Blog

SOPHOS UTM Up2Date 9.210 Released

 

Bugfixes

  • 27257 RED50 frequently reconnecting because configuring an Additional Address as UTM-Hostname is not supported
  • 27588 Unable to fetch POP3 accounts on iOS devices via POP3 Proxy
  • 27647 aua does not work with facility http while installing basic guard license
  • 27905 [BETA] log the mac addresses human readable with leading zeros in the packetfilter log
  • 28056 it’s not possible to view or download large log files in the webadmin because root partition is too small
  • 28400 Syslog not started after ipsbundle pattern installation
  • 28842 HA takeover if master reboots takes too much time
  • 28966 exceptions for Common Threat Filters do not work individually
  • 29412 Wireless Security Manager Role can’t accept new AP’s
  • 30800 [BETA] Some double byte characters aren’t filtered by DLP custom rule and AntiSpam Expressions filter.
  • 31083 Remote SSL VPN view is empty in printable configuration
  • 31340 rsyncd not started after switching to master mode (slave node hangs in syncing state)
  • 31387 ad-sid-sync.pl is executed even if AD sync is disabled
  • 31534 Wrong date in executive report
  • 31581 Up2date pattern rpm’s fails to install if hostname contains ‘/’ character.
  • 31859 Make http proxy handle uncompressed DNS responses
  • 32034 Full transparent AD SSO redirect URL request gets dropped by packetfilter
  • 32079 UMTS modem device hanging
  • 32097 High load after pattern installation [9.2]
  • 32190 Policy tester always returns “allowed” if warn page is proceeded once
  • 32391 UMTS interface doesn’t come up again after the speed changed from 4G to 3G
  • 32433 Not possible to delete VPN tunnel managed by SUM after use “cleanup object”
  • 32537 Guest login fails in transparent browser auth mode if “terms of use” confirmation is required
  • 32552 Quarantined mail will be quarantine again after release with the same reason
  • 32588 Can’t restore backup beacause of an undefined value
  • 32602 Web control policy not applying to endpoints
  • 32604 Special characters like umlauts didn’t work in passwords with reverse authentication for the WAF
  • 32607 Not possible to use virtual mac on lag interfaces
  • 32683 Can’t send a VPN Profile to the SMC if the Organization Name includes a umlaut
  • 32690 It’s not possible to use Subfolders for Remote Log File Archives over SMB on CIFS share
  • 32696 Hotspot: only one login possible per username for backend authentication hotspot
  • 32703 Multicast traffic problems after upgrading to SG430 and 9.204
  • 32711 Mail preview should display kyrilic or chinese chars too.
  • 32713 Console keyboard doesn’t work
  • 32726 Dashboard does not show Antivirus active protocols for HTTP/S
  • 32794 vpn-reporter.pl segfault in get_amazonvpc
  • 32805 NETDEV WATCHDOG: eth0 (tg3): transmit queue 0 timed out
  • 32832 Remote Syslog Server IPv6 support
  • 32837 vpn-reporter.pl segfaults, error 4 in libc-2.11.3.so
  • 32851 Device auth reports wrong client information
  • 32852 Any SSL traffic through HTTP proxy gets classified as “Sophos Portal” if a “Sophos Portal” AppCtrl rule exists
  • 32870 ad-sid-sync.pl fails to lookup trusted domains groups
  • 32940 SG550: Licensing does not work if module is relocated after installation
  • 32950 Configuring a whitelist in webfilter filter action appears in blacklist on UTM
  • 32957 winbindd died in kernel_vsyscall
  • 32969 Coredumps from reverseproxy after update to v9.206
  • 32972 IPS exception does not work for SID 18575
  • 32980 Remove RC4 from TLS ciphers in Exim
  • 33019 After upgrading to iOS 8 UTM does not recognize iOS anymore (Device-specific Authentication)
  • 33111 Group matching incorrect if user belongs to static and backend groups
  • 33277 [9.2] Add support for passthrough NTLM connection
  • 33307 Not possible to change TLS certificate
  • 33323 Using @ in hostname results in corrupt /etc/syslog-ng.conf
  • 33382 Config changes in IPsec remote access sometime causing a drop of established connections
  • 33429 AP100: Unable to authenticate with an SSID using a PSK with a dollar character
  • 33515 SMTP Vulnerability in SSL v3.0
  • 33516 POP3 Vulnerability in SSL v3.0
  • 33613 OS X HTTPS traffic identified as iOS

Microsoft: Patch MS14-066 führt zu Kompatibilitätsproblemen

Der Konzern empfiehlt betroffenen Nutzern, vier Zeichenfolgen in der Registry zu löschen. Dass Anwender betroffen sind, erkennen sie daran, dass bestimmte Prozesse und Dienste nicht mehr reagieren. Das Update, mit dem es mindestens eine als kritisch eingestufte Sicherheitslücke in seiner SSL/TLS-Implementierung schließt, zieht Microsoft jedoch nicht zurück.


Microsoft hat auf Probleme mit dem Sicherheits-Update MS14-066 hingewiesen und Anwendern Hinweise gegeben, wie eine behelfsmäßige Lösung aussehen kann. Das Update zieht der Konzern allerdings nicht zurück. Und er rät Nutzer auch nicht wie in früheren Fällen schon einmal zur Deinstallation des Patches.

Die mit dem Patch geschlossene Schwachstelle in Schannel, Microsofts Implementierung der SSL/TLS-Verschlüsselung, wird als sehr gravierend eingestuft. Nutzer sollten den Patch daher schnellstmöglich installieren. Bei einigen Nutzern treten danach aber schwerwiegende Fehler auf.

Laut Microsoft geschieht dies vor allem dann, wenn TLS 1.2 voreingestellt ist und das Aushandeln einer verschlüsselten Verbindung scheitert. “TLS-1.2-Verbindungen brechen ab, Prozesse und Dienste reagieren nicht mehr”, teilt das Unternehmen mit. Darüber hinaus findet sich im Ereignisprotokoll ein Eintrag mit der Event-ID 36887, wonach das TLS-Protokoll einen Fehlercode 40 erzeugt.

Die eigentliche Ursache für das Problem sind vier neue Zeichenfolgen für TLS, die Microsoft zusätzlich zu dem Fix für die Sicherheitslücke ausliefert. In einem Hilfeartikel empfiehlt Microsoft, diese Zeichenfolgen zu löschen. Dafür ist allerdings ein Eingriff in die Registrierungsdatenbank und ein Neustart von Windows erforderlich.

Den Patch zu deinstallieren empfiehlt sich nicht. Laut Microsoft kann ein Angreifer die damit geschlossene Lücke im Secure Channel (Schannel) nämlich mittels präparierter Netzwerkpakete ausnutzen und beliebigen Schadcode auf einem betroffenen System ausführen. Cisco weist zudem darauf hin, dass es sich trotz einer einzelnen CVE (CVE-2014-6321) um mehrere Schwachstellen handelt, die Microsoft beseitigt, darunter mehrere Pufferüberläufe und mindestens ein Bug, mit dem sich die Prüfung von Sicherheitszertifikaten umgehen lässt.

Microsoft musste in den vergangenen Monaten mehrere Updates aufgrund von Fehlern zurückziehen. Im August waren eine Sicherheitsaktualisierung und mehrere nicht sicherheitsrelevante Updates zunächst wieder entfernt und später neu veröffentlicht worden. Im September stellte es die Verteilung von Updates für Lync Server und OneDrive for Business vorübergehend ein.

Quelle: https://www.itespresso.de/2014/11/17/microsoft-patch-ms14-066-fuehrt-zu-kompatibilitaetsproblemen/

 

SOPHOS UTM Advantage (9.3) Soft-Release

Up2Date 9.300005 package description:

Remarks:
System will be rebooted
Configuration will be upgraded
Connected RED devices will perform firmware upgrade
Connected Wifi APs will perform firmware upgrade

News:
9.300 GA Release
.
Main Features:
Web Filter: Time Quotas
Web Filter: Policy Tagging
Web Filter: Selective HTTPS Filtering
SMTP/POP3 Proxy: Live AV Lookups in Sophos Antivirus
SMTP Proxy: SPX Self-Registration
SMTP Proxy: Support Attachments on Reply Portal
Network: Support for Multiple Bridges
Wifi: Various Hotspot Imporovements
Hardware: Support for new SG1xx series
.
Other Features:
Web Filter/SMTP Proxy: True File Type Detection
Application Control: IPv6 Support
ATP: Scan DNS Traffic going through UTM
Network: DHCPv6 Relay
Network: DHCP for VLAN Interfaces
Network: Allow VLAN and non-VLAN Interfaces on same Hardware
WAF: IP-based Access Control
WAF: Wildcard Extension
WAF: Username Prefix and Suffix
Support: Sophos Customer Support Secure Access to UTM

Bugfixes:
Fix [22468]: HTML5 iptables rule doesn’t match for IPSec-routed hosts
Fix [27257]: RED50 frequently reconnecting because configuring an Additional Address as UTM-Hostname is not supported
Fix [27588]: Unable to fetch POP3 accounts on iOS devices via POP3 Proxy
Fix [27750]: IPv6: Add support for DynDNS (Dyn & FreeDNS)
Fix [27905]: [BETA] log the mac addresses human readable with leading zeros in the packetfilter log
Fix [28056]: it’s not possible to view or download large log files in the webadmin because root partition is too small
Fix [28164]: OSPF and default route priority issues
Fix [28400]: Syslog not started after ipsbundle pattern installation
Fix [28842]: HA takeover if master reboots takes too much time
Fix [28966]: exceptions for Common Threat Filters do not work individually
Fix [29095]: [BETA] improve reporting filter naming for ATP
Fix [29412]: Wireless Security Manager Role can’t accept new AP’s
Fix [29963]: profile mode ‚monitor‘ does not work for Cookie signing
Fix [30008]: Problem with Remote IPsec access in case of ID type is ASN1 Distinguished Name and using static RAS IP
Fix [30254]: Import of non UTF-8 certificate breaks Webadmin access
Fix [30504]: Sometimes the sender_confd_profile is undefined in the profile object
Fix [30800]: [BETA] Some double byte characters aren’t filtered by DLP custom rule and AntiSpam Expressions filter.
Fix [30825]: IPv6: Add support for DHCPv6 ‚rapid commit‘
Fix [30851]: emailpki_generate_user fails if pkcs12 file contains a cert twice
Fix [31083]: Remote SSL VPN view is empty in printable configuration
Fix [31105]: DynDNS: Add support for interface strategy for FreeDNS
Fix [31116]: Performance and scalability improvements of HTTP proxy
Fix [31164]: [BETA] Routing domain wildcards aren’t working for SMTP profiles.
Fix [31337]: Too long hostname will break layout in dashboard
Fix [31340]: rsyncd not started after switching to master mode (slave node hangs in syncing state)
Fix [31373]: Form hardening exception match but doesn’t work
Fix [31387]: ad-sid-sync.pl is executed even if AD sync is disabled
Fix [31581]: Up2date pattern rpm’s fails to install if hostname contains ‚/‘ character.
Fix [31814]: nextgen-agent restarting permanently
Fix [31859]: Make http proxy handle uncompressed DNS responses
Fix [31992]: network range in network group shouldnt be allowed in allowed networks as per 21588
Fix [32012]: Postgres startup problem because pg_xlog files are missing
Fix [32034]: Full transparent AD SSO redirect URL request gets dropped by packetfilter
Fix [32079]: UMTS modem device hanging
Fix [32097]: High load after pattern installation [9.2]
Fix [32190]: Policy tester always returns „allowed“ if warn page is proceeded once
Fix [32237]: Release of IPsec Pool IPs not working
Fix [32286]: Sorting of APs in Webadmin
Fix [32391]: UTM interface doesn’t come up again after the speed changed from 4G to 3G
Fix [32433]: Not possible to delete VPN tunnel managed by SUM after use „cleanup object“
Fix [32537]: Guest login fails in transparent browser auth mode if „terms of use“ confirmation is required
Fix [32571]: [V9] Blocked HTTPS-Sites in Filter Action Mode ‚Blacklist‘ doesn’t match if Exception is matching on Categories
Fix [32588]: Can’t restore backup beacause of an undefined value
Fix [32602]: Web control policy not applying to endpoints
Fix [32604]: Special characters like umlauts didn’t work in passwords with reverse authentication for the WAF
Fix [32607]: Not possible to use virtual mac on lag interfaces
Fix [32683]: Can’t send a VPN Profile to the SMC if the Organization Name includes a umlaut
Fix [32690]: It’s not possible to use Subfolders for Remote Log File Archives over SMB on CIFS share
Fix [32696]: Hotspot: only one login possible per username for backend authentication hotspot
Fix [32703]: Multicast traffic problems after upgrading to SG430 and 9.204
Fix [32711]: Mail preview should display kyrilic or chinese chars too.
Fix [32713]: Console keyboard doesn’t work
Fix [32726]: Dashboard does not show Antivirus active protocols for HTTP/S
Fix [32794]: vpn-reporter.pl segfault in get_amazonvpc
Fix [32805]: NETDEV WATCHDOG: eth0 (tg3): transmit queue 0 timed out
Fix [32832]: Remote Syslog Server IPv6 support
Fix [32837]: vpn-reporter.pl segfaults, error 4 in libc-2.11.3.so
Fix [32851]: Device auth reports wrong client information
Fix [32852]: Any SSL traffic through HTTP proxy gets classified as „Sophos Portal“ if a „Sophos Portal“ AppCtrl rule exists
Fix [32870]: ad-sid-sync.pl fails to lookup trusted domains groups
Fix [32940]: SG550: Licensing does not work if module is relocated after installation
Fix [32950]: Configuring a whitelist in webfilter filter action appears in blacklist on UTM
Fix [32957]: winbindd died in kernel_vsyscall
Fix [32969]: Coredumps from reverseproxy after update to v9.206
Fix [32972]: IPS exception does not work for SID 18575
Fix [32980]: Remove RC4 from TLS ciphers in Exim
Fix [33019]: After upgrading to iOS 8 UTM does not recognize iOS anymore (Device-specific Authentication)
Fix [33095]: RED50 frequently reconnecting because configuring an Additional Address as UTM-Hostname is not supported [9.3]
Fix [33111]: Group matching incorrect if user belongs to static and backend groups
Fix [33277]: [9.2] Add support for passthrough NTLM connection
Fix [33307]: Not possible to change TLS certificate
Fix [33323]: Using @ in hostname results in corrupt /etc/syslog-ng.conf
Fix [33382]: Config changes in IPsec remote access sometime causing a drop of established connections
Fix [33429]: AP100: Unable to authenticate with an SSID using a PSK with a dollar character
Fix [33515]: SMTP Vulnerability in SSL v3.0
Fix [33613]: OS X HTTPS traffic identified as iOS

Trend Micro(TM) Worry-Free(TM) Business Security 9.0 Advanced and Standard Editions Service Pack 1

 

Trend Micro(TM) Worry-Free(TM) Business Security 9.0 Advanced and Standard Editions Service Pack 1

Enhancement 1: Outbreak Prevention – This Service Pack adds outbreak prevention protection against compressed executable files (packers).
Enhancement 2: Damage Cleanup Engine (DCE) – This Service Pack improves DCE performance.
Enhancement 3: Web Reputation Logs – This Service Pack enables Web Reputation logs to include information about processes that were running at the time each log was generated.
Enhancement 4: Log-on Screen – This Service Pack enables the Worry-Free Business Security console log on screen  to display the Security Server Version.
Enhancement 5: User Information – This Service Pack updates the information on the Worry-Free Business Security Console to better reflect how WFBS works
Link: https://files.trendmicro.com/documentation/readme/Readme_WFBS_90_WIN_SP1_new.txt

 

SOPHOS UTM Up2Date 9.209 Released 23-10-2014

A new Up2Date package for Sophos UTM is available as of today.
This update will disable SSLv3 support for many services to eliminate the risks from CVE-2014-3566 (POODLE).

Furthermore, we have introduced some additional fixes and improved the Up2Date client in anticipation of the ucoming 9.3 release.

Sophos UTM 9.209 – Details

News

Security Release
Disable SSLv3 support in many services to remove vulnerability to SSLv3 protocol vulnerability (“POODLE”, CVE-2014-3566)
Improve Up2Date client support for staged rollout of 9.3.
Updating to 9.209 will be required to be able to download the 9.2 to 9.3 Up2Date.

Remarks

System will be rebooted

Bugfixes

32930 Kernel Panic in 9.206 RIP nf_nat_setup_info+0x209/0x652 [nf_nat]
33159 Timezone update needed for Russia [v9]

IBM Domino 9.0.1 Fix Pack 2 Interim Fix 1

IBM Domino 9.0.1 Fix Pack 2 Interim Fix 1

  • CVE-2014-3566 – SSLv3 POODLE (Padding Oracle On Downgraded Legacy Encryption)
    Technote: https://www-01.ibm.com/support/docview.wss?uid=swg21687167
  • Add support for TLS 1.0 inbound
  • Add HTTP support for TLS 1.0
  • Remove weak SSL/TLS CipherSpecs
  • SSLv2 not disabled for IMAP
  • Enhancement Request: Support for TLS specifically for SMTP
  • XPage Mobile Controls Fail On iOS 8
  • Update Ckeditor to 4.4.3 or later
  • Enhancement: SHA-2 for certreq database
  • SHA-2 capable tools needed to manage Domino SSL keyring files

#HPC Systeme für #ANSYS Mechanical und #CFD mit #FUJITSU optimal konfigurieren

27. November 2014, HLRS Universität Stuttgart

Das Seminar richtet sich an Entwickler und Entscheider, die Simulationsprogramme im Bereich Strukturmechanik und Strömungssimulation anwenden und die beschleunigte Entwicklung und/oder Optimierung ihrer Produkte durch den Einsatz von High Performance Computing Systemen effektiv vorantreiben wollen.

Das ideale und aufeinander abgestimmte Zusammenspiel von CAE-Hardware und -Software ist ein wesentlicher Faktor für die Wirtschaftlichkeit. Deshalb erfahren Sie in diesem Seminar, welche Komponenten Sie benötigen und wie Sie diese optimal konfigurieren und nutzen.

Damit Sie die volle Rechnleistung bei Ihren Simulationsaufgaben erreichen, haben wir ausreichend Zeit eingeplant, um Ihnen einige Best-Practise-Tips mit auf den Weg zu geben.

Melden Sie sich hier an:

Anmeldung

As early as 1994, #Fujitsu developed the first x86-based industry-standard servers. #PRIMERGY

The development of Fujitsu servers is based on 60 years of experience in the mainframe development sector. As early as 1994, Fujitsu developed the first x86-based industry-standard servers. Since then Fujitsu has focused with its PRIMERGY servers on providing the innovations that customers expect from one of the leading IT infrastructure providers. Fujitsu PRIMERGY servers provide an unparalleled mixture of quality, efficiency and agility. The servers offer the most powerful and most flexible solutions on the market for companies of all sizes and all branches of industry, and for every type of application. They form a perfect basis for today’s requirements and future developments towards a business-centric data center.