Hi Daniel, Thanks for the fix. I do a upgrade on 2 win2k3 sp2 server. But still same problem get email alert level 10 but not block. I check route print no blokking route to null Also i add this line at last win_nullroute600 - route-null.cmd - 600 in af.conf but after restart he change and last rule not there anymore.
But i do not now if my client config is 100% okay. Best regards, Michel ----- Original Message ----- From: "Daniel Cid" <[EMAIL PROTECTED]> To: <[email protected]> Sent: Friday, September 05, 2008 4:11 PM Subject: [ossec-list] Re: Windows active response not working > > Hi all, > > I think I figured out what was going on. Depending on the argument (if > it had spaces), > the command to block would not be called properly. I am pretty sure it is > fixed > on the following snapshot: > > http://www.ossec.net/files/snapshots/ossec-win32-080904.exe > > Can you try with this version? You don't need to update the server, > just the agent side. > > *I will release a v1.6.1 soon with the fixes for some of the reported > bugs so far. > > > Thanks, > > -- > Daniel B. Cid > dcid ( at ) ossec.net > > > > On Thu, Sep 4, 2008 at 12:15 PM, Michel van Dop <[EMAIL PROTECTED]> wrote: >> >> Hello, >> >> I try again, to make sure. >> I have see a problem on C:\Program Files\ossec-agent\shared\ar.conf >> I add a line win_nullroute600 after restart he change the file and is >> remove the last rule. win_nullroute600 - route-null.cmd - 600 >> >> I do a upgrade from ossec agent 1.5.1 on windows 2k3 sp2 to ossec 1.6. >> >> I also make a uninstall of ossec agent 1.6 and try again, same problem. >> >> Can any one give a good full example of ossec.conf for windows agent and >> active response? >> >> This is my begin: >> <ossec_config> >> >> <active-response> >> <disabled>no</disabled> >> </active-response> >> >> <command> >> <name>win_nullroute</name> >> <executable>route-null.cmd</executable> >> <expect>srcip</expect> >> <timeout_allowed>yes</timeout_allowed> >> </command> >> >> <active-response> >> <command>win_nullroute</command> >> <location>local</location> >> <level>10</level> >> <timeout>600</timeout> >> </active-response> >> >> Thanks, >> Michel >> >>> >>> Forgot one thing: I also verified that I have the ar.conf file, and >>> it contains a line with win_nullroute600 as you mentioned. >>> >>> On Wed, Sep 3, 2008 at 7:33 PM, Wes <[EMAIL PROTECTED]> wrote: >>>> Daniel, >>>> >>>> I'm running the management server on Ubuntu 8.04, and the agent on >>>> Win2K3 SP2. 1.6 release of OSSEC installed on both agent and server. >>>> >>>> When I run the test with agent_control, everything works as expected. >>>> >>>> I'm trying to get the response to block any IP that causes a level 10 >>>> (or higher) alert. To test, I put an empty file called "union+1.html" >>>> on my web server. When I access the file via a browser on another >>>> machine, it triggers a false positive on rule 31106. I receive an >>>> e-mail alert and the event is written to the OSSEC log, as follows (IP >>>> addresses and server names have been removed): >>>> >>>> ** Alert 1220482999.7011126: mail - web,accesslog,attack, >>>> 2008 Sep 03 19:03:19 ([agent name]) [agent IP >>>> address]->\WINDOWS\System32\LogFiles\W3SVC1\ex080903.log >>>> Rule: 31106 (level 12) -> 'A web attack returned code 200 (success).' >>>> Src IP: [source IP address] >>>> User: (none) >>>> 2008-09-03 23:00:53 W3SVC1 [agent] [agent IP] GET /union+1.html - 80 - >>>> [source IP] HTTP/1.1 >>>> Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.1;+SV1) - - [agent >>>> URL] 200 0 0 250 443 156 >>>> >>>> Though I removed the source IP address above, it shows up fine in the >>>> log. >>>> >>>> I'm not attempting the test immediately after restarting the server. >>>> >>>> The IP I'm testing from is not whitelisted. >>>> >>>> I have the following in ossec.log on the agent, from the last time I >>>> restarted it: >>>> >>>> 2008/09/02 11:52:42 ossec-agent: INFO: Started (pid: 336). >>>> >>>> I also see the other entries you%2 >> >> >
