LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-27-2010, 02:13 PM   #1
Kapn.K
LQ Newbie
 
Registered: Oct 2010
Distribution: RHEL, Fedora, Ubuntu
Posts: 15

Rep: Reputation: 0
Question Credentialed Foundstone scan against RHEL5.5 won't connect.


Our org uses Foundstone. I gave them a wheel user and verified connectivity with putty from their server to my RH box. Foundstone never makes it in and I don't see anything from faillog, sshd logs, etc. Anyone ever deal with this?
Thanks,
Steve
 
Old 10-27-2010, 02:56 PM   #2
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 25,830

Rep: Reputation: 7761Reputation: 7761Reputation: 7761Reputation: 7761Reputation: 7761Reputation: 7761Reputation: 7761Reputation: 7761Reputation: 7761Reputation: 7761Reputation: 7761
Quote:
Originally Posted by Kapn.K View Post
Our org uses Foundstone. I gave them a wheel user and verified connectivity with putty from their server to my RH box. Foundstone never makes it in and I don't see anything from faillog, sshd logs, etc. Anyone ever deal with this?
Thanks,
Steve
Based on what you posted, it looks like a problem in Foundstone. Since you've checked the logs, and don't see anything failing, and you've already verified connectivity from server to server, the only piece left is Foundstone.

You can try to give them another (temporary) user ID to see if you can see anything. Check the logs for SUCCESSFUL logins from that user ID too, since Foundstone may be logging in correctly, then not actually doing anything.
 
Old 11-10-2010, 09:58 AM   #3
rnlott
LQ Newbie
 
Registered: Nov 2010
Posts: 3

Rep: Reputation: 0
Foundstone Credentialed Scanning

Make sure that you are using the "bash" or "ksh" shells in the account that is being used to scan. Also, we use sshv2 certificates to credential scan and it works well.
 
Old 11-10-2010, 10:02 AM   #4
rnlott
LQ Newbie
 
Registered: Nov 2010
Posts: 3

Rep: Reputation: 0
In Foundstone, make sure and select " trust unknown remote-shell targets" when you enter credentials into the Foundstone Scanning Tool.
 
Old 11-11-2010, 10:52 AM   #5
Kapn.K
LQ Newbie
 
Registered: Oct 2010
Distribution: RHEL, Fedora, Ubuntu
Posts: 15

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by rnlott View Post
In Foundstone, make sure and select " trust unknown remote-shell targets" when you enter credentials into the Foundstone Scanning Tool.
Great Ideas! For the first suggestion, is there a setting in foundstone for the shell or should I make sure the red hat account uses bash or ksh? I never verified what is was set up with. I will also try the trust unk...I am forwarding this info to our it security. They normally run the scans but don't have access to our systems(we enter the credentials for them).
Thanks!
 
Old 11-18-2010, 07:26 AM   #6
rnlott
LQ Newbie
 
Registered: Nov 2010
Posts: 3

Rep: Reputation: 0
Foundstone Credential Scans

The shell for the account created on the Linux machine should be "bash" or "ksh".
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Not able to connect RHEL5 ES through Xmanager saraswatashish Linux - Newbie 6 07-09-2010 01:53 AM
PCI Wireless, set it up, can scan, but not connect Terror Linux - Wireless Networking 11 03-08-2008 03:47 PM
Fedora 8, Wireless can scan network, asks for password, fails to connect. Learn41 Linux - Newbie 2 02-19-2008 08:46 PM
DWL-G122 Ubuntu Feisty wont connect, shows up on scan amphibioustoaster Linux - Hardware 1 09-29-2007 03:50 AM
Can Scan for Wireless Network.. view it..but cant connect?! Damien295x Fedora 8 10-14-2006 12:24 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:59 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration