[ossec-list] OSSEC 2.7 and Windows 2008 server: never connected

2013-04-17 Thread Michiel van Es
Hello, We have installed OSSEC 2.7 on a CentOS machine which is working fine with several Windows and Linux agents. We are trying to install the OSSEC 2.7 agent package on a Windows 2008 server which goes well but at end, after the manual agent config (ip and secret) and restarting of the

RE: [ossec-list] OSSEC 2.7 and Windows 2008 server: never connected

2013-04-17 Thread Nathaniel Bentzinger
From the server have you verified that the windows agent is actually connecting to the server via tcpdump? Tcpdump -i eth0 'host agent IP and udp' You can also verify the same thing from the windows agent using wireshark using 'ip.addr == server IP' If you don't see anything check to see what

Re: [ossec-list] OSSEC 2.7 and Windows 2008 server: never connected

2013-04-17 Thread Michiel van Es
I will test that but besides the fact if it is really connecting or not, why would the agent report that it is connected to the server then? Op woensdag 17 april 2013 12:50:47 UTC+2 schreef Nathaniel Bentzinger het volgende: From the server have you verified that the windows agent is

Re: [ossec-list] OSSEC 2.7 and Windows 2008 server: never connected

2013-04-17 Thread dan (ddp)
On Wed, Apr 17, 2013 at 6:27 AM, Michiel van Es vanesmich...@gmail.com wrote: Hello, We have installed OSSEC 2.7 on a CentOS machine which is working fine with several Windows and Linux agents. We are trying to install the OSSEC 2.7 agent package on a Windows 2008 server which goes well but

Re: [ossec-list] OSSEC Web UI PGP Signature Invalid?

2013-04-17 Thread dan (ddp)
On Tue, Apr 16, 2013 at 1:13 PM, Jake Johns johns...@gmail.com wrote: Super old code? Does this mean it's not advisable to use? I've been advising against using it for a long time now. There is slightly better code in https://bitbucket.org/jbcheng/ossec-wui If it is usable, shouldn't that

Re: [ossec-list] Integrity checksum changed on executables. No prelinking.

2013-04-17 Thread Aliev, Dmitry
I've found that checksum modification starts with file /etc/alternatives/mozilla-flashplugin and ends with /bin/rbash. Such order is the same on all hosts. Mozilla is the cause? which way? -/bin/rbash File: /bin/rbash Agent: dbi-726-14x Modification time: 2013 Apr 16 11:03:37 -/bin/bash

Re: [ossec-list] OSSEC 2.7 and Windows 2008 server: never connected

2013-04-17 Thread Michiel van Es
Op woensdag 17 april 2013 15:19:38 UTC+2 schreef dan (ddpbsd) het volgende: On Wed, Apr 17, 2013 at 6:27 AM, Michiel van Es vanesm...@gmail.comjavascript: wrote: Hello, We have installed OSSEC 2.7 on a CentOS machine which is working fine with several Windows and Linux

Re: [ossec-list] Help with rule for qmail and cmd5checkpw

2013-04-17 Thread Nick
Guys/Dan, I have this custom encoder rules running for cmd5checkpw and it seems to be working well. Of course, now I have another brute force attack going on that OSSEC doesn't seem to be catching: Apr 17 07:00:33 clients15 smtp_auth: FAILED: rob...@redacted.com - password incorrect from

Re: [ossec-list] Help with rule for qmail and cmd5checkpw

2013-04-17 Thread dan (ddp)
I should start charging for the basic stuff. On Wed, Apr 17, 2013 at 10:37 AM, Nick nickv...@gmail.com wrote: Guys/Dan, I have this custom encoder rules running for cmd5checkpw and it seems to be working well. Of course, now I have another brute force attack going on that OSSEC doesn't

Re: [ossec-list] OSSEC 2.7 and Windows 2008 server: never connected

2013-04-17 Thread dan (ddp)
On Wed, Apr 17, 2013 at 10:39 AM, Michiel van Es vanesmich...@gmail.com wrote: Op woensdag 17 april 2013 15:44:03 UTC+2 schreef Michiel van Es het volgende: Op woensdag 17 april 2013 15:19:38 UTC+2 schreef dan (ddpbsd) het volgende: On Wed, Apr 17, 2013 at 6:27 AM, Michiel van Es

Re: [ossec-list] OSSEC Web UI PGP Signature Invalid?

2013-04-17 Thread Jake Johns
If it's not recommended for use due to lack of development, shouldn't it be removed? What if someone wants to work on it? Lots (for some value of lots) of people seem interested in it, but maybe one day someone will step up and do more work on it. Some people have fixed some of the

Re: [ossec-list] OSSEC 2.7 and Windows 2008 server: never connected

2013-04-17 Thread Michiel van Es
Op woensdag 17 april 2013 17:08:48 UTC+2 schreef dan (ddpbsd) het volgende: On Wed, Apr 17, 2013 at 10:39 AM, Michiel van Es vanesm...@gmail.comjavascript: wrote: Op woensdag 17 april 2013 15:44:03 UTC+2 schreef Michiel van Es het volgende: Op woensdag 17 april 2013

Re: [ossec-list] OSSEC 2.7 and Windows 2008 server: never connected

2013-04-17 Thread dan (ddp)
On Wed, Apr 17, 2013 at 11:46 AM, Michiel van Es vanesmich...@gmail.com wrote: Op woensdag 17 april 2013 17:08:48 UTC+2 schreef dan (ddpbsd) het volgende: On Wed, Apr 17, 2013 at 10:39 AM, Michiel van Es vanesm...@gmail.com wrote: Op woensdag 17 april 2013 15:44:03 UTC+2 schreef

[ossec-list] Remove Ossec MySQL database

2013-04-17 Thread w3ndtr
Hello, I am currently running ossec 2.5.1 and will be upgrading to 2.7 in the next few months. The ossec server was first installed with the database enabled from the steps on the wiki walk-through. It has been running fine, but the database has never been used and I would like to remove that

Re: [ossec-list] Remove Ossec MySQL database

2013-04-17 Thread dan (ddp)
On Wed, Apr 17, 2013 at 12:36 PM, w3ndtr w3n...@gmail.com wrote: Hello, I am currently running ossec 2.5.1 and will be upgrading to 2.7 in the next few months. The ossec server was first installed with the database enabled from the steps on the wiki walk-through. It has been running fine,

Re: [ossec-list] Help with rule for qmail and cmd5checkpw

2013-04-17 Thread Nick
The check's in the mail Dan! No seriously, thanks very much for your help. -Nick On Wednesday, April 17, 2013 8:59:35 AM UTC-6, dan (ddpbsd) wrote: I should start charging for the basic stuff. On Wed, Apr 17, 2013 at 10:37 AM, Nick nick...@gmail.com javascript: wrote: Guys/Dan,