From owner-freebsd-stable@FreeBSD.ORG Sun Aug 3 08:20:35 2003 Return-Path: Delivered-To: freebsd-stable@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id DB93637B409; Sun, 3 Aug 2003 08:20:35 -0700 (PDT) Received: from sccrmhc13.comcast.net (sccrmhc13.comcast.net [204.127.202.64]) by mx1.FreeBSD.org (Postfix) with ESMTP id 110B343FCB; Sun, 3 Aug 2003 08:20:35 -0700 (PDT) (envelope-from rootman22@comcast.net) Received: from 12-209-185-111.client.attbi.com ([12.209.185.111]) by comcast.net (sccrmhc13) with SMTP id <20030803152034016009ig68e>; Sun, 3 Aug 2003 15:20:34 +0000 From: Joe Warner To: freebsd-stable@freebsd.org Date: Sun, 3 Aug 2003 09:20:45 -0600 User-Agent: KMail/1.5.2 MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Content-Disposition: inline Message-Id: <200308030920.45437.rootman22@comcast.net> cc: freebsd-security@freebsd.org Subject: Forensics CD Toolkit for FreeBSD X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 03 Aug 2003 15:20:36 -0000 Hi, I'd like to build a toolkit CD specifically for conducting forensics on FreeBSD. I'm not talking about a bootable CD but rather one that I could pop into a CD ROM drive and run trusted commands like ps, netstat, ls, etc., from. I'd like to build a CD that would work on -RELEASE versions of FreeBSD like 5.1 and -STABLE versions of FreeBSD too. Can anyone give me any pointers about how I might accomplish this? I've spent hours searching Google and only found a few links about a guy named Joe Magee who was trying to do the same thing but couldn't find his email addy. I searched the FreeBSD archives but get: None of the archives you requested (freebsd-questions, freebsd-security and freebsd-stable) are available at this time. Please try again later, or return to the search page and select a different archive. Thanks Joe From owner-freebsd-stable@FreeBSD.ORG Sun Aug 3 09:44:18 2003 Return-Path: Delivered-To: freebsd-stable@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 7AECA37B401 for ; Sun, 3 Aug 2003 09:44:18 -0700 (PDT) Received: from hermes.pressenter.com (hermes.pressenter.com [69.58.128.19]) by mx1.FreeBSD.org (Postfix) with ESMTP id 89E0B43FB1 for ; Sun, 3 Aug 2003 09:44:17 -0700 (PDT) (envelope-from nospam@hiltonbsd.com) Received: from [69.58.130.157] (helo=daggar.sbgnet.local) by hermes.pressenter.com with smtp (Exim 3.16 #1) id 19jLxw-0007nK-00; Sun, 03 Aug 2003 11:44:16 -0500 Date: Sun, 3 Aug 2003 11:44:16 -0500 From: Stephen Hilton To: Joe Warner Message-Id: <20030803114416.17cf698f.nospam@hiltonbsd.com> In-Reply-To: <200308030920.45437.rootman22@comcast.net> References: <200308030920.45437.rootman22@comcast.net> X-Mailer: Sylpheed version 0.9.3 (GTK+ 1.2.10; i386-portbld-freebsd4.8) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit cc: freebsd-stable@freebsd.org Subject: Re: Forensics CD Toolkit for FreeBSD X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 03 Aug 2003 16:44:18 -0000 On Sun, 3 Aug 2003 09:20:45 -0600 Joe Warner wrote: > Hi, > > I'd like to build a toolkit CD specifically for conducting > forensics on FreeBSD. I'm not talking about a bootable > CD but rather one that I could pop into a CD ROM drive > and run trusted commands like ps, netstat, ls, etc., from. > > I'd like to build a CD that would work on -RELEASE versions > of FreeBSD like 5.1 and -STABLE versions of FreeBSD too. > > Can anyone give me any pointers about how I might accomplish > this? > > I've spent hours searching Google and only found a few links about > a guy named Joe Magee who was trying to do the same thing but > couldn't find his email addy. I searched the FreeBSD archives but > get: Joe, Try Google-Groups, works great for me, but not all FreeBSD lists are archived (freebsd-gnome is one that I miss that is not there) http://groups.google.com/groups?hl=en&group=mailing.freebsd Regards, Stephen Hilton nospam@hiltonbsd.com From owner-freebsd-stable@FreeBSD.ORG Sun Aug 3 09:53:30 2003 Return-Path: Delivered-To: freebsd-stable@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id B737937B404 for ; Sun, 3 Aug 2003 09:53:30 -0700 (PDT) Received: from mail.yadt.co.uk (yadt.demon.co.uk [158.152.4.134]) by mx1.FreeBSD.org (Postfix) with SMTP id 3B2EE43FA3 for ; Sun, 3 Aug 2003 09:53:27 -0700 (PDT) (envelope-from davidt@yadt.co.uk) Received: (qmail 63838 invoked from network); 3 Aug 2003 16:53:24 -0000 Received: from unknown (HELO mail.gattaca.yadt.co.uk) (@10.0.0.2) by yadt.demon.co.uk with SMTP; 3 Aug 2003 16:53:24 -0000 Received: (qmail 16341 invoked by uid 1000); 3 Aug 2003 16:53:23 -0000 Date: Sun, 3 Aug 2003 17:53:23 +0100 From: David Taylor To: freebsd-stable@freebsd.org, freebsd-security@freebsd.org Message-ID: <20030803165322.GA60646@gattaca.yadt.co.uk> Mail-Followup-To: freebsd-stable@freebsd.org, freebsd-security@freebsd.org References: <200308030920.45437.rootman22@comcast.net> Mime-Version: 1.0 Content-Type: text/plain; charset=iso-8859-15 Content-Disposition: inline In-Reply-To: <200308030920.45437.rootman22@comcast.net> User-Agent: Mutt/1.4.1i Subject: Re: Forensics CD Toolkit for FreeBSD X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 03 Aug 2003 16:53:31 -0000 On Sun, 03 Aug 2003, Joe Warner wrote: > Hi, > > I'd like to build a toolkit CD specifically for conducting > forensics on FreeBSD. I'm not talking about a bootable > CD but rather one that I could pop into a CD ROM drive > and run trusted commands like ps, netstat, ls, etc., from. It would probably need to be a bootable CD-ROM, so that you could trust the kernel wasn't modified to hide information from ps/netstat/ls/etc. > I'd like to build a CD that would work on -RELEASE versions > of FreeBSD like 5.1 and -STABLE versions of FreeBSD too. > > Can anyone give me any pointers about how I might accomplish > this? > > I've spent hours searching Google and only found a few links about > a guy named Joe Magee who was trying to do the same thing but > couldn't find his email addy. I searched the FreeBSD archives but > get: > > None of the archives you requested (freebsd-questions, freebsd-security and > freebsd-stable) are available at this time. > > Please try again later, or return to the search page and select a different > archive. > I think there's other archives of the lists on the mailman site now, but I'm not too sure. -- David Taylor davidt@yadt.co.uk "The future just ain't what it used to be" From owner-freebsd-stable@FreeBSD.ORG Sun Aug 3 10:13:04 2003 Return-Path: Delivered-To: freebsd-stable@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id BABC737B401 for ; Sun, 3 Aug 2003 10:13:04 -0700 (PDT) Received: from lily.ezo.net (nsc.ezo.net [68.23.200.13]) by mx1.FreeBSD.org (Postfix) with ESMTP id EE8D243F3F for ; Sun, 3 Aug 2003 10:13:03 -0700 (PDT) (envelope-from jflowers@ezo.net) Received: from www.ezo.net (peony.ezo.net [68.23.200.11]) by lily.ezo.net (8.12.6/8.12.6) with ESMTP id h73HD7Bj018855 for ; Sun, 3 Aug 2003 13:13:07 -0400 (EDT) (envelope-from jflowers@ezo.net) From: "Jim Flowers" To: freebsd-stable@freebsd.org Date: Sun, 3 Aug 2003 12:14:22 -0500 Message-Id: <20030803165218.M18845@ezo.net> X-Mailer: Open WebMail 1.90 20030310 X-OriginatingIP: 24.93.231.122 (jflowers) MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Subject: Multiple kld loads? X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 03 Aug 2003 17:13:05 -0000 With FreeBSD 4.8-20030731-STABLE #0, dmesg messages indicate: module_register: module miibus/ukphy already exists! linker_file_sysinit "miibus.ko" failed to register! 17 module_register: module pccard/ed already exists! linker_file_sysinit "if_ed.ko" failed to register! 17 This doesn't look dangerous but the rl0 ethernet card just stopped recieving packets suddenly and I'm trying to track down why. Can anyone tell me why this is happening and should I do anything about it? I have installed 100s of versions of fbsd since 2.2 on this same hardware and this has never happened before. I see this was reported on 7/25/03 but, no follow-up: http://lists.freebsd.org/mailman/htdig/freebsd-stable/2003-July/002329.html Thanks. kernel is GENERIC plus the following: ------------------------------------- options IPFIREWALL options IPFIREWALL_VERBOSE options IPFIREWALL_FORWARD options IPFIREWALL_VERBOSE_LIMIT=100 options IPFIREWALL_DEFAULT_TO_ACCEPT options IPDIVERT options HZ=1000 options DUMMYNET Dmesg follows: -------------------------------------- bwm# dmesg Copyright (c) 1992-2003 The FreeBSD Project. Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994 The Regents of the University of California. All rights reserved. FreeBSD 4.8-20030731-STABLE #0: Sun Aug 3 07:47:51 EDT 2003 jflowers@bwm.ezo.net:/usr/src/sys/compile/BWL Timecounter "i8254" frequency 1193182 Hz CPU: Pentium/P54C (133.16-MHz 586-class CPU) Origin = "GenuineIntel" Id = 0x52c Stepping = 12 Features=0x1bf real memory = 67108864 (65536K bytes) config> di bt0 config> di ata1 config> di aic0 config> di aha0 config> di adv0 config> q avail memory = 59940864 (58536K bytes) Preloaded elf kernel "kernel" at 0xc0545000. Preloaded userconfig_script "/boot/kernel.conf" at 0xc054509c. Intel Pentium detected, installing workaround for F00F bug md0: Malloc disk Using $PIR table, 6 entries at 0xc00fdf00 npx0: on motherboard npx0: INT 16 interface pcib0: on motherboard pci0: on pcib0 isab0: at device 7.0 on pci0 isa0: on isab0 atapci0: port 0x7800-0x780f at device 7.1 on pci0 ata0: at 0x1f0 irq 14 on atapci0 ata1: at 0x170 irq 15 on atapci0 pci0: (vendor=0x1106, dev=0x3040) at 7.3 pci0: (vendor=0x7401, dev=0x8139) at 8.0 irq 26 rl0: port 0x7c00-0x7cff mem 0xe4003000-0xe40030ff irq 5 at device 9.0 on pci0 rl0: Ethernet address: 00:30:bd:1d:02:ef miibus0: on rl0 rlphy0: on miibus0 rlphy0: 10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, auto ed0: port 0x8000-0x801f irq 9 at device 17.0 on pci0 ed0: address 00:00:e8:e6:91:3b, type NE2000 (16 bit) pci0: at 18.0 eisa0: on motherboard eisa0: unknown card FP@0000 (0x1a000000) at slot 7 orm0: