It isn't working 100% of the time for me either, not sure why. Can't think of any real troubleshooting ideas at the moment either. I'll keep thinking about it, and post if I come up w/anything.
-----Original Message----- From: Tim Eberhard Sent: 10/11/2010 10:14:43 AM Subject: Re: [ossec-list] dev roadmap? Hrmm.. something is off then. I got the diff once when I changed the root password but I haven't on any other files within /etc/. Suggestions on troubleshooting this? -Thanks Tim Eberhard On Mon, Oct 11, 2010 at 8:44 AM, dan (ddp) <[email protected]> wrote: > It should send the diff in the email. It does for me anyways. > > On Sat, Oct 9, 2010 at 10:41 PM, Tim Eberhard <[email protected]> wrote: > > So taking a look at report_changes I'm having some trouble figuring it > > out... > > > > my ossec.conf config: > > <!-- Directories to check (perform all possible verifications) --> > > <directories realtime="yes" report_changes="yes" > > check_all="yes">/etc</directories> > > <directories check_all="yes">/bin,/sbin</directories> > > > > > > and here is what I get: > > > > > > OSSEC HIDS Notification. > > 2010 Oct 09 19:35:14 > > > > Received From: ossec->syscheck > > Rule: 552 fired (level 7) -> "Integrity checksum changed again (3rd > time)." > > Portion of the log(s): > > > > Integrity checksum changed for: '/etc/php.ini' > > Size changed from '45121' to '45152' > > Old md5sum was: 'dc26fb421dae7b52b620c386e4a3de61' > > New md5sum is : 'c146509741aa97cd53ef124b6b5dcd86' > > Old sha1sum was: '3c04c9b4072d1b0ac662f8985715de13fc9e2971' > > New sha1sum is : '21e6d3d31f28fa4850aa90a8ae8d5bd39a472f51' > > > > -END OF NOTIFICATION > > > > It's doing a diff, that I can tell. Looking at the diff directory I can > see > > the changes. > > > > r...@ossec:/var/ossec/queue/diff/local/etc/php.ini# cat diff.1286675781 > > 12c12 > > < ; the -c argument in command line mode. > > --- > >> ; the -c argument in command line mode. and some other stuff > > > > I had assumed there would be some kind of alert with config written into > the > > log or emailed (I understand this can be considered insecure). Am I once > > again missing something obvious? > > > > Thanks again for your help, > > -Tim Eberhard > > > > > > > > On Sat, Oct 9, 2010 at 5:56 PM, Tim Eberhard <[email protected]> wrote: > >> > >> Thanks sweet, thanks again guys. Amazing work. > >> > >> I would still love to see a roadmap posted just to see what cool new > stuff > >> is getting worked on. Just tossing that out there :) > >> > >> -Tim Eberhard > >> > >> On Oct 9, 2010, at 5:20 PM, Daniel Cid <[email protected]> wrote: > >> > >> > It is a new feature added on v2.5, so not available during the write > >> > of the book. > >> > > >> > Just add report_changes="yes" to add monitored directory and you will > >> > get > >> > the "diff" between versions. > >> > > >> > Thanks, > >> > > >> > On Sat, Oct 9, 2010 at 4:17 PM, Tim Eberhard <[email protected]> > wrote: > >> >> Wow, very nice. I'm amazed I haven't seen that feature before. I read > >> >> the sygress book and it made no mention of that feature. > >> >> > >> >> Excellent stuff, I greatly appreciate the response. I'll check it out > >> >> read up. Sorry to add white noise to the list. > >> >> > >> >> -Tim Eberhard > >> >> > >> >> On Oct 9, 2010, at 1:55 PM, "[email protected]" <[email protected]> > >> >> wrote: > >> >> > >> >>> Oops, I meant the report_changes option in syscheck, check_diff is > >> >>> different. > >> >>> > >> >>> > >> >>> -----Original Message----- > >> >>> From: Tim Eberhard > >> >>> Sent: 10/09/2010 12:15:51 PM > >> >>> Subject: [ossec-list] dev roadmap? > >> >>> > >> >>> All, > >> >>> > >> >>> I hate to ask such a basic question but after browsing/googling I > have > >> >>> been > >> >>> unable to find any kind of documented roadmap for OSSEC. > >> >>> > >> >>> Of course I had a few specific features in mind that I wanted to see > >> >>> if were > >> >>> on the roadmap. > >> >>> > >> >>> I searched the archive and I've found a few of them have been asked > in > >> >>> the > >> >>> past. The primary feature I'm looking for is the central repo/diff > >> >>> capability for configuration files built into ossec. When evaluating > >> >>> OSSEC > >> >>> vs some commercial alternatives some of the short comings we found > >> >>> were > >> >>> mainly around the ability to track/alert on not only signature > changes > >> >>> to > >> >>> files but evaluate the configuration file and answer the commonly > >> >>> asked > >> >>> question "great the md5 signature changed.. but WHAT changed?" > >> >>> > >> >>> I know you can hack something up with some active response combo > with > >> >>> a > >> >>> change repo but that really isn't a decent solution that integrates > >> >>> with > >> >>> OSSEC. > >> >>> > >> >>> Thanks for your help, sorry if I missed the obvious. > >> >>> -Tim Eberhard > >> >>> > >> >> > > > > >
