[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[ossec-list] Re: Can't get OSSEC to fire active response for custom proftpd rule
- To: ossec-list@xxxxxxxxxxxxxxxx
- Subject: [ossec-list] Re: Can't get OSSEC to fire active response for custom proftpd rule
- From: Steve West <stevewest15@xxxxxxxxx>
- Date: Wed, 24 Oct 2007 13:32:34 -0400
- Authentication-results: mx.google.com; spf=pass (google.com: domain of stevewest15@xxxxxxxxx designates 64.233.170.191 as permitted sender) smtp.mail=stevewest15@xxxxxxxxx; dkim=pass (test mode) header.i=@xxxxxxxxx
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:reply-to:user-agent:mime-version:to:subject:references:in-reply-to:content-type:content-transfer-encoding; bh=oApG21iv8k9ih8YlmZwr1AhNuUW4cYLrNQqFTCaCCDQ=; b=CpjG4HHg9IJMy3jmDJHw+3aXi7ISyG0dSLQ3o2UlHNIWDGeBgOEiL2mSD9zLLOWsmmUBKYrXE8HOrq1kdmKBug7IlqbttwCE4XWqupV2NJKnQO70UBKuH8/xyV+DowwWRRtHX4/mxSXhM+cTuDI4HYnNv1morzocMVW2QuDWAdY=
Michael Starks wrote:
> Try 21 or 22 invalid logins in 60 seconds.
>
> -Mike
>
Hi Mike,
Thanks for the suggestion! I try over 25 invalid logins and still ossec
active response doesn't fire. Not really sure why but I think it might
be related to my rule or the underlaying proftpd group rule 11200.
SW
OSSEC home |
Main Index |
Thread Index
OSSEC project: www.ossec.net.
Mailling list information: http://www.ossec.net/en/mailing_lists.html.