What type of system did your syslog message come from? What others did you test?
Looks like an okay change to me. On Thu, Oct 28, 2010 at 1:22 PM, blacklight <[email protected]> wrote: > Hello Folks, > > We noticed that rule 11109 failed to trigger the active response that > we had specified. We traced the failure of rule 11109 to trigger the > active response that we had specified in ossec.conf to to a syntax > error in the "ftpd-mac-failure" decoder in the decoder.xml file that > comes by default with the OSSEC 2.5.1 tarball. > > Here below is the text of the "ftpd-mac-failure" decoder in the > decoder.xml file of the OSSEC 2.5.1 tarball: > > <decoder name="ftpd-mac-failure"> > <parent>ftpd</parent> > <prematch>^Failed authentication from: \S+ |</prematch> > <prematch>^repeated login failures from </prematch> > <regex offset="after_prematch">[(\d+.\d+.\d+.\d+)]$</regex> > <order>srcip</order> > </decoder> > > Here below is the text of the "ftpd-mac-failure" decoder in our > decoder.xml file > > <decoder name="ftpd-mac-failure"> > <parent>ftpd</parent> > <prematch>^Failed authentication from: \S+ |</prematch> > <prematch>^repeated login failures from </prematch> > <!-- > <regex offset="after_prematch">[(\d+.\d+.\d+.\d+)]$</regex> > --> > <regex offset="after_prematch">(\S+)</regex> > <order>srcip</order> > </decoder> > > Here below is the text of the syslog statement that will trigger rule > 11109: > Oct 27 17:53:00 omd ftpd[8538]: repeated login failures from > 226.226.226.226 () -- test by V. > > 1. Note that running ossec-logtest using the syslog statement above > yields the following result for the version of "ftpd-mac-failure" in > decoder.xml of OSSEC 2.5.1: > > [r...@wiggum etc]# ossec-logtest -f -D /tmp/ossectest-121509/ -c /tmp/ > ossectest-121509/etc/ossec.conf > 2010/10/28 13:13:26 ossec-testrule: INFO: Reading local decoder file. > > 2010/10/28 13:13:43 ossec-testrule: INFO: Started (pid: 4684). > ossec-testrule: Type one log per line. > > Oct 27 17:53:00 omd ftpd[8538]: repeated login failures from > 226.226.226.226 () -- test by V. > > > **Phase 1: Completed pre-decoding. > full event: 'Oct 27 17:53:00 omd ftpd[8538]: repeated login > failures from 226.226.226.226 () -- test by V.' > hostname: 'omd' > program_name: 'ftpd' > log: 'repeated login failures from 226.226.226.226 () -- test > by V.' > > **Phase 2: Completed decoding. > decoder: 'ftpd' > <--- Note that srcip is missing > > **Rule debugging: > Trying rule: 1 - Generic template for all syslog rules. > *Rule 1 matched. > *Trying child rules. > Trying rule: 5500 - Grouping of the pam_unix rules. > Trying rule: 5700 - SSHD messages grouped. > Trying rule: 5600 - Grouping for the telnetd rules > Trying rule: 2100 - NFS rules grouped. > Trying rule: 2701 - Ignoring procmail messages. > Trying rule: 2800 - Pre-match rule for smartd. > Trying rule: 5100 - Pre-match rule for kernel messages > Trying rule: 5200 - Ignoring hpiod for producing useless logs. > Trying rule: 2830 - Crontab rule group. > Trying rule: 5300 - Initial grouping for su messages. > Trying rule: 5400 - Initial group for sudo messages > Trying rule: 9100 - PPTPD messages grouped > Trying rule: 9200 - Squid syslog messages grouped > Trying rule: 2900 - Dpkg (Debian Package) log. > Trying rule: 2930 - Yum logs. > Trying rule: 2931 - Yum logs. > Trying rule: 7200 - Grouping of the arpwatch rules. > Trying rule: 7300 - Grouping of Symantec AV rules. > Trying rule: 7400 - Grouping of Symantec Web Security rules. > Trying rule: 4300 - Grouping of PIX rules > Trying rule: 12100 - Grouping of the named rules > Trying rule: 13100 - Grouping for the smbd rules. > Trying rule: 11400 - Grouping for the vsftpd rules. > Trying rule: 11300 - Grouping for the pure-ftpd rules. > Trying rule: 11200 - Grouping for the proftpd rules. > Trying rule: 11500 - Grouping for the Microsoft ftp rules. > Trying rule: 11100 - Grouping for the ftpd rules. > *Rule 11100 matched. > *Trying child rules. > Trying rule: 11102 - File created via FTP > Trying rule: 11103 - File deleted via FTP > Trying rule: 11104 - User uploaded a file to server. > Trying rule: 11105 - User downloaded a file to server. > Trying rule: 11109 - Multiple FTP failed login attempts. > *Rule 11109 matched. > > **Phase 3: Completed filtering (rules). > Rule id: '11109' > Level: '10' > Description: 'Multiple FTP failed login attempts.' > **Alert to be generated. > > > > 2. Note that running ossec-logtest using the syslog statement above > yields the following result for our version of "ftpd-mac-failure": > > [r...@wiggum ~]# ossec-logtest -f > 2010/10/28 12:28:17 ossec-testrule: INFO: Reading local decoder file. > 2010/10/28 12:28:17 ossec-testrule: INFO: Started (pid: 21521). > ossec-testrule: Type one log per line. > > Oct 27 15:25:46 omd ftpd[8538]: repeated login failures from > 202.106.110.190 () > > > **Phase 1: Completed pre-decoding. > full event: 'Oct 27 15:25:46 omd ftpd[8538]: repeated login > failures from 202.106.110.190 () -- test by V.' > hostname: 'omd' > program_name: 'ftpd' > log: 'repeated login failures from 202.106.110.190 () -- test > by V.' > > **Phase 2: Completed decoding. > decoder: 'ftpd' > srcip: '202.106.110.190' <--- Note that srcip is > captured > > **Rule debugging: > Trying rule: 1 - Generic template for all syslog rules. > *Rule 1 matched. > *Trying child rules. > Trying rule: 5500 - Grouping of the pam_unix rules. > Trying rule: 5700 - SSHD messages grouped. > Trying rule: 5600 - Grouping for the telnetd rules > Trying rule: 2100 - NFS rules grouped. > Trying rule: 2550 - rshd messages grouped. > Trying rule: 2701 - Ignoring procmail messages. > Trying rule: 2800 - Pre-match rule for smartd. > Trying rule: 5100 - Pre-match rule for kernel messages > Trying rule: 5200 - Ignoring hpiod for producing useless logs. > Trying rule: 2830 - Crontab rule group. > Trying rule: 5300 - Initial grouping for su messages. > Trying rule: 5400 - Initial group for sudo messages > Trying rule: 9100 - PPTPD messages grouped > Trying rule: 9200 - Squid syslog messages grouped > Trying rule: 2900 - Dpkg (Debian Package) log. > Trying rule: 2930 - Yum logs. > Trying rule: 2931 - Yum logs. > Trying rule: 7200 - Grouping of the arpwatch rules. > Trying rule: 7300 - Grouping of Symantec AV rules. > Trying rule: 7400 - Grouping of Symantec Web Security rules. > Trying rule: 4300 - Grouping of PIX rules > Trying rule: 12100 - Grouping of the named rules > Trying rule: 13100 - Grouping for the smbd rules. > Trying rule: 11400 - Grouping for the vsftpd rules. > Trying rule: 11300 - Grouping for the pure-ftpd rules. > Trying rule: 11200 - Grouping for the proftpd rules. > Trying rule: 11500 - Grouping for the Microsoft ftp rules. > Trying rule: 11100 - Grouping for the ftpd rules. > *Rule 11100 matched. > *Trying child rules. > Trying rule: 11102 - File created via FTP > Trying rule: 11103 - File deleted via FTP > Trying rule: 11104 - User uploaded a file to server. > Trying rule: 11105 - User downloaded a file to server. > Trying rule: 11109 - Multiple FTP failed login attempts. > *Rule 11109 matched. > > **Phase 3: Completed filtering (rules). > Rule id: '11109' > Level: '10' > Description: 'Multiple FTP failed login attempts.' > **Alert to be generated. > > > I suggest that you fix the syntax of ftpd-mac-failure" the way we did > so as to actually capture the srcip parameter. > >
