Thanks for the tip! I'll definitely check that out! On Friday, December 12, 2014 2:28:41 PM UTC-8, Nathaniel Bentzinger wrote: > > Just a side note since you mention IIS is your biggest liability for > some reason consider running the free version of dotDefender on your > Windows server then monitor with OSSEC the Event logs for dotDefender. That > way you can create active-responses against what dotDefender finds and it > finds everything. Just be sure to update your agent’s OSSEC config to look > at dotdefender event logs. > > > > here are my local_rules for dotdefender: > > <rule id="100015" level="7"> > > <if_sid>18100</if_sid> > > <match>Applicure|dotDefender</match> > > <description>dotDefender Alert</description> > > <group>system_error, Applicure</group> > > </rule> > > > > <rule id="100016" level="8" frequency="20" timeframe="120"> > > <if_matched_sid>100015</if_matched_sid> > > <description>Multiple dotDefender Alerts</description> > > <group>system_error, Applicure</group> > > </rule> > > > > <rule id="100017" level="7"> > > <if_sid>100015</if_sid> > > <match>Session Protection</match> > > <description>dotDefender Alert: Session Protection</description> > > <group>system_error, Applicure, Session_Protection</group> > > </rule> > > > > <rule id="100018" level="7"> > > <if_sid>100015</if_sid> > > <match>SQL Injection|Classic SQL</match> > > <description>dotDefender Alert: SQL Injection Attempt</description> > > <group>system_error, Applicure, SQL_Injection_attempt</group> > > </rule> > > > > <rule id="100019" level="7"> > > <if_sid>100015</if_sid> > > <match>Compromised/Hacked Servers</match> > > <description>dotDefender Alert: Compromised/Hacked > Servers</description> > > <group>system_error, Applicure, Hacked_Servers</group> > > </rule> > > > > <rule id="100020" level="6"> > > <if_sid>100015</if_sid> > > <match>Anti-Proxy Protection|Generic Anti-proxy Protection</match> > > <description>dotDefender Alert: Anti-proxy Protection</description> > > <group>system_error, Applicure, Anti-proxy_Protection</group> > > </rule> > > > > IIS will just give you 4xx/5xx ins OSSEC you’d have to adjust the rules to > capture everything else. > > > > > > *From:* [email protected] <javascript:> [mailto: > [email protected] <javascript:>] *On Behalf Of *Brent Morris > *Sent:* Friday, December 12, 2014 4:07 PM > *To:* [email protected] <javascript:> > *Subject:* [ossec-list] Re: anyone know the status of the issue where IIS > logs are not able to trigger on web_rules.xml > > > > OK - on another system I'm able to get the web_rules.xml to trigger. > > > > I setup IIS logging on this system... in W3C format. selected all the > fields.. > > #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem > cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) > cs(Referer) cs-host sc-status sc-substatus sc-win32-status sc-bytes > cs-bytes time-taken > > > > OSSEC config on the monitored system looks like this. > > > > <localfile> > <location>C:\inetpub\logs\LogFiles\W3SVC1\u_ex%y%m%d.log</location> > <log_format>iis</log_format> > </localfile> > > > > restarted the ossec agent.... and iisreset too... > > > > hammered on it for cmd.exe > > > > and zoop zoop! > > OSSEC HIDS Notification. > 2014 Dec 12 13:01:50 > > Received From: (IIS8-5Server) > 1.2.3.4->\inetpub\logs\LogFiles\W3SVC1\u_ex141212.log > Rule: 31153 fired (level 10) -> "Multiple common web attacks from same > souce ip." > Portion of the log(s): > > 2014-12-12 21:00:55 W3SVC1 IIS8-5Server 1.2.3.4 GET /cmd.exe - 443 - > 2.3.4.5 HTTP/1.1 > Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko - - > IIS8-5Server 404 0 2 1477 256 0 > > > > > > > > > > > On Friday, December 12, 2014 7:37:15 AM UTC-8, James Whittington wrote: > > I was just curious if anyone knew the status of the issue where IIS logs > are not able to trigger on web_rules.xml? > > Basically even with a correct IIS decoder in place the web rules will > never trigger. > > > > I came across some pretty obvious SQL Injection Attacks against IIS > websites and was trying to determine why OSSEC didn’t catch those events. > > > > So really there is no point to running IIS logs through OSSEC if you can’t > trigger against rules. > > > > I see the issue was raised here > https://github.com/ossec/ossec-hids/issues/164 > > With possible fix here https://github.com/ossec/ossec-hids/pull/434 > > > > James Whittington > > > > -- > > --- > You received this message because you are subscribed to the Google Groups > "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected] <javascript:>. > For more options, visit https://groups.google.com/d/optout. >
-- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
