[ossec-list] Re: Active Responses

2007-10-01 Thread [EMAIL PROTECTED]

Thank you Daniel...

Works great !!



[ossec-list] Re: filter rules on host and log file?

2007-10-01 Thread JM

On 9/30/07, Daniel Cid [EMAIL PROTECTED] wrote:

 Hi JM,

 I think you are confusing it a bit. The logformat in the localfile
 configuration is only
 used to tell ossec how to read the logs, not anything else. In fact,
 the apache, squid,
 syslog fields act the same in there (all one entry per line logs)...

 What determines the category of them is the decoder. If the decoder
 reads a PIX
 log, it will set it to the firewall category or if it reads a apache
 log, it will set it as
 web_log (look at the decoders.xml and the type tags).


That makes sense.  Thanks for the clarification.

 Regarding your log, our decoder is not treating it properly as a
 firewall because it has an additional hostname in there.
[trim]
 *btw, you can keep the additional timestamp in there, but not the
 extra hostname.


Ok, so I examined the decoder.xml file and found the location that
detects PIX/ASA.  I then copied the lines and commented out a pair (so
I could undo any damage I might cause.. :-)

I added a \w+ in between the date and the %ASA-... to match the extra
hostname and -- WOW!  I'm getting much better alerts now! :-D

 Hope it helps.


Tremendously!

Thanks again.

JM


[ossec-list] detecting sector changes on disk-space without a filesystem

2007-10-01 Thread peter muller

Hello,

we found out that many sectors changed on disk-space without a filesystem!
(High-level troyaner or hidden volume?)

Therefore we made several point over time(dd-images) of the whole disk and
hoped to be able to analyse the changes later on with commercial forensic 
software. But unfortunately this seems not to be possible with any of the 
public available forensic softwares :-)


Questions:
1.
Is OSSEC able to detect sector changes on disk-space without a filesystem?

2.
If not yet, how many hours would be required to write such a feature?



Thank you very much in advance for any feedback!

Peter


-- 
GMX FreeMail: 1 GB Postfach, 5 E-Mail-Adressen, 10 Free SMS.
Alle Infos und kostenlose Anmeldung: http://www.gmx.net/de/go/freemail