Skip to content

Releases: CISOfy/lynis

Lynis 2.6.7

09 Aug 13:20
2.6.7
50374ec
Compare
Choose a tag to compare

Lynis 2.6.7 (2018-08-09)

Changed

  • BOOT-5104 - Added busybox as a service manager
  • KRNL-5677 - Limit PAE and no-execute test to AMD64 hardware only
  • LOGG-2190 - Ignore /dev/zero and /dev/[aio] as deleted files
  • SSH-7408 - Changed classification of SSH root login with keys
  • Docker scan uses new format for maintainer value
  • New URL structure on CISOfy website implemented for Lynis controls

Lynis 2.6.6

06 Jul 13:09
2.6.6
46bb8c8
Compare
Choose a tag to compare

Lynis 2.6.6 (2018-07-06)

Improvements

Fixed

  • Under some condition no hostid2 value was reported
  • Solved 'extra operand' issue with tr command

Lynis 2.6.5

26 Jun 13:16
2.6.5
6e0ac57
Compare
Choose a tag to compare

Lynis 2.6.5 (2018-06-26)

Tests:

  • [MAIL-8804] - Exim configuration test
  • [NETW-2704] - Use FQDN to test status of a nameserver instead of own IP address
  • [SSH-7402] - Improved test to allow configurations with a Match block

Lynis 2.6.4

02 May 11:37
2.6.4
5300475
Compare
Choose a tag to compare

Lynis 2.6.4 (2018-05-02)

Changes:

  • Several contributions merged, including grammar improvements
  • Initial support for Ubuntu 18.04 LTS
  • Small enhancements for usage

Tests:

  • [AUTH-9308] - Made 'sulogin' more generic for systemd rescue shell
  • [DNS-1600] - Initial work on DNSSEC validation testing
  • [NETW-2704] - Added support for local resolver 127.0.0.53
  • [PHP-2379] - Suhosin test disbled
  • [SSH-7408] - Removed 'DELAYED' from OpenSSH Compression setting
  • [TIME-3160] - Improvements to detect step-tickers file and entries

Lynis 2.6.3

07 Mar 15:26
2.6.3
692dfe9
Compare
Choose a tag to compare

Lynis 2.6.3 (2018-03-07)

Changes:

  • Change in routine for host identifiers

Tests:

  • [CRYP-7902] - Do prevalidation for certificates before testing them
  • [HRDN-7222] - Enhanced compiler permission test
  • [NAME-4402] - Improved test to filter out empty lines
  • [PKGS-7384] - Changes to detect yum-utils package and related tooling

Plugins:

  • [PLGN-2680] - cron file permissions

Lynis 2.6.2

13 Feb 15:19
2.6.2
20e33c8
Compare
Choose a tag to compare

Lynis 2.6.2 (2018-02-13)

Changes:

  • Bugfix for Arch Linux (binary detection)
  • Textual changes for several tests
  • Update of tests database

Lynis 2.6.1

26 Jan 12:09
2.6.1
768446e
Compare
Choose a tag to compare

Lynis 2.6.1 (2018-01-26)

Changes:

  • Tests can have more than 1 required OS (e.g. Linux OR NetBSD)
  • Added 'system-groups' option to profile (Enterprise users)
  • Overhaul of default profile and migrate to new style (setting=value)
  • Show warning if old profile options are used
  • Improved detection of binaries
  • New group 'usb' for tests related to USB devices

Tests:

  • [FILE-6363] - New test for /var/tmp (sticky bit)
  • [MAIL-8802] - Added exim4 process name to improve detection of Exim
  • [NETW-3030] - Changed name of dhcp client name process and added udhcpc
  • [SSH-7408] - Restored UsePrivilegeSeparation
  • [TIME-3170] - Added chrony configuration file for NetBSD

Lynis 2.6.0

18 Jan 16:14
2.6.0
4f1f9bc
Compare
Choose a tag to compare

Lynis 2.6.0 (2018-01-18)

Changes:

  • Binary paths are now sorted
  • Greek language added
  • systemd detection improved
  • VirtualBox detection extended
  • Several code enhancements

Tests:

  • [PHP-2379] - Small enhancement to resolve error on screen in some cases
  • [MALW-3280] - Improved detection for BitDefender tooling

Lynis 2.5.9

12 Jan 14:31
2.5.9
332cc49
Compare
Choose a tag to compare

Lynis 2.5.9 (2018-01-12)

Changes:

  • Don't show upgrade notice when being quiet/silent
  • Added --noplugins as an alias to skip execution of plugins
  • Use PATH variable for path detection, with predefined list as a backup

Tests:

  • [KRNL-6000] Multiple values are now allowed per sysctl key
  • [KRNL-6000] Individual tests can be skipped (skip-test=KRNL-6000:)
  • [KRNL-6000] Solution text has been added

Lynis 2.5.8

28 Dec 11:52
2.5.8
117f3db
Compare
Choose a tag to compare

Changes:

  • Check for empty files improved on several locations
  • New allow-auto-purge setting in profile for short-lived systems
  • Additional checks for log and report file
  • Changes to support time synchronization in old and newer systemd releases
  • Enhanced output for systems other than Linux

Plugins:

  • New class (hardware) added and enabled in default profile