Aslo work on me. I have this rules in my ossec.conf client, must in the server ossec.conf sorry... <command> <name>win_nullroute</name> <executable>route-null.cmd</executable> <expect>srcip</expect> <timeout_allowed>yes</timeout_allowed> </command>
<active-response> <command>win_nullroute</command> <location>local</location> <level>10</level> <timeout>600</timeout> </active-response> And yes now i see this in my route print.:-) But not working on mask 255.255.255.255 ?? I have two network interfaces Try do make do some test to route add x.x.x.x gw 127.0.0.1 but not accepting. I there other null route to make to ip address? Thanks, Michel ----- Original Message ----- From: "Will Metcalf" <[EMAIL PROTECTED]> To: <[email protected]> Sent: Friday, September 05, 2008 5:48 PM Subject: [ossec-list] Re: Windows active response not working > > The updated code WorksForMe(TM) ;-)... Thanx for your help... > > Regards, > > Will > > On Fri, Sep 5, 2008 at 9:11 AM, Daniel Cid <[EMAIL PROTECTED]> wrote: >> >> Hi all, >> >> I think I figured out what was going on. Depending on the argument (if >> it had spaces), >> the command to block would not be called properly. I am pretty sure it is >> fixed >> on the following snapshot: >> >> http://www.ossec.net/files/snapshots/ossec-win32-080904.exe >> >> Can you try with this version? You don't need to update the server, >> just the agent side. >> >> *I will release a v1.6.1 soon with the fixes for some of the reported >> bugs so far. >> >> >> Thanks, >> >> -- >> Daniel B. Cid >> dcid ( at ) ossec.net >> >> >> >> On Thu, Sep 4, 2008 at 12:15 PM, Michel van Dop <[EMAIL PROTECTED]> >> wrote: >>> >>> Hello, >>> >>> I try again, to make sure. >>> I have see a problem on C:\Program Files\ossec-agent\shared\ar.conf >>> I add a line win_nullroute600 after restart he change the file and is >>> remove the last rule. win_nullroute600 - route-null.cmd - 600 >>> >>> I do a upgrade from ossec agent 1.5.1 on windows 2k3 sp2 to ossec 1.6. >>> >>> I also make a uninstall of ossec agent 1.6 and try again, same problem. >>> >>> Can any one give a good full example of ossec.conf for windows agent and >>> active response? >>> >>> This is my begin: >>> <ossec_config> >>> >>> <active-response> >>> <disabled>no</disabled> >>> </active-response> >>> >>> <command> >>> <name>win_nullroute</name> >>> <executable>route-null.cmd</executable> >>> <expect>srcip</expect> >>> <timeout_allowed>yes</timeout_allowed> >>> </command> >>> >>> <active-response> >>> <command>win_nullroute</command> >>> <location>local</location> >>> <level>10</level> >>> <timeout>600</timeout> >>> </active-response> >>> >>> Thanks, >>> Michel >>> >>>> >>>> Forgot one thing: I also verified that I have the ar.conf file, and >>>> it contains a line with win_nullroute600 as you mentioned. >>>> >>>> On Wed, Sep 3, 2008 at 7:33 PM, Wes <[EMAIL PROTECTED]> wrote: >>>>> Daniel, >>>>> >>>>> I'm running the management server on Ubuntu 8.04, and the agent on >>>>> Win2K3 SP2. 1.6 release of OSSEC installed on both agent and server. >>>>> >>>>> When I run the test with agent_control, everything works as expected. >>>>> >>>>> I'm trying to get the response to block any IP that causes a level 10 >>>>> (or higher) alert. To test, I put an empty file called "union+1.html" >>>>> on my web server. When I access the file via a browser on another >>>>> machine, it triggers a false positive on rule 31106. I receive an >>>>> e-mail alert and the event is written to the OSSEC log, as follows (IP >>>>> addresses and server names have been removed): >>>>> >>>>> ** Alert 1220482999.7011126: mail - web,accesslog,attack, >>>>> 2008 Sep 03 19:03:19 ([agent name]) [agent IP >>>>> address]->\WINDOWS\System32\LogFiles\W3SVC1\ex080903.log >>>>> Rule: 31106 (level 12) -> 'A web attack returned code 200 (success).' >>>>> Src IP: [source IP address] >>>>> User: (none) >>>>> 2008-09-03 23:00:53 W3SVC1 [agent] [agent IP] GET /union+1.html - 80 - >>>>> [source IP] HTTP/1.1 >>>>> Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.1;+SV1) - - [agent >>>>> URL] 200 0 0 250 443 156 >>>>> >>>>> Though I removed the source IP address above, it shows up fine in the >>>>> log. >>>>> >>>>> I'm not attempting the test immediately after restarting the server. >>>>> >>>>> The IP I'm testing from is not whitelisted. >>>>> >>>>> I have the following in ossec.log on the agent, from the last time I >>>>> restarted it: >>>>> >>>>> 2008/09/02 11:52:42 ossec-agent: INFO: Started (pid: 336). >>>>> >>>>> I also see the other entries you%2 >>> >>> >> >
