Snare for Linux Version 1.8.0/2.1.0
-------------------
Copyright (c) 1999-2012 InterSect Alliance Pty Ltd.

Snare is a program that facilitates the central collection and processing of
Windows Event Log information. All three primary event logs
(Application, System and Security) are monitored, and the secondary logs
(DNS, Active Directory, and File Replication) are monitored if available. Event
information is converted to tab delimited text format, then delivered over
UDP to a remote server.

Snare is currently configured to deliver audit information to a SYSLOG server
running on a remote (or local) machine. A configuration utility allows you to set
the appropriate syslog target and priority, as well as the target DNS or IP address
of the server that should receive the event information. It should be noted that many
syslog servers are not designed to cope with the sorts of volume of data that multiple
snare agents can potentially generate.
-------------------------------------------------------------------------

* Wed Aug 15 2012 George Cora
- Bug fixes for the remote control page
- Allow Installer to use bash instead of sh
- Redefine gcc compilation order
- Do not overwrite existing snare.conf file if present during installation
- Include ability to view status in remote control page
- Use systemd for audit/snare restart/stop/start, if available
- Bug fixes in defining audit settings
- Bug fix to identify correct syscall architecture in auditctl (Thanks to Wayne Haig for this item)
- Include a README file

* Tue Aug 8 2011 David Mohr
- Updated micro web server authentication (digest)
- Added html entity stripping to the /events web page to prevent XSS
- Removed MD5 string from /remote web page
- Added cookie support for Change Tokens
- Added POST support to micro web server
- Added pre-submit MD5 hashing of remote access password in /remote web page
- Extended Change Token timeout
- Updated auditctl commands to support updated "-i" flag
- Updated SELinux policy module
- Thanks to Andrew Brooks, of Halock Security Labs for identifying items 2, 3 and 4

* Tue Jul 5 2011 David Mohr
- Bug fix for authentication event collection
- Update SELinux policy module

* Sat Dec 18 2010 David Mohr
- Updated architecture identification and syscall handling
- Added ability to pass objective filters directly to auditctl

* Mon Jun 28 2010 David Mohr
- Updated file permissions
- Minor Remote Control Interface updates
- Minor configuration checking updates
- Security patch to prevent Cross Site Request Forgery

* Wed Dec 17 2008 David Mohr
- Streamlined Helper/Dispatcher comms, minor resource saving
- Removed unnecessary regex from Dispatcher, major resource saving
- Made all file handles hot (no buffering)
- Improved signal handling between Helper and Dispatcher
- Fixed potential data corruption in DispatchHelper

* Fri Oct 24 2008 David Mohr
- Completely revised file watch configuration
- Fixed "empty fqdn/criticality" problem
- Improved authentication event handling
- Fixed "remove objective" bug that would delete two objectives
- Fixed message buffering in SnareDispatchHelper
- Fixed Display Recent Events rendering when using syslog
- Final RHEL4 targeted release

* Wed May 28 2008 David Mohr
- Further improved resource handling and collection speed (SnareDispatchHelper)
- Added support for file watches
- Updated compliance objective templates
- Improved objective handling including ability to drop events

* Mon Dec 3 2007 David Mohr
- Added support for login/logout events
- Added support for account modification events
- Improved resource handling and collection speed (SnareDispatchHelper)

* Mon Aug 7 2007 David Mohr
- Added support for compound matching elements (e.g. name=/etc/* name!=/etc/blah/*)
- Improved authentication support for remote control interface
- Updated SELinux policy (RHEL5 support)
- Improved automatic audit configuration using objective returncode detection to pre filter unnecessary records
- Fixed element matching error
- Fixed error in criticality reporting (e.g. criticality was always zero)
- Fixed race condition that could potentially clear all audit rules on restart
- Improved effeciency allowing a higher throughput
- Improved installer for easier deployment

* Mon Jul 2 2007 David Mohr
- Fixed syslog output
- Added file output support to web interface
- Fixed "Other" objective type to allow underscores
- Fixed exclusion lists
- Changed wildcards to match zero or more characters
- Added regex option to config file
- Added better Audit version detection
- DNS timeout for restricted access hosts

* Wed Nov 29 2006 Leigh Purdie
- Initial release - InterSect Alliance - http://www.intersectalliance.com/

- -
InterSect Alliance Pty Ltd
http://www.intersectalliance.com/
