Skip to content

Releases: CISOfy/lynis

Lynis 2.5.7

29 Oct 16:07
2.5.7
be82d80
Compare
Choose a tag to compare

Lynis 2.5.7 (2017-10-29)

Changes:

  • Update of Portuguese translation
  • Added --silent as alias for --quiet
  • Reduced screen output when running non-privileged
  • IsRunning function now allows full name process match

Lynis 2.5.6

27 Oct 11:02
2.5.6
858f849
Compare
Choose a tag to compare

Lynis 2.5.6 (2017-10-27)

Changes:

  • Added additional keywords for banners
  • DirectAdmin extensions
  • Enhancements to process detection
  • Spanish translation extended
  • Extended HP-UX support
  • Only show relevant messages in report

Tests:

  • [NETW-2705] - Allow local resolvers to bypass requirement for 2+ name servers
  • [SSH-7408] - Define default 'delayed' compression as a sane value for SSH tests
  • [SHLL-6220] - Improved detection of shell settings

Lynis 2.5.5

07 Sep 08:37
2.5.5
daeec98
Compare
Choose a tag to compare

Lynis 2.5.5 (2017-09-07)

Changes:

Minor release to solve errors on screen

Tests:

  • CRYP-7902 - certificate validation changed

Lynis 2.5.4

05 Sep 11:51
2.5.4
72dc0de
Compare
Choose a tag to compare

Lynis 2.5.4 (2017-09-05)

Changes:

  • Improve systemd detection
  • Detect Linux Mint version
  • Older versions of Mac OS X are detected as well
  • Norwegian translation added
  • PAM plugin extended

Tests:

  • CRYP-7902 - certificate validation changed
  • FIRE-4508 - Improved screen output
  • PKGS-7380 - NetBSD vulnerability detection adjusted
  • TOOL-5002 - Improved detection of Ansible directories and files

Lynis 2.5.3

17 Aug 12:32
2.5.3
83da68f
Compare
Choose a tag to compare

Lynis 2.5.3 (2017-08-17)

Changes:

  • DirectAdmin location added
  • Small adjustments to text
  • Enhanced detection for LXC and LXC
  • Added /opt/apache as a target location
  • Default log directory set for HP-UX
  • Screen output improvements

Tests:

  • CRYP-7902 - Prevent test from showing error on screen
  • FILE-6310 - Detection of mount point now match exact name
  • HRDN-7230 - Show single line when no malware scanner was detected
  • NETW-3006 - Updated detection of MAC addresses on Linux
  • PKGS-2379 - Improvement for OpenBSD usage of PHP suhosin
  • TOOL-5002 - Detection capabilities for Ansible added

Lynis 2.5.2

10 Jul 14:18
2.5.2
5a66eb8
Compare
Choose a tag to compare

Lynis 2.5.2 (2017-07-10)

Changes:

  • Support for PHP on CloudLinux
  • Check for presence of locale binary
  • Suhosin detection improvements
  • Generic code improvements
  • Changed 'lynis audit system remote' routine
  • Support for macOS High Sierra
  • French translation updated

Lynis Enterprise:

  • Allow 'tags' and 'system-customer-name' to be specified via Lynis client

Tests:

  • CONT-8102 - Check for dockerd instead of docker -d
  • FIRE-4594 - Check for presence Advanced Policy Firewall (APF)
  • PKGS-2379 - New test for PHP suhosin extension status
  • PKGS-7370 - Only use debsums on Debian
  • KRNL-6000 - Added kernel.dmesg_restrict testing

Lynis 2.5.1

31 May 13:58
2.5.1
1be5154
Compare
Choose a tag to compare

Lynis 2.5.1 (2017-05-31)

Changes:

  • Hebrew translation by Dolev Farhi
  • Improved detection of SSL certificate files
  • Minor changes to improve logging and results

Tests:

  • BOOT-5104 - Added support for macOS
  • FIRE-4524 - Determine if CSF is in testing mode
  • HTTP-6716 - Improved log message

Lynis 2.5.0

03 May 09:06
2.5.0
d012f81
Compare
Choose a tag to compare

During the development of this release, the project got informed about a flaw that possibly could be abused by a local attacker. Even with the small risk of success, upgrading is highly recommended. See details on CVE-2017-8108

This release is a special maintenance release with focus on cleaning up the code for readability and future expansion.

Changes:

  • Use ROOTDIR variable instead of fixed paths
  • Introduction of IsEmpty and HasData functions for readability of code
  • Renamed some variables to better indicate their purpose (counting, data type)
  • Removal of unused code and comments
  • Deleted unused tests from database file
  • Correct levels of identation
  • Support for older mac OS X versions (Lion and Mountain Lion)
  • Initialized variables for more binaries
  • Additional sysctls are tested

Tests:

  • MALW-3280 - Extended test with Symantec components
  • PKGS-7332 - Detection of macOS ports tool and installed packages
  • TOOL-5120 - Snort detection
  • TOOL-5122 - Snort configuration file

Lynis 2.4.8

29 Mar 15:10
2.4.8
Compare
Choose a tag to compare

Lynis 2.4.8 (2017-03-29)

Changes:

  • More PHP paths added
  • Minor changes to text
  • Show atomic test in report

Tests:

  • MAIL-8820 - New Postfix configuration check
  • TOOL-5002 - Extended Puppet detection

Lynis 2.4.7

22 Mar 10:54
Compare
Choose a tag to compare

Lynis 2.4.7 (2017-03-22)

Changes:

  • Minor code cleanups

Tests:

  • BANN-7126 - Added more words to test for
  • CUPS-2308 - Improve logging for CUPS configuration test, removed exception handler
  • HTTP-6641 - Support detection for Apache module mod_reqtimeout
  • PKGS-7388 - Minor change to detect security repositories