Hi Joachim,
you should check your vsftpd.conf
I use it long time ...
vsftpd.conf
dual_log_enable=yes
syslog_enable=yes
pam_service_name=vsftpd
than use the vsftpd decoder:
ossec.conf
<localfile>
<log_format>syslog</log_format>
<location>/var/log/vsftpd</location>
</localfile>
so the decoder vsftpd will match.
details from logtest:
---------------------------
match on /var/log/vsftpd.log
Sun Jul 13 10:26:52 2008 [pid 26990] [anonymous] FAIL LOGIN: Client
"84.140.234.76"
**Phase 1: Completed pre-decoding.
full event: 'Sun Jul 13 10:26:52 2008 [pid 26990] [anonymous]
FAIL LOGIN: Client "84.140.234.76"'
hostname: 'www'
program_name: '(null)'
log: 'Sun Jul 13 10:26:52 2008 [pid 26990] [anonymous] FAIL
LOGIN: Client "84.140.234.76"'
**Phase 2: Completed decoding.
decoder: 'vsftpd'
srcip: '84.140.234.76'
**Phase 3: Completed filtering (rules).
Rule id: '11403'
Level: '5'
Description: 'Login failed accessing the FTP server.'
**Alert to be generated.
if you match on syslog or messages file:
--------------------------------------------------------
Jul 13 12:31:20 www vsftpd: Sun Jul 13 10:31:20 2008 [pid 27528]
[anonymous] FAIL LOGIN: Client "84.140.234.76"
**Phase 1: Completed pre-decoding.
full event: 'Jul 13 12:31:20 www vsftpd: Sun Jul 13 10:31:20
2008 [pid 27528] [anonymous] FAIL LOGIN: Client "84.140.234.76"'
hostname: 'www'
program_name: 'vsftpd'
log: 'Sun Jul 13 10:31:20 2008 [pid 27528] [anonymous] FAIL
LOGIN: Client "84.140.234.76"'
**Phase 2: Completed decoding.
No decoder matched.
Hope that helps .....
regards
Joachim Vorrath
Am 11.07.2008 um 11:37 schrieb Joachim Krais:
>
> Hi Daniel,
>
> first of all: thanks a lot for the wiki-link and your efforts. :-)
> OSSEC works very fine in my differential environment.
> Only the FTP-handling gives me a lot of trouble.
>
> proftpd-Logging on my site:
> ===========================
> Jul 11 08:18:54 myserver proftpd[27260] myserver.a-home.de
> (192.168.7.2[192.168.7.2]): FTP session opened.
> Jul 11 08:18:54 myserver proftpd[27260] myserver.a-home.de
> (192.168.7.2[192.168.7.2]): mod_delay/0.5: delaying for 126 usecs
> Jul 11 08:18:58 myserver proftpd[27260] myserver.a-home.de
> (192.168.7.2[192.168.7.2]): USER peter: Login successful.
> Jul 11 08:18:58 myserver proftpd[27260] myserver.a-home.de
> (192.168.7.2[192.168.7.2]): Preparing to chroot to directory '/home/
> peter'
>
> vsftpd-Logging on my site:
> ==========================
> Jul 9 12:24:14 newserver vsftpd: Wed Jul 9 12:24:14 2008 [pid 30082]
> CONNECT: Client "192.168.7.2"
> Jul 9 12:24:14 newserver vsftpd: Wed Jul 9 12:24:14 2008 [pid 30082]
> FTP response: Client "192.168.7.2", "220 (vsFTPd 2.0.4)"
> Jul 9 12:24:14 newserver vsftpd: Wed Jul 9 12:24:14 2008 [pid 30082]
> FTP command: Client "192.168.7.2", "USER ann"
> Jul 9 12:24:14 newserver vsftpd: Wed Jul 9 12:24:14 2008 [pid 30082]
> [ann] FTP response: Client "192.168.7.2", "331 Pleas
> e specify the password."
> Jul 9 12:24:17 newserver vsftpd: Wed Jul 9 12:24:17 2008 [pid 30082]
> [ann] FTP command: Client "192.168.7.2", "PASS <pass
> word>"
> Jul 9 12:24:17 newserver vsftpd: Wed Jul 9 12:24:17 2008 [pid 30081]
> [ann] FAIL LOGIN: Client "192.168.7.2"
> Jul 9 12:24:17 newserver vsftpd: Wed Jul 9 12:24:17 2008 [pid 30082]
> [ann] FTP response: Client "192.168.7.2", "530 Login
> incorrect."
>
>
> Comparing Logging on my site and the log-samples in your wiki:
> ==============================================================
> *** proftpd
> I doesn't find any hints for my problem. :-(
> But when i adding a ":" after the PID [27260]: and send a echo with a
> self-modifed proftpd Logging-line: OSSEC recognizes it in the
> alert.log
>
> *** vsftpd
> Sorry, but I doesn't find any hints for my problem too.
>
>
> What can I do? I have tried this on both linux-distributions SLES
> (SuSE)
> and Debian with the same result. Than i have installed pure-ftp and
> OSSEC works right from the start hand in hand with pure-ftp.
>
> A stupid question: Maybe are there invisible control characters (tabs)
> in the Logging-lines?
> Has everyone else the same problems?
>
> Greetings
> Joachim
>
> Daniel Cid schrieb:
>> Hi Joachim,
>>
>> Can you share the logs that were created by vsftpd and proftpd on
>> your
>> tests? We support these
>> two formats very well and it works on my setup. Maybe you have a
>> difference version or format?
>>
>> This is how we expect them:
>> http://www.ossec.net/wiki/index.php/ProFTPD
>> http://www.ossec.net/wiki/index.php/Vsftpd
>>
>> Thanks,
>>
>> --
>> Daniel B. Cid
>> dcid ( at ) ossec.net
>>
>>
>>
>> On Thu, Jul 10, 2008 at 3:13 AM, Joachim Krais
>> <[EMAIL PROTECTED]> wrote:
>>> Hello group, hello Daniel,
>>>
>>> we use these ftp-Daemons:
>>> * vsftp (problem with OSSEC)
>>> * proftp (problem with OSSEC)
>>> * pure-ftp (works fine with OSSEC)
>>>
>>> The distributions are SLES9SP4 and Debian.
>>>
>>> Ossec 1.5.1 was installed with local-settings, active-response,
>>> firewall-functions. We establish connections to these servers in
>>> the following ways:
>>> * correctly (user and password exists)
>>> * uncorrectly - simulates an attack: (user or password doesn't
>>> exist)
>>>
>>> We set up a tail -f to /var/ossec/log/alerts/alerts.log.
>>>
>>> SSH-Logins for example are correctly identified by OSSEC, but OSSEC
>>> doesn't unfortunately show us ftp-attacks (vsftp and proftp) in the
>>> alert.log
>>>
>>> Messages from pure-ftp are already correctly found by OSSEC. :-)
>>>
>>> Where is the problem?
>>>
>>> Greetings
>>>
>>> Joachim
>>>
>>>
>>>
>
______________________________________
XamimeLT - installed on mailserver for domain at vorrath-net.de
Queries to: postmaster at vorrath-net.de