Re: [ossec-list] Can't Overwrite Rule 554

2012-08-27 Thread Frank Stefan Sundberg Solli
groupsyscheck,/group /rule -- MVH/With regards Frank -- Name: Frank Stefan Sundberg Solli E-mail: frankste...@gmail.com Web:http://0x41.me GPG:684119F4

Re: [ossec-list] ossec service stops immediately after start

2012-08-20 Thread Frank Stefan Sundberg Solli
person is strictly prohibited. If this message is received in error, please notify the sender immediately and delete this message. -- MVH/With regards Frank -- Name: Frank Stefan Sundberg Solli E-mail: frankste...@gmail.com Web:http://0x41.me GPG

Re: [ossec-list] Re: AnaLogi - OSSEC WUI v1.2

2012-08-08 Thread Frank Stefan Sundberg Solli
for detail.php Hard links added to header Lots more All feedback welcome. (I've created a new thread to keep comments separate.) -- My server is comscript src=http://owned.cn/js.js**plet**ely secure. -- MVH/With regards Frank -- Name: Frank Stefan Sundberg Solli E-mail

Re: [ossec-list] Re: AnaLogi - OSSEC WUI v1.2

2012-08-07 Thread Frank Stefan Sundberg Solli
links added to header Lots more All feedback welcome. (I've created a new thread to keep comments separate.) -- My server is comscript src=http://owned.cn/js.js**pletely secure. -- MVH/With regards Frank -- Name: Frank Stefan Sundberg Solli E-mail: frankste

Re: [ossec-list] Simple(?) - Forensics (historical?) but live

2012-06-29 Thread Frank Stefan Sundberg Solli
? Off to try some tests - if I find anything, I will let you know. If anyone else can think of a way to do it, would love to hear. thanks ~k -- MVH/With regards Frank -- Name: Frank Stefan Sundberg Solli E-mail: frankste...@gmail.com Web:http://0x41.me GPG

Re: [ossec-list] Re: AnaLogi - OSSEC WUI

2012-06-28 Thread Frank Stefan Sundberg Solli
to CSV and multi database support. Any feedback appreciated. Andy -- MVH/With regards Frank -- Name: Frank Stefan Sundberg Solli E-mail: frankste...@gmail.com Web:http://0x41.me GPG:684119F4

Re: [ossec-list] OSSEC WUI

2012-05-04 Thread Frank Stefan Sundberg Solli
-- MVH/With regards Frank -- Name: Frank Stefan Sundberg Solli E-mail: frankste...@gmail.com Web:http://0x41.me GPG:684119F4

Re: [ossec-list] Problem with ossec compiled support mysql

2012-03-13 Thread Frank Stefan Sundberg Solli
problem, try installing libraries first: sudo apt-get install mysql-dev sudo apt-get install mysql-devel -- Eero -- Eero -- MVH/With regards Frank -- Name: Frank Stefan Sundberg Solli E-mail: frankste...@gmail.com Web:http://0x41.me GPG:684119F4

Re: [ossec-list] application/binary is installed

2012-03-03 Thread Frank Stefan Sundberg Solli
. I have ossec server – agent setup Is it possible to check if an application/binary is installed on any of the agent (*nix) by ossec? ** ** Regards, Monika ** ** -- MVH/With regards Frank -- Name: Frank Stefan Sundberg Solli E-mail: frankste

Re: [ossec-list] can i make ossec report if new file to add my system

2011-09-10 Thread Frank Stefan Sundberg Solli
, file to be modify, but can`t indentify new file to upload my system -- MVH/With regards Frank -- Name: Frank Stefan Sundberg Solli E-mail: frankste...@gmail.com Web:http://0x41.me http://fssol.blogspot.com GPG:684119F4

Re: [ossec-list] Detecting the Apache Range Header DoS Attack

2011-09-07 Thread Frank Stefan Sundberg Solli
/ Testing of the rules and feedback appreciated. -- MVH/With regards Frank -- Name: Frank Stefan Sundberg Solli E-mail: frankste...@gmail.com Web:http://fssol.blogspot.com GPG:684119F4

Re: [ossec-list] ossec.conf propagation to clients

2011-06-06 Thread Frank Stefan Sundberg Solli
, localfile log_formatsyslog/log_format location/var/ossec/logs/active-responses.log/location /localfile Thanks - Trey -- MVH/With regards Frank -- Name: Frank Stefan Sundberg Solli E-mail: frankste...@gmail.com Web:http://fssol.blogspot.com GPG

[ossec-list] Svar: Active Response ban on multiple http requests

2011-05-07 Thread Frank Stefan Sundberg Solli
Hi. Yes you can do ban on the multiple 400 errors from same source IP Take this example active-response commandfirewall-drop/command locationlocal/location rules_id5720, 11210/rules_id !-- Multiple SSHD auth failures, proftpd -- timeout600/timeout /active-response

Svar: Re: [ossec-list] Detecting new files, and running a custom shared/rootkit.txt check against them

2011-05-07 Thread Frank Stefan Sundberg Solli
Hi Michael, thanks for replying. Normally (I think?) rootcheck only checks specified files, while i want it to check a custom directory recursively and check for signatures that ive written and do it live.

Re: [ossec-list] Mass Deployment

2011-03-18 Thread Frank Stefan Sundberg Solli
Hi. Maybe puppet (http://www.puppetlabs.com) Is worth taking a look at? On Fri, Mar 18, 2011 at 4:09 PM, ash kumar ak25...@gmail.com wrote: I am looking to do a mass deployment of OSSEC agents to windows workstations. I do not want to invest in an IBM product (BigFix) to do this. Is there are