Hi All,

My ignore rule doesn't seem to be catching the rule at the end of this
email.

  <rule id="100014" level="0">
    <if_sid>11307</if_sid>
    <match>mirage pure-ftpd:</match>
    <description>Ignore this rule for multiple new connections to
ftp.netspace</description>
  </rule>

Have I got it right??? I've restarted both agent and server but keep
getting alerts about it.

-----Original Message-----
From: OSSEC HIDS [mailto:[email protected]]
Sent: Wednesday, 2 June 2010 4:29 PM
To: Andy
Subject: OSSEC Notification - (ftp.netspace) 203.10.110.104 - Alert
level 10

OSSEC HIDS Notification.
2010 Jun 02 16:29:06

Received From: (ftp.netspace) 203.10.110.104->/var/log/xferlog
Rule: 11307 fired (level 10) -> "Multiple connection attempts from
same source."
Portion of the log(s):

Jun  2 16:30:39 mirage pure-ftpd: (?
@220-253-26-53.VIC.netspace.net.au) [INFO] New connection from
220-253-26-53.VIC.netspace.net.au Jun  2 16:30:37 mirage pure-ftpd: (?
@220-253-26-53.VIC.netspace.net.au) [INFO] New connection from
220-253-26-53.VIC.netspace.net.au Jun  2 16:30:36 mirage pure-ftpd: (?
@220-253-26-53.VIC.netspace.net.au) [INFO] New connection from
220-253-26-53.VIC.netspace.net.au Jun  2 16:30:36 mirage pure-ftpd: (?
@220-253-26-53.VIC.netspace.net.au) [INFO] New connection from
220-253-26-53.VIC.netspace.net.au Jun  2 16:30:32 mirage pure-ftpd: (?
@220-253-26-53.VIC.netspace.net.au) [INFO] New connection from
220-253-26-53.VIC.netspace.net.au Jun  2 16:30:31 mirage pure-ftpd: (?
@220-253-26-53.VIC.netspace.net.au) [INFO] New connection from
220-253-26-53.VIC.netspace.net.au Jun  2 16:30:30 mirage pure-ftpd: (?
@220-253-26-53.VIC.netspace.net.au) [INFO] New connection from
220-253-26-53.VIC.netspace.net.au

  <rule id="100014" level="0">
    <if_sid>11307</if_sid>
    <match>mirage pure-ftpd:</match>
    <description>Ignore this rule for multiple new connections to
ftp.netspace</description>
  </rule>

Thanks.

Andy

Reply via email to