I'm having the same issue with the 1.6 release for windows (2003 server).

Regards,

Michel

----- Original Message ----- 
From: "Wes" <[EMAIL PROTECTED]>
To: <[email protected]>
Sent: Wednesday, September 03, 2008 2:27 AM
Subject: [ossec-list] Re: Windows active response not working


>
> Unfortunately, no -- even after upgrading to the official 1.6 release,
> I still can't get active response to work on the Windows side.
>
>
> On Tue, Sep 2, 2008 at 4:52 PM, Will Metcalf <[EMAIL PROTECTED]> 
> wrote:
>>
>> I'm having the same issue with the 1.6 release... Did you ever get
>> this figured out?
>>
>> Regards,
>>
>> Will
>>
>> On 8/29/08, Wes <[EMAIL PROTECTED]> wrote:
>>>
>>> I was happy to learn that active response is now available for
>>> Windows, but as of yet I've had no luck getting it working.  Here's
>>> what I've done so far:
>>>
>>> - Installed 8/28 server snapshot and 8/28 Windows agent snapshot
>>>
>>> - Added the following to ossec.conf on the agent side:
>>>
>>> <active-response>
>>> <disabled>no</disabled>
>>> </active-response>
>>>
>>> - Added the following to ossec.conf on the server side (the goal being
>>> to trigger the active response when any rule level 10 or higher fires,
>>> and block the source IP for 10 minutes):
>>>
>>> <command>
>>> <name>win_nullroute</name>
>>> <executable>route-null.cmd</executable>
>>> <expect>srcip</expect>
>>> <timeout_allowed>yes</timeout_allowed>
>>> </command>
>>>
>>> <active-response>
>>> <command>win_nullroute</command>
>>> <location>local</location>
>>> <level>10</level>
>>> <timeout>600</timeout>
>>> </active-response>
>>>
>>> - Restarted both the server and the agent
>>>
>>> - Checked ossec.log (on the agent) to verify that active response is 
>>> working:
>>>
>>> 2008/08/29 13:35:29 ossec-execd: INFO: Started (pid: 2772).
>>>
>>> - Tested the active response with:
>>>
>>> # /var/ossec/bin/agent_control -b 2.3.4.5 -f win_nullroute600 -u 011
>>>
>>> After running the test, the IP 2.3.4.5 shows up when running a 'route
>>> print' on the agent machine.  Up until this point, everything appears
>>> to be working fine.
>>>
>>> However, when I send a request to the server that fires a level 12
>>> false positive (specifically, rule 31106), the alert is logged and I
>>> get the e-mail notification as per usual, but the active response is
>>> not triggered.  The IP that I'm sending the test request from does not
>>> get temporarily blocked, nor does anything show up when running a
>>> 'route print'.  I've verified that this IP is not whitelisted in
>>> ossec.conf.
>>>
>>> Any ideas what I might be doing wrong?  Thanks!
>>>
>>
> 

Reply via email to