Re: [ossec-list] OSSEC rule for Shellshock CGI attacks?

2014-10-07 Thread Jan Andrasko
Michael, if you remove if_sid, will it match anything? I am trying now to play with it a bit and it doesn't match. I created vulnerable cgi script. All 40x attempts are matched by 31101. **Phase 1: Completed pre-decoding. full event: '111.111.111.111 - - [07/Oct/2014:12:53:51 +] GET

[ossec-list] connection refused error after key exchange using ossec-authd

2014-10-07 Thread Abhi
Hi, We have automated the OSSEC key distribution with the help of ossec-authd. Initially, it worked well with no issues. All the agents were getting the keys and able to communicate fine with the server. Lately, whenever I am trying to install OSSEC, the key distribution works correctly, but

Re: [ossec-list] Authentication key file '/etc/client.keys' not found.

2014-10-07 Thread Bryan Pearson
So it turns out the using prevars in the install process was uneeded. Uninstalling and reinstalling with it removed solved this issue. On Monday, October 6, 2014 5:15:46 AM UTC-4, dan (ddpbsd) wrote: On Oct 6, 2014 5:11 AM, Bryan Pearson bpea...@reverbnation.com javascript: wrote: I did

[ossec-list] Re: OSSEC CON 2014 - Malware detection with OSSEC, video and slides available

2014-10-07 Thread SoulAuctioneer
Awesome. Thanks for sharing. I look forward to seeing the rest of the presentations when they get posted. -- --- You received this message because you are subscribed to the Google Groups ossec-list group. To unsubscribe from this group and stop receiving emails from it, send an email to