Search found 278 matches

by Imaging
Tue Jul 02, 2019 12:54 pm
Forum: Atomic Protector (formerly ASL)
Topic: SACK
Replies: 7
Views: 19828

Re: SACK

What table in iptables is the mss rule added to? At present, after enabling, I'm not seeing a rule added (restarted the firewall, ran asl -s -f, rebooted the box etc., all the usuals JIC to make sure it was active).
by Imaging
Thu Jun 27, 2019 4:20 pm
Forum: Atomic Protector (formerly ASL)
Topic: SACK
Replies: 7
Views: 19828

Re: SACK

Thanks. The wiki could use an update as it has: === FW_MSS_DROP === Note: This option is available in ASL 4.x and up. This will detect and drop packets that have an invalid MSS. Default: no https://wiki.atomicorp.com/wiki/index.php/ASL_firewall#FW_MSS_DROP versus === FW_MSS_DROP === Note: This optio...
by Imaging
Tue Jun 25, 2019 3:56 pm
Forum: Atomic Protector (formerly ASL)
Topic: SACK
Replies: 7
Views: 19828

Re: SACK

Mike:

Thanks for the explanation. From what I recall the MSS setting defaults to no on a fresh ASL install so many may not have it enabled. Perhaps it should default to yes moving forward?
by Imaging
Thu Jun 20, 2019 12:56 pm
Forum: Atomic Protector (formerly ASL)
Topic: SACK
Replies: 7
Views: 19828

SACK

Are the SACK panic related vulnerabilities an issue with ASL kernels? If not, which versions are immune? If so, when is an update expected?

Thanks!
by Imaging
Fri Apr 19, 2019 2:48 pm
Forum: Atomic Protector (formerly ASL)
Topic: Machine learning features in ASL Question
Replies: 2
Views: 15900

Re: Machine learning features in ASL Question

Great, thanks for the clarification.
by Imaging
Tue Apr 16, 2019 3:27 pm
Forum: Atomic Protector (formerly ASL)
Topic: Machine learning features in ASL Question
Replies: 2
Views: 15900

Machine learning features in ASL Question

For the announcement post about the new machine learning features at: https://forums.atomicorp.com/viewtopic.php?f=8&t=8843 it notes: "You don't need to do anything to take advantage of this feature if you're an ASL or OSSEC customer, this new capability is enabled in these products automat...
by Imaging
Wed Mar 27, 2019 3:48 pm
Forum: Requests
Topic: ClamAV 0.101.2
Replies: 0
Views: 46557

ClamAV 0.101.2

FYI, ClamAV 0.101.2 is out:

https://blog.clamav.net/2019/03/clamav- ... -have.html

with security fixes.

Could you please update both the ASL and Atomic repo packages?

Thanks.
by Imaging
Tue Jan 08, 2019 1:56 pm
Forum: Requests
Topic: ClamAV 0.101.1
Replies: 0
Views: 45733

ClamAV 0.101.1

FYI, ClamAV 0.101.1 is out:

https://blog.clamav.net/2019/01/clamav- ... eased.html

The release appears to primarily be a patch/bug fix release.

Could you please update both the ASL and Atomic repo packages?

Thanks.
by Imaging
Tue Dec 04, 2018 1:48 pm
Forum: Requests
Topic: ClamAV 0.101.0
Replies: 0
Views: 46330

ClamAV 0.101.0

FYI, ClamAV 0.101.0 is out:

https://blog.clamav.net/2018/12/clamav- ... eased.html

The release appears to primarily be a bug fix/feature release.

Could you please update both the ASL and Atomic repo packages?

Thanks.
by Imaging
Sat Oct 06, 2018 7:46 am
Forum: Requests
Topic: ClamAV 0.100.2
Replies: 0
Views: 46185

ClamAV 0.100.2

FYI, ClamAV 0.100.2 is out:

https://blog.clamav.net/2018/10/clamav- ... eased.html

with both bug and security fixes.

Could you please update both the ASL and Atomic repo packages?

Thanks.
by Imaging
Tue Jul 24, 2018 2:53 pm
Forum: Atomic Protector (formerly ASL)
Topic: CloudFlare Client API
Replies: 5
Views: 17968

Re: CloudFlare Client API

Mike:

Thanks for the clarification. I'd previously thought that the mention of the IP limit at Cloudflare was due to the shunned IPs building up over time as they weren't being removed at Cloudflare (making it likely that the overall limit would be reached).
by Imaging
Sat Jul 21, 2018 3:22 pm
Forum: Atomic Protector (formerly ASL)
Topic: CloudFlare Client API
Replies: 5
Views: 17968

Re: CloudFlare Client API

Mike:

Has there been consideration for adding removal code as well? Perhaps a periodic function that would remove IPs that were X days old would help with the issue of the IP buildup over time?
by Imaging
Fri Jul 13, 2018 3:04 pm
Forum: Requests
Topic: ClamAV 0.100.1
Replies: 3
Views: 13422

Re: ClamAV 0.100.1

Thanks for getting the updates posted for both the ASL and atomic repos!
by Imaging
Thu Jul 12, 2018 1:45 pm
Forum: Requests
Topic: ClamAV 0.100.1
Replies: 3
Views: 13422

Re: ClamAV 0.100.1

Mike:

Thanks. Helpful to know for the boxes that run the ASL kernel (but would still be a concern for boxes that can't run the ASL kernel and for rules only boxes).
by Imaging
Tue Jul 10, 2018 12:31 pm
Forum: Requests
Topic: ClamAV 0.100.1
Replies: 3
Views: 13422

ClamAV 0.100.1

FYI, ClamAV 0.100.1 is out:

https://blog.clamav.net/2018/07/clamav- ... eased.html

with security fixes.

Could you please update both the ASL and Atomic repo packages?

Thanks.