Outstanding issues
Andreas Östling
andreaso at it.su.se
Mon Sep 25 04:02:45 EDT 2006
On Mon, 25 Sep 2006, Russell Fulton wrote:
> snort is very close to what argus needs. It allows you to specify which
> user and group to run as after it has connected to the pcap/bpf -- it
> also has a chroot option (that I use).
The patch I sent is pretty much identical to what Snort does, i.e. the
most basic privilege dropping. If it doesn't get incorporated I'll
update it for Argus 3 and publish it in case anyone else would like to
use it.
/Andreas
More information about the argus
mailing list