Hi all!
First of all thank you very much for the attention.
I have
another problem with submit-norman.
It seems to work,where
submit-
norman.conf:
{
// this is the adress where norman sandbox
reports will be sent
email "verra.ero@...";
urls ("http://sandbox.norman.no/live_4.html",
"http:
//luigi.informatik.uni-mannheim.de/submit.php?action=verify");
};
nepenthes.log (just the interesting part):
[23052007 01:06:32 info mgr
submit] File 4e26b5051d1b027ab716d61dcb418abb has type MS-DOS
executable, MZ for MS-DOS
[23052007 01:06:32 info handler event
module] LogPrelude EVENT EV_SUBMISSION ftp://1:1@...
1003.exe 4e26b505
1d1b027ab716d61dcb418abb 70656
[23052007 01:06:32
info handler event module] LogPrelude EVENT EV_SOCK_TCP_CLOSE
[23052007
01:06:44 debug info fixme] Submitted file
4e26b5051d1b027ab716d61dcb418abb to sandbox http://luigi.informatik.uni-
m
annheim.de/submit.php?action=verify
[23052007 01:06:48 debug info
fixme] Submitted file 4e26b5051d1b027ab716d61dcb418abb to sandbox http:
//sandbox.norman.no/live
_4.html
and, output nepenthes at startup:
[
info mgr ] Loaded Nepenthes Configuration from
"/opt/nepenthes//etc/nepenthes/nepenthes.conf".
[ debug info fixme ]
Submitting via http post to http://sandbox.norman.no/live_4.html
[
debug info fixme ] Submitting via http post to http://luigi.informatik.
uni-mannheim.de/submit.php?action=verify
prelude_string_set_ref_fast:
482: warning, string is not NULL terminated.
prelude_string_set_ref_fast:482: warning, string is not NULL
terminated.
- Connecting to 127.0.0.1:4690 prelude Manager server.
-
TLS authentication succeed with Prelude Manager.
[ crit net handler ]
Could not Bind Socket to Port 25
Address already in use
[ crit net
handler ] ERROR Could not init Socket Address already in use
[ crit net
mgr ] ERROR Binding :25 failed
[ info sc module ] Loading signatures
from file var/cache/nepenthes/signatures/shellcode-signatures.sc
[ crit
mgr ] Compiled without support for capabilities, no way to run
capabilities
[ info mgr ] Process groupid 115
[ info mgr ] Process
userid 110
But two days have passed and i've received no report..What
i've missing??
Thank you so much!
|