X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?a=blobdiff_plain;ds=sidebyside;f=etc%2Frules%2Fdropbear_rules.xml;fp=etc%2Frules%2Fdropbear_rules.xml;h=8609234b15982c7b705b877e368b14cab13a2f3e;hb=ff0e686ac67bbd82b60c277eb324910dbc60f65f;hp=0000000000000000000000000000000000000000;hpb=33a81e69474ae91ecec4e991debe59e26bb330fd;p=ossec-hids.git diff --git a/etc/rules/dropbear_rules.xml b/etc/rules/dropbear_rules.xml new file mode 100755 index 0000000..8609234 --- /dev/null +++ b/etc/rules/dropbear_rules.xml @@ -0,0 +1,86 @@ + + + + + + + + + + dropbear + Grouping for dropbear rules. + + + + 51000 + Failed to get kex value + Failed to get key exchange value + + + + 51000 + Premature kexdh_init message received + Premature kexdh_init message + + + + 51000 + bad password attempt for + Bad password attempt. + authentication_failed, + + + + 51003 + + dropbear brute force attempt. + authentication_failures, + + + + 51000 + exit after auth \(\S+\): Disconnect received + User disconnected. + + + + 51000 + exit before auth + Client exited before authentication. + recon, + + + + 51000 + + dropbear brute force attempt. + authentication_failures, + + + + + 51000 + Incompatible remote version + Incompatible remote version. + recon, + + + + 51000 + password auth succeeded for + User successfully logged in using a password. + authentication_success, + + + + + + +