Thanks for the tip!  I'll definitely check that out!  

On Friday, December 12, 2014 2:28:41 PM UTC-8, Nathaniel Bentzinger wrote:
>
>  Just a side note since you mention IIS is your biggest liability for 
> some reason consider running the free version of dotDefender on your 
> Windows server then monitor with OSSEC the Event logs for dotDefender. That 
> way you can create active-responses against what dotDefender finds and it 
> finds everything. Just be sure to update your agent’s OSSEC config to look 
> at dotdefender event logs.
>
>  
>
> here are my local_rules for dotdefender:
>
>   <rule id="100015" level="7">
>
>     <if_sid>18100</if_sid>
>
>     <match>Applicure|dotDefender</match>
>
>     <description>dotDefender Alert</description>
>
>     <group>system_error, Applicure</group>
>
>   </rule>
>
>  
>
>   <rule id="100016" level="8" frequency="20" timeframe="120">
>
>     <if_matched_sid>100015</if_matched_sid>
>
>     <description>Multiple dotDefender Alerts</description>
>
>     <group>system_error, Applicure</group>
>
>   </rule>
>
>  
>
>   <rule id="100017" level="7">
>
>     <if_sid>100015</if_sid>
>
>     <match>Session Protection</match>
>
>     <description>dotDefender Alert: Session Protection</description>
>
>     <group>system_error, Applicure, Session_Protection</group>
>
>   </rule>
>
>  
>
>   <rule id="100018" level="7">
>
>     <if_sid>100015</if_sid>
>
>     <match>SQL Injection|Classic SQL</match>
>
>     <description>dotDefender Alert: SQL Injection Attempt</description>
>
>     <group>system_error, Applicure, SQL_Injection_attempt</group>
>
>   </rule>
>
>  
>
>   <rule id="100019" level="7">
>
>     <if_sid>100015</if_sid>
>
>     <match>Compromised/Hacked Servers</match>
>
>     <description>dotDefender Alert: Compromised/Hacked 
> Servers</description>
>
>     <group>system_error, Applicure, Hacked_Servers</group>
>
>   </rule>
>
>  
>
>    <rule id="100020" level="6">
>
>     <if_sid>100015</if_sid>
>
>     <match>Anti-Proxy Protection|Generic Anti-proxy Protection</match>
>
>     <description>dotDefender Alert: Anti-proxy Protection</description>
>
>     <group>system_error, Applicure, Anti-proxy_Protection</group>
>
>   </rule>
>
>  
>
> IIS will just give you 4xx/5xx ins OSSEC you’d have to adjust the rules to 
> capture everything else.
>
>  
>
>  
>
> *From:* [email protected] <javascript:> [mailto:
> [email protected] <javascript:>] *On Behalf Of *Brent Morris
> *Sent:* Friday, December 12, 2014 4:07 PM
> *To:* [email protected] <javascript:>
> *Subject:* [ossec-list] Re: anyone know the status of the issue where IIS 
> logs are not able to trigger on web_rules.xml
>
>  
>  
> OK - on another system I'm able to get the web_rules.xml to trigger.
>  
>  
>  
> I setup IIS logging on this system... in W3C format.  selected all the 
> fields..
>  
> #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem 
> cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) 
> cs(Referer) cs-host sc-status sc-substatus sc-win32-status sc-bytes 
> cs-bytes time-taken
>  
>  
>  
> OSSEC config on the monitored system looks like this.
>  
>  
>  
> <localfile>
>     <location>C:\inetpub\logs\LogFiles\W3SVC1\u_ex%y%m%d.log</location>
>     <log_format>iis</log_format>
> </localfile>
>  
>  
>  
> restarted the ossec agent....  and iisreset too...
>  
>  
>  
> hammered on it for cmd.exe
>  
>  
>  
> and zoop zoop!
>  
> OSSEC HIDS Notification.
> 2014 Dec 12 13:01:50
>  
> Received From: (IIS8-5Server) 
> 1.2.3.4->\inetpub\logs\LogFiles\W3SVC1\u_ex141212.log
> Rule: 31153 fired (level 10) -> "Multiple common web attacks from same 
> souce ip."
> Portion of the log(s):
>  
> 2014-12-12 21:00:55 W3SVC1 IIS8-5Server 1.2.3.4 GET /cmd.exe - 443 - 
> 2.3.4.5 HTTP/1.1 
> Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko - - 
> IIS8-5Server 404 0 2 1477 256 0
>  
>  
>  
>  
>  
>  
>  
>  
>  
>
> On Friday, December 12, 2014 7:37:15 AM UTC-8, James Whittington wrote:
>  
>  I was just curious if anyone knew the status of the issue where IIS logs 
> are not able to trigger on web_rules.xml?
>
> Basically even with a correct IIS decoder in place the web rules will 
> never trigger.
>
>  
>
> I came across some pretty obvious SQL Injection Attacks against IIS 
> websites and was trying to determine why OSSEC didn’t catch those events.
>
>  
>
> So really there is no point to running IIS logs through OSSEC if you can’t 
> trigger against rules.
>
>  
>
> I see the issue was raised here 
> https://github.com/ossec/ossec-hids/issues/164 
>
> With possible fix here https://github.com/ossec/ossec-hids/pull/434
>
>  
>
> James Whittington
>
>  
>  
>  -- 
>
> --- 
> You received this message because you are subscribed to the Google Groups 
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to [email protected] <javascript:>.
> For more options, visit https://groups.google.com/d/optout.
>  

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to