This is kind of cool, we can atleast stop future attacks. Also we can
place honeypot and fine tune ossec for SQL injection kind of attack.
--
Sent from my iPhone
On Feb 5, 2011, at 11:52 AM, Michael Starks <[email protected]
> wrote:
Exactly. The first injection connection can be bad. I have run
systems
that were found to be vulnerable to SQL injection. OSSEC detected
the
attack, but we were being hit from multiple IPs over a long time at a
low rate. Active response wouldn't have helped. We were able to use
OSSECs logs (and system logs) to figure out what scripts the
attackers
were using. We took our systems off the internet, ran the same
scans at
a high rate, and determined which parts of the system had not been
hardened against injection attacks. We then coded in a protection
layer.
When we went back on the internet, OSSEC showed that the attacks
continued but without any success.
This is a great testimonial to how OSSEC can raise awareness.
Without something like OSSEC, most people are simply unaware of what
is happening. So this allowed you to focus on a particular area that
was problematic and fix it.