Closes: 458823 460344 462674 462865
Changes: 
 snort (2.7.0-10) unstable; urgency=low
 .
   * Add a new ALLOW_UNAVAILABLE definition in /etc/default/snort which
     makes the init.d not complain if a configured interface is not available.
     Also make the init.d script not break if no instances are configured
     through debconf (to make it possible to use snort using just if-up.d
     by providing a given interface instance as a 'start' parameter)
     (Closes: #458823)
   * Fix typo in templates, unfuzzy translations I can "understand" and
     which seem to have fixed the typo themselves.
   * Po-debconf updates:
     - Update German translation provided by Erik Schanze (Closes: #462674)
     - Updated Italian translation provided by Gianluca Cotr (Closes: #462865)
     - Romanian translation provided by Eddy Petrisor (Closes: #460344)
Files: 
 fc4dc9087e0db9f8cf0745a7da233d3c 923 net optional snort_2.7.0-10.dsc
 eceb891bd52d39b94f0054229934f302 1554152 net optional snort_2.7.0-10.diff.gz
 386d3f6863b8fd48db4388d0a1f5e698 457746 net optional snort_2.7.0-10_i386.deb
 afa12f5dbd76ff1ac49f4c2cc49c0d3d 466444 net extra snort-mysql_2.7.0-10_i386.deb
 4cb4563412eaf2f3ab30fa76ce47995a 466168 net optional 
snort-pgsql_2.7.0-10_i386.deb
 931f8a72b2309fdaded351e8a7a49df5 255832 net optional 
snort-common-libraries_2.7.0-10_i386.deb
 d39ad3a5d47a6272d50e703743e45e46 134948 net optional 
snort-common_2.7.0-10_all.deb
 2eb6fe07c0c703ad6b49b42ef141e4d2 2300340 doc optional 
snort-doc_2.7.0-10_all.deb
 77d557d9e6866fbad7fee70a21bb5b98 397380 net optional 
snort-rules-default_2.7.0-10_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFHnRxLsandgtyBSwkRAjKeAJ93GFNl2QDRJgVr2b3QDQIA1npx6wCeP17r
qATvvzAfRp6OBmKv2OqIq+k=
=HRQf
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to