Awesome! Thanks for addressing that. Is there a rule for noticing a "first time su to root" for a user?
Thanks, Mitch On Aug 18, 1:23 pm, "Daniel Cid" <[EMAIL PROTECTED]> wrote: > Hi, > > I fixed the decoder to extract the username from that log. You can try > it out at:http://www.ossec.net/files/snapshots/ossec-hids-080818.tar.gz > > Output o the log test: > > **Phase 1: Completed pre-decoding. > full event: 'Aug 1 12:24:12 saturn su: [ID 810491 auth.crit] > 'su root' failed for chapman on /dev/pts/1' > hostname: 'saturn' > program_name: 'su' > log: ''su root' failed for chapman on /dev/pts/1' > > **Phase 2: Completed decoding. > decoder: 'su' > dstuser: 'root' > srcuser: 'chapman' > > **Phase 3: Completed filtering (rules). > Rule id: '5302' > Level: '9' > Description: 'User missed the password to change UID to root.' > **Alert to be generated. > > Thanks, > > -- > Daniel B. Cid > dcid ( at ) ossec.net > > > > On Tue, Aug 5, 2008 at 2:09 PM, kidplug <[EMAIL PROTECTED]> wrote: > > > Can you post your su decoder configuration? > > I think that's where the problem is - the rule will work if the > > decoder properly recognizes the destination user as root. > > > On Aug 5, 10:16 am, "Quiroz, Genaro (GE, Corporate, consultant)" > > <[EMAIL PROTECTED]> wrote: > >> Here is the example of that rule. It is working for us just change the > >> #### for the number which correspond in your custome rules. > >> By the way we have enable BSM and send the BSM logs to a syslog format > >> probably that might help with your problem. > > >> <!-- If user tries and success to switch to root --> > >> <rule id="####" level="15"> > >> <if_sid>6102</if_sid> > >> <options>alert_by_email</options> > >> <match>text success for user root</match> > >> <description>User successfully switched to root user.</description> > >> <group>authentication_success,</group> > >> </rule> > > >> <!-- Rule to alert if user tries and success to switch to root --> > >> <rule id="#####" level="15"> > >> <if_sid>6102</if_sid> > >> <options>alert_by_email</options> > >> <match>text success for user root</match> > >> <description>User successfully switched to root user.</description> > >> <group>authentication_success,</group> > >> </rule> > > >> <!-- Rule to alert if user tries and fails to switch to root --> > >> <rule id="#####" level="10"> > >> <if_sid>6101</if_sid> > >> <options>alert_by_email</options> > >> <match>text bad auth. for user root</match> > >> <description>User failed to switch to root user.</description> > >> <group>authentication_failed,</group> > >> </rule> > > >> <!-- Rule to alert if user tries and fails to switch to root --> > >> <rule id="#####" level="10"> > >> <if_sid>6101</if_sid> > >> <options>alert_by_email</options> > >> <match>text bad auth. for user root</match> > >> <description>User failed to switch to root user.</description> > >> <group>authentication_failed,</group> > >> </rule> > > >> -----Original Message----- > >> From: [email protected] [mailto:[EMAIL PROTECTED] > > >> On Behalf Of kidplug > >> Sent: Friday, August 01, 2008 11:31 AM > >> To: ossec-list > >> Subject: [ossec-list] Failed su to root not detected on Solaris - rule > >> 5302 > > >> Rule 5301 is kicking in: > > >> ** Alert 1217607852.29755: - syslog, su,authentication_failed, > >> 2008 Aug 01 12:24:12 (saturn) 192.168.1.76->/var/log/authlog > >> Rule: 5301 (level 5) -> 'User missed the password to change UID (user > >> id).' > >> Src IP: (none) > >> User: (none) > >> Aug 1 12:24:12 saturn su: [ID 810491 auth.crit] 'su root' failed for > >> chapman on /dev/pts/1 > > >> But as you can see, the decoder is apparently not parsing out the user > >> properly, so 5302 is not being applied (level 9 rule for failed su to > >> root). > > >> It would also be nice to have a rule for successful su to root - > >> especially "First time su to root for user X". > > >> Thanks, > >> Mitch- Hide quoted text - > > >> - Show quoted text -- Hide quoted text - > > - Show quoted text -
