Announcing the availability of RealSecure SiteProtector X-Press Update (XPU) enhancements to support Internet Scanner XPU 6.10 and Internet Scanner XPU 6.11. For additional information, please refer to the supporting Readme files attached.
The available X-Press Updates for SiteProtector include the following: * SiteProtector XPU Version: May 20, 2002 (SP_XPU_20020520) Applicable Versions: Applicable to SiteProtector 1.2 =========================================================== This SiteProtector XPU supports Internet Scanner XPU 6.10. SiteProtector 1.2 must be installed before this XPU can be applied (SiteProtector 1.0 with Service Release 3). * SiteProtector XPU Version: May 22, 2002 (SP_XPU_20020522) Applicable Versions: Applicable to SiteProtector 1.2 =========================================================== This SiteProtector XPU supports Internet Scanner XPU 6.11. SiteProtector 1.2 must be installed before this XPU can be applied (SiteProtector 1.0 with Service Release 3). For more information on this release, please contact the following: * For additional product information: - SiteProtector: http://www.iss.net/products_services/enterprise_protection/rssite_protector/ - Internet Scanner: http://www.iss.net/products_services/enterprise_protection/vulnerability_ass essment/ - X-Press Updates: http://www.iss.net/db_data/xpu/IS.php - Jamie Lau, X-Press Updates Product Manager, [EMAIL PROTECTED] * For sales information: - [EMAIL PROTECTED] - 888-901-7477 (North America) * For education, consulting and support information, including ISS SecureU training on SiteProtector and Internet Scanner: - Customer Support - [EMAIL PROTECTED], 888-447-4861 - CSG West - John Franklin, Business Development Manager, [EMAIL PROTECTED], 949-916-8037 - CSG East - Joel Williams, Business Development Manager, [EMAIL PROTECTED], 404-236-3971 - SecureU training - http://education.iss.net/course_descriptions/iss_courses/advanced.php, 888-263-8739.
============================================================= SiteProtector X-Press Update Release Notes - May 20, 2002 ============================================================= SiteProtector XPU Version: May 20, 2002 (SP_XPU_20020520) Applicable Versions: Applicable to SiteProtector 1.2 **PLEASE READ COMPLETELY BEFORE INSTALLING THE XPU** 1. X-Press Update Contents ============================================================= This SiteProtector XPU supports Internet Scanner XPU 6.10. SiteProtector 1.2 must be installed before this XPU can be applied (SiteProtector v 1.0 with Service Release 3). SiteProtector XPUs update the SiteProtector console and Site DB to reflect new exploits and vulnerabilities. XPUs also contain new and modified Help files for these security issues and updated policies for sensors. SiteProtector XPUs are sequential, and applying an XPU requires the installation of previous SiteProtector XPUs not already included on the Site. It may also be necessary for Service Releases to also be installed prior to applying an XPU. It is also possible to apply sensor XPUs through SiteProtector. ISS advises installing all X-Press Updates to ensure your systems are up to date for the latest vulnerabilities and attacks. 2. Installing X-Press Updates ============================================================= 2.1 Using SiteProtector to Install X-Press Updates By default, the SiteProtector update mechanism intermittently checks the main ISS Web site (https://www.iss.net) for a file called XPU_1_2.xml. This XML file contains information regarding all available product updates. When a new update is indicated, SiteProtector updates the database with the relevant information so that SiteProtector console displays that the new update is available. By default, XPU_1_2.XML is downloaded every 24 hours. The first time you apply an update, it is automatically downloaded to a repository on the RealSecure application server and applied remotely to the components you've chosen. Subsequent updates will attempt to use the application server's cached copy of the update. Applying X-Press Updates requires administrative status. To apply X-Press Updates, right-click on a sensor or a group of sensors, and then select "to apply update." You must apply XPUs to both the sensors and the SiteProtector console before the new checks and signatures can go into effect. However, applying the updates to sensors will result in the appropriate updates automatically being downloaded and applied to the SiteProtector console. When an X-Press Update is scheduled on more than 20 assets, the sensor controller performs the requested operation on 20 assets in parallel before moving to another block of 20 assets. This operation is repeated until all the assets are configured. 2.2 Automating Application of X-Press Updates You can automate the updating of components by creating a recurring update schedule for those components and by ensuring that a new XPU_1_2.XML is scheduled to be downloaded intermittently. You can customize this automation by group. It is also possible to automate application of updated policies to sensors. Network Sensor customers should note that it is necessary to manually install the Network Sensor Policy Group File before the policy can be edited to enable the new signatures. Be aware that automating installation of updates will apply any available new updates; this is not limited to X-Press Updates only. 2.3 Manually Downloading and Applying X-Press Updates If your SiteProtector system cannot access the ISS Web site and a proxy server is not in place to provide this visibility, you can download the updates from the ISS Download Center and manually apply them. The easiest way to do this is to manually retrieve https://www.iss.net/XPU_1_2.xml and save it in the Program Files\ISS\RealSecure SiteProtector\Application Server\Xpu directory. You must then download the Internet Scanner Policy update into the \Program Files\ISS\RealSecure SiteProtector\Application Server \XPU\Update\Site_Protector\ directory. You will also need to download all Internet Scanner XPUs (6.1-6.10) and place these files in the \Program Files\ISS\RealSecure SiteProtector\Application Server \XPU\Update\RealSecure directory. A tool to automate that process is forthcoming. If you do that, instruct the SiteProtector console not to go to the web any more; edit the properties for SP Core, pick the X-Press and Product Update tab, and uncheck the "Auto Download" box. The following files are relevant to this XPU. - Readme - Internet Scanner Policy Update for XPU 6.10 - Internet Scanner XPU 6.10 (sensor update) 2.4 Customizing SiteProtector Updates Navigate to your SiteProtector host asset and choose SP Core, then Edit Properties, the X-Press and Product Update tab and select interval, Web site, and other properties. 2.5 Using a Proxy Server to Download XPUs SiteProtector uses the proxy settings from Internet Explorer on the Application Server host to download XPUs. To modify these, navigate to Start, Settings, Control Panel, Internet Options, Connections, LAN Settings, Proxy Server, and then add the proxy server host and port. Note that you must use a proxy server that does not require authentication. If your proxy server requires authentication, you must manually download XPUs from the ISS Download Center, as discussed above. IMPORTANT The proxy settings in IE are associated with a user name. For SiteProtector to read them, you have to modify the service to log in as that user name. Find the service "RealSecure SiteProtector Sensor Controller Service," right-click and choose properties, click the log-on tab, and enter the user information for a user with the proxy settings configured. 3. Updating Policies ============================================================= Updated policies are contained in the SiteProtector XPU. Once you have applied XPUs to both the sensor(s) and to SiteProtector, you must push the policy to the sensors. It is possible to automate this. Default RealSecure policies will have new signatures added, but not enabled. You must customize the policies to enable the new signatures. Default Internet Scanner policies will have new checks enabled as appropriate for each default policy. If you utilize custom policies, the new checks and signatures will be added to your policy, but not automatically enabled. Customize your custom policies to enable new checks and signatures. 4. Updating SiteProtector Help Files ============================================================= Once you apply the SiteProtector XPU, new and revised Help files will be placed in a directory on the RealSecure sensor controller. If you have chosen a default installation for the SiteProtector console, the Help files will be located in the following directory: \Program Files\ISS\RealSecure SiteProtector\Application Server\Xpu\Install\HelpFile Updates. This will be true for every SiteProtector XPU. If you have chosen a non-standard implementation for the SiteProtector console, and have placed Help files in a different location, you will need to move the Help files delivered in the XPU from the above directory to your customized location. 5. Updating the Security Fusion Module ============================================================= Applying a SiteProtector XPU automatically updates the security fusion module so that it can correctly correlate new and updated checks and signatures. 6. Customer Support ============================================================= Technical Support is available 24 hours a day through the Americas Location. All other locations are open Monday through Friday, 9:00 am to 6:00 pm, during their local time, excluding ISS published holidays. Telephone (in the U.S.): +1-888-447-4861 Telephone (outside the U.S.): +1-404-236-2700 Email: [EMAIL PROTECTED] 7. Required Information for Bugs ============================================================== If you encounter a problem with this release, please make notes that are as detailed as possible about the following: * Build versions * Sensor and console host configurations * Network deployment * Network traffic rates * Network traffic characteristics * Specific failure symptoms or undesirable behavior This information helps us reproduce the problem and resolve it as quickly as possible.
============================================================= SiteProtector X-Press Update Release Notes - May 22, 2002 ============================================================= SiteProtector XPU Version: May 22, 2002 (SP_XPU_20020522) Applicable Versions: Applicable to SiteProtector 1.2 **PLEASE READ COMPLETELY BEFORE INSTALLING THE XPU** 1. X-Press Update Contents ============================================================= This SiteProtector XPU supports Internet Scanner XPU 6.11. SiteProtector 1.2 must be installed before this XPU can be applied (SiteProtector v 1.0 with Service Release 3). SiteProtector XPUs update the SiteProtector console and Site DB to reflect new exploits and vulnerabilities. XPUs also contain new and modified Help files for these security issues and updated policies for sensors. SiteProtector XPUs are sequential, and applying an XPU requires the installation of previous SiteProtector XPUs not already included on the Site. It may also be necessary for Service Releases to also be installed prior to applying an XPU. It is also possible to apply sensor XPUs through SiteProtector. ISS advises installing all X-Press Updates to ensure your systems are up to date for the latest vulnerabilities and attacks. 2. Installing X-Press Updates ============================================================= 2.1 Using SiteProtector to Install X-Press Updates By default, the SiteProtector update mechanism intermittently checks the main ISS Web site (https://www.iss.net) for a file called XPU_1_2.xml. This XML file contains information regarding all available product updates. When a new update is indicated, SiteProtector updates the database with the relevant information so that SiteProtector console displays that the new update is available. By default, XPU_1_2.XML is downloaded every 24 hours. The first time you apply an update, it is automatically downloaded to a repository on the RealSecure application server and applied remotely to the components you've chosen. Subsequent updates will attempt to use the application server's cached copy of the update. Applying X-Press Updates requires administrative status. To apply X-Press Updates, right-click on a sensor or a group of sensors, and then select "to apply update." You must apply XPUs to both the sensors and the SiteProtector console before the new checks and signatures can go into effect. However, applying the updates to sensors will result in the appropriate updates automatically being downloaded and applied to the SiteProtector console. When an X-Press Update is scheduled on more than 20 assets, the sensor controller performs the requested operation on 20 assets in parallel before moving to another block of 20 assets. This operation is repeated until all the assets are configured. 2.2 Automating Application of X-Press Updates You can automate the updating of components by creating a recurring update schedule for those components and by ensuring that a new XPU_1_2.XML is scheduled to be downloaded intermittently. You can customize this automation by group. It is also possible to automate application of updated policies to sensors. Network Sensor customers should note that it is necessary to manually install the Network Sensor Policy Group File before the policy can be edited to enable the new signatures. Be aware that automating installation of updates will apply any available new updates; this is not limited to X-Press Updates only. 2.3 Manually Downloading and Applying X-Press Updates If your SiteProtector system cannot access the ISS Web site and a proxy server is not in place to provide this visibility, you can download the updates from the ISS Download Center and manually apply them. The easiest way to do this is to manually retrieve https://www.iss.net/XPU_1_2.xml and save it in the Program Files\ISS\RealSecure SiteProtector\Application Server\Xpu directory. You must then download the Internet Scanner Policy update into the \Program Files\ISS\RealSecure SiteProtector\Application Server \XPU\Update\Site_Protector\ directory. You will also need to download all Internet Scanner XPUs (6.1-6.10) and place these files in the \Program Files\ISS\RealSecure SiteProtector\Application Server \XPU\Update\RealSecure directory. A tool to automate that process is forthcoming. If you do that, instruct the SiteProtector console not to go to the web any more; edit the properties for SP Core, pick the X-Press and Product Update tab, and uncheck the "Auto Download" box. The following files are relevant to this XPU. - Readme - Internet Scanner Policy Update for XPU 6.11 - Internet Scanner XPU 6.11 (sensor update) 2.4 Customizing SiteProtector Updates Navigate to your SiteProtector host asset and choose SP Core, then Edit Properties, the X-Press and Product Update tab and select interval, Web site, and other properties. 2.5 Using a Proxy Server to Download XPUs SiteProtector uses the proxy settings from Internet Explorer on the Application Server host to download XPUs. To modify these, navigate to Start, Settings, Control Panel, Internet Options, Connections, LAN Settings, Proxy Server, and then add the proxy server host and port. Note that you must use a proxy server that does not require authentication. If your proxy server requires authentication, you must manually download XPUs from the ISS Download Center, as discussed above. IMPORTANT The proxy settings in IE are associated with a user name. For SiteProtector to read them, you have to modify the service to log in as that user name. Find the service "RealSecure SiteProtector Sensor Controller Service," right-click and choose properties, click the log-on tab, and enter the user information for a user with the proxy settings configured. 3. Updating Policies ============================================================= Updated policies are contained in the SiteProtector XPU. Once you have applied XPUs to both the sensor(s) and to SiteProtector, you must push the policy to the sensors. It is possible to automate this. Default RealSecure policies will have new signatures added, but not enabled. You must customize the policies to enable the new signatures. Default Internet Scanner policies will have new checks enabled as appropriate for each default policy. If you utilize custom policies, the new checks and signatures will be added to your policy, but not automatically enabled. Customize your custom policies to enable new checks and signatures. 4. Updating SiteProtector Help Files ============================================================= Once you apply the SiteProtector XPU, new and revised Help files will be placed in a directory on the RealSecure sensor controller. If you have chosen a default installation for the SiteProtector console, the Help files will be located in the following directory: \Program Files\ISS\RealSecure SiteProtector\Application Server\Xpu\Install\HelpFile Updates. This will be true for every SiteProtector XPU. If you have chosen a non-standard implementation for the SiteProtector console, and have placed Help files in a different location, you will need to move the Help files delivered in the XPU from the above directory to your customized location. 5. Updating the Security Fusion Module ============================================================= Applying a SiteProtector XPU automatically updates the security fusion module so that it can correctly correlate new and updated checks and signatures. 6. Customer Support ============================================================= Technical Support is available 24 hours a day through the Americas Location. All other locations are open Monday through Friday, 9:00 am to 6:00 pm, during their local time, excluding ISS published holidays. Telephone (in the U.S.): +1-888-447-4861 Telephone (outside the U.S.): +1-404-236-2700 Email: [EMAIL PROTECTED] 7. Required Information for Bugs ============================================================== If you encounter a problem with this release, please make notes that are as detailed as possible about the following: * Build versions * Sensor and console host configurations * Network deployment * Network traffic rates * Network traffic characteristics * Specific failure symptoms or undesirable behavior This information helps us reproduce the problem and resolve it as quickly as possible.
