What type of system did your syslog message come from?
What others did you test?

Looks like an okay change to me.


On Thu, Oct 28, 2010 at 1:22 PM, blacklight <[email protected]> wrote:
> Hello Folks,
>
> We noticed that rule 11109 failed to trigger the active response that
> we had specified. We traced the failure of rule 11109 to trigger the
> active response that we had specified in ossec.conf to to a syntax
> error in the "ftpd-mac-failure" decoder in the decoder.xml file that
> comes by default with the OSSEC 2.5.1 tarball.
>
> Here below is the text of the "ftpd-mac-failure" decoder in the
> decoder.xml file of the OSSEC 2.5.1 tarball:
>
> <decoder name="ftpd-mac-failure">
>  <parent>ftpd</parent>
>  <prematch>^Failed authentication from: \S+ |</prematch>
>  <prematch>^repeated login failures from </prematch>
>  <regex offset="after_prematch">[(\d+.\d+.\d+.\d+)]$</regex>
>  <order>srcip</order>
> </decoder>
>
> Here below is the text of the "ftpd-mac-failure" decoder in our
> decoder.xml file
>
> <decoder name="ftpd-mac-failure">
>  <parent>ftpd</parent>
>  <prematch>^Failed authentication from: \S+ |</prematch>
>  <prematch>^repeated login failures from </prematch>
> <!--
>  <regex offset="after_prematch">[(\d+.\d+.\d+.\d+)]$</regex>
> -->
>  <regex offset="after_prematch">(\S+)</regex>
>  <order>srcip</order>
> </decoder>
>
> Here below is the text of the syslog statement that will trigger rule
> 11109:
> Oct 27 17:53:00 omd ftpd[8538]: repeated login failures from
> 226.226.226.226 () -- test by V.
>
> 1. Note that running ossec-logtest using the syslog statement above
> yields the following result for the version of "ftpd-mac-failure" in
> decoder.xml of OSSEC 2.5.1:
>
> [r...@wiggum etc]# ossec-logtest -f -D /tmp/ossectest-121509/ -c /tmp/
> ossectest-121509/etc/ossec.conf
> 2010/10/28 13:13:26 ossec-testrule: INFO: Reading local decoder file.
>
> 2010/10/28 13:13:43 ossec-testrule: INFO: Started (pid: 4684).
> ossec-testrule: Type one log per line.
>
> Oct 27 17:53:00 omd ftpd[8538]: repeated login failures from
> 226.226.226.226 () -- test by V.
>
>
> **Phase 1: Completed pre-decoding.
>       full event: 'Oct 27 17:53:00 omd ftpd[8538]: repeated login
> failures from 226.226.226.226 () -- test by V.'
>       hostname: 'omd'
>       program_name: 'ftpd'
>       log: 'repeated login failures from 226.226.226.226 () -- test
> by V.'
>
> **Phase 2: Completed decoding.
>       decoder: 'ftpd'
>                              <--- Note that srcip is missing
>
> **Rule debugging:
>    Trying rule: 1 - Generic template for all syslog rules.
>       *Rule 1 matched.
>       *Trying child rules.
>    Trying rule: 5500 - Grouping of the pam_unix rules.
>    Trying rule: 5700 - SSHD messages grouped.
>    Trying rule: 5600 - Grouping for the telnetd rules
>    Trying rule: 2100 - NFS rules grouped.
>    Trying rule: 2701 - Ignoring procmail messages.
>    Trying rule: 2800 - Pre-match rule for smartd.
>    Trying rule: 5100 - Pre-match rule for kernel messages
>    Trying rule: 5200 - Ignoring hpiod for producing useless logs.
>    Trying rule: 2830 - Crontab rule group.
>    Trying rule: 5300 - Initial grouping for su messages.
>    Trying rule: 5400 - Initial group for sudo messages
>    Trying rule: 9100 - PPTPD messages grouped
>    Trying rule: 9200 - Squid syslog messages grouped
>    Trying rule: 2900 - Dpkg (Debian Package) log.
>    Trying rule: 2930 - Yum logs.
>    Trying rule: 2931 - Yum logs.
>    Trying rule: 7200 - Grouping of the arpwatch rules.
>    Trying rule: 7300 - Grouping of Symantec AV rules.
>    Trying rule: 7400 - Grouping of Symantec Web Security rules.
>    Trying rule: 4300 - Grouping of PIX rules
>    Trying rule: 12100 - Grouping of the named rules
>    Trying rule: 13100 - Grouping for the smbd rules.
>    Trying rule: 11400 - Grouping for the vsftpd rules.
>    Trying rule: 11300 - Grouping for the pure-ftpd rules.
>    Trying rule: 11200 - Grouping for the proftpd rules.
>    Trying rule: 11500 - Grouping for the Microsoft ftp rules.
>    Trying rule: 11100 - Grouping for the ftpd rules.
>       *Rule 11100 matched.
>       *Trying child rules.
>    Trying rule: 11102 - File created via FTP
>    Trying rule: 11103 - File deleted via FTP
>    Trying rule: 11104 - User uploaded a file to server.
>    Trying rule: 11105 - User downloaded a file to server.
>    Trying rule: 11109 - Multiple FTP failed login attempts.
>       *Rule 11109 matched.
>
> **Phase 3: Completed filtering (rules).
>       Rule id: '11109'
>       Level: '10'
>       Description: 'Multiple FTP failed login attempts.'
> **Alert to be generated.
>
>
>
> 2. Note that running ossec-logtest using the syslog statement above
> yields the following result for our version of "ftpd-mac-failure":
>
> [r...@wiggum ~]# ossec-logtest -f
> 2010/10/28 12:28:17 ossec-testrule: INFO: Reading local decoder file.
> 2010/10/28 12:28:17 ossec-testrule: INFO: Started (pid: 21521).
> ossec-testrule: Type one log per line.
>
> Oct 27 15:25:46 omd ftpd[8538]: repeated login failures from
> 202.106.110.190 ()
>
>
> **Phase 1: Completed pre-decoding.
>       full event: 'Oct 27 15:25:46 omd ftpd[8538]: repeated login
> failures from 202.106.110.190 () -- test by V.'
>       hostname: 'omd'
>       program_name: 'ftpd'
>       log: 'repeated login failures from 202.106.110.190 ()  -- test
> by V.'
>
> **Phase 2: Completed decoding.
>       decoder: 'ftpd'
>       srcip: '202.106.110.190'         <--- Note that srcip is
> captured
>
> **Rule debugging:
>    Trying rule: 1 - Generic template for all syslog rules.
>       *Rule 1 matched.
>       *Trying child rules.
>    Trying rule: 5500 - Grouping of the pam_unix rules.
>    Trying rule: 5700 - SSHD messages grouped.
>    Trying rule: 5600 - Grouping for the telnetd rules
>    Trying rule: 2100 - NFS rules grouped.
>    Trying rule: 2550 - rshd messages grouped.
>    Trying rule: 2701 - Ignoring procmail messages.
>    Trying rule: 2800 - Pre-match rule for smartd.
>    Trying rule: 5100 - Pre-match rule for kernel messages
>    Trying rule: 5200 - Ignoring hpiod for producing useless logs.
>    Trying rule: 2830 - Crontab rule group.
>    Trying rule: 5300 - Initial grouping for su messages.
>    Trying rule: 5400 - Initial group for sudo messages
>    Trying rule: 9100 - PPTPD messages grouped
>    Trying rule: 9200 - Squid syslog messages grouped
>    Trying rule: 2900 - Dpkg (Debian Package) log.
>    Trying rule: 2930 - Yum logs.
>    Trying rule: 2931 - Yum logs.
>    Trying rule: 7200 - Grouping of the arpwatch rules.
>    Trying rule: 7300 - Grouping of Symantec AV rules.
>    Trying rule: 7400 - Grouping of Symantec Web Security rules.
>    Trying rule: 4300 - Grouping of PIX rules
>    Trying rule: 12100 - Grouping of the named rules
>    Trying rule: 13100 - Grouping for the smbd rules.
>    Trying rule: 11400 - Grouping for the vsftpd rules.
>    Trying rule: 11300 - Grouping for the pure-ftpd rules.
>    Trying rule: 11200 - Grouping for the proftpd rules.
>    Trying rule: 11500 - Grouping for the Microsoft ftp rules.
>    Trying rule: 11100 - Grouping for the ftpd rules.
>       *Rule 11100 matched.
>       *Trying child rules.
>    Trying rule: 11102 - File created via FTP
>    Trying rule: 11103 - File deleted via FTP
>    Trying rule: 11104 - User uploaded a file to server.
>    Trying rule: 11105 - User downloaded a file to server.
>    Trying rule: 11109 - Multiple FTP failed login attempts.
>       *Rule 11109 matched.
>
> **Phase 3: Completed filtering (rules).
>       Rule id: '11109'
>       Level: '10'
>       Description: 'Multiple FTP failed login attempts.'
> **Alert to be generated.
>
>
> I suggest that you fix the syntax of ftpd-mac-failure" the way we did
> so as to actually capture the srcip parameter.
>
>

Reply via email to