UNITY 360: Issueshttp://www.prelude-siem.org/http://www.prelude-siem.org/welcome/themes/prelude/favicon/Prelude-icon.png2017-09-21T16:38:48ZUNITY 360
Redmine Prelude Correlator rules - Tache #907 (New): CVE-2017-9798 - OptionsBleed - Correlationhttp://www.prelude-siem.org/issues/9072017-09-21T16:38:48ZThomas ANDREJAKthomas.andrejak@csgroup.eu
<p>Options Bleed is a simple OPTIONS request, there is no specific patterns. But, to gather enough leaked piece of information to make a full one, the attacker need to request OPTIONS many time.</p> Libprelude - Bug #893 (New): libprelude-errors failed compile on hhurd-i386http://www.prelude-siem.org/issues/8932017-06-24T14:23:44ZThomas ANDREJAKthomas.andrejak@csgroup.eu
<pre>
make[6]: Entering directory '/<<PKGBUILDDIR>>/src/libprelude-error'
LANG="" gawk -f ./mkstrtable.awk -v textidx=3 \
./err-sources.h.in >err-sources.h
LANG="" gawk -f ./mkstrtable.awk -v textidx=3 \
./err-codes.h.in >err-codes.h
LANG="" gawk -f ./mkerrcodes1.awk ./errnos.in >_mkerrcodes.h
gcc -E -P _mkerrcodes.h | grep PRELUDE_ERROR_ | LANG="" gawk -f ./mkerrcodes.awk >mkerrcodes.h
rm _mkerrcodes.h
gcc -g -O2 -fdebug-prefix-map=/<<PKGBUILDDIR>>=. -specs=/usr/share/dpkg/pie-compile.specs -fstack-protector-strong -Wformat -Werror=format-security -I. -I. -o mkerrcodes ./mkerrcodes.c
In file included from ./mkerrcodes.c:26:0:
./mkerrcodes.h:3:3: error: expected identifier or '(' before numeric constant
((0x10 << 26) | ((7) & 0x3fff)) PRELUDE_ERROR_E2BIG
^~~~
./mkerrcodes.h:3:15: error: expected ')' before '|' token
((0x10 << 26) | ((7) & 0x3fff)) PRELUDE_ERROR_E2BIG
^
./mkerrcodes.c: In function 'main':
./mkerrcodes.c:59:31: error: 'err_table' undeclared (first use in this function)
for (i = 0; i < sizeof (err_table) / sizeof (err_table[0]) - 1; i++)
^~~~~~~~~
./mkerrcodes.c:59:31: note: each undeclared identifier is reported only once for each function it appears in
Makefile:1790: recipe for target 'mkerrcodes' failed
</pre> Libprelude - Bug #887 (New): Timer tests on slow systemhttp://www.prelude-siem.org/issues/8872017-05-14T14:22:27ZThomas ANDREJAKthomas.andrejak@csgroup.eu
<p>On slow system, sometimes, timer tests (tests/prelude-timer.c) work works.</p>
<p>Adding "1" to max_expire in for loop solve this</p>
<pre>
- for ( i = 0; i <= max_expire && timer_alive; i++ ) {
+ for ( i = 0; i <= max_expire + 1 && timer_alive; i++ ) {
</pre> Libprelude - Bug #886 (New): Sometimes, test-lock from libmissing wont workshttp://www.prelude-siem.org/issues/8862017-05-14T14:19:50ZThomas ANDREJAKthomas.andrejak@csgroup.eu
<p>Same issues in coreutils and other packages : <a class="external" href="http://pkgs.fedoraproject.org/cgit/rpms/coreutils.git/commit/?id=8d346246">http://pkgs.fedoraproject.org/cgit/rpms/coreutils.git/commit/?id=8d346246</a></p>
<p>Hope that gnulib will update this test</p> Libprelude - Bug #885 (New): Segfault with atfork on arm64, armhf and ppc64elhttp://www.prelude-siem.org/issues/8852017-05-14T14:16:45ZThomas ANDREJAKthomas.andrejak@csgroup.eu
<p>See <a class="external" href="https://bugs.launchpad.net/ubuntu/+source/libprelude/+bug/1262430">https://bugs.launchpad.net/ubuntu/+source/libprelude/+bug/1262430</a></p> Libprelude - Bug #879 (New): M4 for Ruby on Debian 9 not workinghttp://www.prelude-siem.org/issues/8792017-03-27T22:48:17ZThomas ANDREJAKthomas.andrejak@csgroup.eu
<p>The actual M4 (3.1, m4/am_path_ruby) can't detect ruby on debian 9</p>
<p>Here is an example of patch :</p>
<pre>
--- libprelude-3.1.0/m4/am_path_ruby.m4 2017-02-28 18:00:21.227299410 -0500
+++ libprelude-3.1.0/m4/am_path_ruby.m4 2017-02-28 18:01:06.702306372 -0500
@@ -95,7 +95,7 @@
dnl (shared libraries)
AC_CACHE_CHECK([for $am_display_RUBY extension module directory],
[am_cv_ruby_rbexecdir],
- [am_cv_ruby_rbexecdir=`$RUBY -rrbconfig -e "drive = File::PATH_SEPARATOR == ';' ? /\A\w:/ : /\A/; prefix = Regexp.new('\\A' + Regexp.quote(RbConfig::CONFIG[['prefix']])); \\$prefix = RbConfig::CONFIG[['prefix']].sub(drive, ''); \\$sitearchdir = RbConfig::CONFIG[['sitearchdir']].sub(prefix, '\\$(prefix)').sub(drive, ''); print \\$sitearchdir;" 2>/dev/null || echo "${RUBY_EXEC_PREFIX}/local/lib/site_ruby/${RUBY_VERSION}/${RUBY_PLATFORM}"`])
+ [am_cv_ruby_rbexecdir=`$RUBY -r rbconfig -e "print RbConfig::CONFIG[['vendorarchdir']]"`])
AC_SUBST([rbexecdir], [$am_cv_ruby_rbexecdir])
dnl if PKG-CONFIG is available, we use it. Else, we try to dectect RUBY_INCLUDES manually
</pre> Prelude Manager - Bug #878 (New): prelude-manager and Systemdhttp://www.prelude-siem.org/issues/8782017-02-27T22:38:08ZThomas ANDREJAKthomas.andrejak@csgroup.eu
<p>prelude-manager run dir is /var/run/prelude-manager</p>
<p>With systemd, /var/run move to /run</p> Prelude-LML - Bug #872 (New): Prelude-LML check not workinghttp://www.prelude-siem.org/issues/8722017-01-28T18:26:52ZThomas ANDREJAKthomas.andrejak@csgroup.eu
<p>Since we move rules to another subproject (prelude-lml-rules), make check is not working. Error in "tests" folder.</p> PRELUDE SIEM - Bug #870 (New): prelude-lml /etc permissionshttp://www.prelude-siem.org/issues/8702017-01-26T08:38:01ZThomas ANDREJAKthomas.andrejak@csgroup.eu
<p>Why in the /etc/prelude-lml directory, the permissions are forced to 700 and 600?</p> PRELUDE SIEM - Bug #865 (New): make distcheck not working on 32bithttp://www.prelude-siem.org/issues/8652016-12-05T22:33:54ZThomas ANDREJAKthomas.andrejak@csgroup.eu
<p>make distcheck is not working on 32 bits architecture because of timegm behavior.</p> PRELUDE SIEM - Bug #863 (New): FSF address in libprelude-errorhttp://www.prelude-siem.org/issues/8632016-11-30T23:14:57ZThomas ANDREJAKthomas.andrejak@csgroup.eu
<p>Please update FSF address in libprelude-error</p> LibpreludeDB - Bug #392 (Assigned): Potential security risc in preludedb-admin?http://www.prelude-siem.org/issues/3922011-01-15T15:37:50ZPaul Buetowprelude@mx.buetow.org
<p>Hi!</p>
<p>I wanted to ask a question regarding preludedb-admin.</p>
<p>I am using 0.9.14.1-2 (Debian GNU/Linux Lenny). There is no way not to<br />define the database password (e.g. mysql password) NOT in the command<br />line argument. The password shows up in plain text in the system<br />process list while using preludedb-admin.</p>
<p>It should be possible to "pipe" the arguments to preludedb-admin</p>
<p>The current way:</p>
<p>preludedb-admin delete alert "type=mysql name=prelude user=prelude<br />pass=prelude" --criteria "alert.create_time < $DATE"</p>
<p>"Better way":</p>
<p>some-script-generating-arguments | preludedb-admin</p>
<p>(Alternatively just pipe the "type=mysql name=prelude user=prelude" <br />part)</p>
<p>And / Or:</p>
<p>preludedb-admin --args filename</p>
<p>(Alternatively just read the "type=mysql name=prelude user=prelude" <br />part from file)</p>
<p>And / Or:</p>
<p>Read password from an environment variable:</p>
<p>#/bin/sh</p>
<p>export PRELUDE_PASS=prelude<br />exec preludedb-admin delete alert "type=mysql name=prelude<br />user=prelude" --criteria "alert.create_time < $DATE"</p>
<p>And / Or:</p>
<p>Read password from stdin if missing in the argument.</p>
<p>Hope you got my point <img src="/plugin_assets/redmine_wiki_extensions/images/smile.png" alt=":)"></p>
<p>Thanks a lot and best regards,</p> PRELUDE SIEM - Bug #349 (New): SANCP - problem on installhttp://www.prelude-siem.org/issues/3492009-05-18T09:27:51Zjulien aussibaljulien.aussibal@univ-pau.fr
<p>Hello everybody,</p>
<p>I'm trying to install sancp on my computer for looking my network.</p>
<p>First, the link of the tar.gz is dead on this page (<a class="external" href="https://dev.prelude-ids.com/wiki/prelude/InstallingAgentThirdpartySancp">https://dev.prelude-ids.com/wiki/prelude/InstallingAgentThirdpartySancp</a>) .</p>
<p>Secondly, I found a different version on this page : <a class="external" href="http://metre.net/files/">http://metre.net/files/</a><br />but the lastest version doesn't compile with prelude option.</p>
<p>Anybody have a stable version of sancp working with prelude ? Could you indicate how to configure it to log Alert in prelude-manager.</p>
<p>Thanks</p> PRELUDE SIEM - Bug #343 (New): OSSEC-HIDS 1.6.1 always sets assessment.impact.completion = succededhttp://www.prelude-siem.org/issues/3432009-01-25T20:06:12Z
<p>Example: the IDMEF alerts for both of these logs</p>
<pre>
[[WinEvtLog]]: Security: AUDIT_SUCCESS(673): Security: SYSTEM: NT AUTHORITY: SERVER: user@DOMAIN DOMAIN PC$ %{SOMERANDOMUIDHERE} 0x40810010 0x17 10.10.10.10 - {SOMEOTHERUID} -
[[WinEvtLog]]: Security: AUDIT_FAILURE(673): Security: SYSTEM: NT AUTHORITY: SERVER: - 0x2 - 10.10.10.10 0x20 - -
</pre>
<p>have assessment.impact.completion = succeeded</p>
<p>See also: <a class="external" href="http://marc.info/?t=123274084100006&r=1&w=2">http://marc.info/?t=123274084100006&r=1&w=2</a></p> LibpreludeDB - Bug #337 (New): Fake result number of deleted records in preludedb-adminhttp://www.prelude-siem.org/issues/3372008-12-08T17:16:54Z
<p>The output of preludedb-admin was:</p>
<p>delete event failed: Lost connection to [[MySQL]] server during query.</p>
<p>Error at transaction 448000. Use --offset 874000 to resume operation.</p>
<p>2152124949 'delete' events processed in 2783.401760 seconds (0.000001 seconds/events - 773199.535880 delete/sec average).</p>
<p>2152124949 events processed in 2783.401760 seconds (0.000001 seconds/events - 773199.535880 events/sec average).</p>
<p>2152124949 is the fake as '--offset 874000' says where it stopped.</p>