Sunday, 11 September 2016

MHN mnemosyne FATAL status

I found this page

http://webcache.googleusercontent.com/search?q=cache:luZNj4e2uL4J:www.malovisky.com/&num=1&hl=en&gl=uk&strip=1&vwsrc=0

The application mnemosyne is responsible for informing the attacks suffered by the honeypot and without her the operation framework becomes somewhat inoperable.
 If the terminal give the command #python-V you will check that the python version is 2.7.3 and for the application's operation it must be to 2.7.4.

Some more naughty already would drop an apt-get upgrade but from what I have researched the
python 2.7.4 is not part of the source list for ubuntu 12.04.5 only from the 13.

From then on will work.  I hit my head more than a week to fix this problem


wget https://www.python.org/ftp/python/2.7.4/Python-2.7.4.tgz
tar -zxvf Python-2.7.4.tgz
cd Python-2.7.4/
./configure
make
make install
shutdown -r now


cd /opt
rm -rv mnemosyne
cd /opt/mhn/scripts
./install_mnemosyne.sh
shutdown -r now


===
Thanks to https://github.com/malovisky

Sunday, 3 January 2016

MHN and Raspberry Pi

Pi Bits

Back up NOOBs

load up
turn on SSH
note the IP address



Ubuntu MHN install

https://github.com/threatstream/mhn

cd /opt/
sudo apt-get install git -y
sudo git clone https://github.com/threatstream/mhn.git
cd mhn/
sudo ./install.sh




https://github.com/threatstream/mhn/wiki/Deploying-Dionaea-on-a-Raspberry-Pi



Browse from a Windows PC

https://www.bitvise.com/ssh-client-download


Test 1


MHN Troubleshooting

PyMongo Connection Refused 

sudo rm -r /opt/hpfeeds

sudo rm -r /opt/mnemosyne

mongod --repair



./install.sh


Check if firewall port redirects are causing this trouble.



edit the /etc/mongod.conf file and set your bind_ip = 0.0.0.0 in order to make connections externally.





Thanks----


http://stackoverflow.com/questions/24899849/connection-refused-to-mongodb-errno-111

Wednesday, 7 January 2015

MHN - Celery Worker is not working



I needed to navigate to


cd /opt/mhn/servers


Then


cd $MHN_HOME/server
sudo chown www-data mhn.log
sudo supervisorctl start mhn-celery-worker









==Thanks==


https://github.com/threatstream/mhn/wiki/MHN-Troubleshooting-Guide



Wednesday, 29 October 2014

My Live Test

MHN Dionaea ThreatMap





Set MHN for local rfc1918 addresses

#!/bin/bash

# LocalMHN to set MHN for rfc1918 private / local networks CEM 29/Oct/2014

cd /opt/mnemosyne/
git fetch origin
git stash
git merge origin/master
git stash pop

sed -i 's/ignore_rfc1918 = True/ignore_rfc1918 = False/g' mnemosyne.cfg

supervisorctl restart mnemosyne

supervisorctl status


====take two ===


#!/bin/bash

# LocalMHN to set MHN for rfc1918 private / local networks CEM 22/Sept/2014
# Also trap mac addresses in Dionaea for analysis

cd /opt/mnemosyne/
git fetch origin
git stash
git merge origin/master
git stash pop

sed -i 's/ignore_rfc1918 = True/ignore_rfc1918 = False/g' mnemosyne.cfg

sed -i 's/lookup_ethernet_addr = "no"/lookup_ethernet_addr = "yes"/g' /etc/dionaea/dionaea.conf


supervisorctl restart mnemosyne


sudo supervisorctl restart dionaea


supervisorctl status



Friday, 24 October 2014

Enable MHN Dionaea Sandbox submission

Regarding the sandbox submission, we don't have this enabled now. Do do so, you need to do a couple things.  

sudo gedit /etc/dionaea/dionaea.conf
.

1. find the line that looks like this (in the ihandlers section):
// "virustotal",
and uncomment it.

2. Find the section that looks like this:
virustotal = {
     apikey = "........." // grab it from your virustotal account at My account -> Inbox -> Public API
     file = "var/dionaea/vtcache.sqlite"
}

and fill in your API key.


2f226f10dfe3a6b2d==
f0102876b42070cd2==
7f86543ae28d79443==
bdd98eb539708

3 Save dionaea.conf and restart
sudo supervisorctl restart dionaea


--
Thanks 

Jason @ Threatstream