Hi, I am running on windows 2003 server agent 1.6 and linux (centos 5.1) server same version. I get the e-mail level 10 but agent not reponse. It not in the white_list (on server ossec.conf)
ossec.conf client: <active-response> <disabled>no</disabled> </active-response> <command> <name>win_nullroute</name> <executable>route-null.cmd</executable> <expect>srcip</expect> <timeout_allowed>yes</timeout_allowed> </command> <active-response> <command>win_nullroute</command> <location>local</location> <level>10</level> <timeout>600</timeout> </active-response> Log ossec client (some part): 2008/09/03 21:02:03 ossec-execd: INFO: Started (pid: 5548). 2008/09/03 21:02:05 ossec-agent: INFO: Started (pid: 5548). 2008/09/03 21:08:09 ossec-agent: INFO: Starting syscheck scan (db). 2008/09/03 21:15:25 ossec-agent: INFO: Ending syscheck scan (db). 2008/09/03 21:15:45 ossec-agent: INFO: Starting rootcheck scan. 2008/09/03 21:17:16 ossec-agent: INFO: Ending rootcheck scan. 2008/09/03 22:25:51 ossec-agent: INFO: Active response command not present: 'active-response/bin/host-deny.sh'. Not using it on this system. 2008/09/03 22:25:51 ossec-agent: INFO: Active response command not present: 'active-response/bin/firewall-drop.sh'. Not using it on this system. I have C:\Program Files\ossec-agent\active-response/bin/route-null.cmd but see no active-responses.log file. I add in C:\Program Files\ossec-agent\shared\ar.conf on the last line win_nullroute600 - route-null.cmd - 600 (first stop agent) Now i see host-deny600 - host-deny.sh - 600 firewall-drop600 - firewall-drop.sh - 600 win_nullroute600 - route-null.cmd - 600 After restart i see the host-deny600 - host-deny.sh - 600 firewall-drop600 - firewall-drop.sh - 600 No rule i add -> win_nullroute600 - route-null.cmd - 600 Sorry i have not many time to anser your other question and sorry for my bad english. Best regards, Michel ----- Original Message ----- From: "Daniel Cid" <[EMAIL PROTECTED]> To: <[email protected]> Sent: Wednesday, September 03, 2008 8:10 PM Subject: [ossec-list] Re: Windows active response not working > > Hey, > > Can you guys give more information about your setup? I have it running > well in here, and tested > on XP and 2003. > > -Does it work when you run with the agent_control tool? > -Which alerts were you expecting the response to run? Note that it > will only run if the source ip was > decoded properly. Can you show the alert pasted from > /var/ossec/logs/alerts/alerts.log ? > -Did you just tried it after restarting the server? Note that when you > restart the server, it loses the connection > to the agent, so the responses will only be called again on the next > keep alive (which can take a few > minutes). It may also take a few more minutes, for the ar.conf to be > shared with the agent (see bellow). > -Is the ip your are testing white_listed? > > -What do you see in your ossec.log (agent-side?). > > Make sure that you have: (meaning active response started) > 2008/08/31 16:31:18 ossec-execd: INFO: Started (pid: 3448). > > And you will probably see messages like this when the first response is > called: > 2008/09/01 00:02:14 ossec-agent: INFO: Active response command not > present: 'active-response/bin/host-deny.sh'. Not using it on this > system. > 2008/09/01 00:02:14 ossec-agent: INFO: Active response command not > present: 'active-response/bin/firewall-drop.sh'. Not using it on this > system. > > > If you see the following, it is because you didn't enable it properly. > 2008/08/13 14:17:49 ossec-execd(1350): INFO: Active response disabled. > Exiting. > > > -What do you have at C:\Program Files\ossec-agent\active-response ? > You should have a "bin" directory > with the route-null command and a active-responses.log file. > > These are some of the entries I have the responses log file: > 08/29/2008 03:45 "active-response/bin/route-null.cmd" add - > xx.168.2.99 1220035222.362251 31106 (winhome2) 192.168.2.0- > 08/29/2008 03:59 "active-response/bin/route-null.cmd" delete - > xx.168.2.99 1220035222.362251 31106 (winhome2) 192.168.2.0- > 08/29/2008 05:31 "active-response/bin/route-null.cmd" add - x.6.7.4 > (from_the_server) (no_rule_id) > 08/29/2008 05:31 "active-response/bin/route-null.cmd" add - x.6.7.5 > (from_the_server) (no_rule_id) > > *Note that the first one is a real live response, while the other is > just a test from the agent_control tool. > > > -Inside C:\Program Files\ossec-agent\shared you should have an ar.conf > file, with the following entry > at least: > win_nullroute600 - route-null.cmd - 600 > > This file can take a few minutes to be populated from the server, so > that might be a reason why it is not > working. > > > Thanks. > > > -- > Daniel B. Cid > dcid ( at ) ossec.net > > > On Wed, Sep 3, 2008 at 1:28 PM, Michel van Dop <[EMAIL PROTECTED]> wrote: >> >> I'm having the same issue with the 1.6 release for windows (2003 server). >> >> Regards, >> >> Michel >> >> ----- Original Message ----- >> From: "Wes" <[EMAIL PROTECTED]> >> To: <[email protected]> >> Sent: Wednesday, September 03, 2008 2:27 AM >> Subject: [ossec-list] Re: Windows active response not working >> >> >>> >>> Unfortunately, no -- even after upgrading to the official 1.6 release, >>> I still can't get active response to work on the Windows side. >>> >>> >>> On Tue, Sep 2, 2008 at 4:52 PM, Will Metcalf <[EMAIL PROTECTED]> >>> wrote: >>>> >>>> I'm having the same issue with the 1.6 release... Did you ever get >>>> this figured out? >>>> >>>> Regards, >>>> >>>> Will >>>> >>>> On 8/29/08, Wes <[EMAIL PROTECTED]> wrote: >>>>> >>>>> I was happy to learn that active response is now available for >>>>> Windows, but as of yet I've had no luck getting it working. Here's >>>>> what I've done so far: >>>>> >>>>> - Installed 8/28 server snapshot and 8/28 Windows agent snapshot >>>>> >>>>> - Added the following to ossec.conf on the agent side: >>>>> >>>>> <active-response> >>>>> <disabled>no</disabled> >>>>> </active-response> >>>>> >>>>> - Added the following to ossec.conf on the server side (the goal being >>>>> to trigger the active response when any rule level 10 or higher fires, >>>>> and block the source IP for 10 minutes): >>>>> >>>>> <command> >>>>> <name>win_nullroute</name> >>>>> <executable>route-null.cmd</executable> >>>>> <expect>srcip</expect> >>>>> <timeout_allowed>yes</timeout_allowed> >>>>> </command> >>>>> >>>>> <active-response> >>>>> <command>win_nullroute</command> >>>>> <location>local</location> >>>>> <level>10</level> >>>>> <timeout>600</timeout> >>>>> </active-response> >>>>> >>>>> - Restarted both the server and the agent >>>>> >>>>> - Checked ossec.log (on the agent) to verify that active response is >>>>> working: >>>>> >>>>> 2008/08/29 13:35:29 ossec-execd: INFO: Started (pid: 2772). >>>>> >>>>> - Tested the active response with: >>>>> >>>>> # /var/ossec/bin/agent_control -b 2.3.4.5 -f win_nullroute600 -u 011 >>>>> >>>>> After running the test, the IP 2.3.4.5 shows up when running a 'route >>>>> print' on the agent machine. Up until this point, everything appears >>>>> to be working fine. >>>>> >>>>> However, when I send a request to the server that fires a level 12 >>>>> false positive (specifically, rule 31106), the alert is logged and I >>>>> get the e-mail notification as per usual, but the active response is >>>>> not triggered. The IP that I'm sending the test request from does not >>>>> get temporarily blocked, nor does anything show up when running a >>>>> 'route print'. I've verified that this IP is not whitelisted in >>>>> ossec.conf. >>>>> >>>>> Any ideas what I might be doing wrong? Thanks! >>>>> >>>> >>> >> >> >
