Michael Rash, Security Researcher

Software Release - psad-1.4.6

The 1.4.6 release of psad is ready for download. Here is an excerpt from the ChangeLog:
  • Added ENABLE_AUTO_IDS_REGEX and AUTO_BLOCK_REGEX to allow filtering on logging prefixes.
  • Added IPTABLES_PREREQ_CHECK to allow the administrator to control the frequency of Netfilter checks (for auto-block compatibility).
  • Added IGNORE_LOG_PREFIXES to allow certain log prefixes to be completely ignored by psad.
  • Added classification.config file from Snort-2.3.3 so that psad can assign danger levels based upon Snort rule class type. This is useful when also running fwsnort.
  • Added reference.config so that psad can include reference information in email alerts that are derived from attacks detected by fwsnort.