Snort - the de facto standard for intrusion detection/prevention
next up previous
Next: 7.20 My snort crashes, Up: 7 Problems Previous: 7.18 I am still


7.19 Why does chrooted Snort die when I send it a SIGHUP?

It's a known problem with permissions. Workaround, restart snort instead.

But the short answer is this: Due to the way the execv(2) call works, it "Restarts" snort from scratch. This has the odd side effect of making HUPS to a chrooted snort become recursive. For example, chroot to /snort. It now sees /snort as / . Now HUP snort. Snort now expects to have /snort/snort as /. In other words, you have to re-create your directories for your jail inside it. 4 HUPS and you will be in /snort/snort/snort/snort.



Nigel Houghton 2006-10-02