Greetings:

Given the following alert...

Dec 13 23:07:24 web2 suhosin[18198]: ALERT - script tried to increase
memory_limit to 134217728 bytes which is above the allowed value
(attacker '[IP ADDRESS OF ALLEGED ATTACKER]', file '[full path to file
goes here]', line 65)


... if this rule was tied to an active response "as is" would ossec
know to block the [IP ADDRESS OF ALLEGED ATTACKER]?

If not, what modifications would I have to make?

Thank you.

Reply via email to