Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 26 Mar 2011 02:05:06 GMT
From:      Muhammad Najmi Ahmad Zabidi <najmi.zabidi@gmail.com>
To:        freebsd-gnats-submit@FreeBSD.org
Subject:   misc/155941: mwserv library support is not included in nepenthes.conf config file for Nepenthes honeypot port
Message-ID:  <201103260205.p2Q256sZ047061@red.freebsd.org>
Resent-Message-ID: <201103260210.p2Q2AB04003837@freefall.freebsd.org>

next in thread | raw e-mail | index | archive | help

>Number:         155941
>Category:       misc
>Synopsis:       mwserv library support is not included in nepenthes.conf config file for Nepenthes honeypot port
>Confidential:   no
>Severity:       non-critical
>Priority:       medium
>Responsible:    freebsd-bugs
>State:          open
>Quarter:        
>Keywords:       
>Date-Required:
>Class:          update
>Submitter-Id:   current-users
>Arrival-Date:   Sat Mar 26 02:10:11 UTC 2011
>Closed-Date:
>Last-Modified:
>Originator:     Muhammad Najmi Ahmad Zabidi
>Release:        FreeBSD 8.2
>Organization:
International Islamic University Malaysia
>Environment:
FreeBSD freebsd 8.2-RELEASE FreeBSD 8.2-RELEASE #0: Fri Feb 18 02:24:46 UTC 2011     root@almeida.cse.buffalo.edu:/usr/obj/usr/src/sys/GENERIC  i386

>Description:
Support for mwserv is not included while the mwserv library is already in /lib

[root@freebsd /usr/local/etc]# ls -lh ../lib/nepenthes/submitmwserv.*
-rw-r--r--  1 root  wheel    79K Feb  3 09:41 ../lib/nepenthes/submitmwserv.a
-rwxr-xr-x  1 root  wheel   923B Feb  3 09:41 ../lib/nepenthes/submitmwserv.la
-rwxr-xr-x  1 root  wheel    68K Feb  3 09:41 ../lib/nepenthes/submitmwserv.so


>How-To-Repeat:
It's default in the port came in. Basically whoever have an access to https://alliance.mwcollect.org/ for malware heartbeat will need this
>Fix:
Patch for nepenthes.conf:


+   "submitmwserv.so",              "submit-mwserv.conf",       ""


Patch attached with submission follows:

+   "submitmwserv.so",	            "submit-mwserv.conf",	"" 


>Release-Note:
>Audit-Trail:
>Unformatted:



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201103260205.p2Q256sZ047061>