You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 11 Next »

Released

Linux SHA256:

Linux md5sum:

Linked article - Discovering using seed.

From 4.1.0 onwards we allow more flexibility when creating a discovery regarding setting individual discovery scan options. You can now change individual options without having to create a "custom" discovery scan options entry. The Discovery Scan Options for a given discovery now function as the match rules. You choose an option set, but you can override individual options. They'll default to the discovery scan option chosen, if not explicitly set. Much more flexible and intuitive. These are still restricted to Enterprise licensed customers.

Small reminder that Open-AudIT Community is still at version 3.5.3, not 4.1.0. This will be updated in a future release.

VersionTypeCollectionDescription
ProfessionalBugAllModal for Help -> About not firing.
CommunityBugDevices

Audit Results Overwriting attributes. In some cases, if an audit is processed, a change made using the GUI and another audit then processed, the change made by the GUI was being reverted. Bug in SQL when updating a device and determining if to set an attribute in the system table, by weight.

ProfessionalBugAllSome templates (discoveries, credentials, clouds) had a JS issue and were not removing the edit buttons.
CommunityImprovementAllReplace all passwords with ****** in interface (irrespective of using the html 'password' type).
EnterpriseBugRacksPopulate system.type correct on racks and rack devices read templates.
EnterpriseImprovementAllEvaluation and Trial Licenses should enable all Enterprise features.
ProfessionalImprovementDevicesImprove SAN disks on devices read template.
ProfessionalImprovementDevicesImprove display of discovery error logs on device details template.
ProfessionalImprovementQueriesAdd an 'All Queries' item to the report menu.
ProfessionalImprovementAllUse striped rows in tables for improved readability.
EnterpriseNew FeatureDiscoveriesNew type of discovery - seed. Provide a starting IP and add detected IPs/MACs to the discovery as we query devices. SNMP, Linux, Windows ARP tables, routes, etc. Enterprise only. Can restrict to a given subnet. Can restrict to private IPs only.
ProfessionalBugAll

On the VersionCheck from JS, only check for Open-AudIT, as opposed to Open-AudIT Pro, Ent, et al.

ProfessionalImprovementDevicesAdd the change_log.id on the devices_read template (helpful when sorting).
CommunityImprovementAllCode review of all input and output to minimise XSS attacks.
CommunityBugDevicesFix a bug preventing auditing Debian in audit_linux script (software and other sections).
CommunityImprovementDevicesAdd os_arch (x86_64, for example) to the DB schema and audit scripts.
CommunityImprovementDiscoveriesIn ssh_helper, do not set type if manufacturer === Ubiquiti.
CommunityImprovementDevicesSilence warnings when processing SAN due to uninitialised object.
CommunityNew FeatureDiscoveriesAdd support for radio stats retrieval from Cambium devices. New DB table - radio. Used when interface model = radio and OID is Cambium, via SNMP. Displayed in Professional / Enterprise.
CommunityImprovementDevicesFor Windows targets, retrieve user password last changed and last logon timestamps.
CommunityImprovementDevicesDisabled SVG uploading for device images because of XSS issues when requesting the direct image. Actual image display in the web pages is fine.
CommunityImprovementDevicesSet to '*' (all columns) if we're not passed a property list when reading a device sub_component.
CommunityImprovementDiscoveriesInclude Nmap results of port scans in log->command_output.
CommunityBugAllFix incorrect variable name in request helper for access token.
CommunityImprovementAllImprove Nmap version detection.
CommunityImprovementAllAdd extra headers to template recommended by OWASP Zap.
CommunityImprovementAllUpgrade jQuery to 3.6.0. Upgrade Bootstrap to 3.4.1.
ProfessionalImprovementAllUpgrade jQuery to 3.6.0. Upgrade Bootstrap to 3.4.1.
ProfessionalBugLocationsFix populating lat/long and GeoCode on locations read template. Also fix link in No API Key warning in alert on same template.
ProfessionalImprovementDiscoveriesDisable attributes for discoveries and discovery scan options for excluding ports when Nmap <7 detected.
ProfessionalBugDevicesTemplate fix on devices_read for policies section.
CommunityImprovementNetworksAssign networks.org_id to discoveries.org_id or discoveries.devices_assigned_to_org (if set) if network is created via discovery.
CommunityImprovementNetworksAssign networks.location_id to discoveries.devices_assigned_to_location (if set) if network is created via discovery.
ProfessionalImprovementNetworksAdd networks.environment attribute.
  • No labels