Search found 22 matches

by jgodwin
Thu Jun 20, 2019 12:34 pm
Forum: Atomic OSSEC
Topic: which agent reported the event?
Replies: 4
Views: 20795

Re: which agent reported the event?

The QA build may be installed with the following command:

Code: Select all

yum -y --enablerepo=asl-4.0-testing upgrade asl
This update will be in the normal release channel on Monday.
by jgodwin
Mon Jan 29, 2018 6:17 pm
Forum: OSSEC
Topic: [UPDATE] Constant /etc/asl/whitelist checksum alerts
Replies: 9
Views: 11428

Re: [UPDATE] Constant /etc/asl/whitelist checksum alerts

They're actually distinct issues, and neither of them are cause for concern. The file/directory not found messages will be addressed in a future update to Ossec. For the events being generated for /etc/asl/whitelist, adding an ignore rule for this file in the file integrity settings is suggested. Th...
by jgodwin
Wed Nov 29, 2017 2:53 pm
Forum: Atomicorp Free Modsecurity Rules
Topic: Unable to update sec rules on CloudLinux 7.4
Replies: 2
Views: 9213

Re: Unable to update sec rules on CloudLinux 7.4

What are the contents of any of these files that you have present on your system:

/etc/centos-release
/etc/redhat-release
/etc/os-release
by jgodwin
Tue Jul 11, 2017 4:52 pm
Forum: Atomic Protector (formerly ASL)
Topic: PHP Fatal error during AUM update
Replies: 4
Views: 13041

Re: PHP Fatal error during AUM update

Does this still occur today running /var/asl/bin/aum -uf
by jgodwin
Thu Jun 22, 2017 1:06 pm
Forum: Atomic Protector (formerly ASL)
Topic: Empty cron messages
Replies: 6
Views: 14007

Re: Empty cron messages

A fix for this will be in an update Monday. The emails may be ignored, there's just something in the cron outputting a blank line.
by jgodwin
Wed May 04, 2016 3:03 pm
Forum: Atomic Protector (formerly ASL)
Topic: IP address not clickable if 'flame' icon present
Replies: 1
Views: 3482

Re: IP address not clickable if 'flame' icon present

A fix for this will be available in our next release.
by jgodwin
Wed Sep 02, 2015 5:45 pm
Forum: Atomic Protector (formerly ASL)
Topic: ossec.conf scan time
Replies: 2
Views: 4288

Re: ossec.conf scan time

You may set this in ASL Web in the options tab of the File Integrity window.

Files in /var/asl/data should not be manipulated.
by jgodwin
Mon Aug 17, 2015 11:33 am
Forum: Atomicorp Announcements
Topic: Atomic Secured Linux™ 4.0.14 (Johnny Cab)
Replies: 0
Views: 7576

Atomic Secured Linux™ 4.0.14 (Johnny Cab)

Atomic Secured Linux™ 4.0.14 (Johnny Cab) now available! Release Notes This is a maintenance update to ASL 4.0.14 Changelog - Enhanced IPS reporting for CVE-2015-5477 - Bugfix #1873 - Adds SSLProxyEngine setting to twaf when end point is https - Bugfix #1872 - changing tlsserverciphers and tlsclient...
by jgodwin
Sat Aug 01, 2015 6:05 pm
Forum: Atomicorp Modsecurity Rules Support
Topic: license via plesk billing
Replies: 4
Views: 11214

Re: license via plesk billing

There shouldn't be any action required. Upgrading via their store should result in an updated license for you, which AUM would notice the next time it was run.
by jgodwin
Mon Jul 20, 2015 1:00 pm
Forum: Atomicorp Announcements
Topic: Atomic Secured Linux™ 4.0.13 (Maximilian)
Replies: 0
Views: 7460

Atomic Secured Linux™ 4.0.13 (Maximilian)

Release Notes This is a mainteance update to ASL 4.0.13 Changelog - Added ip_set_hash_ip to forced module load - Updated low level portscan detection to automatically exclude localhost - Modified syn scan engine to ignore half open requests on loopback - Updated ASL to support new fuzzy malware det...
by jgodwin
Fri Mar 20, 2015 1:30 pm
Forum: Atomic Protector (formerly ASL)
Topic: Tortix never stops hammering my database
Replies: 4
Views: 6017

Re: Tortix never stops hammering my database

Don't see anything odd in the my.cnf, and 70m isn't much for mysql to be dealing with. The alert and aslw_archive_tmp tables are cleaned automatically and don't have much in them, 3 days and the current calendar month respectively. Is this load constant or only happens when you try to load ASL Web? ...
by jgodwin
Thu Jan 29, 2015 3:12 pm
Forum: Atomic Protector (formerly ASL)
Topic: High mysql load on a high traffic server
Replies: 7
Views: 8198

Re: High mysql load on a high traffic server

Couple of questions:

What does your mysql config look like?
What does your system load look like when no ASL Web is open?
by jgodwin
Sat Jun 28, 2014 12:13 pm
Forum: Atomic Protector (formerly ASL)
Topic: ASL 4 web interface issues
Replies: 9
Views: 10758

Re: ASL 4 web interface issues

If it is not corrected by running ' /var/asl/bin/aum -uf ', please open a case in the support portal.

The issue will be with the creation of triggers in the database, but cause and solution can vary.
by jgodwin
Tue Jun 24, 2014 10:52 am
Forum: Atomic Protector (formerly ASL)
Topic: ASL Web Interface menu is messed up
Replies: 1
Views: 4142

Re: ASL Web Interface menu is messed up

Ah, thats happening because some browsers dont expand your custom reports name in the menu. Corrected css will be in our next update.

For now, just make the report names shorter if you are using an effected browser. Chrome seems to have this issue.
by jgodwin
Wed Jun 04, 2014 1:08 pm
Forum: Atomic Protector (formerly ASL)
Topic: ASL 4.0.2 - Invalid configuration values detected
Replies: 2
Views: 4718

Re: ASL 4.0.2 - Invalid configuration values detected

UPDATE_TYPE needs to be set to one of the listed allowed values. Disabling should be done by setting AUTOMATIC_UPDATES to "none" CLAMAV_LogFileMaxSize - fix for this erroring when set to its default value has been committed and will be in our next release CLAMAV_MaxFileSize - case matters,...