<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://systems.nic.uoregon.edu/internal-wiki/index.php?action=history&amp;feed=atom&amp;title=Samhain</id>
	<title>Samhain - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://systems.nic.uoregon.edu/internal-wiki/index.php?action=history&amp;feed=atom&amp;title=Samhain"/>
	<link rel="alternate" type="text/html" href="https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Samhain&amp;action=history"/>
	<updated>2026-08-19T16:56:24Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.12</generator>
	<entry>
		<id>https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Samhain&amp;diff=1508&amp;oldid=prev</id>
		<title>128.223.202.180: Redirecting to Service:Samhain</title>
		<link rel="alternate" type="text/html" href="https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Samhain&amp;diff=1508&amp;oldid=prev"/>
		<updated>2006-08-02T01:42:22Z</updated>

		<summary type="html">&lt;p&gt;Redirecting to &lt;a href=&quot;/internal-wiki/index.php?title=Service:Samhain&quot; class=&quot;mw-redirect&quot; title=&quot;Service:Samhain&quot;&gt;Service:Samhain&lt;/a&gt;&lt;/p&gt;
&lt;a href=&quot;https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Samhain&amp;amp;diff=1508&amp;amp;oldid=1410&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>128.223.202.180</name></author>
	</entry>
	<entry>
		<id>https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Samhain&amp;diff=1410&amp;oldid=prev</id>
		<title>128.223.202.180: /* Installation */</title>
		<link rel="alternate" type="text/html" href="https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Samhain&amp;diff=1410&amp;oldid=prev"/>
		<updated>2006-08-01T18:07:33Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Installation&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 18:07, 1 August 2006&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l98&quot;&gt;Line 98:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 98:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;make&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;make&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;{|&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;{| &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;border=&amp;quot;1&amp;quot; cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|&amp;lt;pre&amp;gt;--enable-micro-stealth=177&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|&amp;lt;pre&amp;gt;--enable-micro-stealth=177&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|XORs all strings in the binary and log file by 177.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|XORs all strings in the binary and log file by 177.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>128.223.202.180</name></author>
	</entry>
	<entry>
		<id>https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Samhain&amp;diff=1409&amp;oldid=prev</id>
		<title>128.223.202.180: /* Installation */</title>
		<link rel="alternate" type="text/html" href="https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Samhain&amp;diff=1409&amp;oldid=prev"/>
		<updated>2006-08-01T18:05:49Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Installation&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 18:05, 1 August 2006&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l99&quot;&gt;Line 99:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 99:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;{|&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;{|&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;| --enable-micro-stealth=177&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;pre&amp;gt;&lt;/ins&gt;--enable-micro-stealth=177&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;/pre&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|XORs all strings in the binary and log file by 177.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|XORs all strings in the binary and log file by 177.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;| --enable-static&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;pre&amp;gt;&lt;/ins&gt;--enable-static&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;/pre&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|Statically binds all libraries at compile time&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|Statically binds all libraries at compile time&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;| --enable-install-name=nicmon&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;pre&amp;gt;&lt;/ins&gt;--enable-install-name=nicmon&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;/pre&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|Installs all samhain files with &amp;quot;samhain&amp;quot; replaced by &amp;quot;nicmon&amp;quot;.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|Installs all samhain files with &amp;quot;samhain&amp;quot; replaced by &amp;quot;nicmon&amp;quot;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;| --with-gpg=/usr/bin/gpg&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;pre&amp;gt;&lt;/ins&gt;--with-gpg=/usr/bin/gpg&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;/pre&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|Compiles the location of gpg into the binary.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|Compiles the location of gpg into the binary.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;| --with-checksum&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;pre&amp;gt;&lt;/ins&gt;--with-checksum&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;/pre&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|Compiles the checksum of the gpg binary into the samhain binary.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|Compiles the checksum of the gpg binary into the samhain binary.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;| --with-fp=&amp;lt;fingerprint&amp;gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;pre&amp;gt;&lt;/ins&gt;--with-fp=&amp;lt;fingerprint&amp;gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;/pre&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|Includes the fingerprint of the gpg key used to sign the config file and checksum database in the binary.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|Includes the fingerprint of the gpg key used to sign the config file and checksum database in the binary.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|-&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;| --enable-base=1353031580,1621368721&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;pre&amp;gt;&lt;/ins&gt;--enable-base=1353031580,1621368721&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;/pre&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|All messages send by samhain include this base.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|All messages send by samhain include this base.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|}&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;|}&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>128.223.202.180</name></author>
	</entry>
	<entry>
		<id>https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Samhain&amp;diff=1408&amp;oldid=prev</id>
		<title>128.223.202.180 at 18:04, 1 August 2006</title>
		<link rel="alternate" type="text/html" href="https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Samhain&amp;diff=1408&amp;oldid=prev"/>
		<updated>2006-08-01T18:04:23Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 18:04, 1 August 2006&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l98&quot;&gt;Line 98:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 98:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;make&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;make&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;{|&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;{{{&lt;/del&gt;--enable-micro-stealth=177&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;}}} &lt;/del&gt;XORs all strings in the binary and log file by 177.&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[BR]]&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;| &lt;/ins&gt;--enable-micro-stealth=177&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;{{{&lt;/del&gt;--enable-static&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;}}} &lt;/del&gt;Statically binds all libraries at compile time&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;.[[BR]]&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|&lt;/ins&gt;XORs all strings in the binary and log file by 177.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;{{{&lt;/del&gt;--enable-install-name=nicmon&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;}}} &lt;/del&gt;Installs all samhain files with &amp;quot;samhain&amp;quot; replaced by &amp;quot;nicmon&amp;quot;.&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[BR]]&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|-&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;{{{&lt;/del&gt;--with-gpg=/usr/bin/gpg&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;}}} &lt;/del&gt;Compiles the location of gpg into the binary.&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[BR]]&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;| &lt;/ins&gt;--enable-static&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;{{{&lt;/del&gt;--with-checksum&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;}}} &lt;/del&gt;Compiles the checksum of the gpg binary into the samhain binary.&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[BR]]&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|&lt;/ins&gt;Statically binds all libraries at compile time&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;{{{&lt;/del&gt;--with-fp=&amp;lt;fingerprint&amp;gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;}}} &lt;/del&gt;Includes the fingerprint of the gpg key used to sign the config file and checksum database in the binary.&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[BR]]&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|-&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;{{{&lt;/del&gt;--enable-base=1353031580,1621368721&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;}}} &lt;/del&gt;All messages send by samhain include this base.&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[BR]]&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;| &lt;/ins&gt;--enable-install-name=nicmon&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|&lt;/ins&gt;Installs all samhain files with &amp;quot;samhain&amp;quot; replaced by &amp;quot;nicmon&amp;quot;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|-&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;| &lt;/ins&gt;--with-gpg=/usr/bin/gpg&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|&lt;/ins&gt;Compiles the location of gpg into the binary.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|-&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;| &lt;/ins&gt;--with-checksum&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|&lt;/ins&gt;Compiles the checksum of the gpg binary into the samhain binary.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|-&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;| &lt;/ins&gt;--with-fp=&amp;lt;fingerprint&amp;gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|&lt;/ins&gt;Includes the fingerprint of the gpg key used to sign the config file and checksum database in the binary.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|-&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;| &lt;/ins&gt;--enable-base=1353031580,1621368721&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|&lt;/ins&gt;All messages send by samhain include this base.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;|}&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>128.223.202.180</name></author>
	</entry>
	<entry>
		<id>https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Samhain&amp;diff=1407&amp;oldid=prev</id>
		<title>128.223.202.180 at 18:01, 1 August 2006</title>
		<link rel="alternate" type="text/html" href="https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Samhain&amp;diff=1407&amp;oldid=prev"/>
		<updated>2006-08-01T18:01:21Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 18:01, 1 August 2006&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l77&quot;&gt;Line 77:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 77:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Use fingerprint above in the configure command line below. &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt; {{{&lt;/del&gt;--with-fp=&amp;lt;fingerprint&amp;gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;}}}&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Use fingerprint above in the configure command line below.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;pre&amp;gt; &lt;/ins&gt;--with-fp=&amp;lt;fingerprint&amp;gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;lt;/pre&amp;gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>128.223.202.180</name></author>
	</entry>
	<entry>
		<id>https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Samhain&amp;diff=1406&amp;oldid=prev</id>
		<title>128.223.202.180 at 18:00, 1 August 2006</title>
		<link rel="alternate" type="text/html" href="https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Samhain&amp;diff=1406&amp;oldid=prev"/>
		<updated>2006-08-01T18:00:18Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;a href=&quot;https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Samhain&amp;amp;diff=1406&amp;amp;oldid=1405&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>128.223.202.180</name></author>
	</entry>
	<entry>
		<id>https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Samhain&amp;diff=1405&amp;oldid=prev</id>
		<title>128.223.202.180 at 17:48, 1 August 2006</title>
		<link rel="alternate" type="text/html" href="https://systems.nic.uoregon.edu/internal-wiki/index.php?title=Samhain&amp;diff=1405&amp;oldid=prev"/>
		<updated>2006-08-01T17:48:59Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;[[TableOfContents]]&lt;br /&gt;
&lt;br /&gt;
= Introduction =&lt;br /&gt;
&lt;br /&gt;
== Purpose ==&lt;br /&gt;
&lt;br /&gt;
Host based intrusion detection systems(IDS) allow tracking of critical systems files, making unauthorized changes obvious.&lt;br /&gt;
&lt;br /&gt;
== Justification ==&lt;br /&gt;
&lt;br /&gt;
Samhain is the most featureful open source IDS currently under development.&lt;br /&gt;
&lt;br /&gt;
= Setup =&lt;br /&gt;
&lt;br /&gt;
== Installation ==&lt;br /&gt;
&lt;br /&gt;
Generate gpg key used in signing config file and checksum database.&lt;br /&gt;
{{{&lt;br /&gt;
gpg --gen-key&lt;br /&gt;
gpg (GnuPG) 1.2.4; Copyright (C) 2003 Free Software Foundation, Inc.&lt;br /&gt;
This program comes with ABSOLUTELY NO WARRANTY.&lt;br /&gt;
This is free software, and you are welcome to redistribute it&lt;br /&gt;
under certain conditions. See the file COPYING for details.&lt;br /&gt;
&lt;br /&gt;
Please select what kind of key you want:&lt;br /&gt;
   (1) DSA and ElGamal (default)&lt;br /&gt;
   (2) DSA (sign only)&lt;br /&gt;
   (4) RSA (sign only)&lt;br /&gt;
Your selection? 1&lt;br /&gt;
DSA keypair will have 1024 bits.&lt;br /&gt;
About to generate a new ELG-E keypair.&lt;br /&gt;
              minimum keysize is  768 bits&lt;br /&gt;
              default keysize is 1024 bits&lt;br /&gt;
    highest suggested keysize is 2048 bits&lt;br /&gt;
What keysize do you want? (1024) 2048&lt;br /&gt;
Requested keysize is 2048 bits       &lt;br /&gt;
Please specify how long the key should be valid.&lt;br /&gt;
         0 = key does not expire&lt;br /&gt;
      &amp;lt;n&amp;gt;  = key expires in n days&lt;br /&gt;
      &amp;lt;n&amp;gt;w = key expires in n weeks&lt;br /&gt;
      &amp;lt;n&amp;gt;m = key expires in n months&lt;br /&gt;
      &amp;lt;n&amp;gt;y = key expires in n years&lt;br /&gt;
Key is valid for? (0) 0&lt;br /&gt;
Key does not expire at all&lt;br /&gt;
Is this correct (y/n)? y&lt;br /&gt;
                        &lt;br /&gt;
You need a User-ID to identify your key; the software constructs the user id&lt;br /&gt;
from Real Name, Comment and Email Address in this form:&lt;br /&gt;
    &amp;quot;Heinrich Heine (Der Dichter) &amp;lt;heinrichh@duesseldorf.de&amp;gt;&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Real name: Neuroinformatics Center&lt;br /&gt;
Email address: systems@nic.uoregon.edu&lt;br /&gt;
Comment: NIC                          &lt;br /&gt;
You selected this USER-ID:&lt;br /&gt;
    &amp;quot;Neuroinformatics Center (NIC) &amp;lt;systems@nic.uoregon.edu&amp;gt;&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Change (N)ame, (C)omment, (E)mail or (O)kay/(Q)uit? o&lt;br /&gt;
You need a Passphrase to protect your secret key.    &lt;br /&gt;
&lt;br /&gt;
gpg: gpg-agent is not available in this session&lt;br /&gt;
We need to generate a lot of random bytes. It is a good idea to perform&lt;br /&gt;
some other action (type on the keyboard, move the mouse, utilize the&lt;br /&gt;
disks) during the prime generation; this gives the random number&lt;br /&gt;
generator a better chance to gain enough entropy.&lt;br /&gt;
+++++.+++++...+++++.+++++++++++++++++++++++++++++++++++++++++++++.+++++++++++++++.+++++.+++++.+++++.++++++++++.++++++++++.+++++..+++++..++++++++++&amp;gt;+++++.+++++.....................&amp;gt;.+++++.+++++&lt;br /&gt;
We need to generate a lot of random bytes. It is a good idea to perform&lt;br /&gt;
some other action (type on the keyboard, move the mouse, utilize the&lt;br /&gt;
disks) during the prime generation; this gives the random number&lt;br /&gt;
generator a better chance to gain enough entropy.&lt;br /&gt;
+++++.+++++.++++++++++++++++++++++++++++++.+++++++++++++++..++++++++++.++++++++++++++++++++++++++++++..++++++++++.+++++..++++++++++.++++++++++++++++++++..+++++&amp;gt;+++++.+++++&amp;gt;+++++&amp;gt;+++++...............&amp;gt;+++++......................+++++^^^^^^^^^&lt;br /&gt;
public and secret key created and signed.&lt;br /&gt;
key marked as ultimately trusted.&lt;br /&gt;
&lt;br /&gt;
pub  1024D/0E52D35E 2005-07-05 Neuroinformatics Center (NIC) &amp;lt;systems@nic.uoregon.edu&amp;gt;&lt;br /&gt;
     Key fingerprint = 9813 EDAA 19BF CAC5 4697  CC17 1DD9 AA76 0E52 D35E&lt;br /&gt;
sub  2048g/077454E4 2005-07-05&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
Use fingerprint above in the configure command line below.  {{{--with-fp=&amp;lt;fingerprint&amp;gt;}}}&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
mkdir source&lt;br /&gt;
cd source&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
Download newest version of Samhain from http://la-samhna.de/samhain/.&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
tar -zxvf samhain-&amp;lt;version&amp;gt;.tar.gz&lt;br /&gt;
cd samhain-&amp;lt;version&amp;gt;&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
Need the next two steps because TIGER192 checksum support isn't compiled in gpg by default so we have to use samhain itself.&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
./configure&lt;br /&gt;
make&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
{{{--enable-micro-stealth=177}}} XORs all strings in the binary and log file by 177.[[BR]]&lt;br /&gt;
{{{--enable-static}}} Statically binds all libraries at compile time.[[BR]]&lt;br /&gt;
{{{--enable-install-name=nicmon}}} Installs all samhain files with &amp;quot;samhain&amp;quot; replaced by &amp;quot;nicmon&amp;quot;.[[BR]]&lt;br /&gt;
{{{--with-gpg=/usr/bin/gpg}}} Compiles the location of gpg into the binary.[[BR]]&lt;br /&gt;
{{{--with-checksum}}} Compiles the checksum of the gpg binary into the samhain binary.[[BR]]&lt;br /&gt;
{{{--with-fp=&amp;lt;fingerprint&amp;gt;}}} Includes the fingerprint of the gpg key used to sign the config file and checksum database in the binary.[[BR]]&lt;br /&gt;
{{{--enable-base=1353031580,1621368721}}} All messages send by samhain include this base.[[BR]]&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
./configure --enable-micro-stealth=177 --enable-static \&lt;br /&gt;
            --enable-install-name=nicmon --with-gpg=/usr/bin/gpg \&lt;br /&gt;
            --with-checksum \&lt;br /&gt;
            --with-fp=&amp;quot;&amp;lt;fingerprint from output of gpg --gen-key&amp;gt;&amp;quot; \&lt;br /&gt;
            --enable-base=1353031580,1621368721&lt;br /&gt;
make&lt;br /&gt;
mv samhainrc.linux samhainrc.linux.stock&lt;br /&gt;
scp root@neuronic.nic.uoregon.edu:/etc/nicmonrc ./samhainrc.linux&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
Edit samhainrc.linux and remove gpg header and footer in preparation for signing.&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
make install&lt;br /&gt;
make install-boot&lt;br /&gt;
rm /usr/local/man/man8/nicmon.8&lt;br /&gt;
rm /usr/local/man/man5/nicmonrc.5&lt;br /&gt;
/usr/local/sbin/nicmon -t init&lt;br /&gt;
gpg -a --clearsign --not-dash-escaped /var/lib/nicmon/nicmon_file&lt;br /&gt;
mv /var/lib/nicmon/nicmon_file.asc /var/lib/nicmon/nicmon_file&lt;br /&gt;
/usr/local/sbin/nicmon -t check&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
== Configuration ==&lt;br /&gt;
&lt;br /&gt;
Samhainrc setup.  See comments in rc file for explanation of settings.&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
[Misc]&lt;br /&gt;
&lt;br /&gt;
[Attributes]&lt;br /&gt;
file=/etc/mtab&lt;br /&gt;
file=/etc/resolv.conf&lt;br /&gt;
file=/etc/localtime&lt;br /&gt;
file=/etc/ioctl.save&lt;br /&gt;
file=/etc&lt;br /&gt;
&lt;br /&gt;
[LogFiles]&lt;br /&gt;
file=/var/run/utmp&lt;br /&gt;
file=/etc/motd&lt;br /&gt;
&lt;br /&gt;
[GrowingLogFiles]&lt;br /&gt;
file=/var/log/messages&lt;br /&gt;
file=/var/log/wtmp&lt;br /&gt;
&lt;br /&gt;
[IgnoreAll]&lt;br /&gt;
&lt;br /&gt;
[IgnoreNone]&lt;br /&gt;
&lt;br /&gt;
[Prelink]&lt;br /&gt;
&lt;br /&gt;
[ReadOnly]&lt;br /&gt;
dir=/usr/bin&lt;br /&gt;
dir=/usr/local/bin&lt;br /&gt;
dir=/bin&lt;br /&gt;
dir=/boot&lt;br /&gt;
dir=3/sbin&lt;br /&gt;
dir=/usr/sbin&lt;br /&gt;
dir=2/lib&lt;br /&gt;
dir=2/usr/lib&lt;br /&gt;
dir=2/usr/local/lib&lt;br /&gt;
dir=3/etc&lt;br /&gt;
dir=/usr/X11R6/bin&lt;br /&gt;
&lt;br /&gt;
[User0]&lt;br /&gt;
[User1]&lt;br /&gt;
&lt;br /&gt;
[EventSeverity]&lt;br /&gt;
SeverityIgnoreAll=info&lt;br /&gt;
&lt;br /&gt;
[Log]&lt;br /&gt;
MailSeverity=crit&lt;br /&gt;
LogSeverity=mark&lt;br /&gt;
&lt;br /&gt;
[Misc]&lt;br /&gt;
Daemon = yes&lt;br /&gt;
ChecksumTest=check&lt;br /&gt;
UseCaps = yes&lt;br /&gt;
SetLoopTime = 60&lt;br /&gt;
SetFileCheckTime = 600&lt;br /&gt;
SetMailTime = 60&lt;br /&gt;
SetMailNum = 100&lt;br /&gt;
SetMailAddress=systems@nic.uoregon.edu&lt;br /&gt;
SetPrelinkPath = /usr/local/sbin/nicmon&lt;br /&gt;
SyslogFacility=LOG_LOCAL2&lt;br /&gt;
&lt;br /&gt;
[EOF]&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Maintenance =&lt;br /&gt;
&lt;br /&gt;
== Start ==&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
/etc/init.d/nicmon start&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
or&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
/usr/local/sbin/nicmon -t check&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
== Stop ==&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
/etc/init.d/nicmon stop&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
or&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
ps auxw|grep nicmon&lt;br /&gt;
kill &amp;lt;pid&amp;gt;&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
or&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
killall nicmon&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
== Update Database ==&lt;br /&gt;
&lt;br /&gt;
Stop samhain.&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
rm /var/lib/nicmon/nicmon_file&lt;br /&gt;
/usr/local/sbin/nicmon -t init&lt;br /&gt;
gpg -a --clearsign --not-dash-escaped /var/lib/nicmon/nicmon_file&lt;br /&gt;
mv /var/lib/nicmon/nicmon_file.asc /var/lib/nicmon/nicmon_file&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
Start samhain.&lt;br /&gt;
&lt;br /&gt;
== Update Configuration File ==&lt;br /&gt;
&lt;br /&gt;
Stop samhain.&lt;br /&gt;
&lt;br /&gt;
Remove gpg header and footer from /etc/nicmonrc.&lt;br /&gt;
&lt;br /&gt;
Modify /etc/nicmonrc.&lt;br /&gt;
&lt;br /&gt;
Re-sign /etc/nicmonrc.&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
gpg -a --clearsign --not-dash-escaped /etc/nicmonrc&lt;br /&gt;
mv /etc/nicmonrc.asc /etc/nicmonrc&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
Remove and recreate file database.&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
rm /var/lib/nicmon/nicmon_file&lt;br /&gt;
/usr/local/sbin/nicmon -t init&lt;br /&gt;
gpg -a --clearsign --not-dash-escaped /var/lib/nicmon/nicmon_file&lt;br /&gt;
mv /var/lib/nicmon/nicmon_file.asc /var/lib/nicmon/nicmon_file&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
Start samhain.&lt;br /&gt;
&lt;br /&gt;
== Debugging ==&lt;br /&gt;
&lt;br /&gt;
To debug a problem, run samhain using the following option.  It will print all messages with ''info'' or greater priority to standard out.&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
/usr/local/sbin/nicmon -t &amp;lt;init or check&amp;gt; -p info&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
== Log Files ==&lt;br /&gt;
&lt;br /&gt;
View log using&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
/usr/local/sbin/nicmon -jL /var/log/nicmon_log&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
== Rehashing the checksum database ==&lt;br /&gt;
&lt;br /&gt;
Here's a useful script to rebuild the samhain checksum database.&lt;br /&gt;
&lt;br /&gt;
Samhain's &amp;quot;growing log files&amp;quot; policy will verify selected files' checksums only if their size is below what it was when the database was built. If the database is hashed while the files are large (ie, near the end of the month), you may be deluged with messages after the first of the month when the files are rotated and returned to 0 size. The best way to get around this is to rotate them before hashing the database. This does make the check next to useless, a hacker's wiping of the log files would not trigger this alert.&lt;br /&gt;
&lt;br /&gt;
So I guess the policy is pretty much useless for files that are rotated - you're either spammed after rotation, or not warned when they're nuked.&lt;br /&gt;
&lt;br /&gt;
Anyways, here's the script.&lt;br /&gt;
&lt;br /&gt;
{{{&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Shutting down Nicmon...&amp;quot;&lt;br /&gt;
/etc/init.d/nicmon stop&lt;br /&gt;
killall -9 nicmon&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Removing old checksum database...&amp;quot;&lt;br /&gt;
rm -f /var/lib/nicmon/nicmon_file&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Would you like to rotate the logfiles before re-initializing the database?&amp;quot;&lt;br /&gt;
echo &amp;quot;This may help prevent bogus warnings when files checked by GROWINGLOGFILES are&amp;quot;&lt;br /&gt;
echo &amp;quot;rotated later on. y or yes to rotate, anything else to skip rotation.&amp;quot;&lt;br /&gt;
echo -n &amp;quot;Rotate log files: &amp;quot;&lt;br /&gt;
ROTATE=''&lt;br /&gt;
read ROTATE&lt;br /&gt;
&lt;br /&gt;
if [[ &amp;quot;${ROTATE}&amp;quot; == y* ]] || [[ &amp;quot;${ROTATE}&amp;quot; == Y* ]] ; then&lt;br /&gt;
  echo &amp;quot;Rotating log files...&amp;quot;&lt;br /&gt;
  logrotate -vf /etc/logrotate.conf&lt;br /&gt;
else&lt;br /&gt;
  echo &amp;quot;Skipping log rotation&amp;quot;&lt;br /&gt;
fi&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Initializing database...&amp;quot;&lt;br /&gt;
/usr/local/sbin/nicmon --foreground -t init&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Signing database...&amp;quot;&lt;br /&gt;
gpg -a --clearsign --not-dash-escaped /var/lib/nicmon/nicmon_file&lt;br /&gt;
mv -f /var/lib/nicmon/nicmon_file.asc /var/lib/nicmon/nicmon_file&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Restarting Nicmon...&amp;quot;&lt;br /&gt;
/etc/init.d/nicmon start&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Done!&amp;quot;&lt;br /&gt;
}}}&lt;br /&gt;
&lt;br /&gt;
== Rebuilding an existing install ==&lt;br /&gt;
&lt;br /&gt;
Samhain hard-codes some important checksums at build time. After upgrading system libraries or binaries (such as gpg), samhain may instruct you to recompile it to incorporate the new checksums.&lt;br /&gt;
&lt;br /&gt;
Here's a shell script that will do just that:&lt;br /&gt;
{{{&lt;br /&gt;
#!/bin/bash&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Shutting down Nicmon...&amp;quot;&lt;br /&gt;
/etc/init.d/nicmon stop&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Removing old checksum database...&amp;quot;&lt;br /&gt;
rm -f /var/lib/nicmon/nicmon_file&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Downloading current Samhain source...&amp;quot;&lt;br /&gt;
cd /usr/src&lt;br /&gt;
mkdir samhain-current&lt;br /&gt;
svn checkout http://svn.la-samhna.de/samhain/trunk/ samhain-current&lt;br /&gt;
&lt;br /&gt;
if [[ -f /usr/src/samhain-current/LICENSE ]] ; then&lt;br /&gt;
  echo &amp;quot;SVN Checkout OK&amp;quot;&lt;br /&gt;
  cd samhain-current&lt;br /&gt;
else&lt;br /&gt;
  echo &amp;quot;SVN Checkout of Samhain source failed, falling back to download...&amp;quot;&lt;br /&gt;
  rm -rf samhain-current&lt;br /&gt;
  wget http://la-samhna.de/samhain/samhain-current.tar.gz&lt;br /&gt;
&lt;br /&gt;
  echo &amp;quot;Unpacking source...&amp;quot;&lt;br /&gt;
  tar -zxf samhain-current.tar.gz&lt;br /&gt;
  tar -zxf samhain-2.2.0.tar.gz&lt;br /&gt;
  cd samhain-2.2.0&lt;br /&gt;
  if [[ -f /usr/src/samhain-2.2.0 ]] ; then&lt;br /&gt;
    echo &amp;quot;Download failed too!&amp;quot;&lt;br /&gt;
    exit 0&lt;br /&gt;
  fi&lt;br /&gt;
fi&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Configuring Stage 1...&amp;quot;&lt;br /&gt;
./configure&lt;br /&gt;
make&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Selecting GPG fingerprint...&amp;quot;&lt;br /&gt;
FINGERPRINT=`gpg --fingerprint |grep fingerprint |awk -F' = ' '{print $2}'`&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Fingerprint is: ${FINGERPRINT} - if this does not look correct, please enter the correct fingerprint now:&amp;quot;&lt;br /&gt;
NEW_FP=`read`&lt;br /&gt;
if [[ -z &amp;quot;${NEW_FP}&amp;quot; ]]&lt;br /&gt;
then&lt;br /&gt;
  echo &amp;quot;No fingerprint entered, using preselected value.&amp;quot;&lt;br /&gt;
else&lt;br /&gt;
  echo &amp;quot;Using manually entered fingerprint ${NEW_FP}&amp;quot;&lt;br /&gt;
  FINGERPRINT=&amp;quot;${NEW_FP}&amp;quot;&lt;br /&gt;
fi&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Configuring final stage...&amp;quot;&lt;br /&gt;
./configure --enable-micro-stealth=177 --enable-static \&lt;br /&gt;
            --enable-install-name=nicmon --with-gpg=/usr/bin/gpg \&lt;br /&gt;
            --with-checksum \&lt;br /&gt;
            --with-fp=&amp;quot;${FINGERPRINT}&amp;quot; \&lt;br /&gt;
            --enable-base=1353031580,1621368721&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Building...&amp;quot;&lt;br /&gt;
make&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Installing...&amp;quot;&lt;br /&gt;
make install&lt;br /&gt;
make install-boot&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Cleaning up...&amp;quot;&lt;br /&gt;
cd ~&lt;br /&gt;
rm -rf /usr/src/samhain*&lt;br /&gt;
rm -f /usr/local/man/man8/nicmon.8&lt;br /&gt;
rm -f /usr/local/man/man5/nicmonrc.5&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Initializing database...&amp;quot;&lt;br /&gt;
/usr/local/sbin/nicmon --foreground -t init&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Signing database...&amp;quot;&lt;br /&gt;
gpg -a --clearsign --not-dash-escaped /var/lib/nicmon/nicmon_file&lt;br /&gt;
mv -f /var/lib/nicmon/nicmon_file.asc /var/lib/nicmon/nicmon_file&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Starting rebuilt Nicmon...&amp;quot;&lt;br /&gt;
/etc/init.d/nicmon start&lt;br /&gt;
&lt;br /&gt;
echo &amp;quot;Done!&amp;quot;&lt;br /&gt;
&lt;br /&gt;
}}}&lt;/div&gt;</summary>
		<author><name>128.223.202.180</name></author>
	</entry>
</feed>