projects
/
ossec-hids.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
new upstream release (3.3.0); modify package compatibility for Stretch
[ossec-hids.git]
/
etc
/
rules
/
proftpd_rules.xml
diff --git
a/etc/rules/proftpd_rules.xml
b/etc/rules/proftpd_rules.xml
old mode 100755
(executable)
new mode 100644
(file)
index
56704e1
..
37189da
--- a/
etc/rules/proftpd_rules.xml
+++ b/
etc/rules/proftpd_rules.xml
@@
-1,4
+1,5
@@
-<!-- @(#) $Id$
+<!-- @(#) $Id: ./etc/rules/proftpd_rules.xml, 2011/09/08 dcid Exp $
+
- Official Proftpd rules for OSSEC.
-
- Copyright (C) 2009 Trend Micro Inc.
- Official Proftpd rules for OSSEC.
-
- Copyright (C) 2009 Trend Micro Inc.
@@
-157,9
+158,16
@@
<if_sid>11200</if_sid>
<match>error setting IPV6_V6ONLY: Protocol not available|</match>
<match> - mod_delay/|PAM(setcred): System error|</match>
<if_sid>11200</if_sid>
<match>error setting IPV6_V6ONLY: Protocol not available|</match>
<match> - mod_delay/|PAM(setcred): System error|</match>
- <match>PAM(close_session): System error</match>
+ <match>PAM(close_session): System error|cap_set_proc failed|reverting to normal operation|error retrieving information about user</match>
<description>IPv6 error and mod-delay info (ignored).</description>
</rule>
<description>IPv6 error and mod-delay info (ignored).</description>
</rule>
+
+ <rule id="11222" level="4">
+ <if_sid>11200</if_sid>
+ <match>unable to open incoming connection</match>
+ <description>Couldn't open the incoming connection. </description>
+ <description>Check log message for reason.</description>
+ </rule>
<rule id="11251" level="10" frequency="6" timeframe="120">
<if_matched_sid>11204</if_matched_sid>
<rule id="11251" level="10" frequency="6" timeframe="120">
<if_matched_sid>11204</if_matched_sid>