No one has ever encountered this problem ?

On 10 oct, 15:48, tux3132 <[email protected]> wrote:
> I
>
> I have installed OSSEC 2.5 on Debian Lenny and all is working fine.
>
> I have created a command :
>
>   <command>
>     <name>firewall_drop</name>
>     <executable>firewall-drop.sh</executable>
>     <expect>srcip</expect>
>     <timeout_allowed>yes</timeout_allowed>
>   </command>
>
> and two active-response, one for each agents 007 (its name is
> James ...lol) and 008. All parameters are identical but <agent_id>...</
> agent_id>
> agent 007
>   <active-response>
>     <command>firewall_drop</command>
>     <location>defined-agent</location>
>     <agent_id>007</agent_id>
>
> <rules_id>3301,3302,3303,3304,3305,3306,3351,3352,3353,3354,3355,3356,3357,</
> rules_id>
>     <timeout>3610</timeout>
>   </active-response>
> agent 008
>   <active-response>
>     <command>firewall_drop</command>
>     <location>defined-agent</location>
>     <agent_id>008</agent_id>
>
> <rules_id>3301,3302,3303,3304,3305,3306,3351,3352,3353,3354,3355,3356,3357,</
> rules_id>
>     <timeout>3610</timeout>
>   </active-response>
>
> When, for example, the rule 3306 is fired up by the agent 007 the
> script firewall-drop.sh is ran on its host and is also ran on the
> other host where agent 008 reside.
>
> Obviously in this case of spam it is not really a problem because an
> active spammer is blacklisted even on a machine where it is not
> active ... But for some other kinds of responses it may become a
> problem.
>
> Have-I understood the OSSEC principle and/or syntax ?
> Have-you encountered this problem and how do you solve it ?
>
> Thank you for your help.
>
> Best regards.

Reply via email to