<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="http://dev1galaxy.org/extern.php?action=feed&amp;tid=1598&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / Strange Bash under grsecurity's exec logging]]></title>
		<link>http://dev1galaxy.org/viewtopic.php?id=1598</link>
		<description><![CDATA[The most recent posts in Strange Bash under grsecurity's exec logging.]]></description>
		<lastBuildDate>Sat, 16 Jun 2018 18:44:05 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: Strange Bash under grsecurity's exec logging]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=10111#p10111</link>
			<description><![CDATA[<p>It is the same info that I have, as I just posted at:</p><p>Re: Grsecurity/Pax installation on Debian GNU/Linux<br /><a href="http://forums.debian.net/viewtopic.php?f=16&amp;t=108616&amp;p=675341#p675341" rel="nofollow">http://forums.debian.net/viewtopic.php? … 41#p675341</a></p><p>(or would it be better that I simply paste it here, I don&#039;t know... The link, this time, should suffice).</p>]]></description>
			<author><![CDATA[dummy@example.com (miroR)]]></author>
			<pubDate>Sat, 16 Jun 2018 18:44:05 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=10111#p10111</guid>
		</item>
		<item>
			<title><![CDATA[Re: Strange Bash under grsecurity's exec logging]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=5133#p5133</link>
			<description><![CDATA[<p>In case there&#039;s anybody looking more seriously into these quirks/(exploits?), the system is Asrock Extreme 4<br /><a href="https://www.asrock.com/mb/AMD/970%20Extreme4/" rel="nofollow">https://www.asrock.com/mb/AMD/970%20Extreme4/</a><br />You can also find out more datails at:<br />Use old amd64 gentoo image on new amd64 hardware, possible?<br /><a href="https://forums.gentoo.org/viewtopic-t-940916.html" rel="nofollow">https://forums.gentoo.org/viewtopic-t-940916.html</a><br />That&#039;s when I bought those MBO&#039;s and most of the other components.</p>]]></description>
			<author><![CDATA[dummy@example.com (miroR)]]></author>
			<pubDate>Sun, 24 Sep 2017 11:39:56 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=5133#p5133</guid>
		</item>
		<item>
			<title><![CDATA[Re: Strange Bash under grsecurity's exec logging]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=5077#p5077</link>
			<description><![CDATA[<p>I&#039;ve posted what I promised at:<br />Strange script planted with Bash 2<br /><a href="https://www.croatiafidelis.hr/foss/cap/cap-170504-strange-bash/strange-bash-2.php" rel="nofollow">https://www.croatiafidelis.hr/foss/cap/ … bash-2.php</a></p><p>I don&#039;t believe the possible issue here, and it does seem to me to be something very fishy in there... is related in particular way to Devuan, other than Devuan being a Linux, the vulnerable distro, because the good ways have been rejected because the geniuses that kept patching Mr Linux&#039;s kernel were attempted to be ripped off of their code, by Google, and likely in (but that I don&#039;t claim) with at least the approval of, if not in cahoots with, the aforesaid mister in charge...</p><p>Ah, but grsecurity has been taken the baton of by, I hope to God, competent people, one of them being our own, Devuan&#039;s own developer <span style="color: brown">parazyd</span>! I hope <span style="color: brown">miniply</span>, <span style="color: brown">parazyd</span> and friends make it... (Read about it in the link to grsec installation on Devuan below, in post(s) three days ago or so, of mine there.)</p><p>Aah...</p><p>Use grsecurity:</p><p>Grsecurity/Pax installation on Devuan GNU/Linux<br /><a href="https://dev1galaxy.org/viewtopic.php?id=596" rel="nofollow">https://dev1galaxy.org/viewtopic.php?id=596</a></p><p>It&#039;s the only hope left for Linux kernel&#039;s security...</p>]]></description>
			<author><![CDATA[dummy@example.com (miroR)]]></author>
			<pubDate>Mon, 18 Sep 2017 13:12:38 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=5077#p5077</guid>
		</item>
		<item>
			<title><![CDATA[Strange Bash under grsecurity's exec logging]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=5076#p5076</link>
			<description><![CDATA[<p>title: Strange Bash under grsecurity&#039;s exec logging<br />---<br />I&#039;m almost certain it will happen, because I tried it in my master Air-Gapped system which this systemmodel MBO and most other hardware) is a dd&#039;ed clone of, and very fresh: only browsed <a href="https://dev1galaxy.org/" rel="nofollow">https://dev1galaxy.org/</a> just to send an email and to post (first or only today&#039;s post) in<br />Grsecurity/Pax installation on Devuan GNU/Linux<br /><a href="https://dev1galaxy.org/viewtopic.php?id=596" rel="nofollow">https://dev1galaxy.org/viewtopic.php?id=596</a><br />(BTW see there about what <span style="color: green">exec_logging</span> and <span style="color: green">audit_chdir</span> features of grsecurity are).</p><div class="codebox"><pre><code>mr@gdOv:~$ cd src/linux-4.9.50
mr@gdOv:~/src/linux-4.9.50$</code></pre></div><p>And now I type, without hitting Tab up to this point &quot;make menucon&quot;:</p><div class="codebox"><pre><code>mr@gdOv:~/src/linux-4.9.50$ make menucon</code></pre></div><p>And, sure, I need the complete command, which is &quot;make menuconfig&quot;. And I will next hit Tab.</p><p>But I&#039;ll run my <a href="https://github.com/miroR/uncenz" rel="nofollow">uncenz</a> script, but without going online, to get to the reader very clear understanding (along with the paste of the lines that will appear before viewer&#039;s eyes in the <strong>/var/log/kern.log</strong>, which is being tail&#039;ed to the fore in the terminal on my screen in bottom left with &quot;tail -f&quot;.</p><p>There. It&#039;s 46 seconds of mistery, for me, now... The Screen_170918_0646_gdO.mkv which I get with my uncenz (primitive) program I need to convert to be web-friendly. I&#039;ll do it with:</p><div class="codebox"><pre><code>i=Screen_170918_0646_gdO ; ffmpeg -i ${i}.mkv -map 0:v -b:v 200k -c:v libvpx -qmin 0 -qmax 20 -crf 5 ${i}.webm</code></pre></div><p>At second 28 from the start, after I moved the mouse for you to turn your attention where the logs will start to flow, in bottom left, I just, you of course don&#039;t see it, but I just hit Tab, while the cursor being positioned right after &quot;make menucon&quot;. </p><p>Previously you saw me copy the time count of the rsyslog&#039;s line, and paste it into the prepared command line that only waited for that input, and it, upon my later hitting Enter on that command, went like this:</p><div class="codebox"><pre><code>root@gdOv:/home/mr# echo 0 &gt; /proc/sys/kernel/grsecurity/tpe ; echo 0 &gt;  /proc/sys/kernel/grsecurity/tpe_restrict_all ; 
root@gdOv:/home/mr# cat /var/log/kern.log | grep -aE -A300000  12983.777942 &gt; kern.log_$(date +%y%m%d_%H%M%S)_$(hostname)0
root@gdOv:/home/mr# ls -l kern.log_170918_064755_gdOv0 
-rw-r--r-- 1 root root 97748 2017-09-18 06:47 kern.log_170918_064755_gdOv0
root@gdOv:/home/mr# </code></pre></div><p>That&#039;s a lot of log line isn&#039;t it?</p><p>And here I&#039;ll post it for your perusal, in the next post.</p><p>Just, I believe in hashing and timestamping when credibility is necessary with strange events in computing. So, first, before I make the screencast available on <a href="https://www.CroatiaFidelis.hr" rel="nofollow">https://www.CroatiaFidelis.hr</a>, as well as the <strong>kern.log_170918_064755_gdOv0</strong> created above, here&#039;s their hashes:</p><div class="codebox"><pre><code>f687eb6412b9880eb5bffe076671e942f2eaa061344dac25e1c88d762138ec8b  Screen_170918_0646_gdO.webm
1d3b3ba803567142c01b9014d9d509802781b31397509950d98a7fa79ce76cfc  kern.log_170918_064755_gdOv0</code></pre></div><p>Till the next post.</p>]]></description>
			<author><![CDATA[dummy@example.com (miroR)]]></author>
			<pubDate>Mon, 18 Sep 2017 07:10:23 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=5076#p5076</guid>
		</item>
	</channel>
</rss>
