<feed xmlns='http://www.w3.org/2005/Atom'>
<title>pkgsrc/security/base, branch pkgsrc_2008Q1</title>
<subtitle>[no description]</subtitle>
<id>https://git.osdyson.ru/mirror/pkgsrc/atom?h=pkgsrc_2008Q1</id>
<link rel='self' href='https://git.osdyson.ru/mirror/pkgsrc/atom?h=pkgsrc_2008Q1'/>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/'/>
<updated>2007-11-25T18:09:53Z</updated>
<entry>
<title>- 11/20/2007 1.3.9 (anne)</title>
<updated>2007-11-25T18:09:53Z</updated>
<author>
<name>adrianp</name>
<email>adrianp</email>
</author>
<published>2007-11-25T18:09:53Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=fa791224697f305f6a46e82b3fcb0a269613a438'/>
<id>urn:sha1:fa791224697f305f6a46e82b3fcb0a269613a438</id>
<content type='text'>
- Update to Spanish -- David Gil
- Bug 1750697 base_header() is undefined fixed -- Juergen and Kevin Johnson
- Bug 1680965 sans lookup fails -- Jordan Wiens
- Updated Chinese language file -- Randy
- Added Sean Muller as the Project Manager -- Kevin Johnson
- Fixed error in contrib/base-rss.php -- Dan
- Added INSTALL and INSTALL.rtf files to docs directory -- Sean Muller
- Bug 1801192 XSS bug in BASE fixed -- Kevin Johnson and Sean Muller
- Bug 1760615 Sort order ignored -- Kevin Johnson and Jordan Weins
</content>
</entry>
<entry>
<title>Update to 1.3.8</title>
<updated>2007-10-20T23:22:08Z</updated>
<author>
<name>adrianp</name>
<email>adrianp</email>
</author>
<published>2007-10-20T23:22:08Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=8246f5893194836c5e1912d111416f6d1d3c93a8'/>
<id>urn:sha1:8246f5893194836c5e1912d111416f6d1d3c93a8</id>
<content type='text'>
- Fixed base_conf_contents.php to include colored alerts -- Jonathan W Miner
- Fixed base_main.php to remove an extra table and repair two column display -- Jonathan W Miner
- Added exit() to the redirect to fix security hole -- Jon Hart
- removed fpdf file to save room since we are not using them. -- Kevin Johnson
- Fixed bug #1723928 Top Right, Database and User not shown -- Kevin Johnson
- Added base_header wrapper, please use it instead of header if you're not sure -- GaRaGeD
- Fixed Bug #1675094 snort signature information links broken (really a hack!) -- Kevin Johnson
- Fixed Bug #1689885 Maybe need count(DISTINCT ip_src) to sort by IP correctly -- Kevin Johnson
- Fixed Bug #1649659 Use of archive DB seems broken in "karen" release -- Kevin Johnson
- Cleaned a warning -- Marek Cruz
- Spanish install guide -- Daniel Medianero
</content>
</entry>
<entry>
<title>Make it easier to build and install packages "unprivileged", where</title>
<updated>2007-07-04T20:54:31Z</updated>
<author>
<name>jlam</name>
<email>jlam</email>
</author>
<published>2007-07-04T20:54:31Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=45233ac07a4c6f9e80f4f9350cbb54ee23d8bd54'/>
<id>urn:sha1:45233ac07a4c6f9e80f4f9350cbb54ee23d8bd54</id>
<content type='text'>
the owner of all installed files is a non-root user.  This change
affects most packages that require special users or groups by making
them use the specified unprivileged user and group instead.

(1) Add two new variables PKG_GROUPS_VARS and PKG_USERS_VARS to
    unprivileged.mk.  These two variables are lists of other bmake
    variables that define package-specific users and groups.  Packages
    that have user-settable variables for users and groups, e.g. apache
    and APACHE_{USER,GROUP}, courier-mta and COURIER_{USER,GROUP},
    etc., should list these variables in PKG_USERS_VARS and PKG_GROUPS_VARS
    so that unprivileged.mk can know to set them to ${UNPRIVILEGED_USER}
    and ${UNPRIVILEGED_GROUP}.

(2) Modify packages to use PKG_GROUPS_VARS and PKG_USERS_VARS.
</content>
</entry>
<entry>
<title>Must be restricted to PHP4 as adodb is not available for PHP5.</title>
<updated>2007-06-30T13:47:38Z</updated>
<author>
<name>joerg</name>
<email>joerg</email>
</author>
<published>2007-06-30T13:47:38Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=0d2b89a4366c0c861d45ff07e3dc61e347e3d141'/>
<id>urn:sha1:0d2b89a4366c0c861d45ff07e3dc61e347e3d141</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Update to 1.3.6</title>
<updated>2007-05-18T23:27:22Z</updated>
<author>
<name>adrianp</name>
<email>adrianp</email>
</author>
<published>2007-05-18T23:27:22Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=e6e67628323a879fa65add4b2b89f3551fb69ddf'/>
<id>urn:sha1:e6e67628323a879fa65add4b2b89f3551fb69ddf</id>
<content type='text'>
Lots of updates but some highlights in brief:

- Added base64 encoding support for ICMP payload additional table in base_qr
y_alert.php -- Juergen Leising
- Changed input type of the password field to actually be password in setup3
.php -- Nikns
- Fixed Time error in searches -- Jeff Kell
- Added FQDN to display -- Jonathan W Miner
- Fixed issues with graphing -- Kevin J
 - Updated tons of HTML for complience -- Marek Cruz
</content>
</entry>
<entry>
<title>Update to 1.2.7</title>
<updated>2007-02-17T19:18:24Z</updated>
<author>
<name>adrianp</name>
<email>adrianp</email>
</author>
<published>2007-02-17T19:18:24Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=6a05175eff656f58cbcb2f00e93192d292eebcc3'/>
<id>urn:sha1:6a05175eff656f58cbcb2f00e93192d292eebcc3</id>
<content type='text'>
- 8/5/2006 1.2.7 (karen)
- Improved HTML &lt;table&gt; output in "base_qry_alert.php" -- Jonathan W Miner
- Remove message when 0 alerts -- Jonathan W Miner
- PrintBase64PacketPayload fix for payload lenght modulo = 0 -- Juergen Leising
- Added empty function to ProtocolFieldCriteria -- Kevin Johnson
- Fixed issue if sig_gid was empty -- Valter Santos
- Added SnortUnified, a perl replacement for Barnyard -- Jason Brvenik
- Updated base-rss.php -- Dan Michitsch
</content>
</entry>
<entry>
<title>Update to 1.2.5</title>
<updated>2006-10-23T18:19:45Z</updated>
<author>
<name>adrianp</name>
<email>adrianp</email>
</author>
<published>2006-10-23T18:19:45Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=af80512fcf13666fcb2f839cb8d411006794fdf3'/>
<id>urn:sha1:af80512fcf13666fcb2f839cb8d411006794fdf3</id>
<content type='text'>
- Added check for base_users and base_roles tables in base_main.php -
  Kevin Johnson
- Added . to VAR_PUNC to fix query issue - Kevin johnson
- Fixed issue with base_users table being required - Kevin Johnson
- Added search punctuation fix - Bruce Briggs
- Added FQDN to display -- Jonathan W Miner
- PrintForm() fixes - Bruce Briggs
- Settings for automatic expansion of the IP and Payload Criteria
  on Search screen - Bruce Briggs
- Save the fields entered on the Search screen for Back button proper
  refilling - Bruce Briggs
- RFE 1520185 Add support for managing last_cid - Eric Jacobsen
- Changed show_rows to 49 in base_conf.php.dist to fix IE 6/7 bug -
  Bruce Briggs
- Fixed link to FAQ - Juergen Leising
- Fixed VAR_BOOLEAN error and some typos in the footer - Eric Jacobsen
- Trivial patch to make base_stat_time.php use GET insted of POST to
  avoid the 'resend data' warning on refresh - GaRaGeD
- Added base-rss.php to the contrib section - Dan Michitsch
</content>
</entry>
<entry>
<title>Update distinfo missed in the update to 1.2.5</title>
<updated>2006-06-06T20:09:49Z</updated>
<author>
<name>adrianp</name>
<email>adrianp</email>
</author>
<published>2006-06-06T20:09:49Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=e5e52799b764f41e39aa768fafc32c7884054b61'/>
<id>urn:sha1:e5e52799b764f41e39aa768fafc32c7884054b61</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Update to 1.2.5</title>
<updated>2006-06-06T19:41:43Z</updated>
<author>
<name>adrianp</name>
<email>adrianp</email>
</author>
<published>2006-06-06T19:41:43Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=30d08e3ac2e994cc9f75e0fa851a87669eaabf1b'/>
<id>urn:sha1:30d08e3ac2e994cc9f75e0fa851a87669eaabf1b</id>
<content type='text'>
&gt; - 6/4/2006 1.2.5 (sarah)
&gt; - Added base64 encoding support for MAC addresses presented on the screen for FLoP extended database -- Juergen Leising
&gt; - Added base64 encoding support for rebuild of packet in pcap format for FLoP extended database -- Juergen Leising
&gt; - Fixed issue with Oracle and schema version in base_db.inc.php -- Nikns
&gt; - Fixed bug when alerts with sig references would fail to archive causing duplicates error -- Nikns
&gt; - Added base64 encoding support for ICMP payload additional table in base_qry_alert.php -- Juergen Leising
&gt; - Added check for PHP Logging Level against E_NOTICES in setup/index.php -- Nikns
&gt; - Fixed bug when certain preprocessor alerts would not be cached (for example arpspoof) -- Nikns
&gt; - Added setup/setup_db.inc.php with CreateBASEAG() to resolve redundancy in setup and base_db_setup.php -- Nikns
&gt; - Removed unnecessary and broken search index stuff from Create BASE AG, since schemas are already with them  -- Nikns
&gt; - Added XSSPrintSafe() (array safe htmlspecilchars() function) and made filterSql() use ADOdb qmagic() -- Nikns
&gt; - Changed input type of the password field to actually be password in setup3.php -- Nikns
&gt; - Filtered all unfiltred (mainly auth system stuff) $_POST and $_GET variables using filterSql() -- Nikns
&gt; - Santized all $_SERVER variables to be protected against XSS attacks -- Nikns
&gt; - Added "Clear Data Tables" option in base_maintenance.php and "Repair Tables" option to execute CreateBASEAG() -- Nikns
&gt; - Make use of FLoP's event reference. Signature name of alert which trigered "Tagged Packet" alert is shown too -- Nikns
&gt; - Updated chinese.lang.php -- Johnson Chiang
&gt; - Fixed Time error in searches -- Jeff Kell
&gt; - Fixed refresh issue with ~ directories -- Kevin Johnson
&gt; - Fixed cookie stored data and authentication scheme to correct Nikns' report on session forge issue -- GaRaGeD
&gt; - Updated link to the Nessus plug in DB -- Jonathan W Miner
&gt; - Fixed display after deleting alerts -- Bruce Briggs
&gt; - Fixed Bug #1466392 - Back button doesn't work after refresh. -- Juergen Leising
&gt; - Patches from jhart@spoofed.org to add missing ICMP and TCP type and codes - GaRaGeD
&gt; - add support for ICMP redirect decoding. - Jon Hart
&gt; - add decoding support for ICMP source quench and ICMP parameter problem - Jon Hart
&gt; - split up "flags" into DF and MF, much like tcp flags are currently handled - Jon Hart
</content>
</entry>
<entry>
<title>Rename all PHP 4 packages to php4-*, all PHP 5 packages to php5-*,</title>
<updated>2006-06-02T18:27:54Z</updated>
<author>
<name>joerg</name>
<email>joerg</email>
</author>
<published>2006-06-02T18:27:54Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=7fe8ce07cd12d22909180fe6f4c0bc28270c7451'/>
<id>urn:sha1:7fe8ce07cd12d22909180fe6f4c0bc28270c7451</id>
<content type='text'>
all PEAR packages to php?-pear-* and all Apache packages to ap13-* or
ap2-* respectively. Add new variables to simplify the Makefile
handling. Add CONFLICTS on the old names. Reset revisions of bumped
packages. ap-php will now depend on the default Apache and PHP version.
All programs using it have an implicit option of the Apache version
as well.

OK from jlam@ and adrianp@.
</content>
</entry>
</feed>
