Snort 2.9.2.3 pkg v. 2.5.4 won't start
-
Hi,
I just upgraded to Snort 2.9.2.3 pkg v. 2.5.4 and now it won't start. The log shows the following error:
Feb 1 13:35:39 snort[25949]: Loading all dynamic engine libs from /usr/local/lib/snort/dynamicengine... Feb 1 13:35:39 snort[25949]: Loading all dynamic engine libs from /usr/local/lib/snort/dynamicengine... Feb 1 13:35:39 snort[25949]: WARNING: No dynamic libraries found in directory /usr/local/lib/snort/dynamicengine. Feb 1 13:35:39 snort[25949]: WARNING: No dynamic libraries found in directory /usr/local/lib/snort/dynamicengine. Feb 1 13:35:39 snort[25949]: Finished Loading all dynamic engine libs from /usr/local/lib/snort/dynamicengine Feb 1 13:35:39 snort[25949]: Finished Loading all dynamic engine libs from /usr/local/lib/snort/dynamicengine Feb 1 13:21:16 snort[38035]: Loading all dynamic detection libs from /usr/local/lib/snort/dynamicrules... Feb 1 13:21:16 snort[38035]: Loading all dynamic detection libs from /usr/local/lib/snort/dynamicrules... Feb 1 13:21:16 snort[38035]: Loading dynamic detection library /usr/local/lib/snort/dynamicrules/bad-traffic.so... Feb 1 13:21:16 snort[38035]: Loading dynamic detection library /usr/local/lib/snort/dynamicrules/bad-traffic.so... Feb 1 13:21:16 snort[38035]: FATAL ERROR: Failed to load /usr/local/lib/snort/dynamicrules/bad-traffic.so: /usr/local/lib/snort/dynamicrules/bad-traffic.so: Undefined symbol "freeRuleData" Feb 1 13:21:16 snort[38035]: FATAL ERROR: Failed to load /usr/local/lib/snort/dynamicrules/bad-traffic.so: /usr/local/lib/snort/dynamicrules/bad-traffic.so: Undefined symbol "freeRuleData"
I updated the rules but it made no difference. Interestingly, I don't even have the snort_bad-traffic.so.rules ruleset selected to be loaded at startup.
Any ideas? Thanks much…
-
Looks like, from the error messages, you have the same problem others have experienced. Ermal has been trying to make it work better, but for some the PKG icon for re-install does not work properly. It either does not uninstall properly, or else does not re-install properly; but in either case the user is left with a malfunctioning Snort package.
The solution that has worked for others is the following:
On the Installed Packages tab, click the "X" icon to completely remove Snort. If you want to save your settings (most folks do), then click the appropriate box on the Snort interface before going to the Packages tab.
Click on the Available Packages tab and install Snort fresh. This generally works. The goal is to have the PKG icon work properly and re-install the package correctly, but it's not there yet… :(
-
Thanks bmeeks …that did the trick (not sure why I didn't think to do that before posting!) ...thx again!