Re: [ossec-list] Daniel Cid Honored by the OSSEC Community

2010-10-21 Thread John A. Sullivan III
On Thu, 2010-10-21 at 08:57 -0500, Michael Starks wrote: Today, we thank Daniel Cid for creating OSSEC. Daniel has been working on OSSEC for a long time now. He started on it long before being snatched up by Third Brigade, having already put thousands of hours into the project. He chose to

[ossec-list] Re: Week of OSSEC - lots of tips / good information about OSSEC

2009-11-02 Thread John A. Sullivan III
A. Sullivan III Open Source Development Corporation +1 207-985-7880 jsulli...@opensourcedevel.com http://www.spiritualoutreach.com Making Christianity intelligible to secular society

[ossec-list] Re: os_match or os_regex

2009-10-29 Thread John A. Sullivan III
except 0 . holger Can you use Infected: [1-9]? - John -- John A. Sullivan III Open Source Development Corporation +1 207-985-7880 jsulli...@opensourcedevel.com http://www.spiritualoutreach.com Making Christianity intelligible to secular society

[ossec-list] Re: Rootkit check on linux-vserver hosts

2009-10-27 Thread John A. Sullivan III
- John -- John A. Sullivan III Open Source Development Corporation +1 207-985-7880 jsulli...@opensourcedevel.com http://www.spiritualoutreach.com Making Christianity intelligible to secular society

[ossec-list] Re: wildcards

2009-09-01 Thread John A. Sullivan III
for all guests with a call similar to this: localfile log_formatsyslog/log_format location/vservers/[a-zA-Z0-9]*/var/log/messages/location /localfile It's working fine for us. Hope this helps - John -- John A. Sullivan III Open Source Development Corporation +1 207-985-7880 jsulli

[ossec-list] Re: SysCheck SegFault in Apr 17, 2009 snapshot

2009-08-19 Thread John A. Sullivan III
On Tue, 2009-05-12 at 08:26 -0400, John A. Sullivan III wrote: Hello, all. For some reason, I still do not receive messages from this list even though I am subscribed. I thus missed Daniel's reply to this issue quoted below: Hi John, If you disable rootkit

[ossec-list] SysCheck SegFault in Apr 17, 2009 snapshot

2009-05-12 Thread John A. Sullivan III
the syscheck is not running most of time. What can we do next to help troubleshoot this issue? Thanks - John PS - any suggestions on why I never receive the list's messages? - Of course, you'll have to answer me directly! -- John A. Sullivan III Open Source Development Corporation +1 207-985-7880

[ossec-list] syscheck segfaults

2009-05-05 Thread John A. Sullivan III
spinning out of control and is only remedied by a hard boot : We've now seen this with things other than OSSEC. So, back to the topic at hand, are these segfaults a known issue? We are seeing them on both vservers and KVM guests. All are running CentOS 5.3. Thanks - John -- John A. Sullivan

[ossec-list] wildcards in syscheck

2009-03-30 Thread John A. Sullivan III
, we thought we had better ask before experimenting! Thanks - John -- John A. Sullivan III Open Source Development Corporation +1 207-985-7880 jsulli...@opensourcedevel.com http://www.spiritualoutreach.com Making Christianity intelligible to secular society

[ossec-list] Re: BIG PROBLEM - runaway syscheckd process

2009-03-30 Thread John A. Sullivan III
On Tue, 2009-03-24 at 11:49 -0400, John A. Sullivan III wrote: Here it is. There is another problem. My apologies for wondering why the list was so slow to respond. I am not receiving any email from the list including Nerijus' response below. I only received your direct responses, Daniel

[ossec-list] Re: BIG PROBLEM - runaway syscheckd process

2009-03-30 Thread John A. Sullivan III
On Mon, 2009-03-30 at 06:58 -0400, John A. Sullivan III wrote: On Tue, 2009-03-24 at 11:49 -0400, John A. Sullivan III wrote: Here it is. There is another problem. My apologies for wondering why the list was so slow to respond. I am not receiving any email from the list including

[ossec-list] Re: BIG PROBLEM - runaway syscheckd process

2009-03-30 Thread John A. Sullivan III
On Mon, 2009-03-30 at 07:10 -0400, John A. Sullivan III wrote: On Mon, 2009-03-30 at 07:04 -0400, John A. Sullivan III wrote: On Mon, 2009-03-30 at 06:58 -0400, John A. Sullivan III wrote: On Tue, 2009-03-24 at 11:49 -0400, John A. Sullivan III wrote: Here it is. There is another

[ossec-list] Re: BIG PROBLEM - runaway syscheckd process

2009-03-30 Thread John A. Sullivan III
On Mon, 2009-03-30 at 08:05 -0400, John A. Sullivan III wrote: On Mon, 2009-03-30 at 07:10 -0400, John A. Sullivan III wrote: On Mon, 2009-03-30 at 07:04 -0400, John A. Sullivan III wrote: On Mon, 2009-03-30 at 06:58 -0400, John A. Sullivan III wrote: On Tue, 2009-03-24 at 11:49 -0400

[ossec-list] Re: BIG PROBLEM - runaway syscheckd process

2009-03-30 Thread John A. Sullivan III
, John A. Sullivan III jsulli...@opensourcedevel.com wrote: On Mon, 2009-03-30 at 08:05 -0400, John A. Sullivan III wrote: On Mon, 2009-03-30 at 07:10 -0400, John A. Sullivan III wrote: On Mon, 2009-03-30 at 07:04 -0400, John A. Sullivan III wrote: On Mon, 2009-03-30 at 06:58 -0400, John

[ossec-list] BIG PROBLEM - runaway syscheckd process

2009-03-18 Thread John A. Sullivan III
/ossec_config Any idea what is causing this? How to kill the process without rebooting? How to fix it? We're starting to fall behind on this critical project so any help is greatly appreciated. Thanks - John -- John A. Sullivan III Open Source Development Corporation +1 207-985-7880 jsulli

[ossec-list] Re: local_ip

2009-02-09 Thread John A. Sullivan III
you provide the local_ip (by doing netstat -uan and ps auwx |grep remoted). Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On Thu, Feb 5, 2009 at 5:55 PM, John A. Sullivan III jsulli...@opensourcedevel.com wrote: Hello, all. As you can tell, we are continuing our exploration

[ossec-list] Why both md5 and sha1?

2009-02-06 Thread John A. Sullivan III
-- John A. Sullivan III Open Source Development Corporation +1 207-985-7880 jsulli...@opensourcedevel.com http://www.spiritualoutreach.com Making Christianity intelligible to secular society

[ossec-list] Purpose of database output

2009-02-05 Thread John A. Sullivan III
or is it simply a way of capturing the data for use by other applications? Thanks - John -- John A. Sullivan III Open Source Development Corporation +1 207-985-7880 jsulli...@opensourcedevel.com http://www.spiritualoutreach.com Making Christianity intelligible to secular society

[ossec-list] Limiting OSSEC processes on VServer guests

2009-02-05 Thread John A. Sullivan III
syscheck and logcollector and only using the rootkit functionality in the guests, would we be better off not running OSSEC in the guests at all and running something like rkhunter instead? Thanks - John -- John A. Sullivan III Open Source Development Corporation Street Preacher: Are you SAVED

[ossec-list] local_ip

2009-02-05 Thread John A. Sullivan III
of all? Thanks - John -- John A. Sullivan III Open Source Development Corporation +1 207-985-7880 jsulli...@opensourcedevel.com http://www.spiritualoutreach.com Making Christianity intelligible to secular society