Hi Joachim, For the proftpd and vsftpd, I made a few changes to support them properly (with your old format). Try this version (just choose to update) and it should work:
http://www.ossec.net/files/snapshots/ossec-hids-080716.tar.gz Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On Mon, Jul 14, 2008 at 8:23 AM, Joachim Krais <[EMAIL PROTECTED]> wrote: > > Hello Joachim and group, > > with your hints, vsftpd and OSSEC works fine together! Great! > I'm very happy about that. > Thanks a lot. > > ******** > *vsftpd* > ******** > I modified > > vsftpd.conf: > vsftpd_log_file=/var/log/vsftpd/vsftpd.log > > and ossec.conf: > <localfile> > <log_format>syslog</log_format> > <location>/var/log/vsftpd/vsftpd.log</location> > </localfile> > > > ********* > *proftpd* > ********* > Now i tried it again with proftpd, but sadly the hints from above on > proftpd doesn't work. I have maked tests before with echo-ing > a Logging-line with : after the PID and changing the correct > logging-time into the logfile from proftpd: > > echo "Jul 11 08:18:58 myserver proftpd[27260]: myserver.a-home.de > (192.168.7.2[192.168.7.2]): USER peter: Login successful." >> > /var/log/proftpd/proftpd.log > > and OSSEC recognizes the FTP-Connection from peter it ... > > > Greetings > Joachim > > Joachim Vorrath schrieb: >> >> Hi Joachim, >> >> you should check your vsftpd.conf >> I use it long time ... >> >> vsftpd.conf >> >> dual_log_enable=yes >> syslog_enable=yes >> pam_service_name=vsftpd >> >> than use the vsftpd decoder: >> >> ossec.conf >> >> <localfile> >> <log_format>syslog</log_format> >> <location>/var/log/vsftpd</location> >> </localfile> >> >> so the decoder vsftpd will match. >> >> >> >> details from logtest: >> --------------------------- >> match on /var/log/vsftpd.log >> >> Sun Jul 13 10:26:52 2008 [pid 26990] [anonymous] FAIL LOGIN: Client >> "84.140.234.76" >> >> >> **Phase 1: Completed pre-decoding. >> full event: 'Sun Jul 13 10:26:52 2008 [pid 26990] [anonymous] >> FAIL LOGIN: Client "84.140.234.76"' >> hostname: 'www' >> program_name: '(null)' >> log: 'Sun Jul 13 10:26:52 2008 [pid 26990] [anonymous] FAIL >> LOGIN: Client "84.140.234.76"' >> >> **Phase 2: Completed decoding. >> decoder: 'vsftpd' >> srcip: '84.140.234.76' >> >> **Phase 3: Completed filtering (rules). >> Rule id: '11403' >> Level: '5' >> Description: 'Login failed accessing the FTP server.' >> **Alert to be generated. >> >> >> if you match on syslog or messages file: >> -------------------------------------------------------- >> Jul 13 12:31:20 www vsftpd: Sun Jul 13 10:31:20 2008 [pid 27528] >> [anonymous] FAIL LOGIN: Client "84.140.234.76" >> >> >> **Phase 1: Completed pre-decoding. >> full event: 'Jul 13 12:31:20 www vsftpd: Sun Jul 13 10:31:20 >> 2008 [pid 27528] [anonymous] FAIL LOGIN: Client "84.140.234.76"' >> hostname: 'www' >> program_name: 'vsftpd' >> log: 'Sun Jul 13 10:31:20 2008 [pid 27528] [anonymous] FAIL >> LOGIN: Client "84.140.234.76"' >> >> **Phase 2: Completed decoding. >> No decoder matched. >> >> >> >> >> Hope that helps ..... >> >> regards >> Joachim Vorrath >> >> >> >> >> >> >> >> Am 11.07.2008 um 11:37 schrieb Joachim Krais: >> >>> Hi Daniel, >>> >>> first of all: thanks a lot for the wiki-link and your efforts. :-) >>> OSSEC works very fine in my differential environment. >>> Only the FTP-handling gives me a lot of trouble. >>> >>> proftpd-Logging on my site: >>> =========================== >>> Jul 11 08:18:54 myserver proftpd[27260] myserver.a-home.de >>> (192.168.7.2[192.168.7.2]): FTP session opened. >>> Jul 11 08:18:54 myserver proftpd[27260] myserver.a-home.de >>> (192.168.7.2[192.168.7.2]): mod_delay/0.5: delaying for 126 usecs >>> Jul 11 08:18:58 myserver proftpd[27260] myserver.a-home.de >>> (192.168.7.2[192.168.7.2]): USER peter: Login successful. >>> Jul 11 08:18:58 myserver proftpd[27260] myserver.a-home.de >>> (192.168.7.2[192.168.7.2]): Preparing to chroot to directory '/home/ >>> peter' >>> >>> vsftpd-Logging on my site: >>> ========================== >>> Jul 9 12:24:14 newserver vsftpd: Wed Jul 9 12:24:14 2008 [pid 30082] >>> CONNECT: Client "192.168.7.2" >>> Jul 9 12:24:14 newserver vsftpd: Wed Jul 9 12:24:14 2008 [pid 30082] >>> FTP response: Client "192.168.7.2", "220 (vsFTPd 2.0.4)" >>> Jul 9 12:24:14 newserver vsftpd: Wed Jul 9 12:24:14 2008 [pid 30082] >>> FTP command: Client "192.168.7.2", "USER ann" >>> Jul 9 12:24:14 newserver vsftpd: Wed Jul 9 12:24:14 2008 [pid 30082] >>> [ann] FTP response: Client "192.168.7.2", "331 Pleas >>> e specify the password." >>> Jul 9 12:24:17 newserver vsftpd: Wed Jul 9 12:24:17 2008 [pid 30082] >>> [ann] FTP command: Client "192.168.7.2", "PASS <pass >>> word>" >>> Jul 9 12:24:17 newserver vsftpd: Wed Jul 9 12:24:17 2008 [pid 30081] >>> [ann] FAIL LOGIN: Client "192.168.7.2" >>> Jul 9 12:24:17 newserver vsftpd: Wed Jul 9 12:24:17 2008 [pid 30082] >>> [ann] FTP response: Client "192.168.7.2", "530 Login >>> incorrect." >>> >>> >>> Comparing Logging on my site and the log-samples in your wiki: >>> ============================================================== >>> *** proftpd >>> I doesn't find any hints for my problem. :-( >>> But when i adding a ":" after the PID [27260]: and send a echo with a >>> self-modifed proftpd Logging-line: OSSEC recognizes it in the >>> alert.log >>> >>> *** vsftpd >>> Sorry, but I doesn't find any hints for my problem too. >>> >>> >>> What can I do? I have tried this on both linux-distributions SLES >>> (SuSE) >>> and Debian with the same result. Than i have installed pure-ftp and >>> OSSEC works right from the start hand in hand with pure-ftp. >>> >>> A stupid question: Maybe are there invisible control characters (tabs) >>> in the Logging-lines? >>> Has everyone else the same problems? >>> >>> Greetings >>> Joachim >>> >>> Daniel Cid schrieb: >>>> Hi Joachim, >>>> >>>> Can you share the logs that were created by vsftpd and proftpd on >>>> your >>>> tests? We support these >>>> two formats very well and it works on my setup. Maybe you have a >>>> difference version or format? >>>> >>>> This is how we expect them: >>>> http://www.ossec.net/wiki/index.php/ProFTPD >>>> http://www.ossec.net/wiki/index.php/Vsftpd >>>> >>>> Thanks, >>>> >>>> -- >>>> Daniel B. Cid >>>> dcid ( at ) ossec.net >>>> >>>> >>>> >>>> On Thu, Jul 10, 2008 at 3:13 AM, Joachim Krais >>>> <[EMAIL PROTECTED]> wrote: >>>>> Hello group, hello Daniel, >>>>> >>>>> we use these ftp-Daemons: >>>>> * vsftp (problem with OSSEC) >>>>> * proftp (problem with OSSEC) >>>>> * pure-ftp (works fine with OSSEC) >>>>> >>>>> The distributions are SLES9SP4 and Debian. >>>>> >>>>> Ossec 1.5.1 was installed with local-settings, active-response, >>>>> firewall-functions. We establish connections to these servers in >>>>> the following ways: >>>>> * correctly (user and password exists) >>>>> * uncorrectly - simulates an attack: (user or password doesn't >>>>> exist) >>>>> >>>>> We set up a tail -f to /var/ossec/log/alerts/alerts.log. >>>>> >>>>> SSH-Logins for example are correctly identified by OSSEC, but OSSEC >>>>> doesn't unfortunately show us ftp-attacks (vsftp and proftp) in the >>>>> alert.log >>>>> >>>>> Messages from pure-ftp are already correctly found by OSSEC. :-) >>>>> >>>>> Where is the problem? >>>>> >>>>> Greetings >>>>> >>>>> Joachim >>>>> >>>>> >>>>> >> >> >> ______________________________________ >> XamimeLT - installed on mailserver for domain at vorrath-net.de >> Queries to: postmaster at vorrath-net.de >
