Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
OUTPUT Sun Aug 16 15:47:34 2015 [pid 4864] CONNECT: Client "172.28.5.129" Sun Aug 16 15:47:36 2015 [pid 4863] [ftpuser] FAIL LOGIN: Client "172.28.5.129" Sun Aug 16 15:47:49 2015 [pid 4868] CONNECT: Client "172.28.5.129" Sun Aug 16 15:47:50 2015 [pid 4867] [ftpuser] OK LOGIN: Client "172.28.5.129" Sun Aug 16 15:47:50 2015 [pid 4872] [ftpuser] OK UPLOAD: Client "172.28.5.129", "/index.php", 8099 bytes, 1176.26Kbyte/sec Sun Aug 16 15:48:02 2015 [pid 4832] [ftpuser] OK DELETE: Client "172.28.5.129", "/index.php" Sun Aug 16 16:26:06 2015 [pid 4976] [ftpuser] OK CHMOD: Client "172.28.5.129", "/index.php 777" Sun Aug 16 16:26:21 2015 [pid 4976] [ftpuser] OK RENAME: Client "172.28.5.129", "/index.php /4444index.php" **Phase 1: Completed pre-decoding. full event: 'Sun Aug 16 15:47:34 2015 [pid 4864] CONNECT: Client "172.28.5.129"' hostname: 'ossec-server' program_name: '(null)' log: 'Sun Aug 16 15:47:34 2015 [pid 4864] CONNECT: Client "172.28.5.129"' **Phase 2: Completed decoding. decoder: 'vsftpd' action: 'CONNECT' srcip: '172.28.5.129' **Phase 3: Completed filtering (rules). Rule id: '11401' Level: '3' Description: 'FTP session opened.' **Alert to be generated. **Phase 1: Completed pre-decoding. full event: 'Sun Aug 16 15:47:36 2015 [pid 4863] [ftpuser] FAIL LOGIN: Client "172.28.5.129"' hostname: 'ossec-server' program_name: '(null)' log: 'Sun Aug 16 15:47:36 2015 [pid 4863] [ftpuser] FAIL LOGIN: Client "172.28.5.129"' **Phase 2: Completed decoding. decoder: 'vsftpd' dstuser: 'ftpuser' status: 'FAIL LOGIN' srcip: '172.28.5.129' **Phase 3: Completed filtering (rules). Rule id: '11403' Level: '5' Description: 'Login failed accessing the FTP server.' **Alert to be generated. **Phase 1: Completed pre-decoding. full event: 'Sun Aug 16 15:47:49 2015 [pid 4868] CONNECT: Client "172.28.5.129"' hostname: 'ossec-server' program_name: '(null)' log: 'Sun Aug 16 15:47:49 2015 [pid 4868] CONNECT: Client "172.28.5.129"' **Phase 2: Completed decoding. decoder: 'vsftpd' action: 'CONNECT' srcip: '172.28.5.129' **Phase 3: Completed filtering (rules). Rule id: '11401' Level: '3' Description: 'FTP session opened.' **Alert to be generated. **Phase 1: Completed pre-decoding. full event: 'Sun Aug 16 15:47:50 2015 [pid 4867] [ftpuser] OK LOGIN: Client "172.28.5.129"' hostname: 'ossec-server' program_name: '(null)' log: 'Sun Aug 16 15:47:50 2015 [pid 4867] [ftpuser] OK LOGIN: Client "172.28.5.129"' **Phase 2: Completed decoding. decoder: 'vsftpd' dstuser: 'ftpuser' status: 'OK LOGIN' srcip: '172.28.5.129' **Phase 3: Completed filtering (rules). Rule id: '11402' Level: '3' Description: 'FTP Authentication success.' **Alert to be generated. **Phase 1: Completed pre-decoding. full event: 'Sun Aug 16 15:47:50 2015 [pid 4872] [ftpuser] OK UPLOAD: Client "172.28.5.129", "/index.php", 8099 bytes, 1176.26Kbyte/sec' hostname: 'ossec-server' program_name: '(null)' log: 'Sun Aug 16 15:47:50 2015 [pid 4872] [ftpuser] OK UPLOAD: Client "172.28.5.129", "/index.php", 8099 bytes, 1176.26Kbyte/sec' **Phase 2: Completed decoding. decoder: 'vsftpd' dstuser: 'ftpuser' status: 'OK UPLOAD' srcip: '172.28.5.129' url: '/index.php' **Phase 3: Completed filtering (rules). Rule id: '11404' Level: '0' Description: 'FTP server file upload.' **Phase 1: Completed pre-decoding. full event: 'Sun Aug 16 15:48:02 2015 [pid 4832] [ftpuser] OK DELETE: Client "172.28.5.129", "/index.php"' hostname: 'ossec-server' program_name: '(null)' log: 'Sun Aug 16 15:48:02 2015 [pid 4832] [ftpuser] OK DELETE: Client "172.28.5.129", "/index.php"' **Phase 2: Completed decoding. decoder: 'vsftpd' dstuser: 'ftpuser' status: 'OK DELETE' srcip: '172.28.5.129' url: '/index.php"' **Phase 1: Completed pre-decoding. full event: 'Sun Aug 16 16:26:06 2015 [pid 4976] [ftpuser] OK CHMOD: Client "172.28.5.129", "/index.php 777"' hostname: 'ossec-server' program_name: '(null)' log: 'Sun Aug 16 16:26:06 2015 [pid 4976] [ftpuser] OK CHMOD: Client "172.28.5.129", "/index.php 777"' **Phase 2: Completed decoding. decoder: 'vsftpd' dstuser: 'ftpuser' status: 'OK CHMOD' srcip: '172.28.5.129' url: '/index.php 777"' **Phase 1: Completed pre-decoding. full event: 'Sun Aug 16 16:26:21 2015 [pid 4976] [ftpuser] OK RENAME: Client "172.28.5.129", "/index.php /4444index.php"' hostname: 'ossec-server' program_name: '(null)' log: 'Sun Aug 16 16:26:21 2015 [pid 4976] [ftpuser] OK RENAME: Client "172.28.5.129", "/index.php /4444index.php"' **Phase 2: Completed decoding. decoder: 'vsftpd' dstuser: 'ftpuser' status: 'OK RENAME' srcip: '172.28.5.129' url: '/index.php /4444index.php"'
- Loading branch information