It isn't working 100% of the time for me either, not sure why. Can't think of 
any real troubleshooting ideas at the moment either.
I'll keep thinking about it, and post if I come up w/anything.


-----Original Message-----
From: Tim Eberhard
Sent:  10/11/2010 10:14:43 AM
Subject:  Re: [ossec-list] dev roadmap?

Hrmm.. something is off then. I got the diff once when I changed the root
password but I haven't on any other files within /etc/.

Suggestions on troubleshooting this?

-Thanks
Tim Eberhard

On Mon, Oct 11, 2010 at 8:44 AM, dan (ddp) <[email protected]> wrote:

> It should send the diff in the email. It does for me anyways.
>
> On Sat, Oct 9, 2010 at 10:41 PM, Tim Eberhard <[email protected]> wrote:
> > So taking a look at report_changes I'm having some trouble figuring it
> > out...
> >
> > my ossec.conf config:
> >     <!-- Directories to check  (perform all possible verifications) -->
> >     <directories realtime="yes" report_changes="yes"
> > check_all="yes">/etc</directories>
> >     <directories check_all="yes">/bin,/sbin</directories>
> >
> >
> > and here is what I get:
> >
> >
> > OSSEC HIDS Notification.
> > 2010 Oct 09 19:35:14
> >
> > Received From: ossec->syscheck
> > Rule: 552 fired (level 7) -> "Integrity checksum changed again (3rd
> time)."
> > Portion of the log(s):
> >
> > Integrity checksum changed for: '/etc/php.ini'
> > Size changed from '45121' to '45152'
> > Old md5sum was: 'dc26fb421dae7b52b620c386e4a3de61'
> > New md5sum is : 'c146509741aa97cd53ef124b6b5dcd86'
> > Old sha1sum was: '3c04c9b4072d1b0ac662f8985715de13fc9e2971'
> > New sha1sum is : '21e6d3d31f28fa4850aa90a8ae8d5bd39a472f51'
> >
> > -END OF NOTIFICATION
> >
> > It's doing a diff, that I can tell. Looking at the diff directory I can
> see
> > the changes.
> >
> > r...@ossec:/var/ossec/queue/diff/local/etc/php.ini# cat diff.1286675781
> > 12c12
> > < ; the -c argument in command line mode.
> > ---
> >> ; the -c argument in command line mode. and some other stuff
> >
> > I had assumed there would be some kind of alert with config written into
> the
> > log or emailed (I understand this can be considered insecure). Am I once
> > again missing something obvious?
> >
> > Thanks again for your help,
> > -Tim Eberhard
> >
> >
> >
> > On Sat, Oct 9, 2010 at 5:56 PM, Tim Eberhard <[email protected]> wrote:
> >>
> >> Thanks sweet, thanks again guys. Amazing work.
> >>
> >> I would still love to see a roadmap posted just to see what cool new
> stuff
> >> is getting worked on. Just tossing that out there :)
> >>
> >> -Tim Eberhard
> >>
> >> On Oct 9, 2010, at 5:20 PM, Daniel Cid <[email protected]> wrote:
> >>
> >> > It is a new feature added on v2.5, so not available during the write
> >> > of the book.
> >> >
> >> > Just add report_changes="yes" to add monitored directory and you will
> >> > get
> >> > the "diff" between versions.
> >> >
> >> > Thanks,
> >> >
> >> > On Sat, Oct 9, 2010 at 4:17 PM, Tim Eberhard <[email protected]>
> wrote:
> >> >> Wow, very nice. I'm amazed I haven't seen that feature before. I read
> >> >> the sygress book and it made no mention of that feature.
> >> >>
> >> >> Excellent stuff, I greatly appreciate the response. I'll check it out
> >> >> read up. Sorry to add white noise to the list.
> >> >>
> >> >> -Tim Eberhard
> >> >>
> >> >> On Oct 9, 2010, at 1:55 PM, "[email protected]" <[email protected]>
> >> >> wrote:
> >> >>
> >> >>> Oops, I meant the report_changes option in syscheck, check_diff is
> >> >>> different.
> >> >>>
> >> >>>
> >> >>> -----Original Message-----
> >> >>> From: Tim Eberhard
> >> >>> Sent:  10/09/2010 12:15:51 PM
> >> >>> Subject:  [ossec-list] dev roadmap?
> >> >>>
> >> >>> All,
> >> >>>
> >> >>> I hate to ask such a basic question but after browsing/googling I
> have
> >> >>> been
> >> >>> unable to find any kind of documented roadmap for OSSEC.
> >> >>>
> >> >>> Of course I had a few specific features in mind that I wanted to see
> >> >>> if were
> >> >>> on the roadmap.
> >> >>>
> >> >>> I searched the archive and I've found a few of them have been asked
> in
> >> >>> the
> >> >>> past. The primary feature I'm looking for is the central repo/diff
> >> >>> capability for configuration files built into ossec. When evaluating
> >> >>> OSSEC
> >> >>> vs some commercial alternatives some of the short comings we found
> >> >>> were
> >> >>> mainly around the ability to track/alert on not only signature
> changes
> >> >>> to
> >> >>> files but evaluate the configuration file and answer the commonly
> >> >>> asked
> >> >>> question "great the md5 signature changed.. but WHAT changed?"
> >> >>>
> >> >>> I know you can hack something up with some active response combo
> with
> >> >>> a
> >> >>> change repo but that really isn't a decent solution that integrates
> >> >>> with
> >> >>> OSSEC.
> >> >>>
> >> >>> Thanks for your help, sorry if I missed the obvious.
> >> >>> -Tim Eberhard
> >> >>>
> >> >>
> >
> >
>

Reply via email to