{"id":254,"date":"2002-05-03T12:54:05","date_gmt":"2002-05-03T17:54:05","guid":{"rendered":"http:\/\/blogs.terrorware.com\/geoff\/2002\/05\/03\/76126207\/"},"modified":"2002-05-03T12:54:05","modified_gmt":"2002-05-03T17:54:05","slug":"76126207","status":"publish","type":"post","link":"https:\/\/blogs.terrorware.com\/geoff\/2002\/05\/03\/76126207\/","title":{"rendered":"76126207"},"content":{"rendered":"<h3>project &#8211; 05.03.2002<\/h3>\n<p><i>Originally written 05.03.2002<\/i>.<\/p>\n<ul>\n<li>downloaded the bash patch from <a href=\"http:\/\/project.honeynet.org\/papers\/honeynet\/bash.patch\" target=\"_blank\">http:\/\/project.honeynet.org\/papers\/honeynet\/bash.patch<\/a> and the bash-2.03 source RPM from <a href=\"ftp:\/\/ftp.redhat.com\/pub\/redhat\/linux\/6.2\/en\/os\/i386\/SRPMS\/bash2-2.03-8.src.rpm\" target=\"_blank\">ftp:\/\/ftp.redhat.com\/pub\/redhat\/linux\/6.2\/en\/os\/i386\/SRPMS\/bash2-2.03-8.src.rpm<\/a>. Installed the source RPM, copied the patch to the \/usr\/src\/redhat\/SOURCES\/bash-2.03-syslog.patch and commented out the other patches in the RPM spec file.  The changes I made are here:<br \/>\n<blockquote>\n<pre>\n10,16c10,15\n Patch0: bash-2.03-paths.patch\n&gt; Patch1: bash-2.02-security.patch\n&gt; Patch2: bash-2.02.1-arm.patch\n&gt; Patch3: bash-2.03-profile.patch\n&gt; Patch4: bash-2.03-bash2.patch\n&gt; Patch5: bash-2.03-requires.patch\n44,52c43,50\n _distribution\n _patchlevel\n---\n&gt; %patch0 -p1 -b .paths\n&gt; %patch1 -p1 -b .security\n&gt; %patch2 -p1 -b .arm\n&gt; %patch3 -p1 -b .profile\n&gt; %patch4 -p1 -b .bash2\n&gt; %patch5 -p1 -b .requires\n&gt; echo %{version} &gt; _distribution\n&gt; echo %{release} &gt; _patchlevel\n\t<\/pre>\n<\/blockquote>\n<p>\tI then tried to build a new RPM with the command &#8220;rpm -bb &#8211;clean &#8211;rmsource bash2.spec&#8221; and the bash executable compiled fine, but something messed up on the documentation.  So much for building an RPM.<\/li>\n<li>\n\tcopied the modified bash files to the honeypots.  overwrote the normal \/bin\/bash with the patched version.  deleted \/bin\/tcsh and \/bin\/csh.  \/bin\/bash2 and \/bin\/sh are already symlinked to \/bin\/bash.\n\t<\/li>\n<li>\n\t  here&#8217;s a look at some logged shell commands on hermione sent to the remote syslog server, ron:<\/p>\n<blockquote>\n<pre>\nMay  3 07:29:31 xxx.xxx.xxx.xxx bash: HISTORY: PID=572 UID=0 cd \/bin\/\nMay  3 07:29:31 xxx.xxx.xxx.xxx bash: HISTORY: PID=572 UID=0 ls\nMay  3 07:29:34 xxx.xxx.xxx.xxx bash: HISTORY: PID=572 UID=0 ls -l sh\n\t    <\/pre>\n<\/blockquote>\n<\/li>\n<li>note that this type of dcap isn&#8217;t particularly effective since any cracker worth her salt is going to replace the shell as soon as the box gets rooted.<\/li>\n<li>modified my honeynet setup scripts to copy common files to the mounted honeypot filesystems. <\/li>\n<li>began looking at the firewall configuration.  i&#8217;m going to use iptables to start to keep things simple.  figured a good place to start would be the honeynet projects sample iptables config at <a href=\"http:\/\/project.honeynet.org\/papers\/honeynet\/rc.firewall\" target=\"_blank\">http:\/\/project.honeynet.org\/papers\/honeynet\/rc.firewall<\/a>.  looks like i should read the NAT howto and the packet filtering howto at <a href=\"http:\/\/netfilter.samba.org\/documentation\/\" target=\"_blank\">http:\/\/netfilter.samba.org\/documentation\/<\/a><\/li>\n<li>changed the networking of the virtual honeynet so the honeypots have unroutable ips (192.168.0.*) because it seems like the honeynet project&#8217;s firewalling script wants to do nat.  who am i to argue?<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>project &#8211; 05.03.2002 Originally written 05.03.2002. downloaded the bash patch from http:\/\/project.honeynet.org\/papers\/honeynet\/bash.patch and the bash-2.03 source RPM from ftp:\/\/ftp.redhat.com\/pub\/redhat\/linux\/6.2\/en\/os\/i386\/SRPMS\/bash2-2.03-8.src.rpm. Installed the source RPM, copied the patch to the \/usr\/src\/redhat\/SOURCES\/bash-2.03-syslog.patch and commented out the other patches in the RPM spec file. The changes I made are here: 10,16c10,15 Patch0: bash-2.03-paths.patch &gt; Patch1: bash-2.02-security.patch &gt; Patch2: bash-2.02.1-arm.patch&hellip; <a class=\"more-link\" href=\"https:\/\/blogs.terrorware.com\/geoff\/2002\/05\/03\/76126207\/\">Continue reading <span class=\"screen-reader-text\">76126207<\/span><\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[1],"tags":[],"class_list":["post-254","post","type-post","status-publish","format-standard","hentry","category-uncategorized","entry"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/s4wnIz-76126207","_links":{"self":[{"href":"https:\/\/blogs.terrorware.com\/geoff\/wp-json\/wp\/v2\/posts\/254","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.terrorware.com\/geoff\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.terrorware.com\/geoff\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.terrorware.com\/geoff\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.terrorware.com\/geoff\/wp-json\/wp\/v2\/comments?post=254"}],"version-history":[{"count":0,"href":"https:\/\/blogs.terrorware.com\/geoff\/wp-json\/wp\/v2\/posts\/254\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.terrorware.com\/geoff\/wp-json\/wp\/v2\/media?parent=254"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.terrorware.com\/geoff\/wp-json\/wp\/v2\/categories?post=254"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.terrorware.com\/geoff\/wp-json\/wp\/v2\/tags?post=254"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}