Search found 278 matches

by Imaging
Wed Jul 04, 2018 12:42 pm
Forum: Requests
Topic: ClamAV 0.100.0
Replies: 1
Views: 12678

Re: ClamAV 0.100.0

Could the clamav updates be released for the atomic repo as well? The ASL repo updates appeared awhile back but still not seeing updates for our rules only boxes.

Thanks.
by Imaging
Wed May 30, 2018 12:16 pm
Forum: Atomic Protector (formerly ASL)
Topic: Spectre variants 3A and 4
Replies: 2
Views: 15562

Re: Spectre variants 3A and 4

Thanks!
by Imaging
Wed May 23, 2018 5:34 pm
Forum: Atomic Protector (formerly ASL)
Topic: Spectre variants 3A and 4
Replies: 2
Views: 15562

Spectre variants 3A and 4

For the recently disclosed spectre variants 3A and 4, are the current ASL protections in the kernel sufficient or will new mitigations need to be implemented due to the nature of the variants?

Thanks.
by Imaging
Tue Apr 17, 2018 5:54 pm
Forum: Security Alerts
Topic: Intel CPU flaw
Replies: 13
Views: 41889

Re: Intel CPU flaw

Thank you. Not sure if I'm reading you correctly but are you saying that 4.4.109 has all of the same mitigations as the 4.14.x releases?
by Imaging
Thu Apr 12, 2018 12:29 pm
Forum: Requests
Topic: ClamAV 0.100.0
Replies: 1
Views: 12678

ClamAV 0.100.0

FYI, ClamAV 0.100.0 is out (in regards to updates for the ASL and Atomic repo related packages):

https://blog.clamav.net/2018/04/clamav- ... eased.html

Thanks.
by Imaging
Thu Apr 12, 2018 12:27 pm
Forum: Security Alerts
Topic: Intel CPU flaw
Replies: 13
Views: 41889

Re: Intel CPU flaw

Just in case it wasn't seen, a bump of:

__

Mike:

Could you please post a current status as to what mitigations were introduced in what kernels (so those who don't update their kernel with each release will know the minimum needed updates)?

TIA!

__

Thanks!
by Imaging
Fri Mar 30, 2018 12:13 pm
Forum: Security Alerts
Topic: Intel CPU flaw
Replies: 13
Views: 41889

Re: Intel CPU flaw

Mike:

Could you please post a current status as to what mitigations were introduced in what kernels (so those who don't update their kernel with each release will know the minimum needed updates)?

TIA!
by Imaging
Fri Mar 16, 2018 2:35 pm
Forum: Atomic Protector (formerly ASL)
Topic: Not Compatible with R1Soft Backup
Replies: 6
Views: 20337

Re: Not Compatible with R1Soft Backup

It isn't the same type of software as R1Soft but we've been experimenting with:

https://www.borgbackup.org/

An example:

https://www.jamesthebard.net/backing-up-with-borg/
by Imaging
Wed Mar 07, 2018 10:51 am
Forum: Requests
Topic: ClamAV 0.99.4
Replies: 0
Views: 14284

ClamAV 0.99.4

FYI, ClamAV 0.99.4 with security fixes is out (in regards to updates for the ASL and Atomic repo related packages):

http://blog.clamav.net/2018/03/clamav-0 ... eased.html

Thanks.
by Imaging
Thu Mar 01, 2018 5:32 pm
Forum: OSSEC
Topic: [UPDATE] Constant /etc/asl/whitelist checksum alerts
Replies: 9
Views: 11460

Re: [UPDATE] Constant /etc/asl/whitelist checksum alerts

What's the current status of the next update?

Thanks.
by Imaging
Thu Feb 22, 2018 6:48 pm
Forum: OSSEC
Topic: [UPDATE] Constant /etc/asl/whitelist checksum alerts
Replies: 9
Views: 11460

Re: [UPDATE] Constant /etc/asl/whitelist checksum alerts

Just the one syscheckd process on the boxes I just checked.
by Imaging
Wed Feb 21, 2018 6:05 pm
Forum: Atomic Protector (formerly ASL)
Topic: Not Compatible with R1Soft Backup
Replies: 6
Views: 20337

Re: Not Compatible with R1Soft Backup

It will run but with a caveat - you need a custom module built for the ASL kernel. Their automated build system would always fail when we tried that way. We were then able to get it running when they manually built us a custom module for the ASL kernel we had in use. Unfortunately, it took quite som...
by Imaging
Tue Feb 20, 2018 5:32 pm
Forum: OSSEC
Topic: [UPDATE] Constant /etc/asl/whitelist checksum alerts
Replies: 9
Views: 11460

Re: [UPDATE] Constant /etc/asl/whitelist checksum alerts

Bump. Any update?

Thanks.
by Imaging
Thu Feb 08, 2018 11:34 am
Forum: OSSEC
Topic: [UPDATE] Constant /etc/asl/whitelist checksum alerts
Replies: 9
Views: 11460

Re: [UPDATE] Constant /etc/asl/whitelist checksum alerts

jgodwin: What's the ETA on the update to ossec to deal with the file not found messages? They can get quite voluminous. Any mitigations until the update is released (other than turning off alerts for rule 1002 which we wouldn't want to do since it is a rule that catches other potentially legitimate ...