store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Thu May 23, 2013 3:52 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 11 posts ] 
Author Message
 Post subject: [RESOLVED] Report error after running asl -s -f
Unread postPosted: Thu Jul 21, 2011 8:05 am 
Offline
Forum Regular
Forum Regular

Joined: Mon Apr 14, 2008 8:29 am
Posts: 278
Location: Rhode Island
Not a major issue but just a little annoying, after running asl -s -f after updating, when it starts to do the Generating Report thingy i get the following error. Any way to fix this?

Code:
Generating Report: Error: could not find whitelist_1
Error: could not find whitelist_1
Error: could not find whitelist_1
Error: could not find whitelist_1
Complete


Last edited by JnascECSI on Thu Jul 21, 2011 11:02 am, edited 1 time in total.

Top
 Profile  
 
 Post subject: Re: Report error after running asl -s -f
Unread postPosted: Thu Jul 21, 2011 10:21 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
Yeah that could be a legacy tag from 2.2 creeping up, what do you get from:

grep whitelist /var/asl/data/test*db


Top
 Profile  
 
 Post subject: Re: Report error after running asl -s -f
Unread postPosted: Thu Jul 21, 2011 10:35 am 
Offline
Forum Regular
Forum Regular

Joined: Mon Apr 14, 2008 8:29 am
Posts: 278
Location: Rhode Island
Here's the output.

Code:
[xxxxxx@xxxxx-1 ~]# grep whitelist /var/asl/data/test*db
/var/asl/data/test_.db:high            whitelist       1
/var/asl/data/test_ossec-hids.db:low       ossec-hids     whitelist-low       1
[xxxxxx@xxxxx-1 ~]#


Top
 Profile  
 
 Post subject: Re: Report error after running asl -s -f
Unread postPosted: Thu Jul 21, 2011 11:00 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
yeah thats the culprit, delete this file:

/var/asl/data/test_.db


Top
 Profile  
 
 Post subject: Re: Report error after running asl -s -f
Unread postPosted: Thu Jul 21, 2011 11:01 am 
Offline
Forum Regular
Forum Regular

Joined: Mon Apr 14, 2008 8:29 am
Posts: 278
Location: Rhode Island
Thanks Scott.


Top
 Profile  
 
 Post subject: Re: [RESOLVED] Report error after running asl -s -f
Unread postPosted: Tue Jul 26, 2011 8:55 am 
Offline
Forum Regular
Forum Regular

Joined: Mon Apr 14, 2008 8:29 am
Posts: 278
Location: Rhode Island
Oops, Well thought it was ok until this morning. I ssh'd into the server and ran asl -u then asl -s -f installe dthe ossec update ran asl -s -f again and the error is back again. I went into /var/asl/data and the test_.db is there again deleted it and ran asl -s -f and found that it created it self again.

Any ideas why this is happening?


Top
 Profile  
 
 Post subject: Re: [RESOLVED] Report error after running asl -s -f
Unread postPosted: Tue Jul 26, 2011 12:20 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Are you running 3.0.2?

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: [RESOLVED] Report error after running asl -s -f
Unread postPosted: Tue Jul 26, 2011 12:28 pm 
Offline
Forum Regular
Forum Regular

Joined: Mon Apr 14, 2008 8:29 am
Posts: 278
Location: Rhode Island
Yes,

And like i mentioned it seems every time i run asl -u then asl -s -f the test_.db file recreates it self in var/asl/data folder. There also a bunch more test_ files created also if that helps.

Code:
[xxxxxx@xxx-1 ~]# asl -v
ASL Version 3.0.2: CentOS 5 (SUPPORTED)
[xxxxxx@xxx-1 ~]#


Top
 Profile  
 
 Post subject: Re: [RESOLVED] Report error after running asl -s -f
Unread postPosted: Tue Jul 26, 2011 12:45 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Yeah, thats a null test. The test_foo.db files are for each test category, and should have names like test_php.db, etc. Something may be unique with your system, would it be possible to log in an take a look? If so, please follow this process to provide us with access:

https://www.atomicorp.com/wiki/index.ph ... _system.3F

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: [RESOLVED] Report error after running asl -s -f
Unread postPosted: Tue Jul 26, 2011 1:02 pm 
Offline
Forum Regular
Forum Regular

Joined: Mon Apr 14, 2008 8:29 am
Posts: 278
Location: Rhode Island
Mike,
you guys already have access to the server, so i just opened a support ticket in the portal with the information for you. Thanks for taking a look at it for me as it's driving me nuts.


Top
 Profile  
 
 Post subject: Re: [RESOLVED] Report error after running asl -s -f
Unread postPosted: Tue Jul 26, 2011 1:11 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Our pleasure, and thank you for opening the case in the portal. We dont always remember everyone thats given us access, so we appreciate your reminding us and providing us your IP (and port) for ssh again.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 11 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Bing [Bot] and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group