Hi Kevin,

The active responses are run by the ossec-execd process as root. So
there is no need to use sudo
in there... I initially thought about that, but since sudo is not
widely supported, I decided to stick with
running as root instead.

Kivanio,

Do you mind running the active response manually? Try

# /bin/sh -x /var/ossec/active-response/bin/firewall-drop.sh add XXX 192.168.2.1

And then check the content of the table:

# pfctl -t ossec_fwtable -T show

If that doesn' t work, please show us the output from /bin/sh -x
(debugging enabled)... I tried this
over on OpenBSD and is working fine...


Thanks,


--
Daniel B. Cid
dcid ( at ) ossec.net



On Wed, Apr 23, 2008 at 11:34 AM, Kevin Reiter <[EMAIL PROTECTED]> wrote:
>
>  I haven't had time to play with it yet, but in essence, the ossec user needs 
> to be able to run the pfctl command, which is normally reserved for the root 
> user, hence the usage of sudo.  I should have time today to experiment with 
> it and let you know what I discover.
>
>
>  -Kevin
>
>  -----Original Message-----
>  From: [email protected] [mailto:[EMAIL PROTECTED] Behalf Of 
> Kivanio Barbosa
>
>
> Sent: Tuesday, April 22, 2008 5:38 PM
>  To: [email protected]
>  Subject: [ossec-list] Re: active-response with freebsd and PF
>
>
>  Kevin,
>
>
>  thanks.
>
>
>  i'll try whith sudo.
>
>
>  but, i don't use sudo in my servers.
>
>
>  other solution is possible?
>
>
>  -Kivanio
>
>
>  On Tue, Apr 22, 2008 at 3:07 PM, Kevin Reiter <[EMAIL PROTECTED]> wrote:
>
>
>  I haven't looked at the script yet, but you'll need to add a sudo command in 
> order for the pf commands to work, which means you'll have to edit the 
> sudoers file (using visudo) to allow the ossec user to modify the table.
>
>  The command should look like this:
>
>  sudo /sbin/pfctl -ef /etc/pf.conf
>
>  I'll explain it in more detail later when I have a chance to read the 
> documentation, but that should get you by for now.
>
>  -Kevin
>
>
>
>  -----Original Message-----
>  From: [email protected] [mailto:[EMAIL PROTECTED] Behalf Of 
> Kivanio Barbosa
>  Sent: Tuesday, April 22, 2008 1:32 PM
>  To: [email protected]
>  Subject: [ossec-list] Re: active-response with freebsd and PF
>
>
>  Daniel,
>
>
>
>
>  i think you don't understand what i said.
>
>
>  i did all this.
>
>
>  i add table, add rules, add all.
>
>
>  ossec is using the script and in log show the ip and other things, don't 
> show errors.
>
>
>  but when i show table of PF, the table is clear.
>  The rules of PF don't block ip because ip is not include in table.
>
>
>
>
>  then, the ossec said that ip was added, but the ip is not include in table.
>
>
>
>
>  the block using hosts is fine.
>
>
>
>
>  do you understand?
>
>
>  OBS: Acho que meu inglês está péssimo hehe, o ossec mostra no log a inclusão 
> do ip, porém ele não inclui o ip, quando listo os ips da tabela, ela está 
> limpa, porém ele inclui corretamente no hosts. Se eu mudar o nome da tabela, 
> da erro, com isso sei que ele está usando a tabela certa, o único erro, é que 
> o ip não consta na tabela, ou seja, ele diz que faz, mas na realidade não 
> está fazendo, estou com o mesmo problema em 2 BSDs. tentei corrigir o script, 
> porém aparentemente está tudo certo, e não consegui identificar nada fora do 
> ossec que pudesse estar interferindo, por isso estou perguntando para ver se 
> não era um bug conhecido, desculpe o incomodo. Pode responder em inglês mesmo 
> ;)
>
>
>
>
>
>  On Tue, Apr 22, 2008 at 12:50 PM, Daniel Cid <[EMAIL PROTECTED]> wrote:
>
>
>  Hi Kivanio,
>
>  Did you follow the steps in the configuration for pf?
>
>  http://www.ossec.net/main/manual/#active-response-config
>
>  "
>  On PF, you need to create a table in your config and deny all the
>  traffic to it. Add the following lines at the beginning of your
>  rules and reload pf (pfctl -F all && pfctl -f /etc/pf.conf):
>
>  table <ossec_fwtable> persist #ossec_fwtable
>
>  block in quick from <ossec_fwtable> to any
>  block out quick from any to <ossec_fwtable>
>  "
>
>  Thanks,
>
>
>  --
>  Daniel B. Cid
>  dcid ( at ) ossec.net
>
>
>
>  On Sun, Apr 13, 2008 at 8:50 PM, Kivanio Barbosa <[EMAIL PROTECTED]> wrote:
>  > Hi Daniel,
>  >
>  > i see your mensage about ossec 1.5 so i remove ossec 1.4 and install 1.5.
>  >
>  > the same problem happen.
>  >
>  >
>  >
>  > server server /usr/local/ossec # tail -f logs/active-responses.log
>  > Sun Apr 13 19:42:55 AMT 2008
>  > /usr/local/ossec/active-response/bin/host-deny.sh add - 89.13.24.98
>  > 1208130175.568 20100
>  > Sun Apr 13 19:42:55 AMT 2008
>  > /usr/local/ossec/active-response/bin/firewall-drop.sh add - 89.13.24.98
>  > 1208130175.568 20100
>  > ^C
>  > server server /usr/local/ossec # pfctl -t ossec_fwtable -T show
>  > server server /usr/local/ossec # cat /etc/hosts.deny
>  > ALL:89.48.135.87
>  > ALL:89.48.62.163
>  > ALL:217.235.146.142
>  > ALL:92.228.210.101
>  > ALL:91.37.126.196
>  > ALL:89.57.6.219
>  > ALL:77.181.89.215
>  > ALL:79.234.249.31
>  > ALL:77.134.83.174
>  > ALL:77.178.150.133
>  > ALL:217.235.220.210
>  > ALL:77.179.187.66
>  > ALL:77.183.179.60
>  > ALL:87.167.138.240
>  > ALL:75.126.23.220
>  > ALL:217.232.206.235
>  > ALL:77.179.9.47
>  > ALL:84.145.5.163
>  > ALL:89.13.24.98
>  > ALL:79.234.249.31
>  > ALL:89.48.62.163
>  > ALL:217.235.146.142
>  > ALL:89.48.161.32
>  > ALL:201.3.34.169
>  >
>  >
>  > The host-deny.sh works fine but firewall-drop.sh don't.
>  >
>  >
>  > --
>  > Kivanio Pereira Barbosa
>  > Cel 8121-4248
>  >
>  > www.eiqconsultoria.com.br
>
>
>
>
>  --
>  Kivanio Pereira Barbosa
>  Cel 8121-4248
>
>  www.eiqconsultoria.com.br
>
>
>  This message may contain confidential or proprietary information and is 
> intended solely for the individual(s) to whom it is addressed.  If you are 
> not a named addressee you should not disseminate, distribute or copy this 
> e-mail or act upon the information contained herein.  Please notify the 
> sender immediately by e-mail if you have received this e-mail by mistake and 
> delete this e-mail from your system.
>
>
>
>
>
>  --
>  Kivanio Pereira Barbosa
>  Cel 8121-4248
>
>  www.eiqconsultoria.com.br
>

Reply via email to