Hi all,

I think I figured out what was going on. Depending on the argument (if
it had spaces),
the command to block would not be called properly. I am pretty sure it is fixed
on the following snapshot:

http://www.ossec.net/files/snapshots/ossec-win32-080904.exe

Can you try with this version? You don't need to update the server,
just the agent side.

*I will release a v1.6.1 soon with the fixes for some of the reported
bugs so far.


Thanks,

--
Daniel B. Cid
dcid ( at ) ossec.net



On Thu, Sep 4, 2008 at 12:15 PM, Michel van Dop <[EMAIL PROTECTED]> wrote:
>
> Hello,
>
> I try again, to make sure.
> I have see a problem on C:\Program Files\ossec-agent\shared\ar.conf
> I add a line win_nullroute600 after restart he change the file and is
> remove the last rule. win_nullroute600 - route-null.cmd - 600
>
> I do a upgrade from ossec agent 1.5.1 on windows 2k3 sp2 to ossec 1.6.
>
> I also make a uninstall of ossec agent 1.6 and try again, same problem.
>
> Can any one give a good full example of ossec.conf for windows agent and
> active response?
>
> This is my begin:
> <ossec_config>
>
> <active-response>
> <disabled>no</disabled>
> </active-response>
>
> <command>
> <name>win_nullroute</name>
> <executable>route-null.cmd</executable>
> <expect>srcip</expect>
> <timeout_allowed>yes</timeout_allowed>
> </command>
>
> <active-response>
> <command>win_nullroute</command>
> <location>local</location>
> <level>10</level>
> <timeout>600</timeout>
> </active-response>
>
> Thanks,
> Michel
>
>>
>> Forgot one thing:  I also verified that I have the ar.conf file, and
>> it contains a line with win_nullroute600 as you mentioned.
>>
>> On Wed, Sep 3, 2008 at 7:33 PM, Wes <[EMAIL PROTECTED]> wrote:
>>> Daniel,
>>>
>>> I'm running the management server on Ubuntu 8.04, and the agent on
>>> Win2K3 SP2.  1.6 release of OSSEC installed on both agent and server.
>>>
>>> When I run the test with agent_control, everything works as expected.
>>>
>>> I'm trying to get the response to block any IP that causes a level 10
>>> (or higher) alert.  To test, I put an empty file called "union+1.html"
>>> on my web server.  When I access the file via a browser on another
>>> machine, it triggers a false positive on rule 31106.  I receive an
>>> e-mail alert and the event is written to the OSSEC log, as follows (IP
>>> addresses and server names have been removed):
>>>
>>> ** Alert 1220482999.7011126: mail  - web,accesslog,attack,
>>> 2008 Sep 03 19:03:19 ([agent name]) [agent IP
>>> address]->\WINDOWS\System32\LogFiles\W3SVC1\ex080903.log
>>> Rule: 31106 (level 12) -> 'A web attack returned code 200 (success).'
>>> Src IP: [source IP address]
>>> User: (none)
>>> 2008-09-03 23:00:53 W3SVC1 [agent] [agent IP] GET /union+1.html - 80 -
>>> [source IP] HTTP/1.1
>>> Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.1;+SV1) - - [agent
>>> URL] 200 0 0 250 443 156
>>>
>>> Though I removed the source IP address above, it shows up fine in the
>>> log.
>>>
>>> I'm not attempting the test immediately after restarting the server.
>>>
>>> The IP I'm testing from is not whitelisted.
>>>
>>> I have the following in ossec.log on the agent, from the last time I
>>> restarted it:
>>>
>>> 2008/09/02 11:52:42 ossec-agent: INFO: Started (pid: 336).
>>>
>>> I also see the other entries you%2
>
>

Reply via email to