General

New cxs v3.20

Changes:

  • Changed –options [s] to be –[no]sversionscan (Script Version Scanning) to make it independent of –[no]exploitscan, allowing a fast scan for old script installs. This option is enabled by default. Use –nosversionscan to disable
  • Added the following to Script Version Scanning (see cxs POD):
    Typo3, Invision Power Board, WebCalendar, MyBB, Dolphin, SMF, OpenX Source, SugarCRM Community Edition, Contao CMS, PrestaShop, PHP-Fusion, phpPgAdmin, SquirrelMail, Roundcube, Kayako, osTicket
  • Added new –soptions [a] for –[no]sversionscan to report all versions of found scripts, not just old versions
  • Added new –soptions [d] for –[no]sversionscan to report the directory containing the script, not the trigger file
  • Exploit fingerprint definitions database additions

New csf v6.35

Changes:

  • Security fix with included cse when using inbuilt User Interface: prevent XSS due to malicious directory/file names

New cxs v3.13

Changes:

  • UI button style modifications
  • Added phpList, Moodle, Magento Community Edition and MediaWiki version checking to –options [s]
  • Modified POD to screen wrap HTML code more effectively

 

New csf v6.34

Changes:

  • Load DYNDNS and GLOBAL_DYNDNS from last known values when restarting csf instead of waiting for lfd to load the initial rules
  • Improved performance of file slurping
  • Cluster documentation correction in readme.txt
  • UI button style modifications
  • Added specific check for Spamhaus drop lists so that retrieval is never attempted beofer 2 hours elapses between attempts whether those retrieval attempts are successful or not
  • Improvements to SSHD regexes
  • Modified mod_security logging to include the last triggered rule id if present

New cxs v3.12

Changes:

  • Fixed cxs uninstaller removing csf UI files on cPanel installs
  • Added phpBB version checking to –options [s]. This requires the perl modules DBI and DBD::mysql to be installed
  • Added phpMyAdmin, Zen Cart, osCommerce and VirtueMart version checking to –options [s]

 

New cxs v3.11

Changes:

  • Added to RECOMMENDATIONS to still run a regular scan without –ctime [hours] to ensure new scan techniques and exploit signatures are used to check all existing files
  • Fixed directory creation on installation for unofficial DA plugin
  • Improved performance of file slurping and therefore scanning
  • Added new –options [s] that will search for a few common web script installations and report if older than the latest version on record. See documentation for more information
  • Exploit fingerprint definitions database additions

 

New cxs v3.10

Changes:

  • Changed –throttle [num] to prevent throttling triggering a –timemax [secs] timeout
  • Added detection for some PHP JPEG and TIFF EXIF exploits
  • Improvements to image and zip file type detection
  • Exploit fingerprint definitions database additions

New csf v6.33

Changes:

  • Modified LF_PERMBLOCK to perform IP lookup on blocked IP
  • Perform modprobe when using FASTSTART on server boot to ensure iptables modules are loaded
  • Modified migration detection for particularly old csf installations
  • Check that TAIL and GREP exist and are executable in UI

New cxs v3.09

Changes:

  • Improvements to Virtuozzo/OpenVZ system detection where /proc/vz/veinfo does not exist
  • Added TimeStamp to the top of the scan report
  • If /etc/csuibuttondisable exists then the UI buttons will revert for those that cannot cope with the themed ones