[appsuite-announce] Open-Xchange releases OX Abuse Shield v2.2.0

Open-Xchange App Suite Maintenance Announcements appsuite-announce at open-xchange.com
Thu Nov 7 15:27:03 CET 2019


Dear Open-Xchange Customers and Partners,

Open-Xchange is pleased to announce the release of OX Abuse Shield v2.2.0.

OX Abuse Shield provides abuse-prevention for Web Applications (including Webmail), POP, and IMAP. It is integrated with both OX App Suite and Dovecot Pro to prevent login and authentication abuse as well as protecting against brute-force attacks.

The goal of OX Abuse Shield is to detect brute forcing of passwords across many servers, services and instances, as well as enforce policy for authentication and authorization. In order to support the real world, brute force detection policy can be tailored to deal with "bulk, but legitimate" users of your service, as well as botnet-wide slow-scans of passwords.

The new OX Abuse Shield v2.2.0 provides the following main improvements:

- Lookup individual GeoIP2 values
Previously the GeoIP2 support was limited to retrieving City and County DB information, with a fixed set of fields returned. However this meant that other DBs (e.g. ISPs, Anonymizers etc.) could not be queried, as well as additional fields in City or Country DBs. Now there are four new Lua functions to query arbitrary fields in the Maxmind DBs

- New Kibana Reports and Dashboard
New Kibana Reports and Dashboard have been added to the kibana_saved_objects.json file. These reports are based on "allow" webhooks sent to elasticsearch.

- Built-in Whitelists
In addition to the built-in blacklists there are now built-in whitelists. Entries can be added and deleted from the built-in whitelists using either the REST API or using Lua commands.

- Hooks to create Custom Policies and Fields
New functions to register custom policies, like create a new statsDB field which can be used to track new statistics, create a new policy that uses a threshold based on a specific statsDB field and create a completely custom policy using a Lua function.

What’s New in General and Feature Overview

Open-Xchange now provides more detailed overviews, data sheet and product guide, relating to new product releases. These can be found at https://www.open-xchange.com/portfolio/whats-new/

A more detailed overview of the main functions and technical descriptions of OX Abuse Shield can be found at the OX Whitepaper under: https://software.open-xchange.com/products/weakforced/doc/OX_Whitepaper_OX_Abuse_Shield_2_2_0.pdf

Shipped packages and versions
- OX Abuse Shield v2.2.0-rev1

Complete Release Notes:

- OX Abuse Shield:
http://software.open-xchange.com/products/weakforced/doc/OX_Abuse_Shield_Release_Notes_for_Release_2.2.0_2019-11-07.pdf

Download and Installation

For further details about OX Abuse Shield installation and configuration, mandatory and optional packages, policies, please refer to the documentation provided: https://oxpedia.org/wiki/index.php?title=AppSuite:OX_Abuse_Shield

Best regards,
Your Open-Xchange Team

-------------------------------------------------------------------------------------
Open-Xchange AG, Hohenzollernring 72, 50672 Cologne, District Court Cologne HRB 95366
Managing Board: Rafael Laguna de la Vera, Carsten Dirks, Michael Knapstein, Stephan Martin 
Chairman of the Board: Richard Seibt

European Office:
Open-Xchange GmbH, Olper Huette 5f, D-57462 Olpe, Germany, District Court Siegen, HRB 8718
Managing Director: Frank Hoberg

US Office:
Open-Xchange. Inc., 530 Lytton Avenue, Palo Alto, CA 94301, USA
-------------------------------------------------------------------------------------


More information about the appsuite-announce mailing list