Imported Upstream version 2.5.1
[ossec-hids.git] / etc / rules / vpopmail_rules.xml
1 <!-- @(#) $Id$
2   -  Official rules for vpopmail.
3   -
4   -  Author: Ceg Ryan <cegryan ( at ) gmail.com>
5   -  License: http://www.ossec.net/en/licensing.html
6   -->
7           
8
9 <group name="syslog,vpopmail,">
10   <rule id="9900" level="0">
11     <decoded_as>vpopmail</decoded_as>
12     <description>Grouping for the vpopmail rules.</description>
13   </rule>
14
15   <rule id="9901" level="5">
16     <if_sid>9900</if_sid>
17     <match> password fail </match>
18     <group>authentication_failed,</group>
19     <description>Login failed for vpopmail.</description>
20   </rule>
21
22   <rule id="9902" level="5">
23     <if_sid>9900</if_sid>
24     <match> vpopmail user not found </match>
25     <group>invalid_login,</group>
26     <description>Attempt to login to vpopmail with invalid username.</description>
27   </rule>
28
29   <rule id="9903" level="5">
30     <if_sid>9900</if_sid>
31     <match> null password given </match>
32     <group>authentication_failed,</group>
33     <description>Attempt to login to vpopmail with empty password.</description>
34   </rule>
35
36   <rule id="9904" level="1">
37     <if_sid>9900</if_sid>
38     <match> login success </match>
39     <group>authentication_success,</group>
40     <description>Vpopmail successful login.</description>
41   </rule>
42    
43
44   <rule id="9951" level="10" frequency="8" timeframe="240">
45     <if_matched_sid>9901</if_matched_sid>
46     <same_source_ip />
47     <description>Vpopmail brute force (multiple failed logins).</description>
48     <group>authentication_failures,</group>
49   </rule>
50
51   <rule id="9952" level="10" frequency="8" timeframe="240">
52     <if_matched_sid>9902</if_matched_sid>
53     <same_source_ip />
54     <description>Vpopmail brute force (email harvesting).</description>
55     <group>authentication_failures,</group>
56   </rule>
57
58   <rule id="9953" level="10" frequency="8" timeframe="240">
59     <if_matched_sid>9903</if_matched_sid>
60     <same_source_ip />
61     <description>VPOPMAIL brute force (empty password).</description>
62     <group>authentication_failures,</group>
63   </rule>
64      
65 </group>
66
67 <!-- EOF -->