Snort mailing list archives

Re: Windows: Running Snort at boot time, that is without logging in


From: "Scot Scot" <scotw () hotmail com>
Date: Thu, 17 Jul 2003 20:19:17 -0500

----- Original Message ----- 
From: "Always Bishan" <bishan4u () yahoo co uk>
To: <snort-users () lists sourceforge net>
Sent: Thursday, July 17, 2003 9:20 AM
Subject: [Snort-users] Windows: Running Snort at boot time, that is without
logging in


Hi Snorters,

I've one windows sensor running on windows 2000 and
alerting into a MySQL database on a linux server, but
it stops when I logout.
How can I run snort such that it keeps on running even
when I logout?
example IIS webserver which runs even if noody has
logged in the server.

Any clues, welcome

Regards,
Bishan

Option 1:
---------

Use snort /service /install command line option

Michael Steele has some documentation here you should take a look at:
http://www.silicondefense.com/support/windows/documentation.php

Note: Verify the snort service is configured to start automatically on boot
in the service control manager.
Note: Depending on your Snort build this option may be buggy

Option 2:
---------

Use Instsrv.exe and Srvany.exe from the Windows NT/2K resource kit

Michael Steele threw a how-to together a long time ago, it's somewhere on
this page:
http://www.snort.org/docs/acid-win32.html
Note: Verify the snort service is configured to start automatically on boot
in the service control manager.

Option 3:
---------

Step 1 - Create a snortstart.bat (or whatever you want to call it) file with
your snort command line in it.

Step 2 - Click on Start-->Settings-->Control Panel-->Scheduled Tasks-->Add
Scheduled Task--> Click Next -->Browse out to your snort.bat file, select
it, click Open,-->Select the radial option to Perform this task: "When my
computer starts".--> Click Next-->enter your password & password
confirmation, click Next --> Click Finish.... Wa-Laa

Just my 2.0135 cents worth (tax included)
Scot Wiedenfeld


-------------------------------------------------------
This SF.net email is sponsored by: VM Ware
With VMware you can run multiple operating systems on a single machine.
WITHOUT REBOOTING! Mix Linux / Windows / Novell virtual machines at the
same time. Free trial click here: http://www.vmware.com/wl/offer/345/0
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: