Honeypots mailing list archives

Re: honeyall logs reset


From: "Earl Sammons" <esammons () hush com>
Date: Fri, 3 Mar 2006 10:48:18 -0500

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

James,

I just tried and the "Clean out logging directories" and it does
seem to work.

login as root
'menu'
'Os Administration'
'Clean out logging directories'
'yes'

Granted the process could probably be a little more intelligent by
stoping / starting services that are loging etc. but it kinda gets
the job done.  This is one of the areas we can stand to improve on
in the next generation roo.  Point taken :)

There is a default user "roo" in MySQL with default password
"honey".  This will be locked for 10 minutes if you feed it the
wrong password more than twice.

I hate saying this but if you are really stuck with user/password
problems and you want a clean honeywall anyway (no concern over
lost logs) a re-install takes less than 5 minutes and configuration
is pretty straight forward.

If you want to try to save your config to make re-istall painless
do this on your roo:

login as root
Insert floppy
'menu'
'Honeywall Administration'
'Manager Configuration Subsystem'
'Create /etc/honeywall.conf from /hw/conf files'
'Write /etc/honeywall.conf files to floppy disk'

Leave the floppy in and re-install.  The honeywall.conf created
above and transfered to floppy based on current settings will be
"sucked in" during install.

Earl


On Tue, 28 Feb 2006 10:40:35 -0500 James Lee <jak.james () gmail com>
wrote:
On 2/28/06, Stefan Kelm <stefan.kelm () secorvo de> wrote:
James,

Is it possible to reset all honeywall logs? I would like to
have a
clean honeywall again, what's the best to way to do that?

check out the 'clean out logging directories' sub-menu.
You can do that from both Walleye and the text menu.

I tryed, but it doesn't work.

btw, what's the default user and password for mysql? My honeywall
users don't work too :/

Thanks,
James Lee


Cheers,

        Stefan.

-------------------------------------------------------
Stefan Kelm
Security Consultant

Secorvo Security Consulting GmbH
Ettlinger Strasse 12-14, D-76137 Karlsruhe

Tel. +49 721 255171-304, Fax +49 721 255171-100
stefan.kelm () secorvo de, http://www.secorvo.de/
-------------------------------------------------------
PGP Fingerprint 87AE E858 CCBC C3A2 E633 D139 B0D9 212B


-----BEGIN PGP SIGNATURE-----
Note: This signature can be verified at https://www.hushtools.com/verify
Version: Hush 2.4

wkYEARECAAYFAkQIeeQACgkQk7+e+4lPSm2oHQCcD4cq5bDy3/7PaF1GRDJwC1G77bsA
n3x36QztSPotjP4ggsFgaIsQ1oyn
=F7Xn
-----END PGP SIGNATURE-----



Current thread: