store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Sun May 19, 2013 4:29 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 18 posts ]  Go to page 1, 2  Next
Author Message
 Post subject: [asl-2.0] OSSEC HIDS 2.0
Unread postPosted: Fri Feb 27, 2009 6:13 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7418
Location: earth
Whats new in OSSEC HIDS 2.0:

-Added compiled rules

-Fixed bug on the Windows agent event log reader that was not
working properly when the message size was larger than 2048 *64 chars.

-Fixed alerting when the event log is cleared.

-Fixed su decoder
(Reported by Ricardo Stocco).

-Fixed bug on the Windows agent event log reader where non-standard logs
where failing the configuration test.

-Added option for agentless integrity checking on Linux.

-Added option for agentless integrity checking on BSD systems.

-Added option for generic diffs using the agentless monitoring.

-Ignoring /dev/oprofile alerts on Ubuntu
(reported by gary <garyyuen at gmail.com> ).

-Fixed scan_day value on syscheck that was not working properly
(patch by Matthias Schmidt).

-Added ossec-reported tool to generate text-based reports.

-Fixed bug on syscheckd where it would stop working if ever found a link to a socket or device
(reported by Matthias Schmidt).

-Fixed bug on the installation script that was not disabling rootcheck properly
(by Meir Michanie).

-Added agentless integrity checking on Cisco devices (routers, switches and firewalls)
(thanks to Marcus Maciel for the help and script samples).

-Fixed false positives on some pix rules.

-Added support for Yum rules
(thanks to Michael Starks for the help).

-Added dutch translation
(thanks to Martijn de Boer).

-Added support for picviz
(thanks to Sebastien Tricaud).

-Fixed support for wildcards on logcollector. It was not working if
it was the first entry in the file
(Thanks to Nicolas Arias for the report).

-Fixed MySQL output support that was dying if the server went
down
(thanks to Scott Shinn for the reporting and help debugging it).

-Fixing output of rootcheck_control that was reporting the wrong
ip address
(thanks to Aaron Bliss for the report).

-Added CentOS 5.2 to the RHEL5 CIS checks.

-Added scan_on_start option to rootcheck.

-Fixed init scripts for Mac OSX 10.5
(reported by Martijn de Boer).

-Updated checkpoint decoder
(patch by Dean Takemori).

-Removed false positive on FreeBSD caused by rootcheck looking at libproc.a
(reported by moto kawasaki).


Upgrading to OSSEC-HIDS 2.0:

Step 1) yum upgrade ossec-hids

Step 2) asl -s -f


Top
 Profile  
 
 Post subject: Re: [asl-2.0] OSSEC HIDS 2.0
Unread postPosted: Thu Mar 05, 2009 1:00 pm 
Offline
Forum Regular
Forum Regular

Joined: Sat Aug 12, 2006 8:14 am
Posts: 117
hey
i get this (i dont have testing or bleeding active)

Resolving Dependencies
--> Populating transaction set with selected packages. Please wait.
---> Downloading header for ossec-hids to pack into transaction set.
ossec-hids-2.0-2.el4.art. 100% |=========================| 11 kB 00:00
---> Package ossec-hids.i386 0:2.0-2.el4.art set to be updated
---> Downloading header for ossec-hids-server to pack into transaction set.
ossec-hids-server-2.0-2.e 100% |=========================| 18 kB 00:00
---> Package ossec-hids-server.i386 0:2.0-2.el4.art set to be updated
--> Running transaction check
--> Processing Dependency: ossec for package: asl
--> Finished Dependency Resolution
Error: Missing Dependency: ossec is needed by package asl
[root@star yum.repos.d]#

greets
zek


Top
 Profile  
 
 Post subject: Re: [asl-2.0] OSSEC HIDS 2.0
Unread postPosted: Thu Mar 05, 2009 1:24 pm 
Offline
Forum Regular
Forum Regular

Joined: Mon Apr 14, 2008 8:29 am
Posts: 278
Location: Rhode Island
Same here also.

[root@inet3170 ~]# yum update ossec-hids
Loading "fastestmirror" plugin
Loading mirror speeds from cached hostfile
* plesk: 3es.atomicrocketturtle.com
* base: chi-10g-1-mirror.fastsoft.net
* updates: repo.genomics.upenn.edu
* asl-2.0: atomicorp.com
* addons: mirrors.greenmountainaccess.net
* extras: mirror.myriadnetwork.com
* atomic: www6.atomicorp.com
Setting up Update Process
Resolving Dependencies
--> Running transaction check
--> Processing Dependency: ossec-hids.pp for package: ossec-hids-server
--> Processing Dependency: ossec for package: asl
--> Processing Dependency: ossec-hids = 2.0-1.el5.art for package: ossec-hids-server
---> Package ossec-hids.i386 0:2.0-2.el5.art set to be updated
--> Running transaction check
--> Processing Dependency: ossec for package: asl
---> Package ossec-hids-server.i386 0:2.0-2.el5.art set to be updated
--> Finished Dependency Resolution
Error: Missing Dependency: ossec is needed by package asl


Top
 Profile  
 
 Post subject: Re: [asl-2.0] OSSEC HIDS 2.0
Unread postPosted: Thu Mar 05, 2009 2:19 pm 
Offline
Forum User
Forum User

Joined: Wed Sep 05, 2007 12:37 pm
Posts: 34
+3

Code:

Loading "repoheader" plugin

repo id         repo name                           status
=======         =========                           ======
4PSA            4PSA                                enabled
addons          CentOS-4 - Addons                   enabled
asl-2.0         Atomicorp - 4 - Atomic Secured Linu enabled
atomic          CentOS / Red Hat Enterprise Linux 4 enabled
base            CentOS-4 - Base                     enabled
extras          CentOS-4 - Extras                   enabled
update          CentOS-4 - Updates                  enabled

Setting up Update Process
Setting up repositories
Reading repository metadata in from local files
Resolving Dependencies
--> Populating transaction set with selected packages. Please wait.
---> Package ossec-hids.i386 0:2.0-2.el4.art set to be updated
---> Package ossec-hids-server.i386 0:2.0-2.el4.art set to be updated
--> Running transaction check
--> Processing Dependency: ossec for package: asl
--> Finished Dependency Resolution
Error: Missing Dependency: ossec is needed by package asl




Top
 Profile  
 
 Post subject: Re: [asl-2.0] OSSEC HIDS 2.0
Unread postPosted: Thu Mar 05, 2009 4:49 pm 
Offline
Forum Regular
Forum Regular

Joined: Tue Jul 15, 2008 2:38 pm
Posts: 704
Location: Sweden
+4


Top
 Profile  
 
 Post subject: Re: [asl-2.0] OSSEC HIDS 2.0
Unread postPosted: Thu Mar 05, 2009 5:38 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7418
Location: earth
-4, clear your caches and update to 2.0-3


Top
 Profile  
 
 Post subject: Re: [asl-2.0] OSSEC HIDS 2.0
Unread postPosted: Thu Mar 05, 2009 7:05 pm 
Offline
Forum Regular
Forum Regular

Joined: Sat Aug 12, 2006 8:14 am
Posts: 117
yes, now its ok, thanks


Top
 Profile  
 
 Post subject: Re: [asl-2.0] OSSEC HIDS 2.0
Unread postPosted: Fri Mar 06, 2009 9:01 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7418
Location: earth
Cool, sorry about that one. That was QA'd against ASL 2.1, which doesn't have a Requires: on ossec. ASL 2.0 does, so there was the problem.


Top
 Profile  
 
 Post subject: Re: [asl-2.0] OSSEC HIDS 2.0
Unread postPosted: Tue Sep 01, 2009 7:01 pm 
Offline
Forum User
Forum User

Joined: Sat Jun 07, 2008 11:09 pm
Posts: 53
Is there any solution to the dependency problem?

Error: Missing Dependency: ossec is needed by package asl


I tried the following which did not help:

yum clean all
yum --disablerepo=rpmforge update

_________________
mrwilson

now using asl-2.2-1.el5.art on Centos 5 64-bit - Plesk 9.2.2


Top
 Profile  
 
 Post subject: Re: [asl-2.0] OSSEC HIDS 2.0
Unread postPosted: Tue Sep 01, 2009 7:12 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3242
Location: Chantilly, VA
2.2 is out, and its an upgrade - so try upgrade instead of update.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: [asl-2.0] OSSEC HIDS 2.0
Unread postPosted: Tue Sep 01, 2009 9:33 pm 
Offline
Forum User
Forum User

Joined: Sat Jun 07, 2008 11:09 pm
Posts: 53
Thank you, I tried upgrade, but I still get

Error: Missing Dependency: ossec is needed by package asl

_________________
mrwilson

now using asl-2.2-1.el5.art on Centos 5 64-bit - Plesk 9.2.2


Top
 Profile  
 
 Post subject: Re: [asl-2.0] OSSEC HIDS 2.0
Unread postPosted: Wed Sep 02, 2009 7:11 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7418
Location: earth
You get that when you run: "yum upgrade" ?


Top
 Profile  
 
 Post subject: Re: [asl-2.0] OSSEC HIDS 2.0
Unread postPosted: Wed Sep 02, 2009 8:24 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3242
Location: Chantilly, VA
Make sure also run:

yum clean all

yum upgrade

And if that doesnt work, please post the output from those commands, along with:

rpm -qa | grep "asl|ossec"

yum --version

your repo setups in /etc/yum.repos.d

and confirm what distro you are running.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: [asl-2.0] OSSEC HIDS 2.0
Unread postPosted: Wed Sep 02, 2009 8:43 am 
Offline
Forum User
Forum User

Joined: Sat Jun 07, 2008 11:09 pm
Posts: 53
Quote:
You get that when you run: "yum upgrade" ?


Yes

Quote:
Make sure also run:

yum clean all


Yes I did that

Quote:
rpm -qa | grep "asl|ossec"


[root@wmx-us-08 yum.repos.d]# rpm -qa | grep asl
cyrus-sasl-2.1.22-4
asl-2.0.7-3.el5.art
cyrus-sasl-plain-2.1.22-4
cyrus-sasl-lib-2.1.22-4
asl-web-gui-0.13-1.el5.art
cyrus-sasl-plain-2.1.22-4
cyrus-sasl-2.1.22-4
cyrus-sasl-devel-2.1.22-4
cyrus-sasl-lib-2.1.22-4

[root@wmx-us-08 yum.repos.d]# rpm -qa | grep ossec
ossec-hids-1.5-3.el5.art
ossec-hids-server-1.5-3.el5.art


Quote:
yum --version

3.2.8

Quote:
your repo setups in /etc/yum.repos.d


-rw-r--r-- 1 root root 571 Sep 1 15:37 asl.repo (disabled)
-rw-r--r-- 1 root root 1.2K Dec 29 2008 atomic.repo priority=1
-rw-r--r-- 1 root root 2.1K Aug 20 2008 CentOS-Base.repo priority=3
-rw-r--r-- 1 root root 2.0K Aug 20 2008 CentOS-Base.repo.zipservers priority=3
-rw-r--r-- 1 root root 626 Jun 19 2008 CentOS-Media.repo (disabled)
-rw-r--r-- 1 root root 693 Aug 19 2008 mirrors-rpmforge
-rw-r--r-- 1 root root 189 Dec 29 2008 plesk.repo
-rw-r--r-- 1 root root 440 Aug 19 2008 rpmforge.repo priority=10

Quote:
and confirm what distro you are running.

CentOS release 5.2 (Final)

_________________
mrwilson

now using asl-2.2-1.el5.art on Centos 5 64-bit - Plesk 9.2.2


Top
 Profile  
 
 Post subject: Re: [asl-2.0] OSSEC HIDS 2.0
Unread postPosted: Wed Sep 02, 2009 11:24 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7418
Location: earth
Quote:
-rw-r--r-- 1 root root 571 Sep 1 15:37 asl.repo (disabled)


If the repo is disabled you're not going to be able to get the updates from it. I would go in there and re-enable it before you run yum upgrade again.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 18 posts ]  Go to page 1, 2  Next

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group