[ossec-list] ossec on cent os 7

2017-06-24 Thread satvir8989
how to install ossec on centos 7? -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+unsubscr...@googlegroups.com. For more options, visit https://gr

Re: [ossec-list] OSSEC block vulnerability scanners head user_agent

2017-06-24 Thread Fredrik Hilmersson
I spoke to early, Still getting spammed ... Den lördag 24 juni 2017 kl. 22:20:13 UTC+2 skrev Fredrik Hilmersson: > > Thank you! > > Den lördag 24 juni 2017 kl. 21:21:48 UTC+2 skrev dan (ddpbsd): >> >> On Sat, Jun 24, 2017 at 2:08 PM, Fredrik Hilmersson >> wrote: >> > Hello, >> > >> > so recen

Re: [ossec-list] OSSEC block vulnerability scanners head user_agent

2017-06-24 Thread Fredrik Hilmersson
Thank you! Den lördag 24 juni 2017 kl. 21:21:48 UTC+2 skrev dan (ddpbsd): > > On Sat, Jun 24, 2017 at 2:08 PM, Fredrik Hilmersson > > wrote: > > Hello, > > > > so recently I got spammed by this vulnerability scanner. > > The HEAD is always the same, in regards to the $user_agent, Jorgee > >

Re: [ossec-list] OSSEC block vulnerability scanners head user_agent

2017-06-24 Thread dan (ddp)
On Sat, Jun 24, 2017 at 2:08 PM, Fredrik Hilmersson wrote: > Hello, > > so recently I got spammed by this vulnerability scanner. > The HEAD is always the same, in regards to the $user_agent, Jorgee > > ** Alert 1498324205.1278330: - web,accesslog, > 2017 Jun 24 17:10:05 (OSSEC AGENT) SRCIP->/var/l

[ossec-list] OSSEC block vulnerability scanners head user_agent

2017-06-24 Thread Fredrik Hilmersson
Hello, so recently I got spammed by this vulnerability scanner. The HEAD is always the same, in regards to the $user_agent, *Jorgee* ** Alert 1498324205.1278330: - web,accesslog, 2017 Jun 24 17:10:05 (OSSEC AGENT) SRCIP->/var/log/nginx/access.log Rule: 31101 (level 5) -> 'Web server 400 error cod

[ossec-list] Re: OSSEC ignore ip issue

2017-06-24 Thread Fredrik Hilmersson
Of course my bad, this is how I did set it up. sshd MYIP no_email_alert Ignore rule 5715 for host 5501 agent server hostname (ex. webserver01) no_email_alert Ignore rule 5501 for host Den onsdag 21 juni 2017 kl. 12:00:04 UTC+2 skrev Jesus Linares: > > What hostname?. > > If you s