store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Fri May 24, 2013 11:43 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 6 posts ] 
Author Message
 Post subject: [asl-2.0-testing] OSSEC-HIDS 2.0-9
Unread postPosted: Wed Jun 03, 2009 4:00 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7429
Location: earth
Changelog:

Update to snapshot 060309
- This adds in the ability to restart remote agents from the server

To upgrade:

yum --enablerepo=asl-2.0-testing upgrade ossec-hids


Top
 Profile  
 
 Post subject: Re: [asl-2.0-testing] OSSEC-HIDS 2.0-9
Unread postPosted: Thu Jun 04, 2009 9:24 pm 
Offline
Forum Regular
Forum Regular

Joined: Thu Oct 26, 2006 11:56 pm
Posts: 665
Hi Scott,

With this update I am getting these a few an hour. It varies about 2 to 3 per hour:

From: "psmon@xxx" <psmon@xxx>
To: "xxx" <xxx>
Subject: [psmon/xxx] Spawned 'ossec-syscheckd' with '/sbin/service ossec-hids restart'
Headers: Show All Headers
Command executed: /sbin/service ossec-hids restart
Exit value: 0
Signal number: 0
Dumped core?: 0

Shutting down ossec-hids: [ OK ]
Starting ossec-hids: [ OK ]

Any idea's?

It's also happening on two servers and my test server also.

PS - have you seen damn Trend Micro purchased the company that writes ossec? It's on the ossec page. Guess we might see it go away from free :(


Top
 Profile  
 
 Post subject: Re: [asl-2.0-testing] OSSEC-HIDS 2.0-9
Unread postPosted: Fri Jun 05, 2009 7:30 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7429
Location: earth
the trend micro acquisition shouldnt have any effect on OSSEC. It is still a GPL'd project, and Dan Cid has repeated said hes committed to that. In reality the worst that could happen is that trend micro could run off with the trademark "ossec" and the project would have to change the name. Similar to what happened to OSSIM.

In reference to syscheckd, disable it from monitoring. It runs on demand now.


Top
 Profile  
 
 Post subject: Re: [asl-2.0-testing] OSSEC-HIDS 2.0-9
Unread postPosted: Fri Jun 05, 2009 7:45 am 
Offline
Forum Regular
Forum Regular

Joined: Thu Oct 26, 2006 11:56 pm
Posts: 665
Thanks Scott for the update about Trend and it will continue under GPL :)

How do I disable ossec from psmon?

Thanks!


Top
 Profile  
 
 Post subject: Re: [asl-2.0-testing] OSSEC-HIDS 2.0-9
Unread postPosted: Fri Jun 05, 2009 8:20 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7429
Location: earth
in a word.... vim


Top
 Profile  
 
 Post subject: Re: [asl-2.0-testing] OSSEC-HIDS 2.0-9
Unread postPosted: Fri Jun 05, 2009 9:06 am 
Offline
Forum Regular
Forum Regular

Joined: Thu Oct 26, 2006 11:56 pm
Posts: 665
As soon as I run asl -s -f the /etc/psmon.conf gets overwritten once again checking syscheckd for ossec

:(

But I edited /var/asl/data/services and removed ossec-hids

asl -s -f and its now ok its dropped ossec-hids :)

Is that the fix?


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 6 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Google [Bot] and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group