Jump to content

Morpheus

Administrators
  • Posts

    645
  • Joined

  • Last visited

  • Days Won

    101

Everything posted by Morpheus

  1. I ended up deleteing the log files to get it to correctly update the date. The events were correct but didn't have the correct date. I believe this is due to a corrupted waldo file. To fix; use the Windows Intrusion Detection Systems security console and delete all the events. Stop snort and Barnyard2 from the Task Manager, Go into the d:\winids\snort\logs folder, delete all the files, and reboot.
  2. Did you follow the tutorial, and install IIS as described using the moveiis.bat file?   Attach the configuration files requested above.
  3. So the events are being logged but the date is not being updated?
  4. Make sure MySQL is running by verifying in task manager. Go back to the 'Configuring Barnyard2' section and make SURE it is applied correctly.
  5. Attach the snort.conf, barnyard2.conf, php.ini, and the base.conf.php   If you are unable to post them individually as an attachment, the place them into a zip file and attach. I am unable to work with configuration files posted as raw text.
  6. BASE runs fine on PHP5 when there is a fresh install of any of the supported windows operating system, and the tutorial is followed exactly as instructed.   There could be problems installing the Windows Intrusion Detection System on an existing supported, or unsupported Windows operating system.   Make SURE configuring PHP is followed exactly as outlined in the tutorial.
  7. The tutorial works as is. All the latest files are referenced for installation in the Tutitorals, and only use those files as they have been tested.    Not sure exactly what you mean by running BASE normally. I had no idea the tutorials were running BASE abnormally.
  8. The Windows Intrusion Detection Systems security console (BASE) automatically incraments the alerts based on a setting in the base.conf file. This only happes when the Windows Intrusion Detection Systems security console is open.   If you want to be aleted by email on specific events, then there is a companion add-on for that.
  9. Barnyard2 has to op[en the database to test, and then it closes.   I guess it could be more descriptive, like > database: Opening connection to database "snort"
  10. The section labeled 'Configuring Internet Information Services for PHP' will address that issue.
  11. I find that most of these incidents with Windows 7, 8, 2008, and 2012 using Internet Information Services (IIS), the PHP configuration fails to save.   Return to the section labeled 'Configuring Internet Information Services for PHP', and complete.   Try running the test.php again, and see if it displays. The test.php needs to be copied to the d:winidsinetpubwwwrootbase folder, and accessed from the URL http://winids/test.php
  12. Ok, so I checked my winsnort.rules files. The winids.rules file does contains all three rule sets:  preprocessor.rules decoder.rules sensitive-data.rules   Open the winids.rules file in a text editor (notepad+) and all the rules are categorized.   preprocessor.rules -> # ----- Begin VRT-preprocessor Rules Category ----- #   decoder.rules -> # ----- Begin VRT-decoder Rules Category ----- #   sensitive-data.rules -> # ----- Begin VRT-sensitive-data Rules Category ----- #   As an example open the preprocessor.rules file and there are 500 rules listed (fictional count). Out of those 500 rules there may be 50 disabled (# is disabled). After PulledPork processes, open the winids.rules file and search for the category labeled # ----- Begin VRT-preprocessor Rules Category ----- #. Under that category, all 500 (fictional count) rules should be listed and match exactly what rules are found in the preprocessor.rules file.   Out of the 500 rules (fictional count) listed under the # ----- Begin VRT-preprocessor Rules Category ----- # there may be 480 of those rules (fictional count) disabled, and not just 50 that was disabled in the default preprocessor.rules file. PulledPork will adjust the enabled / disabled status of each rule when compiling a new winids.rules file based on the 'ips_policy=' setting in the pulledpork.conf.   This is the main reason why your preprocessor rule events have dropped after adding the PulledPork add-on.   Note: NEVER, and I repeat NEVER manually alter the winids.rules file. Use the four configuration files listed below to make ALL rule changes.   enablesid=d:winidspulledporketcenablesid.conf dropsid=d:winidspulledporketcdropsid.conf disablesid=d:winidspulledporketcdisablesid.conf modifysid=d:winidspulledporketcmodifysid.conf   As an example; lets say there was a previous rule that was being triggered prior to updating to PulledPork. To enable that rule, add that rules SID to the enablesid.conf file.   As an example; lets say there is a specific event being triggered regarding Internet Information Services. Your enterprise site does not run Internet Information Services, and you don't want to see that event in the Windows Intrusion Detection Systems security console. To disable that rule, add that rules SID to the disablesid.conf file.   By adding the rules sid to the enablesid.conf file, or the disablesid.conf file, the rule will continue to be enabled, or disabled in the winids.rules file. However, when Snort starts it first reads in the original winids.rules file. It then reads in the enablesid.conf file, the disabledsid.conf , and then enables or disables rules based on what Snort finds in each of those .conf files.   PulledPork compiles a basic winids.rules file. The four configuration files listed above are used for rule customizing. Never touch the winids.rules file.   Winsnort gives the basic starting point, but for more advanced help, the PulledPork users group is the next step.  
  13. Here is the original Windows Intrusion Detection Systems configuration for the 'PREPROC' rules.   Original Line(s): # include $PREPROC_RULE_PATH/preprocessor.rules # include $PREPROC_RULE_PATH/decoder.rules # include $PREPROC_RULE_PATH/sensitive-data.rules Change to: include $PREPROC_RULE_PATH/preprocessor.rules include $PREPROC_RULE_PATH/decoder.rules include $PREPROC_RULE_PATH/sensitive-data.rules     Here are the changes for the PulledPork add-on   Original Line(s): include $PREPROC_RULE_PATH/preprocessor.rules include $PREPROC_RULE_PATH/decoder.rules include $PREPROC_RULE_PATH/sensitive-data.rules Change to: # include $PREPROC_RULE_PATH/preprocessor.rules # include $PREPROC_RULE_PATH/decoder.rules # include $PREPROC_RULE_PATH/sensitive-data.rules   After you made the changes are the three rule sets listed below actually located in the 'd:winidssnortrules' folder? preprocessor.rules decoder.rules sensitive-data.rules   As far as I know all the rules are supposed to be processed into the single .rules file (winids.rules). Something may have changed, or I'm not fully understanding how PulledPork works.   Let me query the group on this. I've never seen this problem before.
  14. Make SURE your OS is capable of running the .vbs file. Windows 8 should do this out of the box. In lieu of running the .vbs file; manually execute each command in the .vbs file for your OS, and the architecture used. Follow the tutorial. whatever your Windows OS media drive is, will be x   Windows 8.x / 2008 / 2012: The original OS media CD/DVD is now required to be inserted into the CD/DVD-Player.   In lieu of a Windows OS CD; if you have access to an ISO, or possibly the CD/DVD; just transfer the sourcessxs folder to wherever, and point x to that location. You could also just mount the ISO and point the x to that drive letter.
  15. It reads this registry key: HKLM > SOFTWARE > Microsoft > Windows NT > CurrentVersion Expects a value of 6.3 in the CurrentVersion value for all versions of Windows 8.x You are supposed to run the modder.vbs file from a CMD window that has Administrator privileges. Right-clicking the file, and "Run as Administrator", should also work?
  16. Appears the section labeled 'Configuring the existing Windows Intrusion Detection System (WinIDS)' had a problem. Open a CMD window and type 'type NUL > d:\winids\snort\rules\white_list.rules' (less the outside quotes), and tap the 'Enter' key. Now try the command again.
  17. All fixed. Seems they are having a problem with file extensions, again...
  18. It doesn't hurt to run the modder.vbs file for a second time. Not sure where the problem came from, but sounds like the modder.vbs file had a problem kicking the OS into Administrator mode prior to installing the  MS Visual C ++ redistributables.
  19. Not sure but it's not getting the MSV C++ installed correctly Did you run the modder.vbs file? Is this a fresh install of the operating system? Have you tried installing the MS Visual C ++ redistributable as 'Run as Administrator'?
  20. Looks like you are good to go with a sucessful configuration test.
  21. I just noticed:   Change this: d:winidssnortbinsnort -c d:winidssnortetcsnort.conf -l d:winidssnortlog –i1 -T   To this: d:winidssnortbinsnort -c d:winidssnortetcsnort.conf -l d:winidssnortlog -i1 -T
  22. I fixed the tutorial to be more informative for Windows 8.x. Internet Information Services installs on Windows 8.x exactly like Server 2012. 
  23. I'm not sure what you are getting at here.   According to the log files; the Windows Intrusion Detection System (WinIDS) has had one previous run that detected and logged two events (records).   The Windows Intrusion Detection System (WinIDS) has been ran again, and has detected one event (the data after the "Waiting for new data" shows data for one event)   At that point if Barnyard2 was stopped, you should be able to go into the Windows Intrusion Detection Systems (WinIDS) security console, and there should be a total of three events.   Restarting barnyard2, or rebooting, the barnyard2 terminal window should now show:   record_idx      = 3   Everything is normal...
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.