|
|

|
|
Home
|
|
Written by scott
|
|
Thursday, 10 April 2008 |
Whats new in ASL 2.0 Release Candidate 1 - Support for Fedora 8 and Fedora 9
- Added support for ClamAV, all content uploaded over the web will be scanned for malware automatically
- Added Malware Blacklist support
- Added support for creating vserver virtual servers
- Added ClamAV 0.92.2
- Added chkrootkit 0.48
- Added unhide 0.2
- Added enable/disable support for mod_evasive
- Added daily/weekly settings for web application inventory scanning
- Added disclaimer banner to ssh_checks
- Added capability to configure apache restart policy
- Added capability to define the frequency of rule updates
- Added support for monitoring OSSEC services in client mode
- Updated kernel to 2.6.24.2
- Updated rkhunter to 1.3.2
- Updated mod_security to 2.5.1
|
|
Bugfixes: - bugid #15, detect home dir permissions setting for admin users in Plesk environment
- bugid #16, added conditionals to detect the psmon config correctly on a new install
- bugid #17, rkhunter_check, formatting issues with root checks
- bugid #18, corrected update events to display when updates are available when called with -ck
- bugid #19, configuration_check, improved input validation on max_emails_per hour setting
- bugid #21, configuration_setup, lower bound of OSSEC's maximum alert e-mails per hour to one
- bugid #24, general_check, removed check for messagebus service
- bugid #26, ossec_check if e-mail notification is turned on, don't flag it as "failed"
- bugid #27, corrected issue with process monitoring detection
- bugid #28, removed web_check from ossec rules by default (blocked .cat domains)
- bugid #47, corrected selinux detection at install time
- bugid #50, improved detection on php.d settings
- bugid #67, ssh_checks are more descriptive on why they will not disable root logins
- bugid #74, kernel_check, fixed detection of the kernel for the disable_module check
Write Comment (0 Comments) |
|
|
Written by scott
|
|
Tuesday, 08 January 2008 |
Whats new in ASL 2.0 Beta 4: - Support for Plesk Server Administrator 8.3.0
- Improved web GUI
- New checks for End of Life operating systems
- PMSON updated to 1.39
- ASL command line utilites updated to 1.9.6
- Added notification configuration for OSSEC
- New Mod_security rule manager
- OSSEC updated to 1.4
- New vulnerability checks added for mod_evasive, grsecurity, and Plesk
|
|
Bugfixes: - mod_evasive checks now restart apache correctly
- watchdog module no longer overwrites the default crontab for psmon
- ASL updater now correctly downloads the rule updates
- ssh checks now detect root login conditions correctly
- watchdog no longer checks for non-existant services, pop-ssl and imap-ssl
- rkhunter and mod_evasive checks detect missing configuration files correctly
- removed slow audit dir permissions checks
and much much more! Write Comment (1 Comments) |
|
Last Updated ( Tuesday, 08 January 2008 )
|
|
|
Written by scott
|
|
Monday, 31 December 2007 |
|
This update adds in the Plesk 8.3.0 packages to the archive, and deprecates 8.2.x. Whats New with the archive: - Fedora Core 7 Plesk is now supported
- Layout now uses a symlink to /latest, currently pointed at 8.3.0
- Atomic Installer will prompt to add the Plesk repo to your yum config
- Index pages have been update
- 8.2.x packages have been deprecated and removed (low on space, I'm working on that!)
Write Comment (0 Comments) |
|
|
Written by scott
|
|
Thursday, 13 December 2007 |
|
And it is trouble. Breun and I have spent a considerable time working out issues with it, the major one for anyone out there who has had to deal with it already knows that it breaks Horde in Plesk. This is due to modifications to php_admin_value that once invoked cannot be changed. From what Ive determined so far this is entirely based on the context of the first virtual host to invoke it, making it extremely difficult to track down. I first noticed it when I could no longer log into Joomla, Bruen detected this when he could not modify the include path. Its entirely dependent on the setting being modified. The fix for now is to replace the use of php_admin_value with php_value. I have only tested this as far as the domains on this server. You will find this used all over the place in zz010_psa_httpd.conf, domain level httpd.includes, and most likely in your own customizations. The biggest problems Ive had are with register_globals and include_path, I have not run into any issues with PSA httpd.include files and open_basedir. If you do run into problems with other settings, or specific applications please let me know here, or post about it in the forums. Update: Plesk 8.3 is out, and at the very least Horde has been fixed by default. I haven't had a chance to try 8.3 yet, so I don't know if this solves any other issues. Write Comment (3 Comments) |
|
Last Updated ( Saturday, 22 December 2007 )
|
|
|
Written by scott
|
|
Wednesday, 21 November 2007 |
So if you've been following the RSS feed on the archive, there have been a lot of updates this week. PHP, mysql, dcc, etc. A lot of the time I'm updating previously authored packages, sometimes its a backport from something new, like Fedora 8. Other times I'm reviving some unmaintained thread from someone else. To illustrate my point, this caught my eye from the changelog on the qmhandle package today:
* Wed Nov 21 2007 Scott R. Shinn <
This e-mail address is being protected from spam bots, you need JavaScript enabled to view it
> - 1.3.2-1
- update to 1.3.2
- update 1.5 years later... you aren't kidding.
* Sun Apr 15 2006 Scott R. Shinn <
This e-mail address is being protected from spam bots, you need JavaScript enabled to view it
> 1.2.0-1.art
- update to 1.2.0
- 4 years later. RPM's stick around huh?
* Mon Apr 15 2002 Vincent Danen <
This e-mail address is being protected from spam bots, you need JavaScript enabled to view it
> 1.0.0-2rph
- rebuild for rpmhelp.net
* Mon Dec 17 2001 Oden Eriksson <
This e-mail address is being protected from spam bots, you need JavaScript enabled to view it
> 1.0.0-1mdk
- update to 1.0.0
- changed group
If this doesn't illustrate the point about re-use (Ahem... CPANEL!?) I don't know what does. I do not know you Mr. Danen, or Mr. Eriksson, but your code lives on.
Write Comment (0 Comments) |
|
|
Written by scott
|
|
Tuesday, 13 November 2007 |
I actually got into town last week, and it took me more than last week to catch up on your emails, trouble tickets, and general R&D that happened over 7 days. You'd be surprised at how much can change in a week. At any rate, I made a little maintenance utility for a problem I ran into with a client running some modifications by CPSkins.com. They've put together a pretty large suite of AppVault packages that are not managed by the RPM system. This causes problems when removing packages from the app vault using the sappmng utility. As a safety check this removes packages using the rpm system, if its not installed by an RPM this does the good-neighbor thing, and leaves it alone. The assumption is that whoever installed it has their own install utility. I couldn't find one so I just whipped this little util up to take care of the cleanup for you. You can read more about it here: Plesk_Application_Vault on the wiki at atomicorp.com.
Write Comment (0 Comments) |
|
Last Updated ( Tuesday, 13 November 2007 )
|
|
| | << Start < Prev 1 2 3 4 5 6 7 8 9 10 Next > End >>
| | Results 23 - 33 of 184 | |
|
|