Hi Kevin, The active responses are run by the ossec-execd process as root. So there is no need to use sudo in there... I initially thought about that, but since sudo is not widely supported, I decided to stick with running as root instead.
Kivanio, Do you mind running the active response manually? Try # /bin/sh -x /var/ossec/active-response/bin/firewall-drop.sh add XXX 192.168.2.1 And then check the content of the table: # pfctl -t ossec_fwtable -T show If that doesn' t work, please show us the output from /bin/sh -x (debugging enabled)... I tried this over on OpenBSD and is working fine... Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On Wed, Apr 23, 2008 at 11:34 AM, Kevin Reiter <[EMAIL PROTECTED]> wrote: > > I haven't had time to play with it yet, but in essence, the ossec user needs > to be able to run the pfctl command, which is normally reserved for the root > user, hence the usage of sudo. I should have time today to experiment with > it and let you know what I discover. > > > -Kevin > > -----Original Message----- > From: [email protected] [mailto:[EMAIL PROTECTED] Behalf Of > Kivanio Barbosa > > > Sent: Tuesday, April 22, 2008 5:38 PM > To: [email protected] > Subject: [ossec-list] Re: active-response with freebsd and PF > > > Kevin, > > > thanks. > > > i'll try whith sudo. > > > but, i don't use sudo in my servers. > > > other solution is possible? > > > -Kivanio > > > On Tue, Apr 22, 2008 at 3:07 PM, Kevin Reiter <[EMAIL PROTECTED]> wrote: > > > I haven't looked at the script yet, but you'll need to add a sudo command in > order for the pf commands to work, which means you'll have to edit the > sudoers file (using visudo) to allow the ossec user to modify the table. > > The command should look like this: > > sudo /sbin/pfctl -ef /etc/pf.conf > > I'll explain it in more detail later when I have a chance to read the > documentation, but that should get you by for now. > > -Kevin > > > > -----Original Message----- > From: [email protected] [mailto:[EMAIL PROTECTED] Behalf Of > Kivanio Barbosa > Sent: Tuesday, April 22, 2008 1:32 PM > To: [email protected] > Subject: [ossec-list] Re: active-response with freebsd and PF > > > Daniel, > > > > > i think you don't understand what i said. > > > i did all this. > > > i add table, add rules, add all. > > > ossec is using the script and in log show the ip and other things, don't > show errors. > > > but when i show table of PF, the table is clear. > The rules of PF don't block ip because ip is not include in table. > > > > > then, the ossec said that ip was added, but the ip is not include in table. > > > > > the block using hosts is fine. > > > > > do you understand? > > > OBS: Acho que meu inglês está péssimo hehe, o ossec mostra no log a inclusão > do ip, porém ele não inclui o ip, quando listo os ips da tabela, ela está > limpa, porém ele inclui corretamente no hosts. Se eu mudar o nome da tabela, > da erro, com isso sei que ele está usando a tabela certa, o único erro, é que > o ip não consta na tabela, ou seja, ele diz que faz, mas na realidade não > está fazendo, estou com o mesmo problema em 2 BSDs. tentei corrigir o script, > porém aparentemente está tudo certo, e não consegui identificar nada fora do > ossec que pudesse estar interferindo, por isso estou perguntando para ver se > não era um bug conhecido, desculpe o incomodo. Pode responder em inglês mesmo > ;) > > > > > > On Tue, Apr 22, 2008 at 12:50 PM, Daniel Cid <[EMAIL PROTECTED]> wrote: > > > Hi Kivanio, > > Did you follow the steps in the configuration for pf? > > http://www.ossec.net/main/manual/#active-response-config > > " > On PF, you need to create a table in your config and deny all the > traffic to it. Add the following lines at the beginning of your > rules and reload pf (pfctl -F all && pfctl -f /etc/pf.conf): > > table <ossec_fwtable> persist #ossec_fwtable > > block in quick from <ossec_fwtable> to any > block out quick from any to <ossec_fwtable> > " > > Thanks, > > > -- > Daniel B. Cid > dcid ( at ) ossec.net > > > > On Sun, Apr 13, 2008 at 8:50 PM, Kivanio Barbosa <[EMAIL PROTECTED]> wrote: > > Hi Daniel, > > > > i see your mensage about ossec 1.5 so i remove ossec 1.4 and install 1.5. > > > > the same problem happen. > > > > > > > > server server /usr/local/ossec # tail -f logs/active-responses.log > > Sun Apr 13 19:42:55 AMT 2008 > > /usr/local/ossec/active-response/bin/host-deny.sh add - 89.13.24.98 > > 1208130175.568 20100 > > Sun Apr 13 19:42:55 AMT 2008 > > /usr/local/ossec/active-response/bin/firewall-drop.sh add - 89.13.24.98 > > 1208130175.568 20100 > > ^C > > server server /usr/local/ossec # pfctl -t ossec_fwtable -T show > > server server /usr/local/ossec # cat /etc/hosts.deny > > ALL:89.48.135.87 > > ALL:89.48.62.163 > > ALL:217.235.146.142 > > ALL:92.228.210.101 > > ALL:91.37.126.196 > > ALL:89.57.6.219 > > ALL:77.181.89.215 > > ALL:79.234.249.31 > > ALL:77.134.83.174 > > ALL:77.178.150.133 > > ALL:217.235.220.210 > > ALL:77.179.187.66 > > ALL:77.183.179.60 > > ALL:87.167.138.240 > > ALL:75.126.23.220 > > ALL:217.232.206.235 > > ALL:77.179.9.47 > > ALL:84.145.5.163 > > ALL:89.13.24.98 > > ALL:79.234.249.31 > > ALL:89.48.62.163 > > ALL:217.235.146.142 > > ALL:89.48.161.32 > > ALL:201.3.34.169 > > > > > > The host-deny.sh works fine but firewall-drop.sh don't. > > > > > > -- > > Kivanio Pereira Barbosa > > Cel 8121-4248 > > > > www.eiqconsultoria.com.br > > > > > -- > Kivanio Pereira Barbosa > Cel 8121-4248 > > www.eiqconsultoria.com.br > > > This message may contain confidential or proprietary information and is > intended solely for the individual(s) to whom it is addressed. If you are > not a named addressee you should not disseminate, distribute or copy this > e-mail or act upon the information contained herein. Please notify the > sender immediately by e-mail if you have received this e-mail by mistake and > delete this e-mail from your system. > > > > > > -- > Kivanio Pereira Barbosa > Cel 8121-4248 > > www.eiqconsultoria.com.br >
