LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (https://www.linuxquestions.org/questions/linux-security-4/)
-   -   Credentialed Foundstone scan against RHEL5.5 won't connect. (https://www.linuxquestions.org/questions/linux-security-4/credentialed-foundstone-scan-against-rhel5-5-wont-connect-840812/)

Kapn.K 10-27-2010 02:13 PM

Credentialed Foundstone scan against RHEL5.5 won't connect.
 
Our org uses Foundstone. I gave them a wheel user and verified connectivity with putty from their server to my RH box. Foundstone never makes it in and I don't see anything from faillog, sshd logs, etc. Anyone ever deal with this?
Thanks,
Steve

TB0ne 10-27-2010 02:56 PM

Quote:

Originally Posted by Kapn.K (Post 4141333)
Our org uses Foundstone. I gave them a wheel user and verified connectivity with putty from their server to my RH box. Foundstone never makes it in and I don't see anything from faillog, sshd logs, etc. Anyone ever deal with this?
Thanks,
Steve

Based on what you posted, it looks like a problem in Foundstone. Since you've checked the logs, and don't see anything failing, and you've already verified connectivity from server to server, the only piece left is Foundstone.

You can try to give them another (temporary) user ID to see if you can see anything. Check the logs for SUCCESSFUL logins from that user ID too, since Foundstone may be logging in correctly, then not actually doing anything. :)

rnlott 11-10-2010 09:58 AM

Foundstone Credentialed Scanning
 
Make sure that you are using the "bash" or "ksh" shells in the account that is being used to scan. Also, we use sshv2 certificates to credential scan and it works well.

rnlott 11-10-2010 10:02 AM

In Foundstone, make sure and select " trust unknown remote-shell targets" when you enter credentials into the Foundstone Scanning Tool.

Kapn.K 11-11-2010 10:52 AM

Quote:

Originally Posted by rnlott (Post 4154839)
In Foundstone, make sure and select " trust unknown remote-shell targets" when you enter credentials into the Foundstone Scanning Tool.

Great Ideas! For the first suggestion, is there a setting in foundstone for the shell or should I make sure the red hat account uses bash or ksh? I never verified what is was set up with. I will also try the trust unk...I am forwarding this info to our it security. They normally run the scans but don't have access to our systems(we enter the credentials for them).
Thanks!

rnlott 11-18-2010 07:26 AM

Foundstone Credential Scans
 
The shell for the account created on the Linux machine should be "bash" or "ksh".


All times are GMT -5. The time now is 10:55 AM.