Hi Dennis, Since we don't have decoders for this type of log, we can't run the active response because ossec doesn't know the source ip address. Did you get around writing a decoder? If not, can you give us a few more log samples so we can write something for it? I would like to squeeze it on version 1.5 if possible :)
Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On Wed, Mar 12, 2008 at 9:26 PM, Dennis Golden <[EMAIL PROTECTED]> wrote: > > > Dennis Golden wrote: > > I'm new to ossec and have a question. I searched the archives, but found > > nothing. I got over 370 of these attempts yesterday (the lines have > > wrapped): > > > > Mar 11 16:53:13 mailhost postfix/smtpd[19978]: connect from > > adsl-xx.xx.xxx.xxx.dsl.some.isp[xx.xx.xxx.xxx] > > > > Mar 11 16:53:17 mailhost postfix/smtpd[19978]: warning: > > adsl-xx.xx.xxx.xxx.dsl.some.isp[xx.xx.xxx.xxx]: SASL LOGIN > > authentication failed: authentication failure > > > > Mar 11 16:53:18 mailhost postfix/smtpd[19978]: disconnect from > > adsl-xx.xx.xxx.xxx.dsl.some.isp[xx.xx.xxx.xxx] > > > > I received notification from ossec (level 10) about multiple > > authentication failures: > > > > Received From: mailhost->/var/log/messages > > Rule: 40111 fired (level 10) -> "Multiple authentication failures." > > Portion of the log(s): > > > > Mar 11 18:34:12 mailhost saslauthd[3312]: do_auth : auth > > failure: [user=brandon] [service=smtp] [realm=] [mech=pam] [reason=PAM > > auth error] > > > > My question is have others had this and gotten active-reponse to stop > > allowing connections from the offending host? I'm not sure where to start. > > OK, it looks like I need to write another decoder. Do I just add it to > the decoder.xml file in the etc directory? Will it get written over on > an upgrade? I don't see anywhere else to add this. > > Regards, > > > > Dennis > -- > Dennis Golden > Golden Consulting Services, Inc. >
