Re: [ossec-list] I'd like to ignore these...

2014-08-25 Thread Steven Stern
messages/description /rule replace 11 with the next available ID if 11 is already used by another rule. Hoping this helps. Valere From: Steven Stern [subscribed-li...@sterndata.com] Sent: Friday, August 22, 2014 6:21 PM To: ossec

[ossec-list] I'd like to ignore these...

2014-08-23 Thread Steven Stern
What's the best way to get OSSEC to ignore this particular error in error_log? It's the result of .htaccess rules operating corrrectly, so I don't really need to get emails about it. I suspect that I need to tell it to non notifiy me on a rule 1002 if AH01797 is in the text, but I'm not sure how

[ossec-list] Won't start after upgrade from 2.7.1 to 2.8

2014-06-04 Thread Steven Stern
At the end of ./install.sh OSSEC HIDS v2.7.1 Stopped Starting OSSEC HIDS v2.8 (by Trend Micro Inc.)... ossec-analysisd: Configuration error. Exiting. - Configuration finished properly. service ossec start Starting OSSEC:[FAILED] from ossec.log

[ossec-list] 1 zombie process after starting 2.8

2014-06-04 Thread Steven Stern
# ps -ef |grep ossec ossecm 17982 1 0 11:55 ?00:00:00 /var/ossec/bin/ossec-maild root 17984 1 0 11:55 ?00:00:00 /var/ossec/bin/ossec-execd ossec17990 1 0 11:55 ?00:00:00 /var/ossec/bin/ossec-analysisd root 17994 1 0 11:55 ?00:00:00

Re: [ossec-list] Integrity checksum changed for: '/usr/bin/from'

2014-06-04 Thread Steven Stern
Check your package updater's logs. On 06/04/2014 07:51 AM, dan (ddp) wrote: On Wed, Jun 4, 2014 at 4:53 AM, PAL 18 pal...@ftwgamer.com wrote: I just got this a few minutes ago and i wasn't logged into the box. Should i be worried? Has my server been hacked? You have to investigate the

[ossec-list] Reporting network changes

2014-05-15 Thread Steven Stern
I'm getting network change notifications a couple of times per day on one system. It appears it's comparing the current state to some base state where most of the services weren't started. I can't find anything in the logs to indicate that services are being restarted during the day, so this is a

[ossec-list] keepalive message

2012-04-08 Thread Steven Stern
This just arrived as an alert: OSSEC HIDS Notification. 2012 Apr 08 10:40:50 Received From: breadboard-ossec-keepalive Rule: 1002 fired (level 2) - Unknown problem somewhere in the system. Portion of the log(s): --MARK--:

Re: [ossec-list] Re: Repeated-offenders still not working

2012-03-12 Thread Steven Stern
On 03/12/2012 10:49 AM, Dimitri Yioulos wrote: Anyone have any ideas on this? All, Back at the end of last year, I asked about using the repeated-offenders feature in OH. I added the following directives to ossec.conf on the host that I want this to work in: command

Re: [ossec-list] Re: Repeated-offenders still not working

2012-03-12 Thread Steven Stern
On 03/12/2012 11:53 AM, Dimitri Yioulos wrote: On Monday 12 March 2012 12:24:47 pm Steven Stern wrote: On 03/12/2012 10:49 AM, Dimitri Yioulos wrote: Anyone have any ideas on this? All, Back at the end of last year, I asked about using the repeated-offenders feature in OH. I added

Re: [ossec-list] ossec newbie, increasing tresshold for failed http login and unblock blocked ip

2012-02-05 Thread Steven Stern
On 02/05/2012 11:56 AM, lucas kauffman wrote: Also if an IP is blocked, how can I unblock it through ossec ? Or do I have to do it manually and delete the entries for hosts.deny and iptables ? OSSEC will unblock automatically, based on the timeout parameter in ossec.conf or you your local

Re: [ossec-list] Web Server Trouble

2012-01-25 Thread Steven Stern
I get a lot of 404 alerts, and I let OSSEC block access when it's multiples from the same IP. Typically, they're looking for phpmyadmin or other common (and probably poorly secured tools) in a number of locations. On 01/24/2012 11:33 PM, Damien Hull wrote: It looks like someone was requesting

Re: [ossec-list] perhaps a dump question but need to ask...

2011-12-27 Thread Steven Stern
Be sure to whitelist your own IP address! On 12/27/2011 09:57 AM, Peter Skurczak wrote: Hello there, I was having similar problem. I wanted to find the way how to block an ip permanently. I ended up with increasing the ban time for not 600 but 60 seconds and I think that is

[ossec-list] Trojan false positive and portreserve

2011-12-27 Thread Steven Stern
I just disabled cups on my server (no printer, no need to print) and OSSEC reported Port '631'(tcp) hidden. Kernel-level rootkit or trojaned version of netstat A quick check of netstat shows $ sudo netstat -anp |grep 631 udp0 0 0.0.0.0:631 0.0.0.0:*

Re: [ossec-list] disable-account

2011-09-19 Thread Steven Stern
Disabling root seems like a nice path to a DoS. You'd probably do better to use a rule to block the offending IP rather than killing root's account. (Hint from hard personal experience: Exclude your own IP from the rule.) On 09/19/2011 10:56 AM, dan (ddp) wrote: On Sep 19, 2011 11:53 AM,

Re: [ossec-list] stupid question on ossec configuration

2011-09-07 Thread Steven Stern
On 09/07/2011 09:10 AM, Eero Volotinen wrote: Hi List, I want alert to ossec when linux interface (ethernet) link goes down ? How to do this? -- Eero Dumb question in return: If the network is down, how is it going to notify you? You probably want one or more external boxes monitoring

Re: [ossec-list] OSSEC-Keepalive message -- what does this mean?

2011-06-17 Thread Steven Stern
to be ignored so they don't fire alerts... On Fri, Jun 17, 2011 at 3:52 PM, Steven Stern subscribed-li...@sterndata.com wrote: What does this mean? Where do I look for an error? Received From: ip-10-x-ossec-keepalive Rule: 1002 fired (level 2) - Unknown problem somewhere in the system. Portion

Re: [ossec-list] stupid (?) rule question

2011-06-05 Thread Steven Stern
On 06/05/2011 07:02 AM, Rainer wrote: Hi, I want to block a certain WWW bot called verticalpigeon; it is known to scan for Joomla! installations. You can also trigger it through the website manually. But the nice thing is, it says who it is: 66.103.61.161 - - [05/Jun/2011:09:44:59 +0200] GET

[ossec-list] Timeout value units

2011-03-27 Thread Steven Stern
I just want to confirm In an active response rule, is the timeout value the number seconds? I had someone whacking my website today looking for mysql access and the rule triggered three times (on the same IP address) in two minutes. The first trigger should have locked out his IP for 360 --

Re: [ossec-list] OSSEC for Sql injection attack

2011-02-04 Thread Steven Stern
Response turned out to be fantastic to prevent SQL Injection based attacks. Regards Tanishk On Fri, Feb 4, 2011 at 12:12 AM, Steven Stern subscribed-li...@sterndata.com mailto:subscribed-li...@sterndata.com wrote: On 02/03/2011 12:00 PM, satish patel wrote: How efficient OSSEC

Re: [ossec-list] OSSEC for Sql injection attack

2011-02-03 Thread Steven Stern
On 02/03/2011 12:00 PM, satish patel wrote: How efficient OSSEC is to stop SQL injection ? If not then i have to move on mod_security Is anybody out there who using ossec for sql injection ? Thanks, S It's very good at detecting SQL injection, but your code shouldn't (smile) be

[ossec-list] Active Response not activating

2010-10-27 Thread Steven Stern
OSSEC 2.5.1, Fedora 13 In /var/ossec/etc/osse.conf, I have command  namefirewall-drop/name  executablefirewall-drop.sh/executable  expectsrcip/expect  timeout_allowedyes/timeout_allowed /command active-response  commandfirewall-drop/command  locationlocal/location  rules_id31151/rules_id  

Re: [ossec-list] Re: Active Response not activating

2010-10-27 Thread Steven Stern
It shows in the email alert I get from OSSEC. The snippet below was grabbed from OSSEC's logs. On Wed, Oct 27, 2010 at 1:38 PM, Jeremy Lee jpl...@gmail.com wrote: Does the source IP even show when that rule is tripped? On Wed, Oct 27, 2010 at 11:30 AM, Steven Stern subscribed-li