Showing posts with label sslv3. Show all posts
Showing posts with label sslv3. Show all posts

Tuesday, October 28, 2014

New securityonion-web-page package fixes an issue in the Apache configuration

Yesterday, we released a new version of the securityonion-web-page package:
http://blog.securityonion.net/2014/10/new-securityonion-web-page-and.html

That package updated the Apache configuration to disable SSLv3.  However, the package used "sed" to update /etc/apache2/mods-enabled/ssl.conf, which is a symlink to /etc/apache2/mods-available/ssl.conf.  When sed operates on a symlinked file, it replaces the symlink with a copy of the file and then makes its modifications.  The broken symlink would have caused issues with future package updates, so I've released a new version of the securityonion-web-page package that fixes the symlink and updates the original file properly.

The new package version is as follows:

securityonion-web-page - 20141015-0ubuntu0securityonion7

Issues Resolved

Issue 640: securityonion-web-page: previous update broke ssl symlink
https://code.google.com/p/security-onion/issues/detail?id=629

Updating
The new packages are now available in our stable repo.  Please see the following page for full update instructions:
https://code.google.com/p/security-onion/wiki/Upgrade

Updating using "sudo soup"

Verifying that the update fixed the ssl.conf hyperlink

Verifying that SSLProtocol excludes SSLv3

Restarting Apache using "sudo service apache2 restart"

Verifying that SSLv3 is disabled using "openssl s_client -connect localhost:443 -ssl3"

Thanks
Thanks to David Zawdie for testing!

Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://code.google.com/p/security-onion/wiki/MailingLists

Commercial Support
Need commercial support?  Please see:
http://securityonionsolutions.com

Help Wanted
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:
https://code.google.com/p/security-onion/wiki/TeamMembers

We especially need help in answering support questions on the mailing list:
http://groups.google.com/group/security-onion

We also need help testing new packages:
http://groups.google.com/group/security-onion-testing

Thanks!

Monday, October 27, 2014

New securityonion-web-page and securityonion-elsa-extras packages provide more SSL visibility

A vulnerability in SSLv3 was recently announced (nicknamed POODLE):
http://googleonlinesecurity.blogspot.com/2014/10/this-poodle-bites-exploiting-ssl-30.html
http://www.wired.com/2014/10/poodle-explained/
https://isc.sans.edu/diary/OpenSSL%3A+SSLv3+POODLE+Vulnerability+Official+Release/18827
https://www.imperialviolet.org/2014/10/14/poodle.html

In response to this, we recently added some SSLv3 queries:
http://blog.securityonion.net/2014/10/new-securityonion-web-page-package-adds.html

Today, we're adding some additional ELSA queries to allow you to see your SSL traffic grouped by version or by cipher.

SSL - Top SSL Versions

SSL - Top SSL Ciphers

Today's update will also reconfigure Security Onion's Apache instance to no longer accept connections using SSLv3.

The new package versions are as follows:

securityonion-elsa-extras - 20131117-1ubuntu0securityonion45
securityonion-web-page - 20141015-0ubuntu0securityonion2

Issues Resolved

Issue 629: securityonion-web-page: disable SSLv3 in Apache ssl.conf
https://code.google.com/p/security-onion/issues/detail?id=629

Issue 627: securityonion-web-page: separate syslog-ng into program and host queries
https://code.google.com/p/security-onion/issues/detail?id=627

Issue 631: securityonion-web-page: collapse query categories by default
https://code.google.com/p/security-onion/issues/detail?id=631

Issue 634: securityonion-web-page: add queries for ssl_version and ssl_cipher
https://code.google.com/p/security-onion/issues/detail?id=634

Issue 633: securityonion-elsa-extras: parse ssl_version and ssl_cipher out of Bro ssl.log
https://code.google.com/p/security-onion/issues/detail?id=633

Updating
The new packages are now available in our stable repo.  Please see the following page for full update instructions:
https://code.google.com/p/security-onion/wiki/Upgrade

Updating with "sudo soup"

Restarting Apache with "sudo service apache2 restart"

Verifying that Apache no longer accepts SSLv3 connections

Thanks
Thanks to Lee Sharp for providing the new collapsible query categories!
Thanks to Eddy Simons and David Zawdie for testing!

Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://code.google.com/p/security-onion/wiki/MailingLists

Commercial Support
Need commercial support?  Please see:
http://securityonionsolutions.com

Help Wanted
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:
https://code.google.com/p/security-onion/wiki/TeamMembers

We especially need help in answering support questions on the mailing list:
http://groups.google.com/group/security-onion

We also need help testing new packages:
http://groups.google.com/group/security-onion-testing

Thanks!

Wednesday, October 15, 2014

New securityonion-web-page package adds queries to monitor SSLv3

A vulnerability in SSLv3 was recently announced (nicknamed POODLE):
http://googleonlinesecurity.blogspot.com/2014/10/this-poodle-bites-exploiting-ssl-30.html
http://www.wired.com/2014/10/poodle-explained/
https://isc.sans.edu/diary/OpenSSL%3A+SSLv3+POODLE+Vulnerability+Official+Release/18827
https://www.imperialviolet.org/2014/10/14/poodle.html

I've added a couple of ELSA queries to help you monitor your network for SSLv3:

SSL - Top SSLv3 DST IPs

The new package version is as follows:

securityonion-web-page - 20120722-0ubuntu0securityonion26

Issues Resolved

Issue 628: securityonion-web-page: add ELSA queries for SSLv3
https://code.google.com/p/security-onion/issues/detail?id=628

Updating
The new package is now available in our stable repo.  Please see the following page for full update instructions:
https://code.google.com/p/security-onion/wiki/Upgrade

Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://code.google.com/p/security-onion/wiki/MailingLists

Training
Tomorrow is the LAST day to sign up for the 3-day Security Onion class in Richmond VA!
https://security-onion-class-20141020.eventbrite.com/

Commercial Support
Need commercial support?  Please see:
http://securityonionsolutions.com

Help Wanted
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:
https://code.google.com/p/security-onion/wiki/TeamMembers

We especially need help in answering support questions on the mailing list:
http://groups.google.com/group/security-onion

We also need help testing new packages:
http://groups.google.com/group/security-onion-testing

Thanks!

Search This Blog

Featured Post

Security Onion 3.3.0 Hotfix 20260911 Now Available!

Earlier this week, we released Security Onion 3.3.0: https://blog.securityonion.net/2026/09/security-onion-330-now-available.html Today we a...

Popular Posts

Blog Archive