I'm having the same issue with the 1.6 release for windows (2003 server). Regards,
Michel ----- Original Message ----- From: "Wes" <[EMAIL PROTECTED]> To: <[email protected]> Sent: Wednesday, September 03, 2008 2:27 AM Subject: [ossec-list] Re: Windows active response not working > > Unfortunately, no -- even after upgrading to the official 1.6 release, > I still can't get active response to work on the Windows side. > > > On Tue, Sep 2, 2008 at 4:52 PM, Will Metcalf <[EMAIL PROTECTED]> > wrote: >> >> I'm having the same issue with the 1.6 release... Did you ever get >> this figured out? >> >> Regards, >> >> Will >> >> On 8/29/08, Wes <[EMAIL PROTECTED]> wrote: >>> >>> I was happy to learn that active response is now available for >>> Windows, but as of yet I've had no luck getting it working. Here's >>> what I've done so far: >>> >>> - Installed 8/28 server snapshot and 8/28 Windows agent snapshot >>> >>> - Added the following to ossec.conf on the agent side: >>> >>> <active-response> >>> <disabled>no</disabled> >>> </active-response> >>> >>> - Added the following to ossec.conf on the server side (the goal being >>> to trigger the active response when any rule level 10 or higher fires, >>> and block the source IP for 10 minutes): >>> >>> <command> >>> <name>win_nullroute</name> >>> <executable>route-null.cmd</executable> >>> <expect>srcip</expect> >>> <timeout_allowed>yes</timeout_allowed> >>> </command> >>> >>> <active-response> >>> <command>win_nullroute</command> >>> <location>local</location> >>> <level>10</level> >>> <timeout>600</timeout> >>> </active-response> >>> >>> - Restarted both the server and the agent >>> >>> - Checked ossec.log (on the agent) to verify that active response is >>> working: >>> >>> 2008/08/29 13:35:29 ossec-execd: INFO: Started (pid: 2772). >>> >>> - Tested the active response with: >>> >>> # /var/ossec/bin/agent_control -b 2.3.4.5 -f win_nullroute600 -u 011 >>> >>> After running the test, the IP 2.3.4.5 shows up when running a 'route >>> print' on the agent machine. Up until this point, everything appears >>> to be working fine. >>> >>> However, when I send a request to the server that fires a level 12 >>> false positive (specifically, rule 31106), the alert is logged and I >>> get the e-mail notification as per usual, but the active response is >>> not triggered. The IP that I'm sending the test request from does not >>> get temporarily blocked, nor does anything show up when running a >>> 'route print'. I've verified that this IP is not whitelisted in >>> ossec.conf. >>> >>> Any ideas what I might be doing wrong? Thanks! >>> >> >
