Richard Johnson | 17 Sep 2005 02:20

possible communication problem with argus on 32 bit system, ra on 64 bit system

I'm using a couple of machines to handle our flow data.  One listens on the
network and runs argus.  The second runs ra to take the flow data via a
crossover cable, and store it to an array for analysis.

When running OpenBSD 3.6 i386 (32 bit intel xeon) machines on each side,
they communicate just fine.

When I swap the host running ra out for one based on OpenBSD 3.7 amd64 (64
bit -- amd opteron) with an otherwise identical ra build to the original, I
achieve only the following:

	argus on 32 bit host sends no data
	ra on 64 bit host reports "no data available", and quits

Meanwhile, the hosts can communicate freely on the crossover cable with
pings, netcat connections on various ports, ssh logins, etc.  Ergo, it's an
application layer problem that's affecting only argus->ra.

Have any of you encountered similar difficulties?

Is it insane of me to be trying 32 bit and 64 bit machines together like
this with argus 2.0.6fixes1?  If it's not totally insane, might it be
possible to work around the structure incompatibilities (which I'm just
guessing at here) by building and running a 32 bit ra on the 64 bit machine?

Your hints, guesses, and even brickbats will be greatly appreciated.

Thanks!

Richard
(Continue reading)

Peter Van Epp | 17 Sep 2005 04:29
Picon
Picon
Favicon

Re: possible communication problem with argus on 32 bit system, ra on 64 bit system

	Argus isn't 64 bit clean in the current version which is likely your
problem. If you can build it as a 32 bit binary on the 64 bit machine then you
may be OK. For one time_t is assumed to be 32 bits and on a 64 machine it isn't.
Making argus 64 bit clean is one of the goals of argus-2.0.7 (although I don't
think 2.0.7 has even started yet).

Peter Van Epp / Operations and Technical Support 
Simon Fraser University, Burnaby, B.C. Canada

On Fri, Sep 16, 2005 at 06:20:59PM -0600, Richard Johnson wrote:
> I'm using a couple of machines to handle our flow data.  One listens on the
> network and runs argus.  The second runs ra to take the flow data via a
> crossover cable, and store it to an array for analysis.
> 
> When running OpenBSD 3.6 i386 (32 bit intel xeon) machines on each side,
> they communicate just fine.
> 
> When I swap the host running ra out for one based on OpenBSD 3.7 amd64 (64
> bit -- amd opteron) with an otherwise identical ra build to the original, I
> achieve only the following:
> 
> 	argus on 32 bit host sends no data
> 	ra on 64 bit host reports "no data available", and quits
> 
> Meanwhile, the hosts can communicate freely on the crossover cable with
> pings, netcat connections on various ports, ssh logins, etc.  Ergo, it's an
> application layer problem that's affecting only argus->ra.
> 
> Have any of you encountered similar difficulties?
> 
(Continue reading)

Mike Iglesias | 17 Sep 2005 04:54
Picon

Re: possible communication problem with argus on 32 bit system, ra on 64 bit system

There are problems with 64 bit and 32 bit argus since argus is not 64 bit
clean.  If you can, compile on a 32 bit system and just move the binaries
over.  That's what I do.

Mike Iglesias                          Email:       iglesias <at> draco.acs.uci.edu
University of California, Irvine       phone:       949-824-6926
Network & Academic Computing Services  FAX:         949-824-2069

Peter Van Epp | 22 Sep 2005 18:54
Picon
Picon
Favicon

[hhoffman <at> ip-solutions.net: [unisog] Interesting Visualization Project for Argus]

	For any of you not also on unisog, I expect this will be of even more
interest here :-)

Peter Van Epp / Operations and Technical Support 
Simon Fraser University, Burnaby, B.C. Canada

----- Forwarded message from Harry Hoffman <hhoffman <at> ip-solutions.net> -----

Date: Thu, 22 Sep 2005 11:47:52 -0400
From: Harry Hoffman <hhoffman <at> ip-solutions.net>
To: unisog <at> lists.sans.org
<headers snipped>

Hi All,

I'm sitting in flocon right now (http://www.cert.org/flocon/2005) and 
there is a really neat presentation on visualizing argus flow data.

I figure that if you don't already know about it (like me) that a name 
and URL might be nice, so here goes:
NVisionIP (from ncsa): 
http://security.ncsa.uiuc.edu/distribution/NVisionIPDownLoad.html

Cheers,
Harry

_______________________________________________
unisog mailing list
unisog <at> lists.sans.org
http://www.dshield.org/mailman/listinfo/unisog
(Continue reading)

Russell Fulton | 22 Sep 2005 23:11
Picon
Picon
Favicon

Re: [hhoffman <at> ip-solutions.net: [unisog] Interesting Visualization Project for Argus]

I looked at this a while back.

There isn't  version for OBSD unfortunately -- I asked the developers and their response was that one should
run  the linux version under compatibility system.  I've never bothered with the linux compatibility
stuff before so it has slid back down my priority list.

R

Peter Van Epp wrote:
> 	For any of you not also on unisog, I expect this will be of even more
> interest here :-)
> 
> Peter Van Epp / Operations and Technical Support 
> Simon Fraser University, Burnaby, B.C. Canada
> 
> 
> ----- Forwarded message from Harry Hoffman <hhoffman <at> ip-solutions.net> -----
> 
> Date: Thu, 22 Sep 2005 11:47:52 -0400
> From: Harry Hoffman <hhoffman <at> ip-solutions.net>
> To: unisog <at> lists.sans.org
> <headers snipped>
> 
> Hi All,
> 
> I'm sitting in flocon right now (http://www.cert.org/flocon/2005) and 
> there is a really neat presentation on visualizing argus flow data.
> 
> I figure that if you don't already know about it (like me) that a name 
> and URL might be nice, so here goes:
(Continue reading)

Cale Pantke | 25 Sep 2005 22:05

Argus "Internal Server Error"

Hello everyone,

I am new to the mailing lists and would like to say hi. I also have a problem.

We have a Mandrake Linux box running Argus. We recently had to change the gateway of the box. When we did,
Argus stopped working. I am receiving a "500 internal service error" when trying to view the site in IE. I
know apache has to be working because we have a MRTG site and it produces output just fine.

I restarted httpd and argusd. I also look in "top" and see argus running. When I check the logs of Argus it says
it successfully restarted. When I check the logs of Apache I get 4 lines of errors. (I have to briefly tell
you the errors because I can't copy paste). 
So the errors are like

Premature end of script headers: arguscgi
could not connect to argusd on unix socket '/usr/local/argus
could not connect to argusd on unix socket '/usr/local/argus
cannot tie auth '/usr/local/argus/data/auth' : Resource temporarily (and I guess the other word is
supposed to be unavailable)

This 4 errors are generated when I press "refresh" on the browser window for Argus.

Any help would be appreciated. 

Thanks!
Cale 

eric | 25 Sep 2005 22:35

Re: Argus "Internal Server Error"

On Sun, 2005-09-25 at 16:05:49 -0400, Cale Pantke proclaimed...

> We have a Mandrake Linux box running Argus. We recently had to change the
> gateway of the box. When we did, Argus stopped working. I am receiving a
> "500 internal service error" when trying to view the site in IE. I know
> apache has to be working because we have a MRTG site and it produces
> output just fine.

This isn't an argus problem. This is a web server issue.

> I restarted httpd and argusd. I also look in "top" and see argus running.
> When I check the logs of Argus it says it successfully restarted. When I
> check the logs of Apache I get 4 lines of errors. (I have to briefly tell
> you the errors because I can't copy paste).  So the errors are like
>  
> Premature end of script headers: arguscgi
> could not connect to argusd on unix socket '/usr/local/argus
> could not connect to argusd on unix socket '/usr/local/argus
> cannot tie auth '/usr/local/argus/data/auth' : Resource temporarily (and I guess the other word is
supposed to be unavailable)
>  
> This 4 errors are generated when I press "refresh" on the browser window for Argus.
>  

Again, this still isn't an argus problem; it's a connectivity problem to the
server.

I'd check your webserver config, etc.

(Continue reading)

Olaf Gellert | 30 Sep 2005 09:40
Picon

Prelude 0.9 Sensor for ARGUS

HI all,

I have done a complete rewrite of my sensor "raprelude"
which logs argus records to a prelude manager.

The sensor generates IDMEF (Intrusion Detection Message
Exchange Format) alerts containing most of the information
of an ArgusRecord (right now ARP and RARP-records are
skipped) and sends these to a prelude manager. Right now it
has a set of rules (a little bit like Snort or Firewall
rules) that match ports, addresses, etc and provide a
classification and a severity level for the record.

We use the sensor to visualize the difference between
what our IDS has seen (packets which matched an attack
signature) and what other (especially unwanted) traffic
existed.

It's on: http://www.intrusion-lab.net/raprelude/

Cheers, Olaf

--

-- 
Dipl.Inform. Olaf Gellert                  PRESECURE (R)
Senior Researcher,                       Consulting GmbH
Phone: (+49) 0700 / PRESECURE           og <at> pre-secure.de

                        A daily view on Internet Attacks
                        https://www.ecsirt.net/sensornet

(Continue reading)


Gmane