Showing posts with label AlienVault. Show all posts
Showing posts with label AlienVault. Show all posts

Thursday, 29 June 2017

AlienVault v5.4 Addresses 72 vulnerabilities

Several vulnerabilities were discovered in the underlying OS packages in AlienVault USM Appliance and OSSIM v5.3.7 and earlier. All of the vulnerabilities below have been confirmed and fixed in the AlienVault v5.4. AlienVault encourages customers to upgrade all AlienVault appliances to eliminate the vulnerabilities.

See the v5.4 release notice for details on the release.

Wednesday, 5 October 2016

LDAP Authentication issues in USM and OSSIM v5.3.2

If you are using LDAP authentication for your OSSIM or USM installation you may want to hold off the v5.3.2 upgrade.

In a recent message from AlienVault, an issue has been detected during the password reset process post upgrade.  The Password reset process was initiated to improve the security of password storage within OSSIM and USM, however this process is not working correctly for LDAP authentication.

LDAP Authentication issues in USM and OSSIM v5.3.2

If you are using LDAP authentication for your OSSIM or USM installation you may want to hold off the v5.3.2 upgrade.

In a recent message from AlienVault, an issue has been detected during the password reset process post upgrade.  The Password reset process was initiated to improve the security of password storage within OSSIM and USM, however this process is not working correctly for LDAP authentication.

Friday, 30 September 2016

Collecting McAfee ePO threat data using AlienVault OSSIM

If you are using AlienVault OSSIM you can collect ePO Threat Data and add it to your SIEM Security Events.

AlienVault have already development a database plugin to connect to the ePO Database, collect and parse the data into the OSSIM Database, but I have struggled to get this to work with our MS-SQL Database cluster, resulting in 'ParserDatabase [INFO]: Can't connect to MS-SQL database' errors.

The steps for enabling the plugin and collecting the data are:

  • Enabling the Plugin
  • Creating a local configuration file
  • Configuring the database connection
  • Troubleshooting connection errors