Hello group, hello Daniel, we use these ftp-Daemons: * vsftp (problem with OSSEC) * proftp (problem with OSSEC) * pure-ftp (works fine with OSSEC)
The distributions are SLES9SP4 and Debian. Ossec 1.5.1 was installed with local-settings, active-response, firewall-functions. We establish connections to these servers in the following ways: * correctly (user and password exists) * uncorrectly - simulates an attack: (user or password doesn't exist) We set up a tail -f to /var/ossec/log/alerts/alerts.log. SSH-Logins for example are correctly identified by OSSEC, but OSSEC doesn't unfortunately show us ftp-attacks (vsftp and proftp) in the alert.log Messages from pure-ftp are already correctly found by OSSEC. :-) Where is the problem? Greetings Joachim
