Hi Dennis,

Since we don't have decoders for this type of log, we can't run the
active response because
ossec doesn't know the source ip address. Did you get around writing a
decoder? If not, can
you give us a few more log samples so we can write something for it? I
would like to squeeze
it on version 1.5 if possible :)


Thanks,

--
Daniel B. Cid
dcid ( at ) ossec.net



On Wed, Mar 12, 2008 at 9:26 PM, Dennis Golden
<[EMAIL PROTECTED]> wrote:
>
>
>  Dennis Golden wrote:
>  > I'm new to ossec and have a question. I searched the archives, but found
>  > nothing. I got over 370 of these attempts yesterday (the lines have
>  > wrapped):
>  >
>  > Mar 11 16:53:13 mailhost postfix/smtpd[19978]: connect from
>  > adsl-xx.xx.xxx.xxx.dsl.some.isp[xx.xx.xxx.xxx]
>  >
>  > Mar 11 16:53:17 mailhost postfix/smtpd[19978]: warning:
>  > adsl-xx.xx.xxx.xxx.dsl.some.isp[xx.xx.xxx.xxx]: SASL LOGIN
>  > authentication failed: authentication failure
>  >
>  > Mar 11 16:53:18 mailhost postfix/smtpd[19978]: disconnect from
>  > adsl-xx.xx.xxx.xxx.dsl.some.isp[xx.xx.xxx.xxx]
>  >
>  > I received notification from ossec (level 10) about multiple
>  > authentication failures:
>  >
>  > Received From: mailhost->/var/log/messages
>  > Rule: 40111 fired (level 10) -> "Multiple authentication failures."
>  > Portion of the log(s):
>  >
>  > Mar 11 18:34:12 mailhost saslauthd[3312]: do_auth         : auth
>  > failure: [user=brandon] [service=smtp] [realm=] [mech=pam] [reason=PAM
>  > auth error]
>  >
>  > My question is have others had this and gotten active-reponse to stop
>  > allowing connections from the offending host? I'm not sure where to start.
>
>  OK, it looks like I need to write another decoder. Do I just add it to
>  the decoder.xml file in the etc directory? Will it get written over on
>  an upgrade? I don't see anywhere else to add this.
>
>  Regards,
>
>
>
>  Dennis
>  --
>  Dennis Golden
>  Golden Consulting Services, Inc.
>

Reply via email to