Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

The rule when the user's login failed does not match in some cases #228

Open
bah07 opened this issue Nov 2, 2018 · 0 comments
Open

The rule when the user's login failed does not match in some cases #228

bah07 opened this issue Nov 2, 2018 · 0 comments
Labels
Projects

Comments

@bah07
Copy link
Contributor

bah07 commented Nov 2, 2018

When trying to establish an ssh connection to a machine the password can be failed up to 3 times. The log that appears for the 2nd and 3rd time is different from that of the first time.

pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=127.0.0.1
PAM 2 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=127.0.0.1

The match field for rule 5503 is authentication failure; logname= so it would only match the first event, discarding the following two. It is necessary for this rule to match both cases.

@bah07 bah07 added the bug label Nov 2, 2018
@bah07 bah07 added this to To do in Wazuh 3.7 via automation Nov 2, 2018
@Lopuiz Lopuiz self-assigned this Mar 11, 2019
@Lopuiz Lopuiz removed this from To do in Wazuh 3.7 Mar 11, 2019
@Lopuiz Lopuiz added this to To do in Wazuh 4.0.0 via automation Mar 11, 2019
@Lopuiz Lopuiz moved this from To do to In progress in Wazuh 4.0.0 Mar 11, 2019
@Lopuiz Lopuiz removed their assignment Mar 15, 2019
@albertomn86 albertomn86 moved this from In progress to To do in Wazuh 4.0.0 Mar 20, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
No open projects
Wazuh 4.0.0
  
To do
Development

No branches or pull requests

3 participants