From owner-freebsd-ports-bugs@FreeBSD.ORG Thu Sep 14 09:50:22 2006 Return-Path: X-Original-To: freebsd-ports-bugs@hub.freebsd.org Delivered-To: freebsd-ports-bugs@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 8992316A47C for ; Thu, 14 Sep 2006 09:50:22 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id 0DC2A43D5A for ; Thu, 14 Sep 2006 09:50:20 +0000 (GMT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.4/8.13.4) with ESMTP id k8E9oKaf011185 for ; Thu, 14 Sep 2006 09:50:20 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.13.4/8.13.4/Submit) id k8E9oKJF011184; Thu, 14 Sep 2006 09:50:20 GMT (envelope-from gnats) Resent-Date: Thu, 14 Sep 2006 09:50:20 GMT Resent-Message-Id: <200609140950.k8E9oKJF011184@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-ports-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, Richard Bejtlich Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id E314116A416 for ; Thu, 14 Sep 2006 09:48:58 +0000 (UTC) (envelope-from nobody@FreeBSD.org) Received: from www.freebsd.org (www.freebsd.org [216.136.204.117]) by mx1.FreeBSD.org (Postfix) with ESMTP id 5103943D45 for ; Thu, 14 Sep 2006 09:48:58 +0000 (GMT) (envelope-from nobody@FreeBSD.org) Received: from www.freebsd.org (localhost [127.0.0.1]) by www.freebsd.org (8.13.1/8.13.1) with ESMTP id k8E9mwCA086002 for ; Thu, 14 Sep 2006 09:48:58 GMT (envelope-from nobody@www.freebsd.org) Received: (from nobody@localhost) by www.freebsd.org (8.13.1/8.13.1/Submit) id k8E9mwIW085999; Thu, 14 Sep 2006 09:48:58 GMT (envelope-from nobody) Message-Id: <200609140948.k8E9mwIW085999@www.freebsd.org> Date: Thu, 14 Sep 2006 09:48:58 GMT From: Richard Bejtlich To: freebsd-gnats-submit@FreeBSD.org X-Send-Pr-Version: www-2.3 Cc: Subject: ports/103257: Missing directory prevents Nepenthes from running out-of-the-box X-BeenThere: freebsd-ports-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Ports bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 14 Sep 2006 09:50:22 -0000 >Number: 103257 >Category: ports >Synopsis: Missing directory prevents Nepenthes from running out-of-the-box >Confidential: no >Severity: non-critical >Priority: low >Responsible: freebsd-ports-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: change-request >Submitter-Id: current-users >Arrival-Date: Thu Sep 14 09:50:19 GMT 2006 >Closed-Date: >Last-Modified: >Originator: Richard Bejtlich >Release: 6.1 SECURITY >Organization: TaoSecurity >Environment: FreeBSD vectra.taosecurity.com 6.1-SECURITY FreeBSD 6.1-SECURITY #0: Mon Aug 28 05:21:08 UTC 2006 root@builder.daemonology.net:/usr/obj/usr/src/sys/GENERIC i386 >Description: The Nepenthes port almost works out-of-the-box. All that's missing is the /usr/local/var/nepenthes/binaries directory. Without it, Nepenthes dies. I also noticed /usr/local/etc/nepenthes/nepenthes.conf makes this reference: hexdump_path "var/nepenthes/hexdumps/"; /usr/local/var/nepenthes/hexdumps doesn't exist. >How-To-Repeat: vectra:/root# nepenthes ..edited... Nepenthes Version 0.1.7 Compiled on FreeBSD/x86 at Sep 13 2006 21:15:02 with g++ 3.4.4 [FreeBSD] 20050518 Started on vectra.taosecurity.com running FreeBSD/i386 release 6.1-SECURITY [ info mgr ] Loaded Nepenthes Configuration from "/usr/local/etc/nepenthes/nepenthes.conf". [ info sc module ] Loading signatures from file var/cache/nepenthes/signatures/shellcode-signatures.sc [ crit mgr submit ] Could not open var/nepenthes/binaries/ No such file or directory vectra:/root# vectra:/root# ls /usr/local/var binaries cache hexdumps log spool >Fix: vectra:/root# mkdir -p /usr/local/var/nepenthes/binaries vectra:/root# nepenthes ..edited... Nepenthes Version 0.1.7 Compiled on FreeBSD/x86 at Sep 13 2006 21:15:02 with g++ 3.4.4 [FreeBSD] 20050518 Started on vectra.taosecurity.com running FreeBSD/i386 release 6.1-SECURITY [ info mgr ] Loaded Nepenthes Configuration from "/usr/local/etc/nepenthes/nepenthes.conf". [ info sc module ] Loading signatures from file var/cache/nepenthes/signatures/shellcode-signatures.sc [ info mgr ] logfile var/log/nepenthes/nepenthes.log does not exist yet [ crit mgr ] Compiled without support for capabilities, no way to run capabilities Alternatively, edit /usr/local/etc/nepenthes/nepenthes.conf filesdir "var/nepenthes/binaries/"; change to filesdir "var/binaries/"; The same is true for the hexdumps directory: hexdump_path "var/nepenthes/hexdumps/"; change to hexdump_path "var/hexdumps/"; Another solution is to leave the nepenthes.conf file alone and change the directories that are created. Thank you! >Release-Note: >Audit-Trail: >Unformatted: