Hi Joachim,

Can you share the logs that were created by vsftpd and proftpd on your
tests? We support these
two formats very well and it works on my setup. Maybe you have a
difference version or format?

This is how we expect them:
http://www.ossec.net/wiki/index.php/ProFTPD
http://www.ossec.net/wiki/index.php/Vsftpd

Thanks,

--
Daniel B. Cid
dcid ( at ) ossec.net



On Thu, Jul 10, 2008 at 3:13 AM, Joachim Krais
<[EMAIL PROTECTED]> wrote:
>
> Hello group, hello Daniel,
>
> we use these ftp-Daemons:
> * vsftp         (problem with OSSEC)
> * proftp        (problem with OSSEC)
> * pure-ftp      (works fine with OSSEC)
>
> The distributions are SLES9SP4 and Debian.
>
> Ossec 1.5.1 was installed with local-settings, active-response,
> firewall-functions. We establish connections to these servers in
> the following ways:
> * correctly (user and password exists)
> * uncorrectly - simulates an attack: (user or password doesn't exist)
>
> We set up a tail -f to /var/ossec/log/alerts/alerts.log.
>
> SSH-Logins for example are correctly identified by OSSEC, but OSSEC
> doesn't unfortunately show us ftp-attacks (vsftp and proftp) in the
> alert.log
>
> Messages from pure-ftp are already correctly found by OSSEC. :-)
>
> Where is the problem?
>
> Greetings
>
> Joachim
>
>
>

Reply via email to