LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-12-2008, 09:25 AM   #1
mihalisla
Member
 
Registered: Jun 2006
Location: greece
Distribution: ubuntu 6.06 amd64
Posts: 132

Rep: Reputation: 15
samhain --enable-stealth question


Hello to all of you I have ./configured samhain with steath option enabled.
How can I edit samhainrc???It is in postscript format and the samhain_steath tool only gives me the file in stdout.
If thereis a way to convert it in an editable format ,how can I convert it back to a .ps format???

Great Thanks!!!!
 
Old 12-12-2008, 12:44 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
See 'samhain_stealth'? With "-s" it hides and with "-g" it should reveal configuration.
 
Old 12-12-2008, 06:55 PM   #3
mihalisla
Member
 
Registered: Jun 2006
Location: greece
Distribution: ubuntu 6.06 amd64
Posts: 132

Original Poster
Rep: Reputation: 15
dear unspawn I can see the output of samhain_stealth but i can not edit the samhainrc file.
Is there a way not only to see the file but also to edit it???
 
Old 12-12-2008, 07:57 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
No, as far as I know you'll have to extract it to a file, edit it and put it back in.
 
Old 12-12-2008, 08:24 PM   #5
mihalisla
Member
 
Registered: Jun 2006
Location: greece
Distribution: ubuntu 6.06 amd64
Posts: 132

Original Poster
Rep: Reputation: 15
how can i do this ?
Could you please give me the procedure and an example maybe???
 
Old 12-12-2008, 08:41 PM   #6
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Running 'samhain_stealth -g bar.ps > foo; extracts file foo from bar.ps after which you should be able to edit it. After editing running 'samhain_stealth -s bar.ps foo' places foo back into bar. I don't quite get it because the Samhain manual and running 'samhain_stealth' without arguments show you how to create an uncompressed postscript file and show you the commands?
 
Old 12-12-2008, 08:56 PM   #7
mihalisla
Member
 
Registered: Jun 2006
Location: greece
Distribution: ubuntu 6.06 amd64
Posts: 132

Original Poster
Rep: Reputation: 15
Smile

Lots of thanks unspawn !!!I read only chapter about stealth on the manual!!!

As we say here in Greece you are the corner stone of the house in the security section in our forum!!!!

Our obligation is to pass any knowledge gained for linux to others!!!

Thank you once again!!!
 
Old 12-13-2008, 10:53 AM   #8
mihalisla
Member
 
Registered: Jun 2006
Location: greece
Distribution: ubuntu 6.06 amd64
Posts: 132

Original Poster
Rep: Reputation: 15
The MISTAKE ..... SO AS NOT TO BE MADE BY OTHERS ...................................
the samhain_stealth help file says
-s hide file 'what' in PS image 'where'
-g get hidden data from PS image 'where'
(output to stdout)
When issuing the cmd samhain_stealth -s 'what' 'ps file' IS WRONG
AS UnSpawn said earlier the syntax is samhain_stealth -s 'ps file' (no pipe in the middle) 'what' (the txt file from the extraction of samhain_stealth -g 'ps file' >(with pipe to extraction) 'what'
() are for comments
 
Old 12-14-2008, 08:40 PM   #9
mihalisla
Member
 
Registered: Jun 2006
Location: greece
Distribution: ubuntu 6.06 amd64
Posts: 132

Original Poster
Rep: Reputation: 15
additional problem and question

Although I edited the cnf file of samhain the
samhain -t init doesn't do anything!
1. the lines with one '#'in the samhainrc are read from samhain , or are they quoted???(I mean taken as notes...sorry for my english)
2. if i don't edit the cfg file samhain initiates but it doesn't give anything as output from the cmd samhain -t check
Possible reasons???
Has anybody run on with ubuntu with options
./configure --with-gpg=/usr/bin/gpg --with-fp=DBAB3E5EBD75A9FFD65D0EEAECACA2758C9ACA18 --with-checksum=no --enable-login-watch --enable-suidcheck --enable-install-name=name --enable-stealth=197 --with-log-file=/var/log/name/name_log

I 've been trying aweek know to make it run ...please help

Thank you a lot!!!
 
  


Reply

Tags
help, samhain, stealth



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Does anybody/has anybody used Samhain.. a HIDS similar to Tripwire helptonewbie Linux - Security 4 09-12-2008 12:43 PM
what can or can't OSSEC do compare to samhain? kissfreeman Linux - Newbie 3 06-19-2008 07:56 AM
Is anyone using Samhain with centralized logging? abefroman Linux - Security 6 04-10-2008 12:40 PM
Samhain vs Osiris? Opinions welcome. humbletech99 Linux - Security 1 01-02-2007 03:49 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:26 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration