installing snort on a FRESH install of RH 7.1 Seawolf

installing snort on a FRESH install of RH 7.1 Seawolf

Post by jp » Wed, 25 Jul 2001 23:16:47



hi all, you may have seen a couple of my other posts, i think they were in
this newsgroup. Well, i got rooted and decided to reinstall on my P-90 :-)
RH 7.1 Seawolf my hd is partitioned as so:

/boot 50 megs
/root 1000
/home 300
/var 300
/usr/local 200
/jail (for bind 9.xxx when i install it)
/usr 1300

i have a fresh install and since i got rooted last time, i have done some
research and decided that my first step after installation (before i plug
ANY kind of modem or another computer into it lol) was to install snort and
some kind of system log watcher, i saw one mentioned here in a reply to a
messaage i posted before i think it was syslogwatch or something. But
anyways, i made sure to install libpcap-0.4 and 0.6. Both were installeed
from source with no errors. I did both because i installed 0.4 first (thats
the one that is linked from the snort.org dl page). Once i installed that I
attempted to install snort 1.8 from snort-1.8p1-0.src.rpm. i did:

rpm --rebuild snort-1.8p1-0.src.rpm
the err msg i got was:
Installing snort-1.8p1-0.src.rpm
error: failed build dependancies:
    libpcap >= 0.4 is needed by snort-1.8p1-0

It looks like snort isnt finding libpcap, when i made libpcap i went with
the STOCK defaults, i didnt change anything in Makfile. hmm now that i think
about it maybe thats the prob lol. Well i read the makefiles. etc but i am
still at a loss. Can someone point me in the right direction pleez?

jp

 
 
 

installing snort on a FRESH install of RH 7.1 Seawolf

Post by jp » Wed, 25 Jul 2001 23:17:49


hi all, you may have seen a couple of my other posts, i think they were in
this newsgroup. Well, i got rooted and decided to reinstall on my P-90 :-)
RH 7.1 Seawolf my hd is partitioned as so:

/boot 50 megs
/root 1000
/home 300
/var 300
/usr/local 200
/jail (for bind 9.xxx when i install it)
/usr 1300

i have a fresh install and since i got rooted last time, i have done some
research and decided that my first step after installation (before i plug
ANY kind of modem or another computer into it lol) was to install snort and
some kind of system log watcher, i saw one mentioned here in a reply to a
messaage i posted before i think it was syslogwatch or something. But
anyways, i made sure to install libpcap-0.4 and 0.6. Both were installeed
from source with no errors. I did both because i installed 0.4 first (thats
the one that is linked from the snort.org dl page). Once i installed that I
attempted to install snort 1.8 from snort-1.8p1-0.src.rpm. i did:

rpm --rebuild snort-1.8p1-0.src.rpm
the err msg i got was:
Installing snort-1.8p1-0.src.rpm
error: failed build dependancies:
    libpcap >= 0.4 is needed by snort-1.8p1-0

It looks like snort isnt finding libpcap, when i made libpcap i went with
the STOCK defaults, i didnt change anything in Makfile. hmm now that i think
about it maybe thats the prob lol. Well i read the makefiles. etc but i am
still at a loss. Can someone point me in the right direction pleez?

jp

 
 
 

installing snort on a FRESH install of RH 7.1 Seawolf

Post by Christopher William Palo » Thu, 26 Jul 2001 00:43:37


if you compiled libpcap then rpm has no way of knowing that and as such
things you don't have it... Just install the libpcap rpm instead and
you're all good.

Chris Palow


> hi all, you may have seen a couple of my other posts, i think they were in
> this newsgroup. Well, i got rooted and decided to reinstall on my P-90 :-)
> RH 7.1 Seawolf my hd is partitioned as so:

> /boot 50 megs
> /root 1000
> /home 300
> /var 300
> /usr/local 200
> /jail (for bind 9.xxx when i install it)
> /usr 1300

> i have a fresh install and since i got rooted last time, i have done some
> research and decided that my first step after installation (before i plug
> ANY kind of modem or another computer into it lol) was to install snort and
> some kind of system log watcher, i saw one mentioned here in a reply to a
> messaage i posted before i think it was syslogwatch or something. But
> anyways, i made sure to install libpcap-0.4 and 0.6. Both were installeed
> from source with no errors. I did both because i installed 0.4 first (thats
> the one that is linked from the snort.org dl page). Once i installed that I
> attempted to install snort 1.8 from snort-1.8p1-0.src.rpm. i did:

> rpm --rebuild snort-1.8p1-0.src.rpm
> the err msg i got was:
> Installing snort-1.8p1-0.src.rpm
> error: failed build dependancies:
>     libpcap >= 0.4 is needed by snort-1.8p1-0

> It looks like snort isnt finding libpcap, when i made libpcap i went with
> the STOCK defaults, i didnt change anything in Makfile. hmm now that i think
> about it maybe thats the prob lol. Well i read the makefiles. etc but i am
> still at a loss. Can someone point me in the right direction pleez?

> jp

 
 
 

installing snort on a FRESH install of RH 7.1 Seawolf

Post by John P Whit » Thu, 26 Jul 2001 01:48:04


since i installed libpcap 0.4 and 0.6 from source, i have an rpm now,
libpcap-0.4.13.i386.rpm, from Doors 2.1 (dont know them). I am going to try
to install that, but first i am wondering, should i uninstall libpcap 0.4? I
went in the src dir and did make uninstall for 0.6, so thats fine. but what
do i do for libpcap 0.4? I tried to do make uninstall but there must not be
an uninstall script in there. what should i do? is this going to affect the
rpm when i try to install it?

jp



> if you compiled libpcap then rpm has no way of knowing that and as such
> things you don't have it... Just install the libpcap rpm instead and
> you're all good.

> Chris Palow


> > hi all, you may have seen a couple of my other posts, i think they were
in
> > this newsgroup. Well, i got rooted and decided to reinstall on my P-90
:-)
> > RH 7.1 Seawolf my hd is partitioned as so:

> > /boot 50 megs
> > /root 1000
> > /home 300
> > /var 300
> > /usr/local 200
> > /jail (for bind 9.xxx when i install it)
> > /usr 1300

> > i have a fresh install and since i got rooted last time, i have done
some
> > research and decided that my first step after installation (before i
plug
> > ANY kind of modem or another computer into it lol) was to install snort
and
> > some kind of system log watcher, i saw one mentioned here in a reply to
a
> > messaage i posted before i think it was syslogwatch or something. But
> > anyways, i made sure to install libpcap-0.4 and 0.6. Both were
installeed
> > from source with no errors. I did both because i installed 0.4 first
(thats
> > the one that is linked from the snort.org dl page). Once i installed
that I
> > attempted to install snort 1.8 from snort-1.8p1-0.src.rpm. i did:

> > rpm --rebuild snort-1.8p1-0.src.rpm
> > the err msg i got was:
> > Installing snort-1.8p1-0.src.rpm
> > error: failed build dependancies:
> >     libpcap >= 0.4 is needed by snort-1.8p1-0

> > It looks like snort isnt finding libpcap, when i made libpcap i went
with
> > the STOCK defaults, i didnt change anything in Makfile. hmm now that i
think
> > about it maybe thats the prob lol. Well i read the makefiles. etc but i
am
> > still at a loss. Can someone point me in the right direction pleez?

> > jp

 
 
 

1. Redhat Linux 7.1, fresh install Gnome Hangs machine (in non failsafe mode)

I just installed RedHat linux 7.1 on my NEC versa 6220 laptop. The
install went smoothly and I selected the gnome desktop environment (no
KDE). The log-on screen comes on fine and the mouse also works fine
until I enter the username and password. At that point a big "gnome"
icon comes up which says loading ... - the mouse can still be moved
while several things are loaded. However, at the end when the screen
says "done", the mouse freezes and the machine just hangs.
Control-Alt-Backspace and everything else I've tried fails to work and
I have to power cycle the machine (with the resultant fsck on power
up).

I can log-on in the fail safe mode though in that mode the x-tem
windows don't have border's/scroll bars.

Any info on fixes would be highly appreciated. Please note I'm new to
linux and it would help if you included specific information on how I
would get the fix to work.

Thanks in advance for all responses,

Gary

2. How to search a new line and replace with tab?

3. 7.1 Install Fresh

4. test only

5. Suse 7.1 no kde with fresh install

6. Full Page Scanner Driver

7. CD install hangs for RH 7.1 but works fine for RH 7.0 -- why?

8. Which soundcard for sampling and full duplex operation

9. Creating a serious DHCPD/NAMED setup with seawolf (RedHat 7.1)

10. creating a serious dhcpd/named setup with seawolf (redhat 7.1)

11. Red Hat 7.1 - Installing Red Hat packages after Red Hat is already installed.

12. fresh install, fresh problems

13. RH 7.1 Install Unknown Problem - Please Advise