prelude-lml: Changes to 'refs/tags/prelude-lml-0.9.15'
[email protected] Thu, 16 Jul 2009 15:42:50 +0200 (CEST)
| Newsgroups | gmane.comp.security.ids.prelude.cvs |
|---|---|
| Message-ID | <[email protected]> |
Tag 'prelude-lml-0.9.15' created by Yoann Vandoorselaere <[email protected]> at 2009-07-16 14:44 +0200 0.9.15 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEABECAAYFAkpfLsUACgkQD4LqTXjyBR/zTQCfUxvls4cZfsWp+SLAwGrQVlP6 /jkAn2yoyFfPaYIMwE2PxW2MhOFw1yo8 =uaJy -----END PGP SIGNATURE----- Changes since the dawn of time: Baptiste Malguy (1): * src/*-plugins.c (*_plugins_init): Chia-liang Kao (1): update libmissing Gene Ramon Gomez (156): *** empty log message *** 2004-01-16 Yoann Vandoorselaere <[email protected]> *** empty log message *** *** empty log message *** * plugins/simple/ruleset/cisco-pix.rules: * plugins/simple/ruleset/vigor.rules: * plugins/simple/ruleset * plugins/simple/ruleset/cisco-pix.rules: * plugins/simple/ruleset: * plugins/simple/ruleset: *** empty log message *** * plugins/simples/ruleset/simple.rules: * plugins/simples/ruleset/simple.rules: * plugins/simple/ruleset/simple.rules: * plugins/simple/ruleset/single * plugins/simple/ruleset/cisco-pix.rules: * plugins/simple/ruleset/ssh.rules: * plugins/simple/ruleset/cisco-pix.rules: * plugins/simple/ruleset/simple.rules: * simple/plugins/ruleset/apc-emu.rules: * simple/plugins/ruleset/single.rules: * simple/plugins/ruleset/cisco-pix.rules: * plugins/simple/ruleset/apc-emu.rules: * plugins/simple/ruleset/simple.rules: * plugins/simple/ruleset/single.rules: * simple/plugins/ruleset/Makefile.am: * simple/plugins/ruleset/Makefile.am: * simple/plugins/ruleset/navce.rules: * simple/plugins/ruleset/Makefile.am: * simple/plugins/ruleset/portsentry.rules: * simple/plugins/ruleset/modsecurity.rules: * plugins/simple/ruleset/unsupported/zyxel.rules: * plugins/simple/ruleset/simple.rules: * plugins/simple/ruleset/checkpoint.rules: * plugins/simple/ruleset (multiple): * plugins/simple/ruleset/unsupported/cisco.rules: * plugins/simple/ruleset/cisco.rules: * plugins/simple/ruleset/postfix.rules: * plugins/simple/ruleset/bigip.rules: * plugins/simple/ruleset/contrib: * plugins/simple/ruleset/bigip.rules: * plugins/simple/ruleset/modsecurity.rules: * plugins/simple/ruleset: * plugins/simple/ruleset/sendmail.rules: * plugins/simple/ruleset/sendmail.rules: * plugins/simple/ruleset/: * plugins/simple/ruleset/sendmail.rules: * plugins/simple/ruleset/unsupported/netfilter.rules: * plugins/simple/ruleset/dell-om.rules * plugins/simple/ruleset/simple.rules * plugins/simple/ruleset/sendmail.rules: * plugins/simple/ruleset/simple.rules: * plugins/pcre/ruleset/netapp-ontap.rules * plugins/pcre/ruleset: * plugins/pcre/ruleset/dell-om.rules: * plugins/pcre/ruleset/netapp-ontap.rules: * plugins/pcre/ruleset/netapp-ontap.rules: * plugins/pcre/ruleset/netapp-ontap.rules: * plugins/pcre/ruleset/ntsyslog.rules: * plugins/pcre/ruleset/ssh.rules: * plugins/pcre/ruleset/cisco-pix.rules: * src/plugins/pcre/ruleset/bigip.rules: git-svn-id: file:///home/yoann/dev/prelude/git/nok/SVN/trunk/prelude-lml@6045 09c5ec92-17d4-0310-903a-819935f44dba * src/plugins/pcre/ruleset/pam.rules: * src/plugins/pcre/ruleset/simple.rules * src/plugins/pcre/ruleset/shadow-utils.rules * src/plugins/pcre/ruleset/single.rules * plugins/pcre/ruleset/grsecurity.rules * plugins/pcre/ruleset/grsecurity.rules * plugins/pcre/ruleset/sudo.rules * plugins/pcre/ruleset/single.rules: * plugins/pcre/ruleset/simple.rules: * plugins/pcre/ruleset/single.rules: * plugins/pcre/ruleset/wap11.rules: * plugins/pcre/ruleset/selinux.rules: * plugins/pcre/ruleset/single.rules: * plugins/pcre/ruleset/simple.rules: Replaced simple with pcre, reverted apc-emu and f5-bigip to pre-chained versions, Fixed typo in pcre.rules (pix regex), added NetBIOS address parsing to Audited NTSyslog ruleset for consistency. More changes to come. Introduced corrected IPv6 support (previous method set all address types to Added implied tcp/udp as was appropriate. Added httpd support. s/Prelude/Prelude-LML in f5-bigip.rules, added one httpd rule, so spun httpd.rules out of single.rules Fixed bad httpd and modsecurity interaction. Changed PaX class from Kernel to Memory Violation Exa(protect|probe) supported rules marked as unsupported Made contact information more correct; added additional httpd rules; Added httpd regex explanation, because I know the question is going to be Added systrace, identd, arpwatch support oops Added catch of IP address to 1901. Bug in 408; was assigning user name into user number. Added version information and corrected MAC address regex for arpwatch; Fixed broken regex (log sample was incorrect in one case), improved other Explicit manufacturer names not needed in analyzer.name field Marked rulesets as unmaintained. updated maintainance information Removed end-of-line anchor for some systems that may log different (thanks * Updated SELinux ruleset maintainer information * Transitioned postfix back to supported status. Started work to add --enabled-unsupported-rulesets to configure Added support for pure-ftpd; added device classification information to Various ruleset corrections based on additional LML debug information. git-svn-id: file:///home/yoann/dev/prelude/git/nok/SVN/trunk/prelude-lml@6380 09c5ec92-17d4-0310-903a-819935f44dba Fixed 1700 Ruleset auditing corrections/updates Added preliminary support for PIX conduits Removed silly check for existance *or* non-existance of ssh2 at the end of all Fixed 1912, committed arbor.rules first-run. Made arbor.rules part of the default install. Ruleset clean-up...replaced '.' with '\;' for field parsing. Thanks go to Consistency updates; log messages for services being turned off are now all Added Netscreen support (thanks go to tilaris at wanadoo dor fr) Ruleset audit; standardized service.iana_protocol_name, Updated p3scan rule (id 405) for newer version log format. Forgot to increment the revision. Added 1914 and 1915 for suse-specific log format (PAM2?) Added analyzer().name and analyzer().manufacturer to linksys-wap11.rules. Fixed bad mssql chain regex (from the samples, mssqlserver looks correct, but Made change to clamav chaining regex to handle events in clamav logging format Introduced support for openhostapd (thanks go to [email protected]). forgot to increment revision fields. Further additional_data work. additional_data stuff A couple more additional_data updates... Abstracted Squid chain regex to allow parsing of data directly from Squid log files. A few parsing corrections; lots of additional_data work Corrections, extensions, etc. Ruleset audit! Marked selinux rules as experimental (I need to put some work into them now Added sonicwall.rules (thanks go to Igor M. <imanassypov at Add Router IDS module support. Prep for upgrade from cisco-pix.rules to cisco-asa.rules. Rename Cisco PIX rules to ASA to reflect new device name. Continue PIX -> PIX+ASA rules upgrade More ASA stuff Ruleset was using a portion of the syslog header for matching; corrected. Fix reference to non-existant variable First sweep ruleset audit Move checkpoint.rules back into supported status Clean up checkpoint.rules stuff, start implementing Cisco CSS support Some abstraction work for correlation, improvement of CSS rules Fix format problem with Apache logs from western hemisphere (- versus + TZ) Update honeyd rules Fix chain regex for more recent honeyd logging Introduced Cacti thold plugin support. Greatly simplify ruleset documentation (direct reader to the IDMEF draft). Continued NTSyslog audit Implement Microsoft Cluster Service support Add assessment.impact.completion field to 1408 Updated NAVCE rules; modified ClamAV rules for consistency. Added rule to ignore LML's "could not match prefix" log entries. Cisco ASA IPS module support Update Cisco IPS reference URL to official Cisco site. Fix 302 (wrong field used in description of event) Committed Cisco ruleset (by Alexandre Racine) Removed false dependancy on severity in pattern matching (thanks go to Guillaume Pelat (4): * src/file-server.c (logfile_alert): fix unterminated string. * src/file-server.c (logfile_alert): * src/file-server.c (check_modification_time): 2002-08-24 Guillaume Pelat <[email protected]> Krzysztof Zaraska (14): freebsd compat. fix include <inttypes.h> instead of <stdint.h> FreeBSD compat. fix FreeBSD compat. fix Rules for FreeBSD IPFW *** empty log message *** use clearerr_unlocked() after hitting feof() on file *** empty log message *** added ICMP. cleanup. *** empty log message *** * plugins/simple/ruleset/ipfw.rules: updated to use new SimpleMod include <sys/time.h> so it builds on FreeBSD plugins/simple/ruleset/simple.rules: fix typo * plugins/simple/ruleset/Makefile.am: Laurent Oudot (9): 2002-04-26 Laurent Oudot <[email protected]> 2002-04-27 Laurent Oudot <[email protected]> 2002-04-27 Laurent Oudot <[email protected]> *** empty log message *** 2002-04-28 Laurent Oudot <[email protected]> 2002-05-30 Laurent Oudot <[email protected]> *** empty log message *** *** empty log message *** *** empty log message *** Nicolas Delon (6): * plugins/simple/ruleset/*.rules: * src/lml-alert.c: * plugins/simple/simple.c: fix bad path for configuration file includes bug fix: compatibility with IPv6 addresses fit additional data API improvements Pierre Chifflier (8): Fix a few typos, and use the same type or end-of-lines (do not use Add new ruleset for Honeytrap (Closes #244) Fix regex 1403 in ntsyslog, so it matches the provided example log. Add new ruleset for Kojoney honeypot (Closes #245). Add new ruleset to ignore cron jobs (Closes #266) Cron rules: Add new ruleset for Rishi (Closes #246) Remove dos-style end-of-lines (Closes #338) Rob Holand (29): whitespace fix un(used/tested/supported/wanted) abandoned whitespace police appease gcc missing include allow users to ignore metadata to benchmark and/or test rules change option code to use a struct. makes code cleaner. 'sync' against prelude-manager option parsing code typedef for config struct rename config file define to be inline with prelude-manager rename pconfig.* to lml-options.* main.c -> prelude-lml.c pconfig_init -> lml_options_init() log_container_t -> log_entry_t, and log -> log_entry where relevant more log -> log_entry to aid readability move to using a regex format for syslog prefix parsing. this means more flexibility and support for optional matching of pids, which wasn't possible before fix pid in alerts make program non-greedy so pid matches properly sorry, this is what I meant to commit rename program -> process to be consistant with idmef fix the ordering add log_entry->message as a moving target to allow for optimisation patches to come later. rename log_entry->log to log_entry->original_log to aid readability fix some spacing in sample log entries fix missing prefix fixup target interface regex and remove source regex. We can't know whether the packet was locally generated or not r7@leet: rob | 2005-02-11 16:18:05 +0000 r11@leet: rob | 2005-02-11 16:30:58 +0000 r367@leet: rob | 2005-02-11 16:57:21 +0000 r371@leet: rob | 2005-02-11 17:08:35 +0000 Sebastien Tricaud (11): Fixes a typo error (feature): Asterisk log format and new ruleset for SIP REGISTER method (ruleset): new ruleset for asterisk (bugfix): asterisk ruleset parser fix (bugfix): Add 'LOG:' prefix add suhosin rulesets Append suhosin.rules into makefile, added ruleset id and manufacturer Add offset information when a regex compile fails Change the Cisco ASA urls to the new location Add Cisco ASA rule to handle discarded tcp or udp packets. Point alert message vendor description to the right url. Stephane Loeuillet (7): *** empty log message *** *** empty log message *** *** empty log message *** *** empty log message *** *** empty log message *** *** empty log message *** forgot a back-slash at end of line of a rule. fixed Yoann Vandoorselaere (585): * AUTHORS: * src/file-server.c: * src/regex.c: * src/udp-server.c (udp_server_new): * src/file-server.c (file_server_monitor_file): *** empty log message *** * plugins/simple/simple.c: *** empty log message *** * plugins/pax/pax.c (pax_log_processing): * src/lml-alert.c (lml_emit_alert): *** empty log message *** * prelude-lml.conf.in (file): * src/server-logic.c (server_logic_process_requests): * src/main.c (lml_dispatch_log): *** empty log message *** * plugins/simple/simple.c (parse_impact_desc): * src/file-server.c (file_server_monitor_file): * plugins.rules.in: comment the Debug plugin entry * src/udp-server.c: make the size of our buffer * src/pconfig.c (set_file): now that we do not * src/log-common.c (format_syslog_header): *** empty log message *** *** empty log message *** * src/udp-server.c (udp_server_standalone): * src/file-server.c (file_server_wake_up): * Makefile.am (install-data-local): * plugins/simple/simple.c: try to do time consuming stuff *** empty log message *** *** empty log message *** * src/file-server.c (read_logfile): * src/log-common.c (format_syslog_header): *** empty log message *** * plugins/simple/simple.c (parse_ruleset): * src/file-server.c (file_server_monitor_file): *** empty log message *** *** empty log message *** * plugins/simple/simple.c: * src/log-plugins.c (subscribe): * src/file-server.c (read_logfile): *** empty log message *** *** empty log message *** * plugins/simple/ruleset/netfilter.rules: *** empty log message *** * plugins/simple/simple.c: included patch from * src/include/Makefile.am (include_HEADERS): 2002-05-21 Yoann Vandoorselaere <[email protected]> *** empty log message *** 2002-05-27 Yoann Vandoorselaere <[email protected]> 2002-05-30 Yoann Vandoorselaere <[email protected]> 2002-05-30 Yoann Vandoorselaere <[email protected]> 2002-05-31 Yoann Vandoorselaere <[email protected]> *** empty log message *** 2002-06-03 Yoann Vandoorselaere <[email protected]> *** empty log message *** *** empty log message *** 2002-06-06 Yoann Vandoorselaere <[email protected]> *** empty log message *** *** empty log message *** *** empty log message *** *** empty log message *** *** empty log message *** *** empty log message *** *** empty log message *** 2002-07-29 Yoann Vandoorselaere <[email protected]> * src/regex.c (trim): 2002-07-30 Yoann Vandoorselaere <[email protected]> 2002-08-20 Yoann Vandoorselaere <[email protected]> *** empty log message *** *** empty log message *** *** empty log message *** *** empty log message *** *** empty log message *** *** empty log message *** *** empty log message *** 2002-10-13 Yoann Vandoorselaere <[email protected]> *** empty log message *** 2002-10-26 Yoann Vandoorselaere <[email protected]> 2002-10-28 Yoann Vandoorselaere <[email protected]> 2002-11-06 Yoann Vandoorselaere <[email protected]> 2002-11-12 Yoann Vandoorselaere <[email protected]> *** empty log message *** 2002-12-05 Yoann Vandoorselaere <[email protected]> 2002-12-09 Yoann Vandoorselaere <[email protected]> *** empty log message *** *** empty log message *** *** empty log message *** *** empty log message *** *** empty log message *** *** empty log message *** Updated my mail address. *** empty log message *** *** empty log message *** Merge back from 0-8 to HEAD Backport from 0-8 to HEAD *** empty log message *** * Merge from 0-8. * plugins/simple/simple.c: commit missing, recently added rulesets. * plugins/simple/simple.c (parse_rule_object_value): * src/file-server.c (file_server_wake_up): *** empty log message *** *** empty log message *** * src/lml-alert.c (generate_target): * plugins.rules.in: remove paxmod. Obsoleted. * src/log-common.c test Someone who want to sponsor the Prelude project please send me a new coffee * src/lml-alert.c (generate_target): * plugins/simple/ruleset/grsecurity.rules: updated * plugins/simple/ruleset/simple.rules (regex): * plugins/simple/simple.c: * plugins/simple/simple.c: * plugins/simple/ruleset/simple.rules (regex): * src/udp-server.c (udp_server_new): verbose message (udp_server_process_event, udp_server_new): embed * src/udp-server.c (udp_server_process_event): *** empty log message *** (udp_server_process_event): remove trailling syslog * src/file-server.c: * src/lml-alert.c (generate_target): Fit libprelude IDMEF API change. Add a space after the %tprog assignement on the syslog line, Merge back plugins-instances change into trunk port to new prelude-list.h API * log-plugins.c * regex.c Rework udp-srvr option Fix warnings. fit latest libprelude API change Call lml_alert_init() before prelude_client_init(), so that first heartbeat Fit latest libprelude API change Some more wide available option. Allow version retrieval from admin console. FUll admin console support for the syslog UDP server. Implemented log_source_destroy(), which is needed for the syslog Fix leak on syslog listener destroy. Fix valgrind leak false positive by moving the list member to the top of the structure. The way the list implementation work make valgrind think the object is lost, when we still have a reference to this object through the offset + address of one of it's member. Fix problem when using FAM notification, where we could lose track of a file Cleanup. Remove debugging stuff. Change the prelude_plugin_init function name to support Build plugins first since the core depend on them in case of dlpreopening. Activate dlpreopening support. Call AC_LIBTOOL_DLOPEN() Use socklen_t if available. Fix a warning. Fix format string when printing 64 bits integer on 64 bit system. s/inttypes.h/prelude-inttypes.h/ everywhere, for portability. Include <sys/time.h>, fix compilation problem on certain arch. Use scanf() in combination with SVNu64 macro, instead of strtoull, Oops. s/scanf/sscanf/ cast isspace() and such, value to int. Avoid possible MAX() redefinition. Add missing variable, strict error checking. More portability work, cleanup. Link to libmissing. sync my tree... commit missing files. Use @LIBPRELUDE_LDFLAGS@ to link prelude-lml. Fix configure.in to use AM_PATH_LIBPRELUDE(). Remove obsolete. Slight formating fix. Include AC_PATH_GENERIC from the autoconf macro archive. Increase version number to 0.9.0-svn. Check for libprelude-0.9.0. Propagate libprelude.m4 changes. Fix version. Update gnulib code. Fix missing include. Add missing header file. Use idmef_object_set() in place of deprecated idmef_message_set(). Stop including idmef-tree.h, it is deprecated. Make --disable-fam work again. Add missing libtool.m4. call prelude_client_destroy() in case we're running in batch mode Fit change to prelude_client_destroy(). Update libprelude.m4 Make filename '-' treated as stding. Rename the 'Simple' plugin to 'Pcre'. Implement goto, optgoto, min-opt-goto, git-svn-id: file:///home/yoann/dev/prelude/git/nok/SVN/trunk/prelude-lml@4284 09c5ec92-17d4-0310-903a-819935f44dba Commit missing stuff. Try to improve FAM check. Fit IDMEF message write API change. Use prelude-string instead of idmef-string. Provide a --enable-fam argument. Remove unused. Call try_reopening_inactive_monitor() in prelude_client_init() now take a pointer to argc. Update libprelude.m4, include only idmef-client.conf, Merge idmef-v12-work change back in trunk. Fit latest libprelude API fix. constness fix. Remove deprecated headers inclusion. Use prelude_client_is_setup_needed() to check the prelude_client_init() Use prelude_client_send_idmef(). Fix for libprelude API change. Use a local root option list. Fix leak of resolved backward reference. Provide the ability for the caller to setup it's own analyzer, which will Include the targeted interface into the alert. Update gnulib code. Include getaddrinfo() workaround. git-svn-id: file:///home/yoann/dev/prelude/git/nok/SVN/trunk/prelude-lml@4705 09c5ec92-17d4-0310-903a-819935f44dba Include getaddrinfo.h If aggregated analyzer node/process are not defined, try to define git-svn-id: file:///home/yoann/dev/prelude/git/nok/SVN/trunk/prelude-lml@4708 09c5ec92-17d4-0310-903a-819935f44dba Remove deprecated. Remove deprecated. r4703@arwen: yoann | 2005-01-06T10:32:01.752813Z Fit libprelude prelude_init() change. Add --dry-run (don't connect/send anything to prelude), Arrange so that --dry-run doesn't require the analyzer to be registered. Don't call prelude_client_destroy() in batch mode if dry-run is set. Remove strlen() call for log_entry all over the code. Some of them were called one Fix backward reference numbering. Use IDMEF address rather than IDMEF user. s/optionnal/optional/ Oops. s/log/message/ s/->log/->message/ Don't crash if alert is not set within the provided IDMEF message. Don't construct and IDMEF message if object list is empty. We'll do it as soon Fix qpopper regex. Add missing log entry for regression testing. More work on LML log sample. More rule example log. More log message work... More work on grsecurity LOG sample. Fix missing ';' git-svn-id: file:///home/yoann/dev/prelude/git/nok/SVN/trunk/prelude-lml@4878 09c5ec92-17d4-0310-903a-819935f44dba Fix some log entry. One more log. Fix goto ID when creating from range. Log sample for WAP11. Don't increase the 'required' field when getting a required regex. This is only Don't use the process name for the match. Cleanup so that it use Variation in SSHD 'Invalid user' log message. Ooops. Fixup copyright notice. Add missing copyright notices. remove deprecated header file. Missing copyright notice. r4934@arwen (orig r4982): yoann | 2005-01-30 20:55:09 +0100 git-svn-id: file:///home/yoann/dev/prelude/git/nok/SVN/trunk/prelude-lml@5230 09c5ec92-17d4-0310-903a-819935f44dba r4985@arwen (orig r5033): yoann | 2005-02-07 13:28:30 +0100 r5065@arwen (orig r5113): yoann | 2005-02-14 17:12:40 +0100 git-svn-id: file:///home/yoann/dev/prelude/git/nok/SVN/trunk/prelude-lml@5233 09c5ec92-17d4-0310-903a-819935f44dba git-svn-id: file:///home/yoann/dev/prelude/git/nok/SVN/trunk/prelude-lml@5234 09c5ec92-17d4-0310-903a-819935f44dba r7698@arwen (orig r5227): yoann | 2005-02-18 13:02:54 +0100 r7699@arwen (orig r5228): yoann | 2005-02-18 13:12:31 +0100 Fix missing. Add -D (--debug) option. Debug message can now be seen by setting the -D option Use prelude_log_set_debug_level(). Fix invalid free, and a memory leak when destroying an instance of the plugin. No idea why an analyzer was ever created here. This is done by lml_alert_emit(). Fix for latest libprelude analyzer/list changes. Fix for analyzer path change. Remove debugging spew. Fix call to idmef_path_get_name(). When trying to match a service "port", Fix PAX rule. Add 'signal sent' rules for grsec2. grsec2 version for the 'time changed' rule. use a shared goto. set --debug argument to optional. Updated. Use default prelude_client_new() permissions. Move prelude_client_print_setup_error() to the prelude_client_start() error check. s/prelude_list_del/prelude_linked_object_del/ Use PRELUDE_OPTION_PRIORITY_IMMEDIATE where needed. Print option to stderr, Remove admin hook from plugin for now. Handle cas where arg is "". Copyright transfer from Nicolas Delon, Krzysztof Zaraska, and myself to PreludeIDS Technologies Update libprelude.m4, Makefile.am. Remove deprecated COPYING.OpenSSL file. Use inet_ntop() in place of prelude-inet. Update GNUlib code. Remove deprecated gtk-doc entry from configure.in. Include inet_ntop.h Stop using deprecated prelude_resolve_addr(), use getaddrinfo(). Use PRELUDE_PRIu* in place of PRIu*. git-svn-id: file:///home/yoann/dev/prelude/git/nok/SVN/trunk/prelude-lml@5789 09c5ec92-17d4-0310-903a-819935f44dba Don't use size integer when it's not needed. Keep file option ordering intact. Don't require automake 1.8 Update Bump version number. Update NEWS file. Update GnuLib code with OpenBSD fix. Avoid redefining MIN/MAX if these are already defined. Minimum required PCRE version is 4.1 (usage of pcre_get_named_substring). Thanks Correct FAM library function check. Update GnuLib code. Update. Fit plugins system change (version handling / re-entrancy). Set class to Log Analyzer. Update. Fix PCRE check. Update NEWS, bump version number. This regex was impacting performance by several thousands line/seconds. Correct it. Increase log level. Increase log level. OS -> Kernel. Move PAX in it's own ruleset. Correct comment about the system wide config file. Thanks to Support for alerts / line processed statistics on SIGUSR1, and when Oops. Add a no-resolve option, which avoid LML to try to resolve the full target Fixed some bug that resulted in duplicate alert and slowdown of the whole Fix socklen_t check. Bump version number, update documentation. Fix a crash uppon activation of the debug plugin. Thanks to Fix a Solaris issue where strptime would reset the tm structure to zero. Fix option namespace conflict. Fix --enable-unsupported-rulesets. Only print the number of initialized plugin in debugging mode. Make version option immediate. And make it exit directly. Remove Option priority reordering. Code cleanup. Fix possible crash on badly written rule referencing invalid IDMEF path. Forgot header modifications. Include rule ID in error message for service mapping. - Fix generic grsec2 regular expression. Update. Fix sendmail startup/shutdown rule. Fix grsec match on system that prefix grsec log with grsec: only. Correct example log. Bug fix: Bump version number. Update NEWS. Better error reporting. Fix memleak. Fix select error on remote admin UDP server change. Fix memleak. Provide a destroy hook for UDP server. Free on error. Always free hostname first, since it might be set even when udp_srvr is NULL, More cleanup. Set port within option callback. Kill strptime() warning. Update GnuLib code. s/manager-addr/server-addr/ Kill warnings. Hash mark on the first column. Update GnuLib code. Include strdup() and extensions() module. svk-commitJp931.tmp Remove useless function check. Move gl_EARLY after C compiler check. Implement the "warning-limit" option. Can be used in order to supress reporting of prefix parser error (warning-limit 0), or to define a limit of warning (stop reporting once the threshold is reached). -1 for no limit. Include ordering. Update GnuLib code. Include new GnuLib modules. Update NEWS, bump version number. Fix file descriptor leak. Set close-on-exec. Update for gentoo system. Log tty on authentication failure. File path logging according to IDMEF v14. Typo. Re-establish signal handler for older *nix. Print statistics on SIGQUIT. Add Copyright notice. Remove deprecated prelude.spec. Update GnuLib code. ditto. Use size_t. Preliminary GRSEC2 support. Contribution needed to finish missing rules! Print status message. Slight regex fix. Fix invalid AdditionalData type in Arbor rule. Correct LOG: prefix for regression testing. version bump. Include config.h first. Fix typo: Update GnuLib code. Bump to 0.9.0 Don't rely on ai_flags, but rather check that ai_cannonname is not null. Fix #100. Remove duplicate prelude_log() statement. Decrease required log level. Better syslog priority parsing. More pedantic on input format. Remove EOF error on --help. Implement my_strnchr() and use it in place of memchr(). Should be lighter. Fix a crash with the Debuging plugin. Sanitize the way idmef_message are freed. Allow adding of fd with value 0 to our fd set. This fix a bug where the UDP server Add missing part of [7329]. Correct pcre-config check. Rework of the Netfilter ruleset resulting in simpler and faster ruleset Move prelude-lml metadata from /etc/prelude-lml/metadata to /var/lib/prelude-lml Cleanup fam detection. Don't link plugin to libfam. This fix static compilation. Revert to resolve_failed_fallback() when config.no_resolve was set by the user. Update GnuLib code. Implement the ability to have multiple format per source. Update NEWS, bump version to 0.9.1 Cleanup. Add missing backslash. Fix parser error. Use a prelude_string_t object as dynamic storage for the file monitor. This is needed Handle prelude-string creation / destruction in monitor_open() / monitor_close() correctly. Don't destroy the idmef_message_t object here, since this should be up to the Destroy idmef state in case match_rule_single return an error. Update gnulib code. Update NEWS, bump version number. udp-srvr -> udp-server Missing "chained" keyword. Remove entry added for testing. Fix a bug introduced in [7636], that could result in some rule not being matched. Remove debugging spew. Fix byte ordering issue. Option sanitisation. Update GnuLib code. Include config.h Use AC_SYS_LARGEFILE instead of relying on manually defining _FILE_OFFSET_BITS=64. Update NEWS, bump version number. Signal handling improvement. Use priority immediate for --quiet. Remove trailing space from plugin.rules regex. Fix matching problem Use IDMEF_LIST_APPEND / IDMEF_LIST_PREPEND in place of -1/0. Bump libprelude Call _lml_handle_signal_if_needed() after each parsed log line. Necessary Add --user / --group option. However, make sure it is not allowed to open file drop_privilege() after client start. Correct "format" option priority. Turn out droping privilege after prelude_client_start() is a bad idea, since Usability work... Fix PAM authentication failed rule. Update GnuLib code, update NEWS, bump version number. Handle stat() EACCESS return in the same way as the other check_file_access() Make text-output argument optional. - Improve statistics precision (account for usecond). Abstract dynamic value handling in a new value_container_t object. Most of Missing copyright notice. Introduce the lml_alert_prepare() function, to be used to add information about Context support (ala SEC), in LML. We now handle multiline log matching. Detailed opening error message. Merge some PCRE parser correlator work here. Start of Spamassin ruleset by Gene Gomez. Experimental use of context Install spamassassin.rules. Improve FAM activation switches Update libprelude.m4 Make sonicwall.rules part of the dist. Update GnuLib code Move MTA+Spamassassin specific rules to MTA specific ruleset Remove invalid Service definition Prelude-LML 0.9.5 Alert consistency fix Set the silent flags on heads/inclusion rule. To avoid alerting on triggered events that got the "silent" flag. Reset the message to NULL in case of error Fix indexing problem. Missing end of line marker. More fixes Update configuration template Increase debug level for noisy pcre debug information Hook SonicWall and Spamassassin rulesets Update GnuLib code Update GnuLib code, NEWS. Bump version number. Correct some 'LOG:' entry Update GnuLib code. Should fix OpenBSD getaddrinfo() problem. use prelude_log_debug() to log failing time format. Fix reading input data from stdin. Fix reading data from stdin. Implement ruleset regression suite. Support 'fork failure' grsecurity warning, and fixes 'terminal being sniffed' matche Remove \r ... Ignore specific log entry that are not supposed to generate an alert (context creation). Update Gnulib code, NEWS. Bump version number. Update again. Add missing. Add missing... Move Exim single rule to unsupported, (incomplete rules, incomplete alert generation, missing testing log entry). Contribution are welcome to move the Exim signatures back in the supported state. Add Honeyd format Fix Squid 'process exited' rule. Modified contribution from <[email protected]> Update GnuLib code Update NEWS, bump version number. time.h inclusion fixes. time.h inclusion fixes. Use socklen_t check from GnuLib. Add -no-cpp-precomp on Darwin. Add a check for uid_t. Remove deprecated check. Update GnuLib code. Include socklen_t replacement module. Update NEWS, bump version number. Format string fixes. ModSecurity ruleset update. Remove unnecessary AdditionalData fields + ModSecurity 2.0 compatibility. Module path migration: move /trunk/prelude-lml /prelude-lml/trunk Add rule ID and revision for each rule that match, within AdditionalData. Fix #206. Fix a memory leak when trying to destroy a context that does not exist. Add bonding.rules, by Paul Robert Marino <[email protected]>. Complete log entry for regression testing. Correct multiple assessment.impact.type and -assessment.impact.severity issues. Fix invalid backward reference within rules 4804 and 4805. Use glob() to process filename provided by the user. Update comment in the configuration file. In case the getaddrinfo() nodename argument was an address, getaddrinfo() will return the argument as the canonical name. In this case, we don't want to set the node name. Update GnuLib code. Handle last keyword even if the rule does not contain any IDMEF assignement. Fix #218. Format string fixes. Update, for new GnuLib code. Fix 'type-punned pointer' warnings. Update GnuLib code. Move plugins/pcre/bonding.rules to plugins/pcre/ruleset/bonding.rules. Format string fixes. Increase the delay when checking for FAM writev() bug. Update NEWS, bump version number. More format string check. Remove deprecated use of prelude_client_print_setup_error(), directly handled via prelude_perror(). Fix NULL pointer dereference when a rule reference an existing, but empty context (fix #226). Make the log parser more robust. Ability to use a REGEXP in plugins.rules to define monitored sources. Update GnuLib code. Revert "Update GnuLib code." Update GnuLib code. GnuLib code update. Update NEWS, bump version number Patch from Paul Robert Marino <[email protected]>: Include patch from Robin Gruyters <[email protected]>, to fix Whitespace police. Cleanup: call prelude_client_destroy() & prelude_deinit() on exit. Whitespace police. Remove log prefix. Fix some log priority. Improve error message when no format is found. Fix by Scott Olihovik <[email protected]>: invalid user.user_id(0).name assignement in SSH rule 1913 (fix #243). SSH IPv6 compatibility fixes. Fix typo in Apache regexp: thanks to [email protected] for Update GnuLib code. GnuLib code update. Update NEWS, Bump version number. Replace the 'ignore-metadata' option with a new 'metadata' option: Add kojoney.rules to the distribution. Improve logging message, make them less confusing. Add missing [prelude] section. Remove prefix when dumping statistics. Improve apache regexp. Improve apache regexp. Fix a performance regression introduced by openhostapd.rules. Update NEWS, bump version number. Revert "Update NEWS, bump version number." Revert "Revert "Update NEWS, bump version number."" Remove the 1024 bytes limit per PCRE reference, by using Fix incorrect AdditionalData assignement in spamassassin ruleset. Whitespace police. Fix leak introduced in commit [10495]. Code simplification, the Make sure we destroy all data associated with the PCRE plugin Fix invalid logfile modification alert that could be triggered On logfile consistency alert, do not re-analyze the whole file. Implement slighly modified Nagios ruleset fixes, allow Remove successful/failure keyword from classification (use completion). Remove successful/failure keyword from classification (use completion). Remove successful/failure keyword from classification (use completion). Whitespace police. Remove obsolete headers inclusion. Update GnuLib code, include pathmax module. Include pathmax.h Use PATH_MAX. Build system update, compile with relro. Update NEWS, bump version number. Fix undefined reference when FAM is not available. Update NEWS, bump version number Fix wrong installation path, thanks to Steve Grubb <[email protected]> Update NEWS, bump version number. Add missing 'ignored' file to the distribution. ModSecurity ruleset rewrite, by Peter Vrabec <[email protected]> and Normalize some classification: introduce Remote Login, and Credentials Change. New rulesets for FreeBSD su attempts, thanks Alexander Afonyashin <[email protected]> Add make check. Small fixes. Add su.rules to the build. Add additional prefix-regex to deal with apache error_log file format, Regression test correction. Update GnuLib code, include unit-tests. Remove deprecated header inclusion. Build/run GnuLib unit tests. Update NEWS, bump version. Update build files. Include GnuLib strsep module, fix #309. Remove deprecated header inclusion. Win32 compatibility fixes. Remove deprecated header inclusion. Add missing modules required for complete portability: fnmatch-gnu, Use GnuLib time.h off_t to 64 bits integer, fix win32 warnings. Make a difference between WIN32 and Cygwin. Add missing GnuLib buildir include path. Fix URL. Deprecate Gamin/FAM support in favor of libev. The previous implementation ModSecurity ruleset update, by Daniel Kopecek <[email protected]> Embed libev. Remove deprecated 'FAM support' output. Fix warnings by using ev_statdata typedef. GnuLib code update. Update NEWS, bump version. Match Authentication Rejected message even thought the server field Fixes possible off by one when parsing variable reference number. Thanks Update autogenerated INSTALL file. Remove un-needed check that would always evaluate to TRUE. Thanks Update for libtool 2.x compatibility. New PPP/PPTPD/L2TP ruleset, by Alexander Afonyashin <[email protected]>, Whitespace police. Install ppp.rules. This simplify the whole regular expression handling a lot, making the Upgrade to libev 3.53. Fix extern triggered warning. Use git.mk for automatic .gitignores file generation. Update to libev 3.6 Whitespace police Fix possible uninitialized read Fix signature parsing error due to missing ";" The Prelude-LML UDP server is now fully IPV6 compatible Ability to provides static IDMEF template from defined log format Update GnuLib code Update autogenerated files IPv6 compatible address detection Remove libmissing.h dependency Automatic gitignore generation for GnuLib files Warn the user in case the PCRE vector is too small Automatic ChangeLog generation Update NEWS, bump version cvs2svn (1): This commit was generated by cvs2svn to compensate for changes in r2358, turpeau (1): Initial revision uid1014 (1): *** empty log message *** _______________________________________________ Prelude-cvslog site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-cvslog