store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Thu May 23, 2013 1:56 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 4 posts ] 
Author Message
 Post subject: snort???
Unread postPosted: Tue May 12, 2009 3:49 pm 
Offline
Forum Regular
Forum Regular

Joined: Thu Apr 23, 2009 12:08 pm
Posts: 218
I did updates from your repository yesterday: psa-proftp, mysql, and today i get this message from my rkhunter scan


Warning: Users have been added to the passwd file:
snortd:x:62:62:Snort Daemon:/var/lib/snort:/sbin/nologin
Warning: Groups have been added to the group file:
snortd:x:62:


What is that? Is this something bad? I didn't put this there, so could it be some kind of snoop?


Top
 Profile  
 
 Post subject: Re: snort???
Unread postPosted: Tue May 12, 2009 5:02 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7427
Location: earth
Snort (www.snort.org) is a network based intrusion detection system. You might wanna check your yum logs to see how you got that installed


Top
 Profile  
 
 Post subject: Re: snort???
Unread postPosted: Tue May 12, 2009 6:54 pm 
Offline
Forum Regular
Forum Regular

Joined: Thu Apr 23, 2009 12:08 pm
Posts: 218
got it from art. guess i did not check what was being installed.

May 11 09:41:11 Installed: mysql-libs-5.0.79-1.el5.art.x86_64
May 11 09:41:12 Updated: mysql-5.0.79-1.el5.art.x86_64
May 11 09:41:12 Installed: 14:libpcap-0.9.4-14.el5.x86_64
May 11 09:41:13 Installed: libprelude-0.9.21.2-1.el5.art.x86_64
May 11 09:41:14 Installed: snort-2.8.1-5.el5.art.x86_64
May 11 09:41:16 Updated: mysql-server-5.0.79-1.el5.art.x86_64


So, i assume if from you that all is well. Correct. Therefore i should go ahead and configure? Is this something you recommend?


Top
 Profile  
 
 Post subject: Re: snort???
Unread postPosted: Wed May 13, 2009 8:40 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7427
Location: earth
That would indicate to me that something else you had on the system has installed it as a dependency. Prelude perhaps, etc. Anyway, I cant really say yes or no here, this is one of those "it depends" things.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 4 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group