Re: [Wireshark-dev] External processes in Snort dissector - code execution

2017-08-28 Thread Martin Mathieson via Wireshark-dev
Hi Peter, I had not really thought about someone doing this. I have at times had multiple versions of snort installed in the same VM and used the option to switch between them... Its not a solution really, but I had thought I ought to run the snort binary with -V and check that it got a

[Wireshark-dev] External processes in Snort dissector - code execution

2017-08-28 Thread Peter Wu
Hi Martin and others, I have noticed that the snort dissector (added in Wireshark 2.4) can be configured to execute external processes, is this desirable? When a new pcap is loaded (or when a live capture starts), it will execute the following init routine: static void snort_start(void)