I found this page
http://webcache.googleusercontent.com/search?q=cache:luZNj4e2uL4J:www.malovisky.com/&num=1&hl=en&gl=uk&strip=1&vwsrc=0
The application mnemosyne is responsible for informing the attacks suffered by the honeypot and without her the operation framework becomes somewhat inoperable.
If the terminal give the command #python-V you will check that the python version is 2.7.3 and for the application's operation it must be to 2.7.4.
Some more naughty already would drop an apt-get upgrade but from what I have researched the
python 2.7.4 is not part of the source list for ubuntu 12.04.5 only from the 13.
From then on will work. I hit my head more than a week to fix this problem
wget https://www.python.org/ftp/python/2.7.4/Python-2.7.4.tgz
tar -zxvf Python-2.7.4.tgz
cd Python-2.7.4/
./configure
make
make install
shutdown -r now
cd /opt
rm -rv mnemosyne
cd /opt/mhn/scripts
./install_mnemosyne.sh
shutdown -r now
===
Thanks to https://github.com/malovisky
Sunday, 11 September 2016
Sunday, 3 January 2016
MHN and Raspberry Pi
Pi Bits
Back up NOOBs
load up
turn on SSH
note the IP address
Ubuntu MHN install
https://github.com/threatstream/mhn
cd /opt/
sudo apt-get install git -y
sudo git clone https://github.com/threatstream/mhn.git
cd mhn/
sudo ./install.sh
https://github.com/threatstream/mhn/wiki/Deploying-Dionaea-on-a-Raspberry-Pi
Browse from a Windows PC
https://www.bitvise.com/ssh-client-download
Test 1
Back up NOOBs
load up
turn on SSH
note the IP address
Ubuntu MHN install
https://github.com/threatstream/mhn
cd /opt/
sudo apt-get install git -y
sudo git clone https://github.com/threatstream/mhn.git
cd mhn/
sudo ./install.sh
https://github.com/threatstream/mhn/wiki/Deploying-Dionaea-on-a-Raspberry-Pi
Browse from a Windows PC
https://www.bitvise.com/ssh-client-download
Test 1
MHN Troubleshooting
PyMongo Connection Refused
sudo rm -r /opt/hpfeeds
sudo rm -r /opt/mnemosyne
mongod --repair
edit the /etc/mongod.conf file and set your bind_ip = 0.0.0.0 in order to make connections externally.
Thanks----
http://stackoverflow.com/questions/24899849/connection-refused-to-mongodb-errno-111
sudo rm -r /opt/hpfeeds
sudo rm -r /opt/mnemosyne
mongod --repair
./install.sh
Check if firewall port redirects are causing this trouble.
edit the /etc/mongod.conf file and set your bind_ip = 0.0.0.0 in order to make connections externally.
Thanks----
http://stackoverflow.com/questions/24899849/connection-refused-to-mongodb-errno-111
Wednesday, 7 January 2015
MHN - Celery Worker is not working
I needed to navigate to
cd /opt/mhn/servers
Then
cd $MHN_HOME/server
sudo chown www-data mhn.log
sudo supervisorctl start mhn-celery-worker
==Thanks==
https://github.com/threatstream/mhn/wiki/MHN-Troubleshooting-Guide
Wednesday, 29 October 2014
Set MHN for local rfc1918 addresses
#!/bin/bash
# LocalMHN to set MHN for rfc1918 private / local networks CEM 29/Oct/2014
cd /opt/mnemosyne/
git fetch origin
git stash
git merge origin/master
git stash pop
sed -i 's/ignore_rfc1918 = True/ignore_rfc1918 = False/g' mnemosyne.cfg
supervisorctl restart mnemosyne
supervisorctl status
====take two ===
# LocalMHN to set MHN for rfc1918 private / local networks CEM 29/Oct/2014
cd /opt/mnemosyne/
git fetch origin
git stash
git merge origin/master
git stash pop
sed -i 's/ignore_rfc1918 = True/ignore_rfc1918 = False/g' mnemosyne.cfg
supervisorctl restart mnemosyne
supervisorctl status
====take two ===
#!/bin/bash
# LocalMHN to set MHN for rfc1918 private / local networks CEM 22/Sept/2014
# Also trap mac addresses in Dionaea for analysis
cd /opt/mnemosyne/
git fetch origin
git stash
git merge origin/master
git stash pop
sed -i 's/ignore_rfc1918 = True/ignore_rfc1918 = False/g' mnemosyne.cfg
sed -i 's/lookup_ethernet_addr = "no"/lookup_ethernet_addr = "yes"/g' /etc/dionaea/dionaea.conf
supervisorctl restart mnemosyne
sudo supervisorctl restart dionaea
supervisorctl status
# LocalMHN to set MHN for rfc1918 private / local networks CEM 22/Sept/2014
# Also trap mac addresses in Dionaea for analysis
cd /opt/mnemosyne/
git fetch origin
git stash
git merge origin/master
git stash pop
sed -i 's/ignore_rfc1918 = True/ignore_rfc1918 = False/g' mnemosyne.cfg
sed -i 's/lookup_ethernet_addr = "no"/lookup_ethernet_addr = "yes"/g' /etc/dionaea/dionaea.conf
supervisorctl restart mnemosyne
sudo supervisorctl restart dionaea
supervisorctl status
Friday, 24 October 2014
Enable MHN Dionaea Sandbox submission
Regarding the sandbox submission, we don't have this enabled now. Do do so, you need to do a couple things.
sudo gedit /etc/dionaea/dionaea.conf
.
1. find the line that looks like this (in the ihandlers section):
// "virustotal",
and uncomment it.
2. Find the section that looks like this:
virustotal = {
apikey = "........." // grab it from your virustotal account at My account -> Inbox -> Public API
file = "var/dionaea/vtcache.sqlite"
}
and fill in your API key.
sudo gedit /etc/dionaea/dionaea.conf
.
1. find the line that looks like this (in the ihandlers section):
// "virustotal",
and uncomment it.
2. Find the section that looks like this:
virustotal = {
apikey = "........." // grab it from your virustotal account at My account -> Inbox -> Public API
file = "var/dionaea/vtcache.sqlite"
}
and fill in your API key.
2f226f10dfe3a6b2d==
f0102876b42070cd2==
7f86543ae28d79443==
bdd98eb539708
3 Save dionaea.conf and restart
sudo supervisorctl restart dionaea
--
Thanks
Jason @ Threatstream
Subscribe to:
Posts (Atom)