-
Posts
645 -
Joined
-
Last visited
-
Days Won
101
Content Type
Profiles
Forums
Downloads
Tutorials
Everything posted by Morpheus
-
Base Will Not Update
Morpheus replied to Flonkbob's topic in Discussing Manual Installation for Apache2 with MySQL Logging
I ended up deleteing the log files to get it to correctly update the date. The events were correct but didn't have the correct date. I believe this is due to a corrupted waldo file. To fix; use the Windows Intrusion Detection Systems security console and delete all the events. Stop snort and Barnyard2 from the Task Manager, Go into the d:\winids\snort\logs folder, delete all the files, and reboot. -
Base Will Not Update
Morpheus replied to Flonkbob's topic in Discussing Manual Installation for Apache2 with MySQL Logging
So the events are being logged but the date is not being updated? -
BASE runs fine on PHP5 when there is a fresh install of any of the supported windows operating system, and the tutorial is followed exactly as instructed. There could be problems installing the Windows Intrusion Detection System on an existing supported, or unsupported Windows operating system. Make SURE configuring PHP is followed exactly as outlined in the tutorial.
-
The Windows Intrusion Detection Systems security console (BASE) automatically incraments the alerts based on a setting in the base.conf file. This only happes when the Windows Intrusion Detection Systems security console is open. If you want to be aleted by email on specific events, then there is a companion add-on for that.
- 3 replies
-
- Barnyard2
- barnyard test
-
(and 1 more)
Tagged with:
-
Barnyard2 has to op[en the database to test, and then it closes. I guess it could be more descriptive, like > database: Opening connection to database "snort"
- 3 replies
-
- Barnyard2
- barnyard test
-
(and 1 more)
Tagged with:
-
I find that most of these incidents with Windows 7, 8, 2008, and 2012 using Internet Information Services (IIS), the PHP configuration fails to save. Return to the section labeled 'Configuring Internet Information Services for PHP', and complete. Try running the test.php again, and see if it displays. The test.php needs to be copied to the d:winidsinetpubwwwrootbase folder, and accessed from the URL http://winids/test.php
-
Ok, so I checked my winsnort.rules files. The winids.rules file does contains all three rule sets: preprocessor.rules decoder.rules sensitive-data.rules Open the winids.rules file in a text editor (notepad+) and all the rules are categorized. preprocessor.rules -> # ----- Begin VRT-preprocessor Rules Category ----- # decoder.rules -> # ----- Begin VRT-decoder Rules Category ----- # sensitive-data.rules -> # ----- Begin VRT-sensitive-data Rules Category ----- # As an example open the preprocessor.rules file and there are 500 rules listed (fictional count). Out of those 500 rules there may be 50 disabled (# is disabled). After PulledPork processes, open the winids.rules file and search for the category labeled # ----- Begin VRT-preprocessor Rules Category ----- #. Under that category, all 500 (fictional count) rules should be listed and match exactly what rules are found in the preprocessor.rules file. Out of the 500 rules (fictional count) listed under the # ----- Begin VRT-preprocessor Rules Category ----- # there may be 480 of those rules (fictional count) disabled, and not just 50 that was disabled in the default preprocessor.rules file. PulledPork will adjust the enabled / disabled status of each rule when compiling a new winids.rules file based on the 'ips_policy=' setting in the pulledpork.conf. This is the main reason why your preprocessor rule events have dropped after adding the PulledPork add-on. Note: NEVER, and I repeat NEVER manually alter the winids.rules file. Use the four configuration files listed below to make ALL rule changes. enablesid=d:winidspulledporketcenablesid.conf dropsid=d:winidspulledporketcdropsid.conf disablesid=d:winidspulledporketcdisablesid.conf modifysid=d:winidspulledporketcmodifysid.conf As an example; lets say there was a previous rule that was being triggered prior to updating to PulledPork. To enable that rule, add that rules SID to the enablesid.conf file. As an example; lets say there is a specific event being triggered regarding Internet Information Services. Your enterprise site does not run Internet Information Services, and you don't want to see that event in the Windows Intrusion Detection Systems security console. To disable that rule, add that rules SID to the disablesid.conf file. By adding the rules sid to the enablesid.conf file, or the disablesid.conf file, the rule will continue to be enabled, or disabled in the winids.rules file. However, when Snort starts it first reads in the original winids.rules file. It then reads in the enablesid.conf file, the disabledsid.conf , and then enables or disables rules based on what Snort finds in each of those .conf files. PulledPork compiles a basic winids.rules file. The four configuration files listed above are used for rule customizing. Never touch the winids.rules file. Winsnort gives the basic starting point, but for more advanced help, the PulledPork users group is the next step.
-
Here is the original Windows Intrusion Detection Systems configuration for the 'PREPROC' rules. Original Line(s): # include $PREPROC_RULE_PATH/preprocessor.rules # include $PREPROC_RULE_PATH/decoder.rules # include $PREPROC_RULE_PATH/sensitive-data.rules Change to: include $PREPROC_RULE_PATH/preprocessor.rules include $PREPROC_RULE_PATH/decoder.rules include $PREPROC_RULE_PATH/sensitive-data.rules Here are the changes for the PulledPork add-on Original Line(s): include $PREPROC_RULE_PATH/preprocessor.rules include $PREPROC_RULE_PATH/decoder.rules include $PREPROC_RULE_PATH/sensitive-data.rules Change to: # include $PREPROC_RULE_PATH/preprocessor.rules # include $PREPROC_RULE_PATH/decoder.rules # include $PREPROC_RULE_PATH/sensitive-data.rules After you made the changes are the three rule sets listed below actually located in the 'd:winidssnortrules' folder? preprocessor.rules decoder.rules sensitive-data.rules As far as I know all the rules are supposed to be processed into the single .rules file (winids.rules). Something may have changed, or I'm not fully understanding how PulledPork works. Let me query the group on this. I've never seen this problem before.
-
Make SURE your OS is capable of running the .vbs file. Windows 8 should do this out of the box. In lieu of running the .vbs file; manually execute each command in the .vbs file for your OS, and the architecture used. Follow the tutorial. whatever your Windows OS media drive is, will be x Windows 8.x / 2008 / 2012: The original OS media CD/DVD is now required to be inserted into the CD/DVD-Player. In lieu of a Windows OS CD; if you have access to an ISO, or possibly the CD/DVD; just transfer the sourcessxs folder to wherever, and point x to that location. You could also just mount the ISO and point the x to that drive letter.
-
It reads this registry key: HKLM > SOFTWARE > Microsoft > Windows NT > CurrentVersion Expects a value of 6.3 in the CurrentVersion value for all versions of Windows 8.x You are supposed to run the modder.vbs file from a CMD window that has Administrator privileges. Right-clicking the file, and "Run as Administrator", should also work?
-
I'm not sure what you are getting at here. According to the log files; the Windows Intrusion Detection System (WinIDS) has had one previous run that detected and logged two events (records). The Windows Intrusion Detection System (WinIDS) has been ran again, and has detected one event (the data after the "Waiting for new data" shows data for one event) At that point if Barnyard2 was stopped, you should be able to go into the Windows Intrusion Detection Systems (WinIDS) security console, and there should be a total of three events. Restarting barnyard2, or rebooting, the barnyard2 terminal window should now show: record_idx = 3 Everything is normal...
