[ossec-list] Re: Is ossec reading my IIS logs?

2007-06-16 Thread Daniel Cid
Hi Steve, Did you restart the agent after adding the iis logs? Can you show us your agent ossec.log? Something must in there Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 6/15/07, Steve West [EMAIL PROTECTED] wrote: Hi Rick, Yes, all options under Logging Properties has been

[ossec-list] Re: OSSEC Server Crashing on Solaris 9

2007-06-14 Thread Daniel Cid
can't find out what is going on with it, it would be nice to re-compile ossec with debug enabled to see what is going on... Thanks for the report, -- Daniel B. Cid dcid ( at ) ossec.net On 6/10/07, Erik Delfgaauw [EMAIL PROTECTED] wrote: Hi folks, OSSEC Server is crashing after some time

[ossec-list] Re: Fine tune syslog_rules.xml Rule 1002

2007-06-14 Thread Daniel Cid
/match descriptionEvents ignored./description /rule /group What it means? Every time the rule 1002 is matched, the above will be checked and if matched, ignore (see level = 0). For more info: http://www.ossec.net/wiki/index.php/Know_How:Ignore_Rules Hope it helps. -- Daniel B. Cid dcid

[ossec-list] Re: File anomalies

2007-06-07 Thread Daniel Cid
/Know_How:Ignore_Rules hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 6/7/07, Clayton Dillard [EMAIL PROTECTED] wrote: Can someone provide some insight into why this alert is being fired? I get a lot of these alerts every day. Anomaly detected in file '/usr/local/apache2/htdocs/janeway

[ossec-list] Remote log injection paper

2007-06-06 Thread Daniel Cid
://denyhosts.sourceforge.net/ http://www.aczoom.com/cms/blockhosts http://www.fail2ban.org Link to the article: http://www.ossec.net/en/attacking-loganalysis.html Available patches: http://www.ossec.net/en/attacking-loganalysis.html#patches Thanks, -- Daniel B. Cid dcid ( at ) ossec.net

[ossec-list] Re: regex question

2007-06-04 Thread Daniel Cid
-dcid.pdf hope it helps. -- Daniel B. Cid, dcid ( at ) ossec.net http://www.ossec.net On 6/3/07, David Williams [EMAIL PROTECTED] wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Tim, I tried a similar regex without luck but then saw another way to do the same thing. You may want

[ossec-list] Re: OpenBSD 3.8, OSSEC 1.2 Problem

2007-05-31 Thread Daniel Cid
and re-issuing a new agent id. Re import the keys into the server and see if it works now. *To calculate the msg id, do: (global_id -1) * + local_id. Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 5/30/07, Michael Starks [EMAIL PROTECTED] wrote: Daniel Cid wrote: Hi Michael

[ossec-list] Re: alert fires at level 10 but doesn't do active response

2007-05-30 Thread Daniel Cid
already support horde imp, but I am looking to add support for more (like open webmail, round cube, uebimiau, etc). If you have logs for any of those, please send them to us. Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 5/30/07, Peter Robinson [EMAIL PROTECTED] wrote: Hi I have had about

[ossec-list] Re: OpenBSD 3.8, OSSEC 1.2 Problem

2007-05-29 Thread Daniel Cid
Hi Michael, Can you show us what is in the server log file? Was the agent able to connect to the server after or it is still unavailable? What architecture you are running OpenBSD 3.8? If it is i386 it would not be an endiness issue... Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net

[ossec-list] Re: How to replace hostname with IP in alerts?

2007-05-29 Thread Daniel Cid
on sshd: http://www.ossec.net/wiki/index.php/Sshd Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 5/26/07, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: When I get alerts I want to get the IP address inplace of hostname. How to configure the ossec.conf for the same. Regards, DM

[ossec-list] Re: Ossec using 890k handles in windows

2007-05-26 Thread Daniel Cid
long to reply to you. I was without access to my windows development system for the last two weeks and unable to take a look at this issue. If you can try this version and let us know how it goes, it would be great. Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 5/16/07, Luke Bradeen [EMAIL

[ossec-list] Re: Disable rootcheck / OSSEC inside openvz VPS

2007-05-26 Thread Daniel Cid
-070525.tar.gz Upgrade your ossec install to this one and the problem should go away (just choose upgrade option when you run ./install.sh). Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 5/22/07, Blaine Aldridge [EMAIL PROTECTED] wrote: ossec-execd was not running and refuses to start when

[ossec-list] Re: breakin?

2007-05-24 Thread Daniel Cid
-May/000129.html *Btw, I would suggest disabling it. The performance gain is very small compared to the security costs (not knowing exactly which files changed). Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 5/23/07, Martin West [EMAIL PROTECTED] wrote: ossec just threw up some files

[ossec-list] Re: Behavior of MS Windows Agent

2007-05-24 Thread Daniel Cid
... Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 5/23/07, Vazquez, Ed [EMAIL PROTECTED] wrote: Here's an odd one for you. Three different systems. One running Win2K3 Server on a quad Xeon, one running WinXP Pro x64 on a dual Athlon, one running Win2K3 Server x64 on a Core2 Duo. On all

[ossec-list] Re: Problem about no_log option in rule files

2007-05-22 Thread Daniel Cid
Hi Worawit, The no_log option means do not log (in archives or alerts log) at all. The reason we do that with firewall logs is because they are already logged (in a normalized way) at /var/ossec/logs/firewall/firewall.log Hope it helps to clarify. -- Daniel B. Cid dcid ( at ) ossec.net On 5

[ossec-list] Re: Disable rootcheck / OSSEC inside openvz VPS

2007-05-22 Thread Daniel Cid
. If it starts fine, just restart ossec and see if the problem persist... If that doesn't help, let us know and we will look deep into that :) Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 5/20/07, Blaine Aldridge [EMAIL PROTECTED] wrote: Hey all, I'm running OSSEC on a openvz based VPS

[ossec-list] Re: Integrity Checking Not Working

2007-05-22 Thread Daniel Cid
and restarted apache? -Do you have any file at /var/ossec/queue/syscheck ? Can you show what is in there to us? -Is there any errors at the apache error log? At the ossec log (both server and agent side)? With that information we can start troubleshooting :) thanks, -- Daniel B. Cid dcid

[ossec-list] Re: My rule detects and alerts but doesn't block

2007-05-17 Thread Daniel Cid
regex offset=after_prematch^ (\d+.\d+.\d+.\d+)/regex ordersrcip/order /decoder It tried it here and seemed to work. hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 5/15/07, Peter Robinson [EMAIL PROTECTED] wrote: Hi I've been trying to write a rule to detect and then block hosts

[ossec-list] Re: How to disable IP's trying brute force? Error Alert 10

2007-05-17 Thread Daniel Cid
Hi Thorne, You are right, ossec will by default block the ip address for only a limited period of time. Check at /var/ossec/logs/active-response.log for a list of IP addresses that were blocked. Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 5/16/07, Thorne Lawler [EMAIL PROTECTED

[ossec-list] OSSEC Version 1.2 available

2007-05-15 Thread Daniel Cid
) = 831b03059f279132a4b26f2debd443fff294cb5a MD5 (ossec-agent-win32-1.2.exe) = e9bede4e84b1445ad67a1739564fafad SHA1 (ossec-agent-win32-1.2.exe) = 84f443f2df268096775c56c6d8cab3de0cff59dd We want to thank everyone who contributed or just sent some comments or nice words to us! We really appreciate the feedback! -- Daniel B. Cid

[ossec-list] Re: Firewall active response

2007-05-11 Thread Daniel Cid
. -- Daniel B. Cid dcid ( at ) ossec.net On 5/9/07, Dimitri Yioulos [EMAIL PROTECTED] wrote: Hi, folks. Even though I've been using O-H for w while now, I still think I have this screwed up: I want to use the firewall active response. However, it doesn't seem to be working. My firewall

[ossec-list] Re: IIS 6 log decoder issue

2007-05-04 Thread Daniel Cid
for urls (actually all of them on ossec) are case Insensitive already. So SeLect, SELECT or select will all be treated the same way. Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 5/4/07, Worawit Wang [EMAIL PROTECTED] wrote: Hi all, I've just found bug in decoder.xml, named web-accesslog-iis6

[ossec-list] Re: [ossec-dev] Possible rootkit false positive for Debian? - Advice

2007-05-02 Thread Daniel Cid
Hi Tommy, You don't need to worry about this alert because it is a false positive. The following signature was removed already from ossec... Upgrade to our latest snapshot if you want to try it out: http://www.ossec.net/files/snapshots/ Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 5/2

[ossec-list] Re: SSH Brute Force Attacks and Alerting

2007-05-02 Thread Daniel Cid
/if_matched_sid descriptionSSHD brute force trying to get access to /description descriptionthe system./description optionsno_email_alert/options groupauthentication_failures,/group /rule Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 5/2/07, Ben Ruset [EMAIL PROTECTED] wrote: Well

[ossec-list] Re: Error: unable to send message to server

2007-05-01 Thread Daniel Cid
... Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 5/1/07, List Subscriptions [EMAIL PROTECTED] wrote: Daniel, After several days this issue still exists. I have been monitoring the interface statistics and I'm not even close to saturating the link. Any ideas? On 4/27/07, List Subscriptions

[ossec-list] Re: Log format question

2007-05-01 Thread Daniel Cid
Hi John, Posting your log samples in the wiki is the best way to share them with us. You can probably create an entry for that Linux distribution at: http://www.ossec.net/wiki/index.php/Log_Samples Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 5/1/07, John Lewis [EMAIL PROTECTED] wrote

[ossec-list] Re: Log format question

2007-04-30 Thread Daniel Cid
(from sshd, etc), I can make sure to test them too. Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 4/27/07, John Lewis [EMAIL PROTECTED] wrote: I'm running several servers using the smeserver linux distro (http://wiki.contribs.org/Main_Page) based on centos. I've noticed many

[ossec-list] Re: Client Key Management

2007-04-30 Thread Daniel Cid
. -Wolfsheim, 'Blind' *I am glad to see you guys from the NIH using ossec :) I worked at the NIH/NHLBI department a few years ago ... Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net

[ossec-list] Re: Windows Firewall and OSSEC

2007-04-28 Thread Daniel Cid
* 0/1/0 (79) Hope it helps, -- Daniel B. Cid dcid ( at ) ossec.net On 4/27/07, Michael Starks [EMAIL PROTECTED] wrote: List Subscriptions wrote: The windows firewall is a one-way firewall that only blocks incoming traffic. Since the agent is using UDP to forward to the server no exception

[ossec-list] Re: Error: unable to send message to server

2007-04-25 Thread Daniel Cid
to check your network (not the server itself), to see if you don't have any connectivity issues (I have servers monitoring a much larger number of agents and never had these errors). Btw, does the problem still persists or it is gone? Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 4/25/07, List

[ossec-list] Re: IIS log fields

2007-04-23 Thread Daniel Cid
Yes, it should work. The examples on the manual are for IIS 5 and the order you have is for IIS 6. If you can take a couple of screenshots from the IIS 6 setup, I will post on the site. Thanks, -- Daniek B. Cid dcid ( at ) ossec.net On 4/23/07, List Subscriptions [EMAIL PROTECTED] wrote:

[ossec-list] Re: Clarification of agents behind NAT's

2007-04-23 Thread Daniel Cid
know which IP is being used, just try to connect to the server from the agent and run tcpdump on the server side to see ... Hope that helps clarify... Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 4/23/07, John Lewis [EMAIL PROTECTED] wrote: Could I get some help clarifying how to set up

[ossec-list] Re: another local_rules.xml question

2007-04-20 Thread Daniel Cid
However, if you can't re-configure IIS for any reason, try removing the spaces from your local rule (your log does not have spaces before pageerror) and restarting ossec. from: match pageerror.aspx /match to: matchpageerror.aspx /match Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 4

[ossec-list] Re: IIS rule to alert on blank cs-host

2007-04-20 Thread Daniel Cid
-host. A simple way to do it is with the following regex (just create a local rule using that): regexHTTP/1.0 \d+.\d+.\d+.\d+ \S+/regex Basically it looks for the http version followed by a cs-host that is composed of an IP address. Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 4/19/07

[ossec-list] Re: Waiting for server reply (not started)

2007-04-19 Thread Daniel Cid
the manage_agents tool again and making sure the authentication keys match. Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 4/19/07, Tim [EMAIL PROTECTED] wrote: On Apr 19, 1:58 pm, Jeremy Melanson [EMAIL PROTECTED] wrote: You probably need to reload the OSSEC Server. After you add the host

[ossec-list] Re: Mod Security 2.1.x

2007-04-14 Thread Daniel Cid
Hi Sioban, I had blocked all editing on the wiki for reasons of vandalism ( http://www.ossec.net/dcid/?p=70 ), but it should be open now. I already committed your changes to CVS and it will be included on the next release. Thanks for the help! -- Daniel B. Cid dcid ( at ) ossec.net On 4/13

[ossec-list] Re: timestamp for modified files

2007-04-14 Thread Daniel Cid
to track valid file changes. Thanks. -- Daniel B. Cid dcid ( at ) ossec.net On 4/13/07, Chad Rober [EMAIL PROTECTED] wrote: I've noticed the time a notification is sent regarding file with a different checksum can be greatly different from the actual time the file changed. I'll assume this is due

[ossec-list] Re: adsl rule

2007-04-08 Thread Daniel Cid
to: rule id=101000 level=0 noalert=1 program_namekernel/program_name descriptionGrouping for the adsl rules./description /rule Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 4/7/07, Martin West [EMAIL PROTECTED] wrote: I wrote a rule group name=local,syslog, rule id

[ossec-list] Re: SVN v. OSSEC

2007-04-08 Thread Daniel Cid
/url descriptionIgnored 404 error codes for url svn/trunk/description /rule You can also use the srcip or username tags to refine it even further ... *Some information regarding local rules: http://www.ossec.net/wiki/index.php/Know_How:Ignore_Rules Hope it helps. -- Daniel B. Cid dcid

[ossec-list] Re: IIS logging question

2007-04-06 Thread Daniel Cid
://www.ossec.net/img/w3c-log.jpg http://www.ossec.net/img/w3c-opt1.jpg http://www.ossec.net/img/w3c-opt2.jpg As soon as you fix it, ossec will parse them properly (as web logs). Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 4/6/07, Chad Rober [EMAIL PROTECTED] wrote: I recently setup

[ossec-list] Re: Possible kernel level rootkit and wui0.2

2007-04-05 Thread Daniel Cid
Hi Sebastian, Did you restart apache after adding www-data to the ossec group? Apache will only use the additional group after it... Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 4/5/07, Sebastian Esch [EMAIL PROTECTED] wrote: ok. I checked the permissions and the group ossec

[ossec-list] Re: ossec-wui v0.2

2007-04-05 Thread Daniel Cid
the problem, check if SELinux is enabled and blocking the access... Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 4/2/07, Chris Rimondi [EMAIL PROTECTED] wrote: I have tried to install ossec-wui v.0.2 on a CentOS box. I am getting the No Agent Available on the main page. I have OSSEC v1.1 running

[ossec-list] Re: HP-UX process lock / Incorrectly formated message question

2007-04-03 Thread Daniel Cid
version). Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 4/3/07, Nick Baronian [EMAIL PROTECTED] wrote: Hello, I have an agent on a HP-UX 11i box that is generating some odd things in the logs and I was hoping someone might be able to help me figure out what might be wrong. After install I

[ossec-list] Re: ossec and splunk

2007-04-02 Thread Daniel Cid
to receive remote messages and configure ossec and splunk to read from the files directly. Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 4/2/07, List Subscriptions [EMAIL PROTECTED] wrote: I'm running both ossec and splunk and want both to have access to syslog sources but it seems

[ossec-list] Re: Pushing Policies

2007-03-31 Thread Daniel Cid
/ossec/etc/shared ). Regarding the log analysis signature updates, we generally release them with each new release (+- every 2 months), and you only need to update them on the server. However, we are working on some form of dynamic update for them ... Hope it helps. -- Daniel B. Cid dcid

[ossec-list] Re: Cisco Routers

2007-03-28 Thread Daniel Cid
Hi Nuno, We currently do not have any *rules for Cisco IOS routers. If you have logs to share with us, we can add support for it very easily (anyone else with additional logs to share would be even better). *we have rules for the IDS module for IOS, but nothing else... Thanks, -- Daniel B

[ossec-list] Re: expire rules

2007-03-28 Thread Daniel Cid
with an issue on a Wednesday, you can set the weekday to it and prepend XXX to the description so you can easily grep for rules with the XXX to fix them later... Just some workarounds that may help. Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 3/28/07, Nicolas Arias [EMAIL PROTECTED] wrote: Hello

[ossec-list] Finding ADS on NTFS (yes, rootkit detection on windows coming to OSSEC)

2007-03-25 Thread Daniel Cid
This tool will be the basis for the ossec NTFS ADS detection on ossec ... Thanks, -- Daniel B. Cid dcid ( at ) ossec.net

[ossec-list] Re: Invalid Hostname when using syslog-ng?

2007-03-22 Thread Daniel Cid
Btw, did anyone else have this problem? I am wondering if I should make this the default behavior on ossec Any other syslog-ng user here? Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 3/21/07, Matthew Hilty [EMAIL PROTECTED] wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi OSSEC

[ossec-list] Re: Ignore list

2007-03-18 Thread Daniel Cid
database for a specific system. Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 3/18/07, Marco Supino [EMAIL PROTECTED] wrote: Hi, When adding ignore to ossec, should it be on the agent or on the server ? Also, what does syscheck_update do ? Marco.

[ossec-list] Re: Moving server

2007-03-17 Thread Daniel Cid
. *It shoudn't afect rids or anything related to the agents. It is all stored under /var/ossec. Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 3/17/07, Michael Starks [EMAIL PROTECTED] wrote: Michael Starks wrote: I would do a fresh install so that it creates the startup scripts, users

[ossec-list] Re: how to send mail alert using a different program than ossec-maild?

2007-03-16 Thread Daniel Cid
, but that will be in a future version (1.2 and above).. *Btw, the current ossec-maild works fine with gmail SMTP (I used it all the time), since you are not required to use TLS for it. Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 3/15/07, Thanh Han The [EMAIL PROTECTED] wrote: Hi list

[ossec-list] OSSEC Version 1.1 is available.

2007-03-10 Thread Daniel Cid
-agent-win32-1.1.exe) = 2401fa249de7d0bafb07259c5838674e9b7785bd We want to thank everyone who contributed or just sent some comments or nice words to us! We really appreciate the feedback! -- Daniel B. Cid (in name of the OSSEC team). dcid ( at ) ossec.net

[ossec-list] Re: OSSEC 1.1 BETA2 available

2007-03-05 Thread Daniel Cid
There is no uninstall function for Unix (for Windows there is). You need to delete /var/ossec, /etc/ossec-init.conf and remove the ossec users... Thanks for testing the beta! Daniel On 3/4/07, Martin West [EMAIL PROTECTED] wrote: On Sat, 2007-03-03 at 20:53 -0400, Daniel Cid wrote: If you

[ossec-list] Re: ossec as syslog?

2007-03-03 Thread Daniel Cid
to the ossec server, you can configure ossec to use any of the three methods above or keep using syslog-ng and configure the ossec server to read the log files directly... Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 2/28/07, Nicolas Arias [EMAIL PROTECTED] wrote: Hello list!, how are you

[ossec-list] Re: Separate email_to addresses per agent?

2007-02-25 Thread Daniel Cid
on weekends if it's a big problem, and if I'm likely sleeping, it had better be a real big problem! :) We will keep this in mind for the next version... One feature at a time :) Thanks, -- Daniel B. Cid dcid ( at ) ossec.net

[ossec-list] Re: Overriding Frequency Rules

2007-02-24 Thread Daniel Cid
if_matched_sid18106/if_matched_sid descriptionMultiple Windows Logon Failures./description groupauthentication_failures,/group /rule Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 2/20/07, Michael Starks [EMAIL PROTECTED] wrote: I am having a problem ignoring or otherwise

[ossec-list] Re: Quick Active Response Question

2007-02-24 Thread Daniel Cid
Hi Kurt, The all option means all connected agents, but not the server. However, on 1.0 there was a bug that is was also firing on the server (it is fixed on the latest beta). Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 2/22/07, Kurt [EMAIL PROTECTED] wrote: I wanted to know

[ossec-list] Re: Separate email_to addresses per agent?

2007-02-24 Thread Daniel Cid
want to set email_maxperhour in the global config to a very high value ()... http://www.ossec.net/en/manual.html#global_options Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 1/18/07, Warren Petrofsky [EMAIL PROTECTED] wrote: We are installing ossec agents on a ton

[ossec-list] Re: Problems faced with OSSEC.

2007-02-21 Thread Daniel Cid
for these queries. Any help would be highly appreciated. Thanks, Pankaj P. I hope it helps. If you can send your config (and your client.keys file) and the ossec.log we can see what is going on (please, use the gz format)... Thanks, -- Daniel B. Cid dcid ( at ) ossec.net

[ossec-list] Re: Still getting those smbd alerts I am trying to ignore

2007-02-17 Thread Daniel Cid
smbd denied connection from/description /rule Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 2/17/07, Kayvan A. Sylvan [EMAIL PROTECTED] wrote: On Sat, Feb 17, 2007 at 05:23:36PM -0500, Michael Starks wrote: Kayvan A. Sylvan wrote: My local_rules.xml contains these snippets

[ossec-list] Re: No client configured. Exiting.

2007-02-17 Thread Daniel Cid
Hi OlRoy, By default the server does everything that the agent does, so there is no need to install both. If you want ossec in just one box, choose the local install. Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 2/17/07, OlRoy OlRoy [EMAIL PROTECTED] wrote: Hey Daniel, I've

[ossec-list] Re: Hmmm... More on ignoring certain alerts

2007-02-16 Thread Daniel Cid
://www.ossec.net/wiki/index.php/FAQ Thanks, -- Daniel B. Cid dcid ( at ) ossec.net Feb 16 09:52:21 server smbd[14947]: Denied connection from (0.0.0.0) On 2/16/07, Kayvan A. Sylvan [EMAIL PROTECTED] wrote: On Fri, Feb 16, 2007 at 01:30:13PM -0500, Mark Haney wrote: Kayvan A. Sylvan wrote

[ossec-list] Re: No client configured. Exiting.

2007-02-16 Thread Daniel Cid
have the client config in your agent: http://www.ossec.net/en/manual.html#client_options Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 2/16/07, OlRoy OlRoy [EMAIL PROTECTED] wrote: I'm using OSSEC v1.0 running on OpenBSD 4.0, and am following this tutorial for OSSEC v.9 on FreeBSD 6.1

[ossec-list] Re: How to modify the rules with a local_rules.xml?

2007-02-14 Thread Daniel Cid
/description /rule Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 2/14/07, Kayvan A. Sylvan [EMAIL PROTECTED] wrote: I thought I had an answer for this before, but I can't find it. I have an alert that fires off all the time: OSSEC HIDS Notification. 2007 Feb 14 16:15:03

[ossec-list] Re: Decoder patch of OSSEC v1.0 for snort log decoding

2007-02-10 Thread Daniel Cid
to be: Feb 10 16:58:32 hostname snort[3769]: [1:1420:11] SNMP trap tcp [Classification: Attempted Information Leak] [Priority: 2]: {TCP} 10.4.12.26:37020 - 10.4.10.231 162 Just curious if other people might be affected by this issue. Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 2/2/07, John Li

[ossec-list] Re: Question

2007-02-10 Thread Daniel Cid
level=0 if_sid18106/if_sid id^675/id matchFailure Code:0x19/match /rule Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 2/9/07, Nicolas Arias [EMAIL PROTECTED] wrote: This is the line that is filling my mailbox with rule 8152 fired (level 10) - Multiple Windows Logon Failures.: Feb

[ossec-list] Re: regex problem in OSSEC?

2007-02-08 Thread Daniel Cid
tag, but with a slower algorithm (for regex matching)... Can you give us more information? Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 2/8/07, Mark Haney [EMAIL PROTECTED] wrote: I've encountered what I think is a problem in OSSEC with regular expressions. I have a rule that looks like

[ossec-list] Re: regexp syntax?

2007-02-04 Thread Daniel Cid
support: http://www.ossec.net/wiki/index.php/Know_How:Regex_Readme Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 2/2/07, Sergey Zhumatiy [EMAIL PROTECTED] wrote: Hello! Where can I find full syntax for ossec regexps? It seems to be not fully compatible with POSIX and not fully

[ossec-list] List down (testing)...

2007-01-31 Thread Daniel Cid
Looks like googlegroups is having problems are all messages are being dropped... Testing if it is now working...

[ossec-list] Re: List down (testing)...

2007-01-31 Thread Daniel Cid
-list , please re-send. Thanks and sorry for any problem.. -- Daniel B. Cid dcid ( at ) ossec.net On 1/31/07, Daniel Cid [EMAIL PROTECTED] wrote: Looks like googlegroups is having problems are all messages are being dropped... Testing if it is now working...

[ossec-list] Re: Stuck Agent?

2007-01-30 Thread Daniel Cid
Hi Tommy, A complete uninstall is not required. Just remove the agent name from the /var/ossec/queue/agent-info/ directory. Manage_agents was supposed to remove it, but for some reason it is not (I will fix it in the code later). Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 1/30

[ossec-list] Re: Log host?

2007-01-29 Thread Daniel Cid
that ossec is meant to be a log analysis engine, so you will not have as many options regarding how to archive your logs. Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 1/29/07, John J. Culkin [EMAIL PROTECTED] wrote: Can OSSEC act as a centralized log host for linux machines? Or should I

[ossec-list] Re: RootCheck and Oracle - Disable RootCheck on specific interface?

2007-01-29 Thread Daniel Cid
, Daniel B. Cid dcid ( at ) ossec.net On 1/29/07, Jeremy Melanson [EMAIL PROTECTED] wrote: Hello all. I have several machines in a high-capacity Oracle database environment that I have running with OSSEC. The machines have a separate, dedicated network for that Oracle uses for heartbeat

[ossec-list] OSSEC Logo/Mascot contest

2007-01-28 Thread Daniel Cid
and/or mascot for the ossec project. This logo (or mascot) will be the official symbol of the ossec project and our new face. If you are interested, check the following link: http://www.ossec.net/wiki/index.php/CContest Thanks, -- Daniel B. Cid dcid ( at ) ossec.net

[ossec-list] Re: Agent issue

2007-01-25 Thread Daniel Cid
). -Make sure your agent firewall allows UDP 1514 outbound connections to the server (using proper stateful filtering to allow replies back). -Do the proper port forwarding/natting in the external firewall to the ossec server. Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 1/25/07

[ossec-list] Re: Specifying log format for Lotus Domino Web logs

2007-01-24 Thread Daniel Cid
one has a specific function to read them... **log_format is only used by logcollector (telling it how to read the file), and does not change the way the message is analyzed. Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 1/24/07, Black CryptoKnight [EMAIL PROTECTED] wrote: What

[ossec-list] Re: agent troubles

2007-01-24 Thread Daniel Cid
information (like your ossec config, parts of the log, etc) ... Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 1/24/07, Magnus Egilsson [EMAIL PROTECTED] wrote: Hi Has anyone experienced not beeing able to add more than 5 agents to the server? After restart I can see number six added

[ossec-list] Re: active response

2007-01-23 Thread Daniel Cid
after 60 failed attempts). You can keep the old rule and it is only going to show up after the 6 failed login attempts, but only reporting the last log received... I have a fix ready for that if you are insterested. thanks, norm Hope it clarifies a bit.. -- Daniel B. Cid dcid ( at ) ossec.net

[ossec-list] Re: WebUI problems

2007-01-19 Thread Daniel Cid
apache to chroot to /var instead of /var/www (lot of work). Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 1/19/07, Blot Nicolas [EMAIL PROTECTED] wrote: Hi all, I just discovered OSSEC and his WebUi but I'm having troubles with webui. I run Ossec server and webui on an OpenBSD 4.0

[ossec-list] Re: Local rules ignore problem

2007-01-19 Thread Daniel Cid
: /dev/hde, SMART Prefailure Attribute: 8 Seek_Time_Performance changed from 253 to 252|Unable to connect to shock.cloudmark.com|^MDLOG,\w+,drop,Bad html: Image cidN/regex Hope it helps.. -- Daniel B. Cid dcid ( at ) ossec.net On 1/19/07, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: Hi. I was using

[ossec-list] Re: Windows Agent Syscheck Frequency

2007-01-18 Thread Daniel Cid
changed in the code, if you want. I just don't think it is a good idea (at least for more cases)... Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 1/18/07, Rob [EMAIL PROTECTED] wrote: Hey all, Read the docs and saw the default frequency for syscheck to run is 7200 seconds

[ossec-list] Re: support for custom ids log

2007-01-18 Thread Daniel Cid
,id,system_name/fts /decoder It is basically going to create an FTS entry whenever it sees for the first time an IDS id + system name combination. You can leverage that do add source ips, protocols, usernames, etc... Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 1/17/07, shawn reed [EMAIL

[ossec-list] Re: Question about the UDP communication protocol

2007-01-17 Thread Daniel Cid
it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 1/16/07, cfactor [EMAIL PROTECTED] wrote: Hello All. I only just found out about OSSEC today through the ISC diary. From what I've read, it all seems very cool. Before I start playing around with it, I have a question about the communication

[ossec-list] Re: updated log support

2007-01-17 Thread Daniel Cid
interesting entry missing, please let us know. Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 1/15/07, Dennis Borkhus-Veto [EMAIL PROTECTED] wrote: Could you tell me what format I should list for the routing and remote access logs? Sincerely Dennis Borkhus-Veto Systems Administrator MEE

[ossec-list] Re: OSSEC Version 1.0 is available

2007-01-17 Thread Daniel Cid
all the data, etc). Is that what you meant? I initally got the impression that you wanted the agents to be able to forward messages to more than one server (HA style), but the bug says it differently... Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 1/15/07, Leonardo Goldim [EMAIL PROTECTED

[ossec-list] OSSEC Version 1.0 is available

2007-01-14 Thread Daniel Cid
(ossec-agent-win32-1.0.exe) = 9dd53252ebfb31dd00f8d67c98f6d2a65115d368 Thanks, -- Daniel B. Cid dcid ( at ) ossec.net

[ossec-list] Re: Feature Request - Solution for using OSSEC and NAT

2007-01-10 Thread Daniel Cid
: 192.168.2.0/24 (always using the whole network as the ip) Since the ossec server is going to see them as if they were comming from the nat server (192.168.2.x ip), it should work. Make sure to use one separate key for each agent... Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net

[ossec-list] Re: OSSEC on IPCop

2007-01-07 Thread Daniel Cid
the preloaded-vars.conf file properly (for the binary install): USER_BINARYINSTALL=y USER_DIR=/var/log/ossec *This work is only necessary on binary installs. For everyone else, just using the install.sh script should be fibe. Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 1/7/07, Michael

[ossec-list] Re: OSSEC on IPCop

2007-01-04 Thread Daniel Cid
glibc/gcc major version and share the same architecture (i386 or amd64, etc)... Hope it helps... -- Daniel B. Cid dcid ( at ) ossec.net On 1/3/07, Michael Starks [EMAIL PROTECTED] wrote: Black CryptoKnight wrote: I think when the smoothwall and IPCop guys are doing their mods, many do

[ossec-list] Re: Web UI problem

2007-01-04 Thread Daniel Cid
Hi John, Do you have OSSEC 0.9-3 (or higher snapshot) installed? We added the group information on 0.9-3 and the web ui requires that. Can you check that for us? Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 1/3/07, John Mothershead [EMAIL PROTECTED] wrote: Greetings, I have the exact

[ossec-list] Ossec web ui (beta 2) available.

2007-01-02 Thread Daniel Cid
/ossec-wui-0.1-BETA2.tar.gz Installation instructions: http://www.ossec.net/dcid/?p=26 Let us know of any problems. Thanks, -- Daniel B. Cid dcid ( at ) ossec.net

[ossec-list] Re: Rule 14

2007-01-02 Thread Daniel Cid
, can you show us what is causing these alerts? Maybe there is a false positive on rootcheck that we need to fix. Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 1/2/07, jalal [EMAIL PROTECTED] wrote: So, ossec is setup and ticking along nicely. The only fly in the ointment is emails I get about

[ossec-list] Registry monitoring on ossec (input request)

2007-01-02 Thread Daniel Cid
comments... *btw, next version (1.0) is comming soon... Thanks, -- Daniel B. Cid dcid ( at ) ossec.net

[ossec-list] Re: Problem trying out ossec

2006-12-20 Thread Daniel Cid
Hi Tim, Can you show us your ossec config and your ossec log*? It looks like that you have a configuration error and ossec is not handling it very well. *The files we need are: /var/ossec/etc/ossec.conf and /var/ossec/logs/ossec.log Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 12/19

[ossec-list] Re: ossec.conf for many, many logs

2006-12-20 Thread Daniel Cid
*: http://www.ossec.net/files/snapshots/ossec-hids-061221.tar.gz *Always make sure to check for new versions at http://www.ossec.net/files/snapshots/ before downloading. *Snapshots are not official releases, but somewhat stable (tested in a few systems). Thanks, -- Daniel B. Cid dcid

[ossec-list] Re: Web UI problem

2006-12-06 Thread Daniel Cid
Hi Kurt, Can you try restarting your webserver? Sometimes it will only use the new group information after you restart it. In addition to that, do you see anything in the apache error logs? *I need to test it with PHP 5 to make sure it works... Thanks, -- Daniel B. Cid dcid ( at ) ossec.net

[ossec-list] Re: Trouble with E-mail Alerts

2006-12-04 Thread Daniel Cid
it is not required to match the source ip address (or real hostname of the system). *The SMTP session is very simple and it follows the RFC correctly. Since it is failing on the helo command, I am guessing on an access control issue on the mail server. Thanks, -- Daniel B. Cid dcid

[ossec-list] Re: Windows Agent Stops Unexpectedly

2006-12-04 Thread Daniel Cid
/log_format /localfile /ossec_config Let me know if this fixes your problem. If not, we will need to keep digging. Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 11/29/06, Rob [EMAIL PROTECTED] wrote: Here's the agent config and log. I've checked to make sure nothing was running. I ran

[ossec-list] no mail servers

2006-12-01 Thread Daniel Guido
I'm using OSSEC on a closed network with no mail servers on it. I've only ever gotten OSSEC reports by e-mail, how do you read the reports locally? -- Dan Guido

<    4   5   6   7   8   9   10   11   >