hi, im testing ossec so that later on i can deploy it over our production server. Im wondering with lots of question one of which is how will ossec detect the brute force attack over ssh. I will clarify more: lets say an attacker uses brute force attack over ssh service, attacker succeeds after just 10 attempts with username "root" and password "root1234". Now how will ossec detect this intrusion. It does give the report from auth.log regarding failed login attempts but will it treat successful login from brute force as legitimate one or not? How will active response will react over this scenario?
thanks regards sabin -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
