From owner-freebsd-security Wed May 29 9:31: 6 2002 Delivered-To: freebsd-security@freebsd.org Received: from obsecurity.dyndns.org (adsl-64-169-107-187.dsl.lsan03.pacbell.net [64.169.107.187]) by hub.freebsd.org (Postfix) with ESMTP id CFF3337B406 for ; Wed, 29 May 2002 09:30:53 -0700 (PDT) Received: by obsecurity.dyndns.org (Postfix, from userid 1000) id 5987166DC6; Wed, 29 May 2002 09:30:53 -0700 (PDT) Date: Wed, 29 May 2002 09:30:53 -0700 From: Kris Kennaway To: Lim Wee Guan Cc: freebsd-security@FreeBSD.ORG Subject: Re: Snort producing tcpdump unreadable binary files. Message-ID: <20020529093053.B94904@xor.obsecurity.org> References: <20020529210806.A29200@nexus> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-md5; protocol="application/pgp-signature"; boundary="+g7M9IMkV8truYOl" Content-Disposition: inline User-Agent: Mutt/1.2.5.1i In-Reply-To: <20020529210806.A29200@nexus>; from weeguan@hem.passagen.se on Wed, May 29, 2002 at 09:08:06PM +0800 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org --+g7M9IMkV8truYOl Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Wed, May 29, 2002 at 09:08:06PM +0800, Lim Wee Guan wrote: > However, after a while of logging, snort appears to go "crazy" and > logs apparently all packets (humongous log files are typical), and if > I attempt to read the binary file using tcpdump -r, I get this > message at the end of some valid packets: "tcpdump: pcap_loop: bogus > savefile header"=20 I've seen that too; I think it's a problem with the version of pcap we use. I was getting the same problems with plain tcpdump (this is on my PPPoE router system). I'm also seeing snort dying very often inside libpcap. I can't remember if I've tried linking it against the newer version. This isn't really a security question. Kris --+g7M9IMkV8truYOl Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (FreeBSD) iD8DBQE89QI8Wry0BWjoQKURAjQeAKDFAAja0hmSZK1MHIaRhxnUdtjVVACgpIKe 1sgcBSNGUValm4ZAAyjxWbU= =JNx8 -----END PGP SIGNATURE----- --+g7M9IMkV8truYOl-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message