Outstanding issues

Andreas Östling andreaso at it.su.se
Mon Sep 25 04:02:45 EDT 2006


On Mon, 25 Sep 2006, Russell Fulton wrote:

> snort is very close to what argus needs.  It allows you to specify which
> user and group to run as after it has connected to the pcap/bpf -- it
> also has a chroot option (that I use).

The patch I sent is pretty much identical to what Snort does, i.e. the 
most basic privilege dropping. If it doesn't get incorporated I'll 
update it for Argus 3 and publish it in case anyone else would like to 
use it.

/Andreas



More information about the argus mailing list