General

New cxs v2.54

Changes:
– Added logrotate configuration for cxswatch
– Include an example perl script that will disable directory access with a .htaccess file if a match is found using the –script [script] option: /etc/cxs/htaccessdisable.pl
– Modifications to cxs Watch daemon so that it no longer needs to completely restart when new daily detections are downloaded
– Always log if skipping directories in cxs Watch daemon due to –filemax [num]
– Fixed a problem with a false-positive in the php interpreter timeout
– Exploit regex definitions database additions
– Exploit fingerprint definitions database additions

New cxs v2.53

Changes:
– Timeout added for php interpreter during –decode ([D])
– Do not disable –viruscan if clamd not running in cxs Watch
– Exploit fingerprint definitions database additions

New cxs v2.52

Changes:
– cxs Watch will now fail to start or will terminate on VPS servers if /proc/sys/fs/inotify/max_user_watches is set too low
– Added error reporting if clamd fails to respond, but stop reporting clamd errors if too many consecutive errors occur
– Updated POD regarding the new csf option: LF_CXS

New csf v5.48

Changes:
– New option LF_QOS added which matches hits against the mod_qos Apache module
– New option LF_CXS added which matches hits against the mod_security Apache module rule for cxs if implemented

New cxs v2.51

Changes:
– Improved temporary file cleanup
– Change cxs UI to use /sbin/pidof to determine if the Watch daemon is stopped, starting or running. If /sbin/pidof does not exist, no status is shown
– Modification to prevent scan failure if FTP is down and –options [P] used
– Exploit fingerprint definitions database additions

New cxs v2.50

Changes:
– Improvements to the Fingerprint Matching system
– Exploit regex definitions database additions
– Exploit fingerprint definitions database additions

New csf v5.47

Changes:
– Improvements to non-core perl module loading
– Improvements to PT_LOAD Apache Status retrieval and messages
– Regex modifications to cater for Dovecot v2.1+
– On cPanel servers, block additional ports that exim uses in the WHM > Service Manager for RT_*_BLOCK

New cxs v2.49

Changes:
– Use temporary files when performing a virus scan during –decode ([D])
– Change all clamd STREAM to SCAN scanning
– Use a robust routine for creating random temporary files during –options [Z] (scanning within archives)
– Exploit fingerprint definitions database additions

New cxs v2.48

Changes:
– Allow a value of 0 for –Wrefresh which disables the functionality in the cxs Watch daemon
– Added new advanced PHP decoder for –decode ([D])
– Stop cxs Watch from following symlinks
– Exploit regex definitions database additions
– Exploit fingerprint definitions database additions