Here we are again.

The OSSEC-agent is runnung now since 31 hours without any strange
things happening.

I just created a few rules before I started the agent:

1. allow tcp and udp of dport 1514 from my OSSEC-Server's IP
2. drop tcp and udp of dport 1514 from the rest of the world

My assumption that the agent is vulnerable over port 1514 seems to be
confirmed.

What do you think?

Even if it is a very dangerous action for my systems I'm willing to
help to locate and eliminate the propable existing security bug in the
agent.

Let me know how to move forward.

On 25 Aug., 15:31, "dan (ddp)" <[email protected]> wrote:
> What active response triggers are you currently using? Certain SIDs?
> Which ones are triggering the AR?
>
>
>
> On Wed, Aug 25, 2010 at 3:12 AM, WebWusel <[email protected]> wrote:
> > Okay,
>
> > here's what happened last night.
>
> > There was a rule in the forward chain "ACCEPT all from all" and the
> > default policy for the input chain was DROP. So I was able to reach
> > the virtual Hosts on this machine, but couldnt connect to the host
> > anyhow. The only way to fix the system was to connect via my KVM over
> > IP.
>
> > Again, this never happened before I used OSSEC, so I fear, it's caused
> > by OSSEC in some strange way. The Logfiles are clean, there's nothing
> > suspect inside but I havent had a look at the syslog yet.
>
> > For Information what system we talking about:
>
> > Two Servers, lets say SrvA and SrvB. Both are holding two DRBD Drives
> > while normally SrvA is Holding "R0" and SrvB is holding "R1". They're
> > talking via an internal Network, connected via eth1 to each other with
> > heartbeat. Both running OpenVZ with about 4 virtual machines
> > (containers) on each.
>
> > If SrvA is invisible for SrvB for two minutes, SrvB has to assume SrvA
> > is dead and has then to mount the R0 Partition and start all the
> > virtual hosts on it and visa versa.
>
> > On both servers I have installed OSSEC. While SrvB has a total Traffic
> > (to the real world) of about 16 Gig a day, SrvA has about 13 Gig a day
> > but no email Server on it. So OSSEC is really relaxed on SrvA but very
> > busy at SrvB.
>
> > So, the default setting DROP for the Input Chain has effect to all
> > network-devices. This causes Heartbeat to take over all ressources
> > from SrvA to SrvB and mount the DRBD-Partitions. SrvA is also not
> > seeing SrvB anymore and does the same with it's ressources. We have a
> > split-brain situation.
>
> > I also have two other servers running in the same mode as SrvA and
> > SrvB, also installed OSSEC and no problems so far. But these servers
> > have much less stress as the first cluster has.
>
> > Can it be, that there's a security leak in OSSEC?
>
> > I finnally run a rkhunter and chkrootkit on my servers but couldn't
> > find any thing suspect.
>
> > I would like to use OSSEC but I am helpless at the moment. For the
> > next three days I leave OSSEC stopped on SrvB to see, if any strange
> > things appear again.
>
> > Would be glad for any hint!
>
> > Thanks,
>
> > Oskar- Zitierten Text ausblenden -
>
> - Zitierten Text anzeigen -

Reply via email to