OK - on another system I'm able to get the web_rules.xml to trigger.

I setup IIS logging on this system... in W3C format.  selected all the 
fields..
#Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem 
cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) 
cs(Referer) cs-host sc-status sc-substatus sc-win32-status sc-bytes 
cs-bytes time-taken

OSSEC config on the monitored system looks like this.

<localfile>
    <location>C:\inetpub\logs\LogFiles\W3SVC1\u_ex%y%m%d.log</location>
    <log_format>iis</log_format>
</localfile>

restarted the ossec agent....  and iisreset too...

hammered on it for cmd.exe

and zoop zoop!

OSSEC HIDS Notification.
2014 Dec 12 13:01:50
Received From: (IIS8-5Server) 
1.2.3.4->\inetpub\logs\LogFiles\W3SVC1\u_ex141212.log
Rule: 31153 fired (level 10) -> "Multiple common web attacks from same 
souce ip."
Portion of the log(s):
2014-12-12 21:00:55 W3SVC1 IIS8-5Server 1.2.3.4 GET /cmd.exe - 443 - 
2.3.4.5 HTTP/1.1 
Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko - - 
IIS8-5Server 404 0 2 1477 256 0





On Friday, December 12, 2014 7:37:15 AM UTC-8, James Whittington wrote:

> I was just curious if anyone knew the status of the issue where IIS logs 
> are not able to trigger on web_rules.xml?
>
> Basically even with a correct IIS decoder in place the web rules will 
> never trigger.
>
>  
>
> I came across some pretty obvious SQL Injection Attacks against IIS 
> websites and was trying to determine why OSSEC didn’t catch those events.
>
>  
>
> So really there is no point to running IIS logs through OSSEC if you can’t 
> trigger against rules.
>
>  
>
> I see the issue was raised here 
> https://github.com/ossec/ossec-hids/issues/164 
>
> With possible fix here https://github.com/ossec/ossec-hids/pull/434
>
>  
>
> James Whittington
>
>  
>

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to