#197 |
Allow monitoring of shell command output
|
rainer
|
enhancement
|
major
|
2.6.4
|
main
|
#198 |
Kernel check tries reading inaccessible information, fails
|
rainer
|
defect
|
major
|
2.6.4
|
main
|
#199 |
Persist checkpoints for monitored logfiles across reboot
|
rainer
|
defect
|
major
|
2.6.4
|
main
|
#200 |
Support kernel check on Linux distributions without /dev/kmem
|
rainer
|
enhancement
|
major
|
2.7.0
|
main
|
#201 |
Support kernel check on Linux x86_64
|
rainer
|
enhancement
|
major
|
2.7.0
|
main
|
#202 |
Kernel modules don't get loaded in LSB init script
|
rainer
|
defect
|
major
|
2.7.0
|
main
|
#203 |
Compile error with --enable-login-watch and no pthreads
|
rainer
|
defect
|
major
|
2.7.0
|
main
|
#204 |
Catching SIGABRT seems not to work on AIX 5.3
|
rainer
|
defect
|
major
|
2.7.0
|
main
|
#205 |
Additional checks on user login
|
rainer
|
enhancement
|
major
|
2.7.0
|
main
|
#206 |
Configurable syslog priority for heartbeat messages
|
rainer
|
enhancement
|
major
|
2.7.0
|
main
|
#207 |
Server should be able to log client reports to prelude
|
rainer
|
enhancement
|
major
|
2.7.1
|
main
|
#208 |
The configure script doesn't recognize /dev/kmem
|
rainer
|
defect
|
major
|
2.7.1
|
main
|
#209 |
Check for pcre_dfa_exec (RHEL4 libpcre doesn't have it)
|
rainer
|
defect
|
major
|
2.7.1
|
main
|
#210 |
Can't specify arbitrary valid filenames in configuration file
|
rainer
|
defect
|
major
|
2.7.1
|
main
|
#211 |
samhain_kmem module doesn't compile on 2.6.18
|
rainer
|
defect
|
major
|
2.7.1
|
main
|
#213 |
Report who changed a file (Linux only, use Linux Audit System)
|
rainer
|
enhancement
|
major
|
2.8.0
|
main
|
#214 |
Check MS Windows registry
|
rainer
|
enhancement
|
major
|
2.8.0
|
main
|
#216 |
SeverityUserX doesn't work for X > 0
|
rainer
|
defect
|
major
|
2.7.2
|
main
|
#218 |
Big-/Little-endian cross verification of email signatures does not work
|
rainer
|
defect
|
major
|
2.7.2
|
main
|
#219 |
File download failure on SLES 11
|
rainer
|
defect
|
major
|
2.8.0
|
main
|
#220 |
Compile errors on Solaris 10 with --enable-logfile-monitor
|
rainer
|
defect
|
major
|
2.8.0
|
main
|
#221 |
Client/server communication fails if client hostname contains uppercase characters
|
rainer
|
defect
|
major
|
2.8.0
|
main
|
#222 |
Support IPv6
|
rainer
|
enhancement
|
major
|
2.8.0
|
main
|
#223 |
Compile error on AIX 5.3 and --enable-login-watch
|
rainer
|
defect
|
major
|
2.8.1
|
main
|
#224 |
User define tmp directory not created by 'make install'
|
rainer
|
defect
|
major
|
2.8.1
|
main
|
#225 |
Compile error with --with-kcheck=...
|
rainer
|
defect
|
major
|
2.8.1
|
main
|
#226 |
Missing files not handled correctly if secondary schedule is used
|
rainer
|
defect
|
major
|
2.8.1
|
main
|
#227 |
Incomplete documentation of secondary schedule
|
rainer
|
defect
|
major
|
2.8.1
|
main
|
#228 |
Null pointer dereference in configuration file handler for SetMailAlias
|
rainer
|
defect
|
major
|
2.8.1
|
main
|
#229 |
Malfunction on CentOS 4.8 with gcc 4.1.2
|
rainer
|
defect
|
major
|
2.8.2
|
main
|
#230 |
Deployment scripts use hardcoded temporary directory
|
rainer
|
defect
|
major
|
2.8.2
|
main
|
#231 |
Missing warning on invalid recursion depth
|
rainer
|
defect
|
major
|
2.8.2
|
main
|
#232 |
Option to skip checksumming for some files
|
rainer
|
enhancement
|
major
|
2.8.2
|
main
|
#233 |
Compile error on Windows/Cygwin
|
rainer
|
defect
|
major
|
2.8.3
|
main
|
#234 |
Spurious warnings about unsupported address family
|
rainer
|
defect
|
major
|
2.8.4
|
main
|
#235 |
Server reports error Cannot resolve socket peer IP ... peer=0.0.0.0
|
rainer
|
defect
|
major
|
2.8.3
|
main
|
#236 |
Samhain blocks on hanging NFS mounts
|
rainer
|
defect
|
major
|
2.8.3
|
main
|
#237 |
Potential deadlock in sh_hash_hashdelete()
|
rainer
|
defect
|
major
|
2.8.3
|
main
|
#238 |
Avoid mutex in sl_create_ticket()
|
rainer
|
enhancement
|
major
|
2.8.3
|
main
|
#239 |
Mutex in child after fork()
|
rainer
|
defect
|
major
|
2.8.3
|
main
|
#240 |
The samhain_kmem kernel module should be loaded earlier
|
rainer
|
enhancement
|
major
|
2.8.3
|
main
|
#241 |
Option --local for deploy.sh not sufficiently described in manual
|
rainer
|
defect
|
major
|
2.8.4
|
main
|
#242 |
Compile error on FreeBSD
|
rainer
|
defect
|
major
|
2.8.4
|
main
|
#243 |
samhain_hide build error: in Linux 2.6.33+, autoconf.h moved to linux/generated/
|
rainer
|
defect
|
major
|
2.8.4
|
main
|
#244 |
Timeout error in retry_lstat() not propagated
|
rainer
|
defect
|
major
|
2.8.4
|
main
|
#245 |
Explain how (not to) use quotes in log format for log monitoring
|
rainer
|
defect
|
major
|
2.8.4
|
main
|
#246 |
Add method to specify user-defined regex in APACHE log format
|
rainer
|
enhancement
|
major
|
2.8.4
|
main
|
#247 |
The port range for the open port check should be configurable
|
rainer
|
enhancement
|
major
|
2.8.4
|
main
|
#248 |
samhainadmin.pl option for location of secret keyring
|
rainer
|
enhancement
|
major
|
2.8.4
|
main
|
#249 |
Samhain hangs after reload when compiled with --enable-login-watch
|
rainer
|
defect
|
major
|
2.8.4
|
main
|
#250 |
Compile error if option --enable-udp is used
|
rainer
|
defect
|
major
|
2.8.5
|
main
|
#251 |
Compile error if option --with-prelude is used
|
rainer
|
defect
|
major
|
2.8.5
|
main
|
#253 |
Support /opt/local/bin in unix entropy gathering code
|
rainer
|
enhancement
|
major
|
2.8.5
|
main
|
#254 |
Kernel check not working on Ubuntu 8.04 x86_64
|
rainer
|
defect
|
major
|
2.8.5
|
main
|
#255 |
Improve protection against 'intruder on server' scenario
|
rainer
|
enhancement
|
major
|
2.8.5
|
main
|
#256 |
LogmonMarkSeverity using the wrong config handler
|
rainer
|
defect
|
major
|
2.8.5
|
main
|
#257 |
Error message can be uninitialized
|
rainer
|
defect
|
major
|
2.8.6
|
main
|
#258 |
samhain_kmem keeps name in lsmod
|
rainer
|
defect
|
major
|
2.8.6
|
main
|
#259 |
The --enable-db-reload option is broken
|
rainer
|
defect
|
major
|
2.8.6
|
main
|
#261 |
Show which policy is applied to checked files when verbose logging is in use
|
rainer
|
enhancement
|
major
|
2.8.6
|
main
|
#262 |
Typo in logrotate script listing in the manual
|
rainer
|
defect
|
major
|
2.8.6
|
main
|
#263 |
log correlation may not work
|
rainer
|
defect
|
major
|
2.8.6
|
main
|
#264 |
Add a deadtime for correlate rules to avoid multiple reports
|
rainer
|
enhancement
|
major
|
2.8.6
|
main
|
#265 |
Add inotify support
|
rainer
|
enhancement
|
major
|
3.0.0
|
main
|
#266 |
kern_head does not work on 3.x kernels
|
rainer
|
defect
|
major
|
3.0.0
|
main
|
#267 |
Multiple compiler warnings with gcc 4.6.1
|
rainer
|
defect
|
major
|
3.0.0
|
main
|
#268 |
Insufficient server-side debugging information for IPv6
|
rainer
|
defect
|
major
|
3.0.0
|
main
|
#269 |
Issue with redefinition of policies
|
rainer
|
defect
|
major
|
3.0.0
|
main
|
#270 |
Unit tests for numeric key for AVL tree
|
rainer
|
enhancement
|
major
|
3.0.0
|
main
|
#271 |
Suid check may clash with prelink
|
rainer
|
defect
|
major
|
3.0.0
|
main
|
#273 |
Deadlock in sh_hash.c, check_files()
|
rainer
|
defect
|
major
|
3.0.1
|
main
|
#274 |
Compile errors
|
rainer
|
defect
|
major
|
3.0.1
|
main
|
#275 |
Bail out early on compile error
|
rainer
|
enhancement
|
major
|
3.0.1
|
main
|
#276 |
Update old versions of config.sub, config.guess
|
rainer
|
enhancement
|
major
|
3.0.1
|
main
|
#277 |
SIGPIPE in pmap_getmaps()
|
rainer
|
defect
|
major
|
3.0.1
|
main
|
#278 |
With --disable-ipv6, port check always checks all interfaces
|
rainer
|
defect
|
major
|
3.0.1
|
main
|
#279 |
Flip between null checksum and correct checksum with --enable-suidcheck
|
rainer
|
defect
|
major
|
3.0.1
|
main
|
#280 |
Memory leak in inotify related code
|
rainer
|
defect
|
major
|
3.0.1
|
main
|
#282 |
Compile issues on FreeBSD
|
rainer
|
defect
|
major
|
3.0.1
|
main
|
#283 |
O_NOATIME not seen in sh_files.c
|
rainer
|
defect
|
major
|
3.0.2
|
main
|
#284 |
Non-existent directive in config file template
|
rainer
|
defect
|
major
|
3.0.2
|
main
|
#285 |
NULL pointer dereference on systems without inotify
|
rainer
|
defect
|
major
|
3.0.2
|
main
|
#286 |
Combination of --with-gpg and --enable-nocl incorrectly handled by configure
|
rainer
|
defect
|
major
|
3.0.2
|
main
|
#287 |
samhain-install.sh in /var which might be mounted noexec
|
rainer
|
defect
|
major
|
3.0.2
|
main
|
#288 |
The --with-gpg option can cause startup to hang
|
rainer
|
defect
|
major
|
3.0.2
|
main
|
#289 |
Integer columns not initialized to handle unsigned 64bit in SQL DB
|
rainer
|
defect
|
major
|
3.0.2
|
main
|
#291 |
Compile error on Solaris 10
|
rainer
|
defect
|
major
|
3.0.3
|
main
|
#292 |
O_NOATIME not used on 64bit Linux
|
rainer
|
defect
|
major
|
3.0.3
|
main
|
#293 |
Potential deadlock with inotify + suid check
|
rainer
|
defect
|
major
|
3.0.3
|
main
|
#294 |
Minor issues with stealth mode
|
rainer
|
defect
|
major
|
3.0.3
|
main
|
#295 |
Deadlock if sh_processes_readps hangs
|
rainer
|
defect
|
major
|
3.0.3
|
main
|
#296 |
sh_processes_readps may hang with EAGAIN
|
rainer
|
defect
|
major
|
3.0.3
|
main
|
#297 |
Potential deadlock in sh_ext_popen()
|
rainer
|
defect
|
major
|
3.0.3
|
main
|
#298 |
Suppress messages about already deleted watches
|
rainer
|
defect
|
major
|
3.0.4
|
main
|
#299 |
Extraneous 'file not found' messages
|
rainer
|
defect
|
major
|
3.0.4
|
main
|
#301 |
Incorrect formatting template for registry check reports
|
rainer
|
defect
|
major
|
3.0.5
|
main
|
#302 |
Registry check init triggers database download
|
rainer
|
defect
|
major
|
3.0.5
|
main
|
#303 |
Add option SetReportFile for writing out summary after file check
|
rainer
|
enhancement
|
major
|
3.0.6
|
main
|
#304 |
The --enable-ptrace option does not work with threads
|
rainer
|
defect
|
major
|
3.0.6
|
main
|
#305 |
Erroneous message msg=<No such process>, subroutine=<sh_fInotify_init_internal>
|
rainer
|
defect
|
major
|
3.0.6
|
main
|