Re: [ossec-list] security risks having OSSEC listening on net accessible interface?

2011-10-21 Thread B/K Walker
On Thu, 20 Oct 2011 15:02:11 -0300 Daniel Cid wrote: > I do this often, but I always have a firewall rule only allowing > certain IP addresses > to access it. In that case, even if there is ever a bug on OSSEC it > will be very limited > externally. I might do that.. however I realized that in t

[ossec-list] security risks having OSSEC listening on net accessible interface?

2011-10-20 Thread B/K Walker
I've been using OSSEC for a while internally however I have a need to allow a remote system to talk with my local OSSEC server. Presumably due to the agent setup this should be plenty secure (obvious caveat about bugs and the like applies, make sure to keep up with patches, etc). Anything I sho

Re: [ossec-list] ossec module

2011-01-19 Thread B/K Walker
On Wed, 19 Jan 2011 11:22:48 +0800 seekuel wrote: > Hi, > > My I ask if there is a level we can configure ossec? say: > > level1 - moderate > level2 - Strict > level3 - paranoid > > Since we experience a scenario that the server is used as hosting and > domains that are already expired will sti

Re: [ossec-list] Web UI

2010-07-20 Thread B/K Walker
On Tue, 20 Jul 2010 07:11:20 -0700 (PDT) Timothy wrote: > I have ossec installed on a wide variety of machines, mostly windows, > but some linux. I am using the web user interface and for some reason > I am getting a huge number of php errors with listings of deprecated > functions, I need to fix

Re: [ossec-list] Using OSSEC to Audit Windows Auditing Policies

2010-07-15 Thread B/K Walker
On Thu, 15 Jul 2010 11:46:47 -0400 Tyler Ross wrote: > Hello, > > I am wanting to use OSSEC policy monitoring for auditing Windows > 2003/2008 servers that should be baselined to CIS. Initially, I am > trying to verify and monitor Windows Audit policies, specifically > *Audit Logon Events*. I h

Re: [ossec-list] match tag in rules

2010-05-20 Thread B/K Walker
On Thu, 20 May 2010 12:39:32 -0600 "Swartz, Patrick H" wrote: > Hi All, > > > > Can someone please point in the right direction with the proper use of > the tag. > > > > Is there any difference in using: > > blah | blah1 | blah2 > > > > Versus: > > blah > > blah1 > > blah2 > >

[ossec-list] rule help

2010-05-20 Thread B/K Walker
So, I've got this rule: 550,551,552 Services Enum|BITS Ignoring innocuous registry changes However it fails to catch this: Rule: 552 fired (level 7) -> "Integrity checksum changed again (3rd time)." Portion of the log(s): Integrity checksum changed for: 'HKEY_LOCAL_MACHINE\System\CurrentCo

Re: [ossec-list] Am I the only one getting 4 copies of everything to this list?

2010-05-19 Thread B/K Walker
On Wed, 19 May 2010 12:22:00 -0400 Jimi Schwar wrote: > I'm having the same problem. But it doesn't happen for all messages. > Some have 4 of the same, some have 7. If this continues I'll have to > try to unsubscribe and then subscribe again. Same thing here, and I seem to get duplicates over

Re: [ossec-list] Rule match syntax

2010-05-18 Thread B/K Walker
On Tue, 18 May 2010 09:14:51 -0500 Michael Starks wrote: > > On Tue, 18 May 2010 08:55:47 -0400, B/K Walker > wrote: > > Here's an example, I get smart HDD test syslog events from my NAS > > box: > > > > Received From: fatty->/var/log/messages &

Re: [ossec-list] Rule match syntax

2010-05-18 Thread B/K Walker
On Tue, 18 May 2010 10:51:36 -0400 "dan (ddp)" wrote: > On Tue, May 18, 2010 at 8:55 AM, B/K Walker wrote: > > I've been struggling with cleaning up the notifications from ossec, > > I've had some success but for whatever reason I can't seem to get a >

Re: [ossec-list] Am I the only one getting 4 copies of everything to this list?

2010-05-18 Thread B/K Walker
On Tue, 18 May 2010 07:28:20 -0400 William Montgomery wrote: > B/K Walker wrote: > > I'm getting 4 (maybe more) copies of every post, each with a > > different return-path and envelope-from headers (some sort of id > > used by google groups). > > > > This i

Re: [ossec-list] Am I the only one getting 4 copies of everything to this list?

2010-05-18 Thread B/K Walker
x27;t have a google account of any sort. > > On Mon, May 17, 2010 at 11:05 PM, B/K Walker wrote: > > I'm getting 4 (maybe more) copies of every post, each with a > > different return-path and envelope-from headers (some sort of id > > used by google groups).. >

[ossec-list] Rule match syntax

2010-05-18 Thread B/K Walker
I've been struggling with cleaning up the notifications from ossec, I've had some success but for whatever reason I can't seem to get a grip on it completely. I've got several rules in local_rules.xml that filter out unimportant stuff (windows really likes to twiddle registry keys, in particula

[ossec-list] Am I the only one getting 4 copies of everything to this list?

2010-05-18 Thread B/K Walker
I'm getting 4 (maybe more) copies of every post, each with a different return-path and envelope-from headers (some sort of id used by google groups). This is the first googlegroup I've signed up for, I'm on dozens of other lists and never have seen this kind of behaviour. -- If you write some