Unfortunately, no -- even after upgrading to the official 1.6 release,
I still can't get active response to work on the Windows side.


On Tue, Sep 2, 2008 at 4:52 PM, Will Metcalf <[EMAIL PROTECTED]> wrote:
>
> I'm having the same issue with the 1.6 release... Did you ever get
> this figured out?
>
> Regards,
>
> Will
>
> On 8/29/08, Wes <[EMAIL PROTECTED]> wrote:
>>
>> I was happy to learn that active response is now available for
>> Windows, but as of yet I've had no luck getting it working.  Here's
>> what I've done so far:
>>
>> - Installed 8/28 server snapshot and 8/28 Windows agent snapshot
>>
>> - Added the following to ossec.conf on the agent side:
>>
>> <active-response>
>> <disabled>no</disabled>
>> </active-response>
>>
>> - Added the following to ossec.conf on the server side (the goal being
>> to trigger the active response when any rule level 10 or higher fires,
>> and block the source IP for 10 minutes):
>>
>> <command>
>> <name>win_nullroute</name>
>> <executable>route-null.cmd</executable>
>> <expect>srcip</expect>
>> <timeout_allowed>yes</timeout_allowed>
>> </command>
>>
>> <active-response>
>> <command>win_nullroute</command>
>> <location>local</location>
>> <level>10</level>
>> <timeout>600</timeout>
>> </active-response>
>>
>> - Restarted both the server and the agent
>>
>> - Checked ossec.log (on the agent) to verify that active response is working:
>>
>> 2008/08/29 13:35:29 ossec-execd: INFO: Started (pid: 2772).
>>
>> - Tested the active response with:
>>
>> # /var/ossec/bin/agent_control -b 2.3.4.5 -f win_nullroute600 -u 011
>>
>> After running the test, the IP 2.3.4.5 shows up when running a 'route
>> print' on the agent machine.  Up until this point, everything appears
>> to be working fine.
>>
>> However, when I send a request to the server that fires a level 12
>> false positive (specifically, rule 31106), the alert is logged and I
>> get the e-mail notification as per usual, but the active response is
>> not triggered.  The IP that I'm sending the test request from does not
>> get temporarily blocked, nor does anything show up when running a
>> 'route print'.  I've verified that this IP is not whitelisted in
>> ossec.conf.
>>
>> Any ideas what I might be doing wrong?  Thanks!
>>
>

Reply via email to