From owner-freebsd-ports Mon Aug 20 19:37:17 2001 Delivered-To: freebsd-ports@freebsd.org Received: from obsecurity.dyndns.org (adsl-63-207-60-7.dsl.lsan03.pacbell.net [63.207.60.7]) by hub.freebsd.org (Postfix) with ESMTP id D0D4437B409 for ; Mon, 20 Aug 2001 19:37:13 -0700 (PDT) (envelope-from kris@obsecurity.org) Received: by obsecurity.dyndns.org (Postfix, from userid 1000) id 2E7C566D3E; Mon, 20 Aug 2001 19:37:13 -0700 (PDT) Date: Mon, 20 Aug 2001 19:37:13 -0700 From: Kris Kennaway To: scheidell@fdma.com Cc: freebsd-ports@freebsd.org Subject: Re: anyone else have snort core dump? Message-ID: <20010820193712.A7801@xor.obsecurity.org> References: <200108201929.f7KJTMZ61556@caerulus.cerintha.com> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-md5; protocol="application/pgp-signature"; boundary="BXVAT5kNtrzKuDFl" Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: <200108201929.f7KJTMZ61556@caerulus.cerintha.com>; from freebsd-stable@news.fdma.com on Mon, Aug 20, 2001 at 03:29:22PM -0400 Sender: owner-freebsd-ports@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org --BXVAT5kNtrzKuDFl Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Mon, Aug 20, 2001 at 03:29:22PM -0400, freebsd-stable@news.fdma.com wrot= e: > I have a problem with snort 1.8.1-REL core dumping. >=20 > Tried two different systems >=20 > one, 133mhz PI, 4.3-REL, stock binaries, dec ethernet card >=20 > Two, 850mhz PIII, 4.4-RC2, (not stock) binaries, reltec card >=20 > yes, I make sure I took I686_cpu out of make.conf first. >=20 > and it core dumps when network is silent or noisy, doesn't matter (seems > to core dump mostly when silent) It's probably a code bug. Unfortunately recent releases of snort haven't exactly been very stable. I've learned to run it in a while(1) loop to restart it when it crashes. > So, do I need to run the linux binaries? and at what overhead? No, you should obtain a gdb core traceback and talk to the snort user support mailing list. It's probably already a known problem. Kris --BXVAT5kNtrzKuDFl Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (FreeBSD) Comment: For info see http://www.gnupg.org iD8DBQE7gclYWry0BWjoQKURAkWbAJsFqKLFYvEYsAsG9OId6In1NrRe1gCggQvv cpQpaK4wuqcms5BCOyNPS3g= =t5zl -----END PGP SIGNATURE----- --BXVAT5kNtrzKuDFl-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-ports" in the body of the message