prelude-lml: Changes to 'refs/tags/prelude-lml-0.9.15'

[email protected] Thu, 16 Jul 2009 15:42:50 +0200 (CEST)
Newsgroups gmane.comp.security.ids.prelude.cvs
Message-ID <[email protected]>
Tag 'prelude-lml-0.9.15' created by Yoann Vandoorselaere <[email protected]> at 2009-07-16 14:44 +0200

0.9.15
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEABECAAYFAkpfLsUACgkQD4LqTXjyBR/zTQCfUxvls4cZfsWp+SLAwGrQVlP6
/jkAn2yoyFfPaYIMwE2PxW2MhOFw1yo8
=uaJy
-----END PGP SIGNATURE-----

Changes since the dawn of time:
Baptiste Malguy (1):
      * src/*-plugins.c (*_plugins_init):

Chia-liang Kao (1):
      update libmissing

Gene Ramon Gomez (156):
      *** empty log message ***
      2004-01-16  Yoann Vandoorselaere  <[email protected]>
      *** empty log message ***
      *** empty log message ***
      * plugins/simple/ruleset/cisco-pix.rules:
      * plugins/simple/ruleset/vigor.rules:
      * plugins/simple/ruleset
      * plugins/simple/ruleset/cisco-pix.rules:
      * plugins/simple/ruleset:
      * plugins/simple/ruleset:
      *** empty log message ***
      * plugins/simples/ruleset/simple.rules:
      * plugins/simples/ruleset/simple.rules:
      * plugins/simple/ruleset/simple.rules:
      * plugins/simple/ruleset/single
      * plugins/simple/ruleset/cisco-pix.rules:
      * plugins/simple/ruleset/ssh.rules:
      * plugins/simple/ruleset/cisco-pix.rules:
      * plugins/simple/ruleset/simple.rules:
      * simple/plugins/ruleset/apc-emu.rules:
      * simple/plugins/ruleset/single.rules:
      * simple/plugins/ruleset/cisco-pix.rules:
      * plugins/simple/ruleset/apc-emu.rules:
      * plugins/simple/ruleset/simple.rules:
      * plugins/simple/ruleset/single.rules:
      * simple/plugins/ruleset/Makefile.am:
      * simple/plugins/ruleset/Makefile.am:
      * simple/plugins/ruleset/navce.rules:
      * simple/plugins/ruleset/Makefile.am:
      * simple/plugins/ruleset/portsentry.rules:
      * simple/plugins/ruleset/modsecurity.rules:
      * plugins/simple/ruleset/unsupported/zyxel.rules:
      * plugins/simple/ruleset/simple.rules:
      * plugins/simple/ruleset/checkpoint.rules:
      * plugins/simple/ruleset (multiple):
      * plugins/simple/ruleset/unsupported/cisco.rules:
      * plugins/simple/ruleset/cisco.rules:
      * plugins/simple/ruleset/postfix.rules:
      * plugins/simple/ruleset/bigip.rules:
      * plugins/simple/ruleset/contrib:
      * plugins/simple/ruleset/bigip.rules:
      * plugins/simple/ruleset/modsecurity.rules:
      * plugins/simple/ruleset:
      * plugins/simple/ruleset/sendmail.rules:
      * plugins/simple/ruleset/sendmail.rules:
      * plugins/simple/ruleset/:
      * plugins/simple/ruleset/sendmail.rules:
      * plugins/simple/ruleset/unsupported/netfilter.rules:
      * plugins/simple/ruleset/dell-om.rules
      * plugins/simple/ruleset/simple.rules
      * plugins/simple/ruleset/sendmail.rules:
      * plugins/simple/ruleset/simple.rules:
      * plugins/pcre/ruleset/netapp-ontap.rules
      * plugins/pcre/ruleset:
      * plugins/pcre/ruleset/dell-om.rules:
      * plugins/pcre/ruleset/netapp-ontap.rules:
      * plugins/pcre/ruleset/netapp-ontap.rules:
      * plugins/pcre/ruleset/netapp-ontap.rules:
      * plugins/pcre/ruleset/ntsyslog.rules:
      * plugins/pcre/ruleset/ssh.rules:
      * plugins/pcre/ruleset/cisco-pix.rules:
      * src/plugins/pcre/ruleset/bigip.rules:
      git-svn-id: file:///home/yoann/dev/prelude/git/nok/SVN/trunk/prelude-lml@6045 09c5ec92-17d4-0310-903a-819935f44dba
      * src/plugins/pcre/ruleset/pam.rules:
      * src/plugins/pcre/ruleset/simple.rules
      * src/plugins/pcre/ruleset/shadow-utils.rules
      * src/plugins/pcre/ruleset/single.rules
      * plugins/pcre/ruleset/grsecurity.rules
      * plugins/pcre/ruleset/grsecurity.rules
      * plugins/pcre/ruleset/sudo.rules
      * plugins/pcre/ruleset/single.rules:
      * plugins/pcre/ruleset/simple.rules:
      * plugins/pcre/ruleset/single.rules:
      * plugins/pcre/ruleset/wap11.rules:
      * plugins/pcre/ruleset/selinux.rules:
      * plugins/pcre/ruleset/single.rules:
      * plugins/pcre/ruleset/simple.rules:
      Replaced simple with pcre, reverted apc-emu and f5-bigip to pre-chained versions,
      Fixed typo in pcre.rules (pix regex), added NetBIOS address parsing to
      Audited NTSyslog ruleset for consistency.  More changes to come.
      Introduced corrected IPv6 support (previous method set all address types to
      Added implied tcp/udp as was appropriate.  Added httpd support.
      s/Prelude/Prelude-LML in f5-bigip.rules, added one httpd rule, so spun httpd.rules out of single.rules
      Fixed bad httpd and modsecurity interaction.
      Changed PaX class from Kernel to Memory Violation
      Exa(protect|probe) supported rules marked as unsupported
      Made contact information more correct; added additional httpd rules;
      Added httpd regex explanation, because I know the question is going to be
      Added systrace, identd, arpwatch support
      oops
      Added catch of IP address to 1901.
      Bug in 408; was assigning user name into user number.
      Added version information and corrected MAC address regex for arpwatch;
      Fixed broken regex (log sample was incorrect in one case), improved other
      Explicit manufacturer names not needed in analyzer.name field
      Marked rulesets as unmaintained.
      updated maintainance information
      Removed end-of-line anchor for some systems that may log different (thanks
      * Updated SELinux ruleset maintainer information
      * Transitioned postfix back to supported status.
      Started work to add --enabled-unsupported-rulesets to configure
      Added support for pure-ftpd; added device classification information to
      Various ruleset corrections based on additional LML debug information.
      git-svn-id: file:///home/yoann/dev/prelude/git/nok/SVN/trunk/prelude-lml@6380 09c5ec92-17d4-0310-903a-819935f44dba
      Fixed 1700
      Ruleset auditing corrections/updates
      Added preliminary support for PIX conduits
      Removed silly check for existance *or* non-existance of ssh2 at the end of all
      Fixed 1912, committed arbor.rules first-run.
      Made arbor.rules part of the default install.
      Ruleset clean-up...replaced '.' with '\;' for field parsing.  Thanks go to
      Consistency updates; log messages for services being turned off are now all
      Added Netscreen support (thanks go to tilaris at wanadoo dor fr)
      Ruleset audit; standardized service.iana_protocol_name,
      Updated p3scan rule (id 405) for newer version log format.
      Forgot to increment the revision.
      Added 1914 and 1915 for suse-specific log format (PAM2?)
      Added analyzer().name and analyzer().manufacturer to linksys-wap11.rules.
      Fixed bad mssql chain regex (from the samples, mssqlserver looks correct, but
      Made change to clamav chaining regex to handle events in clamav logging format
      Introduced support for openhostapd (thanks go to [email protected]).
      forgot to increment revision fields.
      Further additional_data work.
      additional_data stuff
      A couple more additional_data updates...
      Abstracted Squid chain regex to allow parsing of data directly from Squid log files.
      A few parsing corrections; lots of additional_data work
      Corrections, extensions, etc.  Ruleset audit!
      Marked selinux rules as experimental (I need to put some work into them now
      Added sonicwall.rules (thanks go to Igor M. <imanassypov at
      Add Router IDS module support.
      Prep for upgrade from cisco-pix.rules to cisco-asa.rules.
      Rename Cisco PIX rules to ASA to reflect new device name.
      Continue PIX -> PIX+ASA rules upgrade
      More ASA stuff
      Ruleset was using a portion of the syslog header for matching; corrected.
      Fix reference to non-existant variable
      First sweep ruleset audit
      Move checkpoint.rules back into supported status
      Clean up checkpoint.rules stuff, start implementing Cisco CSS support
      Some abstraction work for correlation, improvement of CSS rules
      Fix format problem with Apache logs from western hemisphere (- versus + TZ)
      Update honeyd rules
      Fix chain regex for more recent honeyd logging
      Introduced Cacti thold plugin support.
      Greatly simplify ruleset documentation (direct reader to the IDMEF draft).
      Continued NTSyslog audit
      Implement Microsoft Cluster Service support
      Add assessment.impact.completion field to 1408
      Updated NAVCE rules; modified ClamAV rules for consistency.
      Added rule to ignore LML's "could not match prefix" log entries.
      Cisco ASA IPS module support
      Update Cisco IPS reference URL to official Cisco site.
      Fix 302 (wrong field used in description of event)
      Committed Cisco ruleset (by Alexandre Racine)
      Removed false dependancy on severity in pattern matching (thanks go to

Guillaume Pelat (4):
      * src/file-server.c (logfile_alert): fix unterminated string.
      * src/file-server.c (logfile_alert):
      * src/file-server.c (check_modification_time):
      2002-08-24  Guillaume Pelat  <[email protected]>

Krzysztof Zaraska (14):
      freebsd compat. fix
      include <inttypes.h> instead of <stdint.h>
      FreeBSD compat. fix
      FreeBSD compat. fix
      Rules for FreeBSD IPFW
      *** empty log message ***
      use clearerr_unlocked() after hitting feof() on file
      *** empty log message ***
      added ICMP. cleanup.
      *** empty log message ***
      * plugins/simple/ruleset/ipfw.rules: updated to use new SimpleMod
      include <sys/time.h> so it builds on FreeBSD
      plugins/simple/ruleset/simple.rules: fix typo
      * plugins/simple/ruleset/Makefile.am:

Laurent Oudot (9):
      2002-04-26  Laurent Oudot  <[email protected]>
      2002-04-27  Laurent Oudot  <[email protected]>
      2002-04-27  Laurent Oudot  <[email protected]>
      *** empty log message ***
      2002-04-28  Laurent Oudot <[email protected]>
      2002-05-30  Laurent Oudot  <[email protected]>
      *** empty log message ***
      *** empty log message ***
      *** empty log message ***

Nicolas Delon (6):
      * plugins/simple/ruleset/*.rules:
      * src/lml-alert.c:
      * plugins/simple/simple.c:
      fix bad path for configuration file includes
      bug fix: compatibility with IPv6 addresses
      fit additional data API improvements

Pierre Chifflier (8):
      Fix a few typos, and use the same type or end-of-lines (do not use
      Add new ruleset for Honeytrap (Closes #244)
      Fix regex 1403 in ntsyslog, so it matches the provided example log.
      Add new ruleset for Kojoney honeypot (Closes #245).
      Add new ruleset to ignore cron jobs (Closes #266)
      Cron rules:
      Add new ruleset for Rishi (Closes #246)
      Remove dos-style end-of-lines (Closes #338)

Rob Holand (29):
      whitespace fix
      un(used/tested/supported/wanted)
      abandoned
      whitespace police
      appease gcc
      missing include
      allow users to ignore metadata to benchmark and/or test rules
      change option code to use a struct. makes code cleaner. 'sync' against prelude-manager option parsing code
      typedef for config struct
      rename config file define to be inline with prelude-manager
      rename pconfig.* to lml-options.*
      main.c -> prelude-lml.c
      pconfig_init -> lml_options_init()
      log_container_t -> log_entry_t, and log -> log_entry where relevant
      more log -> log_entry to aid readability
      move to using a regex format for syslog prefix parsing. this means more flexibility and support for optional matching of pids, which wasn't possible before
      fix pid in alerts
      make program non-greedy so pid matches properly
      sorry, this is what I meant to commit
      rename program -> process to be consistant with idmef
      fix the ordering
      add log_entry->message as a moving target to allow for optimisation patches to come later. rename log_entry->log to log_entry->original_log to aid readability
      fix some spacing in sample log entries
      fix missing prefix
      fixup target interface regex and remove source regex. We can't know whether the packet was locally generated or not
      r7@leet:  rob | 2005-02-11 16:18:05 +0000
      r11@leet:  rob | 2005-02-11 16:30:58 +0000
      r367@leet:  rob | 2005-02-11 16:57:21 +0000
      r371@leet:  rob | 2005-02-11 17:08:35 +0000

Sebastien Tricaud (11):
      Fixes a typo error
      (feature): Asterisk log format and new ruleset for SIP REGISTER method
      (ruleset): new ruleset for asterisk
      (bugfix): asterisk ruleset parser fix
      (bugfix): Add 'LOG:' prefix
      add suhosin rulesets
      Append suhosin.rules into makefile, added ruleset id and manufacturer
      Add offset information when a regex compile fails
      Change the Cisco ASA urls to the new location
      Add Cisco ASA rule to handle discarded tcp or udp packets.
      Point alert message vendor description to the right url.

Stephane Loeuillet (7):
      *** empty log message ***
      *** empty log message ***
      *** empty log message ***
      *** empty log message ***
      *** empty log message ***
      *** empty log message ***
      forgot a back-slash at end of line of a rule. fixed

Yoann Vandoorselaere (585):
      * AUTHORS:
      * src/file-server.c:
      * src/regex.c:
      * src/udp-server.c (udp_server_new):
      * src/file-server.c (file_server_monitor_file):
      *** empty log message ***
      * plugins/simple/simple.c:
      *** empty log message ***
      * plugins/pax/pax.c (pax_log_processing):
      * src/lml-alert.c (lml_emit_alert):
      *** empty log message ***
      * prelude-lml.conf.in (file):
      * src/server-logic.c (server_logic_process_requests):
      * src/main.c (lml_dispatch_log):
      *** empty log message ***
      * plugins/simple/simple.c (parse_impact_desc):
      * src/file-server.c (file_server_monitor_file):
      * plugins.rules.in: comment the Debug plugin entry
      * src/udp-server.c: make the size of our buffer
      * src/pconfig.c (set_file): now that we do not
      * src/log-common.c (format_syslog_header):
      *** empty log message ***
      *** empty log message ***
      * src/udp-server.c (udp_server_standalone):
      * src/file-server.c (file_server_wake_up):
      * Makefile.am (install-data-local):
      * plugins/simple/simple.c: try to do time consuming stuff
      *** empty log message ***
      *** empty log message ***
      * src/file-server.c (read_logfile):
      * src/log-common.c (format_syslog_header):
      *** empty log message ***
      * plugins/simple/simple.c (parse_ruleset):
      * src/file-server.c (file_server_monitor_file):
      *** empty log message ***
      *** empty log message ***
      * plugins/simple/simple.c:
      * src/log-plugins.c (subscribe):
      * src/file-server.c (read_logfile):
      *** empty log message ***
      *** empty log message ***
      * plugins/simple/ruleset/netfilter.rules:
      *** empty log message ***
      * plugins/simple/simple.c: included patch from
      * src/include/Makefile.am (include_HEADERS):
      2002-05-21  Yoann Vandoorselaere  <[email protected]>
      *** empty log message ***
      2002-05-27  Yoann Vandoorselaere  <[email protected]>
      2002-05-30  Yoann Vandoorselaere  <[email protected]>
      2002-05-30  Yoann Vandoorselaere  <[email protected]>
      2002-05-31  Yoann Vandoorselaere  <[email protected]>
      *** empty log message ***
      2002-06-03  Yoann Vandoorselaere  <[email protected]>
      *** empty log message ***
      *** empty log message ***
      2002-06-06  Yoann Vandoorselaere  <[email protected]>
      *** empty log message ***
      *** empty log message ***
      *** empty log message ***
      *** empty log message ***
      *** empty log message ***
      *** empty log message ***
      *** empty log message ***
      2002-07-29  Yoann Vandoorselaere  <[email protected]>
      * src/regex.c (trim):
      2002-07-30  Yoann Vandoorselaere  <[email protected]>
      2002-08-20  Yoann Vandoorselaere  <[email protected]>
      *** empty log message ***
      *** empty log message ***
      *** empty log message ***
      *** empty log message ***
      *** empty log message ***
      *** empty log message ***
      *** empty log message ***
      2002-10-13  Yoann Vandoorselaere  <[email protected]>
      *** empty log message ***
      2002-10-26  Yoann Vandoorselaere  <[email protected]>
      2002-10-28  Yoann Vandoorselaere  <[email protected]>
      2002-11-06  Yoann Vandoorselaere  <[email protected]>
      2002-11-12  Yoann Vandoorselaere  <[email protected]>
      *** empty log message ***
      2002-12-05  Yoann Vandoorselaere  <[email protected]>
      2002-12-09  Yoann Vandoorselaere  <[email protected]>
      *** empty log message ***
      *** empty log message ***
      *** empty log message ***
      *** empty log message ***
      *** empty log message ***
      *** empty log message ***
      Updated my mail address.
      *** empty log message ***
      *** empty log message ***
      Merge back from 0-8 to HEAD
      Backport from 0-8 to HEAD
      *** empty log message ***
      * Merge from 0-8.
      * plugins/simple/simple.c:
      commit missing, recently added rulesets.
      * plugins/simple/simple.c (parse_rule_object_value):
      * src/file-server.c (file_server_wake_up):
      *** empty log message ***
      *** empty log message ***
      * src/lml-alert.c (generate_target):
      * plugins.rules.in: remove paxmod. Obsoleted.
      * src/log-common.c
      test
      Someone who want to sponsor the Prelude project please send me a new coffee
      * src/lml-alert.c (generate_target):
      * plugins/simple/ruleset/grsecurity.rules:
      updated
      * plugins/simple/ruleset/simple.rules (regex):
      * plugins/simple/simple.c:
      * plugins/simple/simple.c:
      * plugins/simple/ruleset/simple.rules (regex):
      * src/udp-server.c (udp_server_new): verbose message
      (udp_server_process_event, udp_server_new): embed
      * src/udp-server.c (udp_server_process_event):
      *** empty log message ***
      (udp_server_process_event): remove trailling syslog
      * src/file-server.c:
      * src/lml-alert.c (generate_target):
      Fit libprelude IDMEF API change.
      Add a space after the %tprog assignement on the syslog line,
      Merge back plugins-instances change into trunk
      port to new prelude-list.h API
      * log-plugins.c
      * regex.c
      Rework udp-srvr option
      Fix warnings.
      fit latest libprelude API change
      Call lml_alert_init() before prelude_client_init(), so that first heartbeat
      Fit latest libprelude API change
      Some more wide available option.
      Allow version retrieval from admin console.
      FUll admin console support for the syslog UDP server.
      Implemented log_source_destroy(), which is needed for the syslog
      Fix leak on syslog listener destroy.
      Fix valgrind leak false positive by moving the list member to the top of the structure. The way the list implementation work make valgrind think the object is lost, when we still have a reference to this object through the offset + address of one of it's member.
      Fix problem when using FAM notification, where we could lose track of a file
      Cleanup.
      Remove debugging stuff.
      Change the prelude_plugin_init function name to support
      Build plugins first since the core depend on them in case of dlpreopening.
      Activate dlpreopening support.
      Call AC_LIBTOOL_DLOPEN()
      Use socklen_t if available. Fix a warning.
      Fix format string when printing 64 bits integer on 64 bit system.
      s/inttypes.h/prelude-inttypes.h/ everywhere, for portability.
      Include <sys/time.h>, fix compilation problem on certain arch.
      Use scanf() in combination with SVNu64 macro, instead of strtoull,
      Oops. s/scanf/sscanf/
      cast isspace() and such, value to int.
      Avoid possible MAX() redefinition.
      Add missing variable, strict error checking.
      More portability work, cleanup.
      Link to libmissing.
      sync my tree...
      commit missing files.
      Use @LIBPRELUDE_LDFLAGS@ to link prelude-lml. Fix configure.in to use AM_PATH_LIBPRELUDE().
      Remove obsolete.
      Slight formating fix.
      Include AC_PATH_GENERIC from the autoconf macro archive.
      Increase version number to 0.9.0-svn. Check for libprelude-0.9.0.
      Propagate libprelude.m4 changes.
      Fix version.
      Update gnulib code.
      Fix missing include.
      Add missing header file.
      Use idmef_object_set() in place of deprecated idmef_message_set().
      Stop including idmef-tree.h, it is deprecated.
      Make --disable-fam work again.
      Add missing libtool.m4.
      call prelude_client_destroy() in case we're running in batch mode
      Fit change to prelude_client_destroy().
      Update libprelude.m4
      Make filename '-' treated as stding.
      Rename the 'Simple' plugin to 'Pcre'. Implement goto, optgoto, min-opt-goto,
      git-svn-id: file:///home/yoann/dev/prelude/git/nok/SVN/trunk/prelude-lml@4284 09c5ec92-17d4-0310-903a-819935f44dba
      Commit missing stuff.
      Try to improve FAM check.
      Fit IDMEF message write API change.
      Use prelude-string instead of idmef-string.
      Provide a --enable-fam argument.
      Remove unused. Call try_reopening_inactive_monitor() in
      prelude_client_init() now take a pointer to argc.
      Update libprelude.m4, include only idmef-client.conf,
      Merge idmef-v12-work change back in trunk.
      Fit latest libprelude API fix.
      constness fix.
      Remove deprecated headers inclusion.
      Use prelude_client_is_setup_needed() to check the prelude_client_init()
      Use prelude_client_send_idmef().
      Fix for libprelude API change.
      Use a local root option list.
      Fix leak of resolved backward reference.
      Provide the ability for the caller to setup it's own analyzer, which will
      Include the targeted interface into the alert.
      Update gnulib code. Include getaddrinfo() workaround.
      git-svn-id: file:///home/yoann/dev/prelude/git/nok/SVN/trunk/prelude-lml@4705 09c5ec92-17d4-0310-903a-819935f44dba
      Include getaddrinfo.h
      If aggregated analyzer node/process are not defined, try to define
      git-svn-id: file:///home/yoann/dev/prelude/git/nok/SVN/trunk/prelude-lml@4708 09c5ec92-17d4-0310-903a-819935f44dba
      Remove deprecated.
      Remove deprecated.
      r4703@arwen:  yoann | 2005-01-06T10:32:01.752813Z
      Fit libprelude prelude_init() change. Add --dry-run (don't connect/send anything to prelude),
      Arrange so that --dry-run doesn't require the analyzer to be registered.
      Don't call prelude_client_destroy() in batch mode if dry-run is set.
      Remove strlen() call for log_entry all over the code. Some of them were called one
      Fix backward reference numbering. Use IDMEF address rather than IDMEF user.
      s/optionnal/optional/
      Oops. s/log/message/
      s/->log/->message/
      Don't crash if alert is not set within the provided IDMEF message.
      Don't construct and IDMEF message if object list is empty. We'll do it as soon
      Fix qpopper regex.
      Add missing log entry for regression testing.
      More work on LML log sample.
      More rule example log.
      More log message work...
      More work on grsecurity LOG sample.
      Fix missing ';'
      git-svn-id: file:///home/yoann/dev/prelude/git/nok/SVN/trunk/prelude-lml@4878 09c5ec92-17d4-0310-903a-819935f44dba
      Fix some log entry.
      One more log.
      Fix goto ID when creating from range.
      Log sample for WAP11.
      Don't increase the 'required' field when getting a required regex. This is only
      Don't use the process name for the match. Cleanup so that it use
      Variation in SSHD 'Invalid user' log message.
      Ooops.
      Fixup copyright notice.
      Add missing copyright notices.
      remove deprecated header file.
      Missing copyright notice.
      r4934@arwen (orig r4982):  yoann | 2005-01-30 20:55:09 +0100
      git-svn-id: file:///home/yoann/dev/prelude/git/nok/SVN/trunk/prelude-lml@5230 09c5ec92-17d4-0310-903a-819935f44dba
      r4985@arwen (orig r5033):  yoann | 2005-02-07 13:28:30 +0100
      r5065@arwen (orig r5113):  yoann | 2005-02-14 17:12:40 +0100
      git-svn-id: file:///home/yoann/dev/prelude/git/nok/SVN/trunk/prelude-lml@5233 09c5ec92-17d4-0310-903a-819935f44dba
      git-svn-id: file:///home/yoann/dev/prelude/git/nok/SVN/trunk/prelude-lml@5234 09c5ec92-17d4-0310-903a-819935f44dba
      r7698@arwen (orig r5227):  yoann | 2005-02-18 13:02:54 +0100
      r7699@arwen (orig r5228):  yoann | 2005-02-18 13:12:31 +0100
      Fix missing.
      Add -D (--debug) option. Debug message can now be seen by setting the -D option
      Use prelude_log_set_debug_level().
      Fix invalid free, and a memory leak when destroying an instance of the plugin.
      No idea why an analyzer was ever created here. This is done by lml_alert_emit().
      Fix for latest libprelude analyzer/list changes.
      Fix for analyzer path change.
      Remove debugging spew.
      Fix call to idmef_path_get_name(). When trying to match a service "port",
      Fix PAX rule.
      Add  'signal sent' rules for grsec2.
      grsec2 version for the 'time changed' rule. use a shared goto.
      set --debug argument to optional.
      Updated.
      Use default prelude_client_new() permissions.
      Move prelude_client_print_setup_error() to the prelude_client_start() error check.
      s/prelude_list_del/prelude_linked_object_del/
      Use PRELUDE_OPTION_PRIORITY_IMMEDIATE where needed. Print option to stderr,
      Remove admin hook from plugin for now.
      Handle cas where arg is "".
      Copyright transfer from Nicolas Delon, Krzysztof Zaraska, and myself to PreludeIDS Technologies
      Update libprelude.m4, Makefile.am. Remove deprecated COPYING.OpenSSL file.
      Use inet_ntop() in place of prelude-inet. Update GNUlib code.
      Remove deprecated gtk-doc entry from configure.in. Include inet_ntop.h
      Stop using deprecated prelude_resolve_addr(), use getaddrinfo().
      Use PRELUDE_PRIu* in place of PRIu*.
      git-svn-id: file:///home/yoann/dev/prelude/git/nok/SVN/trunk/prelude-lml@5789 09c5ec92-17d4-0310-903a-819935f44dba
      Don't use size integer when it's not needed.
      Keep file option ordering intact.
      Don't require automake 1.8
      Update
      Bump version number. Update NEWS file.
      Update GnuLib code with OpenBSD fix.
      Avoid redefining MIN/MAX if these are already defined.
      Minimum required PCRE version is 4.1 (usage of pcre_get_named_substring). Thanks
      Correct FAM library function check.
      Update GnuLib code.
      Update.
      Fit plugins system change (version handling / re-entrancy).
      Set class to Log Analyzer.
      Update.
      Fix PCRE check.
      Update NEWS, bump version number.
      This regex was impacting performance by several thousands line/seconds. Correct it.
      Increase log level.
      Increase log level.
      OS -> Kernel.
      Move PAX in it's own ruleset.
      Correct comment about the system wide config file. Thanks to
      Support for alerts / line processed statistics on SIGUSR1, and when
      Oops.
      Add a no-resolve option, which avoid LML to try to resolve the full target
      Fixed some bug that resulted in duplicate alert and slowdown of the whole
      Fix socklen_t check.
      Bump version number, update documentation.
      Fix a crash uppon activation of the debug plugin. Thanks to
      Fix a Solaris issue where strptime would reset the tm structure to zero.
      Fix option namespace conflict.
      Fix --enable-unsupported-rulesets.
      Only print the number of initialized plugin in debugging mode.
      Make version option immediate. And make it exit directly. Remove
      Option priority reordering.
      Code cleanup. Fix possible crash on badly written rule referencing invalid IDMEF path.
      Forgot header modifications.
      Include rule ID in error message for service mapping.
      - Fix generic grsec2 regular expression.
      Update.
      Fix sendmail startup/shutdown rule.
      Fix grsec match on system that prefix grsec log with grsec: only.
      Correct example log.
      Bug fix:
      Bump version number. Update NEWS.
      Better error reporting.
      Fix memleak.
      Fix select error on remote admin UDP server change.
      Fix memleak. Provide a destroy hook for UDP server.
      Free on error.
      Always free hostname first, since it might be set even when udp_srvr is NULL,
      More cleanup.
      Set port within option callback.
      Kill strptime() warning.
      Update GnuLib code.
      s/manager-addr/server-addr/
      Kill warnings.
      Hash mark on the first column.
      Update GnuLib code. Include strdup() and extensions() module.
      svk-commitJp931.tmp
      Remove useless function check. Move gl_EARLY after C compiler check.
      Implement the "warning-limit" option. Can be used in order to supress reporting of prefix parser error (warning-limit 0), or to define a limit of warning (stop reporting once the threshold is reached). -1 for no limit.
      Include ordering.
      Update GnuLib code.
      Include new GnuLib modules.
      Update NEWS, bump version number.
      Fix file descriptor leak. Set close-on-exec.
      Update for gentoo system. Log tty on authentication failure.
      File path logging according to IDMEF v14.
      Typo.
      Re-establish signal handler for older *nix. Print statistics on SIGQUIT.
      Add Copyright notice. Remove deprecated prelude.spec.
      Update GnuLib code.
      ditto.
      Use size_t.
      Preliminary GRSEC2 support. Contribution needed to finish missing rules!
      Print status message.
      Slight regex fix.
      Fix invalid AdditionalData type in Arbor rule.
      Correct LOG: prefix for regression testing.
      version bump.
      Include config.h first.
      Fix typo:
      Update GnuLib code.
      Bump to 0.9.0
      Don't rely on ai_flags, but rather check that ai_cannonname is not null. Fix #100.
      Remove duplicate prelude_log() statement. Decrease required log level.
      Better syslog priority parsing. More pedantic on input format.
      Remove EOF error on --help.
      Implement my_strnchr() and use it in place of memchr(). Should be lighter.
      Fix a crash with the Debuging plugin. Sanitize the way idmef_message are freed.
      Allow adding of fd with value 0 to our fd set. This fix a bug where the UDP server
      Add missing part of [7329].
      Correct pcre-config check.
      Rework of the Netfilter ruleset resulting in simpler and faster ruleset
      Move prelude-lml metadata from /etc/prelude-lml/metadata to /var/lib/prelude-lml
      Cleanup fam detection. Don't link plugin to libfam. This fix static compilation.
      Revert to resolve_failed_fallback() when config.no_resolve was set by the user.
      Update GnuLib code.
      Implement the ability to have multiple format per source.
      Update NEWS, bump version to 0.9.1
      Cleanup.
      Add missing backslash. Fix parser error.
      Use a prelude_string_t object as dynamic storage for the file monitor. This is needed
      Handle prelude-string creation / destruction in monitor_open() / monitor_close() correctly.
      Don't destroy the idmef_message_t object here, since this should be up to the
      Destroy idmef state in case match_rule_single return an error.
      Update gnulib code.
      Update NEWS, bump version number.
      udp-srvr -> udp-server
      Missing "chained" keyword.
      Remove entry added for testing.
      Fix a bug introduced in [7636], that could result in some rule not being matched.
      Remove debugging spew.
      Fix byte ordering issue.
      Option sanitisation.
      Update GnuLib code.
      Include config.h
      Use AC_SYS_LARGEFILE instead of relying on manually defining _FILE_OFFSET_BITS=64.
      Update NEWS, bump version number.
      Signal handling improvement.
      Use priority immediate for --quiet.
      Remove trailing space from plugin.rules regex. Fix matching problem
      Use IDMEF_LIST_APPEND / IDMEF_LIST_PREPEND in place of -1/0. Bump libprelude
      Call _lml_handle_signal_if_needed() after each parsed log line. Necessary
      Add --user / --group option. However, make sure it is not allowed to open file
      drop_privilege() after client start.
      Correct "format" option priority.
      Turn out droping privilege after prelude_client_start() is a bad idea, since
      Usability work...
      Fix PAM authentication failed rule.
      Update GnuLib code, update NEWS, bump version number.
      Handle stat() EACCESS return in the same way as the other check_file_access()
      Make text-output argument optional.
      - Improve statistics precision (account for usecond).
      Abstract dynamic value handling in a new value_container_t object. Most of
      Missing copyright notice.
      Introduce the lml_alert_prepare() function, to be used to add information about
      Context support (ala SEC), in LML. We now handle multiline log matching.
      Detailed opening error message.
      Merge some PCRE parser correlator work here.
      Start of Spamassin ruleset by Gene Gomez. Experimental use of context
      Install spamassassin.rules.
      Improve FAM activation switches
      Update libprelude.m4
      Make sonicwall.rules part of the dist.
      Update GnuLib code
      Move MTA+Spamassassin specific rules to MTA specific ruleset
      Remove invalid Service definition
      Prelude-LML 0.9.5
      Alert consistency fix
      Set the silent flags on heads/inclusion rule. To avoid alerting on triggered events that got the "silent" flag.
      Reset the message to NULL in case of error
      Fix indexing problem.
      Missing end of line marker.
      More fixes
      Update configuration template
      Increase debug level for noisy pcre debug information
      Hook SonicWall and Spamassassin rulesets
      Update GnuLib code
      Update GnuLib code, NEWS. Bump version number.
      Correct some 'LOG:' entry
      Update GnuLib code. Should fix OpenBSD getaddrinfo() problem.
      use prelude_log_debug() to log failing time format.
      Fix reading input data from stdin.
      Fix reading data from stdin.
      Implement ruleset regression suite.
      Support 'fork failure' grsecurity warning, and fixes 'terminal being sniffed' matche
      Remove \r ...
      Ignore specific log entry that are not supposed to generate an alert (context creation).
      Update Gnulib code, NEWS. Bump version number.
      Update again.
      Add missing.
      Add missing...
      Move Exim single rule to unsupported, (incomplete rules, incomplete alert generation, missing testing log entry). Contribution are welcome to move the Exim signatures back in the supported state.
      Add Honeyd format
      Fix Squid 'process exited' rule. Modified contribution from <[email protected]>
      Update GnuLib code
      Update NEWS, bump version number.
      time.h inclusion fixes.
      time.h inclusion fixes.
      Use socklen_t check from GnuLib. Add -no-cpp-precomp on Darwin. Add a check for uid_t. Remove deprecated check.
      Update GnuLib code. Include socklen_t replacement module.
      Update NEWS, bump version number.
      Format string fixes.
      ModSecurity ruleset update. Remove unnecessary AdditionalData fields + ModSecurity 2.0 compatibility.
      Module path migration: move /trunk/prelude-lml /prelude-lml/trunk
      Add rule ID and revision for each rule that match, within AdditionalData. Fix #206.
      Fix a memory leak when trying to destroy a context that does not exist.
      Add bonding.rules, by Paul Robert Marino <[email protected]>.
      Complete log entry for regression testing. Correct multiple assessment.impact.type and -assessment.impact.severity issues. Fix invalid backward reference within rules 4804 and 4805.
      Use glob() to process filename provided by the user.
      Update comment in the configuration file.
      In case the getaddrinfo() nodename argument was an address, getaddrinfo() will return the argument as the canonical name. In this case, we don't want to set the node name.
      Update GnuLib code.
      Handle last keyword even if the rule does not contain any IDMEF assignement. Fix #218.
      Format string fixes.
      Update, for new GnuLib code.
      Fix 'type-punned pointer' warnings.
      Update GnuLib code.
      Move plugins/pcre/bonding.rules to plugins/pcre/ruleset/bonding.rules.
      Format string fixes. Increase the delay when checking for FAM writev() bug.
      Update NEWS, bump version number.
      More format string check.
      Remove deprecated use of prelude_client_print_setup_error(), directly handled via prelude_perror().
      Fix NULL pointer dereference when a rule reference an existing, but empty context (fix #226).
      Make the log parser more robust.
      Ability to use a REGEXP in plugins.rules to define monitored sources.
      Update GnuLib code.
      Revert "Update GnuLib code."
      Update GnuLib code.
      GnuLib code update.
      Update NEWS, bump version number
      Patch from Paul Robert Marino <[email protected]>:
      Include patch from Robin Gruyters <[email protected]>, to fix
      Whitespace police.
      Cleanup: call prelude_client_destroy() & prelude_deinit() on exit.
      Whitespace police. Remove log prefix. Fix some log priority.
      Improve error message when no format is found.
      Fix by Scott Olihovik <[email protected]>: invalid user.user_id(0).name assignement in SSH rule 1913 (fix #243).
      SSH IPv6 compatibility fixes.
      Fix typo in Apache regexp: thanks to [email protected] for
      Update GnuLib code.
      GnuLib code update.
      Update NEWS, Bump version number.
      Replace the 'ignore-metadata' option with a new 'metadata' option:
      Add kojoney.rules to the distribution.
      Improve logging message, make them less confusing.
      Add missing [prelude] section.
      Remove prefix when dumping statistics.
      Improve apache regexp.
      Improve apache regexp.
      Fix a performance regression introduced by openhostapd.rules.
      Update NEWS, bump version number.
      Revert "Update NEWS, bump version number."
      Revert "Revert "Update NEWS, bump version number.""
      Remove the 1024 bytes limit per PCRE reference, by using
      Fix incorrect AdditionalData assignement in spamassassin ruleset.
      Whitespace police.
      Fix leak introduced in commit [10495]. Code simplification, the
      Make sure we destroy all data associated with the PCRE plugin
      Fix invalid logfile modification alert that could be triggered
      On logfile consistency alert, do not re-analyze the whole file.
      Implement slighly modified Nagios ruleset fixes, allow
      Remove successful/failure keyword from classification (use completion).
      Remove successful/failure keyword from classification (use completion).
      Remove successful/failure keyword from classification (use completion).
      Whitespace police.
      Remove obsolete headers inclusion.
      Update GnuLib code, include pathmax module.
      Include pathmax.h
      Use PATH_MAX.
      Build system update, compile with relro.
      Update NEWS, bump version number.
      Fix undefined reference when FAM is not available.
      Update NEWS, bump version number
      Fix wrong installation path, thanks to Steve Grubb <[email protected]>
      Update NEWS, bump version number.
      Add missing 'ignored' file to the distribution.
      ModSecurity ruleset rewrite, by Peter Vrabec <[email protected]> and
      Normalize some classification: introduce Remote Login, and Credentials Change.
      New rulesets for FreeBSD su attempts, thanks Alexander Afonyashin <[email protected]>
      Add make check.
      Small fixes.
      Add su.rules to the build.
      Add additional prefix-regex to deal with apache error_log file format,
      Regression test correction.
      Update GnuLib code, include unit-tests.
      Remove deprecated header inclusion.
      Build/run GnuLib unit tests.
      Update NEWS, bump version.
      Update build files.
      Include GnuLib strsep module, fix #309.
      Remove deprecated header inclusion.
      Win32 compatibility fixes.
      Remove deprecated header inclusion.
      Add missing modules required for complete portability: fnmatch-gnu,
      Use GnuLib time.h
      off_t to 64 bits integer, fix win32 warnings.
      Make a difference between WIN32 and Cygwin.
      Add missing GnuLib buildir include path.
      Fix URL.
      Deprecate Gamin/FAM support in favor of libev. The previous implementation
      ModSecurity ruleset update, by Daniel Kopecek <[email protected]>
      Embed libev.
      Remove deprecated 'FAM support' output.
      Fix warnings by using ev_statdata typedef.
      GnuLib code update.
      Update NEWS, bump version.
      Match Authentication Rejected message even thought the server field
      Fixes possible off by one when parsing variable reference number. Thanks
      Update autogenerated INSTALL file.
      Remove un-needed check that would always evaluate to TRUE. Thanks
      Update for libtool 2.x compatibility.
      New PPP/PPTPD/L2TP ruleset, by Alexander Afonyashin <[email protected]>,
      Whitespace police.
      Install ppp.rules.
      This simplify the whole regular expression handling a lot, making the
      Upgrade to libev 3.53.
      Fix extern triggered warning.
      Use git.mk for automatic .gitignores file generation.
      Update to libev 3.6
      Whitespace police
      Fix possible uninitialized read
      Fix signature parsing error due to missing ";"
      The Prelude-LML UDP server is now fully IPV6 compatible
      Ability to provides static IDMEF template from defined log format
      Update GnuLib code
      Update autogenerated files
      IPv6 compatible address detection
      Remove libmissing.h dependency
      Automatic gitignore generation for GnuLib files
      Warn the user in case the PCRE vector is too small
      Automatic ChangeLog generation
      Update NEWS, bump version

cvs2svn (1):
      This commit was generated by cvs2svn to compensate for changes in r2358,

turpeau (1):
      Initial revision

uid1014 (1):
      *** empty log message ***
_______________________________________________
Prelude-cvslog site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-cvslog