    ossec-hids-agent-0:3.2.0-6132.amzn1.art                                                       $   >                                  w{|Ji   >                 =  [7   ?     ['      d                                                   (        	   ,        	   B                                                                                     	  !          <          R          X           _                       0          0  	     0   0  
        0       P   0           0       P   0          0          0                     0                           |                                        "     (     #     8     ,     9     x     :     1K     >     S     ?     S%     B     S-     G     S@   0  H     T    0  I     T   0  X     T     Y     T     Z     U(     [     U,     \     U0   0  ]     U   0  ^     Z     b     Z     d     [     e     [     f     [     l     [   C ossec-hids-agent 3.2.0 6132.amzn1.art     The OSSEC HIDS Client The ossec-hids-agent package contains the agent part of the
OSSEC HIDS. Install this package on every system to be
monitored. \SJkempsridley  $Amazon Linux AMI http://www.ossec.net AGPL Atomicorp <support@atomicorp.com> System Environment/Daemons http://www.ossec.net/ linux x86_64 if [ $1 = 1 ]; then
	/sbin/chkconfig --add ossec-hids
	/sbin/chkconfig ossec-hids on
fi

echo "TYPE=\"agent\"" >> /etc/ossec-init.conf

if [ ! -f  /var/ossec/etc/ossec.conf ]; then
  ln -sf ossec-agent.conf /var/ossec/etc/ossec.conf
fi

ln -sf /var/ossec/bin/ossec-client.sh /var/ossec/bin/ossec-control

# daemon trickery
ln -sf /var/ossec/bin/client-logcollector  /var/ossec/bin/ossec-logcollector 
ln -sf /var/ossec/bin/client-syscheckd  /var/ossec/bin/ossec-syscheckd 

touch /var/ossec/logs/ossec.log
chown ossec:ossec /var/ossec/logs/ossec.log
chmod 0664 /var/ossec/logs/ossec.log


#/sbin/service ossec-hids restart || : if [ $1 = 0 ]; then
  /sbin/chkconfig ossec-hids off
  /sbin/chkconfig --del ossec-hids

  /sbin/service ossec-hids stop || :

  rm -f /var/ossec/etc/localtime
  rm -f /var/ossec/etc/ossec.conf
  rm -f /var/ossec/bin/ossec-control
  rm -f /var/ossec/bin/ossec-logcollector 
  rm -f /var/ossec/bin/ossec-syscheckd 
fi    K  	 P l       p      b  *A     n  /    4    'R        D2  t  A  P   R q  l5   3  & &    >  a  !*      '             hhhhhhhAhAAh                                                                                                \SJp\SJp\SJr\SJr\SJs\SJs\SJs\SJp\SJr\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJp\SJpca68dd62842736a79a71e9cb66e53d54 a08b8c6fabac1d0ca513d709d9cba71d 193a859c3bb240470779811edfee869c d8ce5bab12776e0910bae2c9620c5f26 e8817a293ea46d6693e8a938230d570b 14d0254be9c88575dd637bb3c26211ef 4ded7818fedaf75df66ca61a7f15f7c7 a8deb35414c6ea637dd6c8f53d11f26b d5050719deaa685764d9152932885b8e a1dd1f0bbc314161e24faf5f3ef6cb11 7365ebc5b53122df2d1c89a8358c0162 f9c3bf648630c5ac4c262bf734866078 cda2b20b31e00f21f43b770d379e10d1 b7e95261db48d69b8e0a51d62eb4d80b ef369cb627325b368ff115858b88b2d3 966703e11b6c7f99849f833c26756b30 edda0c19b1b599ba0c05c8156a4180a3 74e421baff5866743077f1393a9920f0 5dac76cfcffd4a92cac52cd76e898625 5944dadb63dc5a85ad1883be5583cc8a 1398ee965c76a016588243ca5e623c53 35f2c78645df44f97bd437ce62af51ac a803ee5e8225e03e07dde6678dbfe90d a9f685121627f1ffddbbad95f2f781c3 0e69cca992d4712c6224dce082c65050 0e0884a98f115381c3a80b9b0f512a45 381c96094ba7dfb120305faee69c2cae 527bae7e585061da35e1496ac291c794 d3c349f0c1506f540ea2d538ce9af96a 6d762779c44dda24901673c0e715f5a9 6b179293b008d27e21bb7484e23ee481 4c3142df2baca284ade71f978ed6112a 9730ffbc3fd1ccd1bc7d3f2f0d902c34 714601fa639634a36c4132f51593068b 37b794d6e0361e52bbc09ee1ff68fd41 e5a01c22432dee58fdd791c841cfeea1 6443af3efe35dffe10b8c993a661fc16 f2363ea4b7db5e4678e4e5970edeb3bf bf8f5e69576d2c24ac99d429b0457182 739b1094ed1fc5b9ed56c90767a4f13c c5c836fe0934b93310e22965dd6008a4 072526aa22390da8d1ae90675daa89ab 8cc6abc69459c3dc6ed57721799a85da 456aead916261071d591e36d9d2ffe7c f946edf404eb1f0a7c4cd7379843d10d                                                                                                                                                                                                                                                 root root root root root root root root root root root root ossec root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root ossec root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root ossec ossec ossec ossec-hids-3.2.0-6132.amzn1.art.src.rpm    ossec-hids-agent ossec-hids-agent(x86-64)                       	   
  
  @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @ ossec-hids /sbin/chkconfig /sbin/chkconfig /sbin/service /sbin/service /bin/sh /bin/sh rpmlib(PayloadFilesHavePrefix) rpmlib(CompressedFileNames) /bin/bash /bin/sh libcrypto.so.10()(64bit) libc.so.6()(64bit) libc.so.6(GLIBC_2.14)(64bit) libc.so.6(GLIBC_2.15)(64bit) libc.so.6(GLIBC_2.2.5)(64bit) libc.so.6(GLIBC_2.3.4)(64bit) libc.so.6(GLIBC_2.3)(64bit) libc.so.6(GLIBC_2.4)(64bit) libc.so.6(GLIBC_2.7)(64bit) libdl.so.2()(64bit) libGeoIP.so.1()(64bit) libm.so.6()(64bit) libpthread.so.0()(64bit) libpthread.so.0(GLIBC_2.2.5)(64bit) librt.so.1()(64bit) libssl.so.10()(64bit) libz.so.1()(64bit) 0:3.2.0-6132.amzn1.art       4.0-1 3.0.4-1                        ossec-hids-server  4.11.3   \R@XXYX@TT@SSS[S@R@R@RʚR@R@RrF@RiRR@Q@QY@Q@@QQ@Q@Qu&@Qu&@QkQg@Q\PDPP@PP@OiO@OЗOЗO	O OpZ@NNS@NK@N;@N;@N6@N-ZNMMM@M@M@M?MM>MUM@MPL~L8LΫLΫLʷ@LeL@L{LL@LA@LLLzL~@@L|LvW@LmLa?@LRL4l@LT@KtK͗@KKK@K[K@K8@K@K@K@J@JJJ@JJJn@JL@JI@J2C@J2C@J/@J&eI@Io@I)@I4IܑIII@I@I&@III~@H@H|@HcHM@H2@H)GJ@GAzGV@Gm@Fޚ@F@F@FF@Fr@Fq-FIF-@EWEEySEIE
E 	DDY@D@DLSupport <support@atomicorp.com> - 3.2.0 Support <support@atomicorp.com> - 2.9.0-50 Support <support@atomicorp.com> - 2.9.0-49 Support <support@atomicorp.com> - 2.9.0-48 Support <support@atomicorp.com> - 2.8.1-47 Support <support@atomicorp.com> - 2.8.0-46 Support <support@atomicorp.com> - 2.8.0-45.1 Support <support@atomicorp.com> - 2.8.0-45 Support <support@atomicorp.com> - 2.7.1-44 Support <support@atomicorp.com> - 2.7.1-43 Support <support@atomicorp.com> - 2.7.1-42 Support <support@atomicorp.com> - 2.7.1-41 Support <support@atomicorp.com> - 2.7.1-40 Support <support@atomicorp.com> - 2.7.1-36 Support <support@atomicorp.com> - 2.7.1-35 Support <support@atomicorp.com> - 2.7-34 Support <support@atomicorp.com> - 2.7-33 Support <support@atomicorp.com> - 2.7-32 Support <support@atomicorp.com> - 2.7-31 Support <support@atomicorp.com> - 2.7-30 Support <support@atomicorp.com> - 2.7-29 Support <support@atomicorp.com> - 2.7-28 Support <support@atomicorp.com> - 2.7-27 Support <support@atomicorp.com> - 2.7-26 Support <support@atomicorp.com> - 2.7-25 Support <support@atomicorp.com> - 2.7-24 Support <support@atomicorp.com> - 2.7-23 Support <support@atomicorp.com> - 2.7-22 Support <support@atomicorp.com> - 2.7-21 Support <support@atomicorp.com> - 2.7-20 Support <support@atomicorp.com> - 2.7-19 Support <support@atomicorp.com> - 2.7-17 Support <support@atomicorp.com> - 2.6-16 Support <support@atomicorp.com> - 2.6-15 Support <support@atomicorp.com> - 2.6-14 Support <support@atomicorp.com> - 2.6-13 Support <support@atomicorp.com> - 2.6-12 Support <support@atomicorp.com> - 2.6-11 Support <support@atomicorp.com> - 2.6-10 Support <support@atomicorp.com> - 2.6-9 Support <support@atomicorp.com> - 2.6-8 Support <support@atomicorp.com> - 2.6-7 Support <support@atomicorp.com> - 2.6-6 Support <support@atomicorp.com> - 2.6-5 Support <support@atomicorp.com> - 2.6-4 Support <support@atomicorp.com> - 2.6-3 Support <support@atomicorp.com> - 2.6-2 Support <support@atomicorp.com> - 2.6-1 Support <support@atomicorp.com> - 2.6.0-0.10 Support <support@atomicorp.com> - 2.6.0-0.9 Support <support@atomicorp.com> - 2.6.0-0.8 Support <support@atomicorp.com> - 2.6.0-0.7 Support <support@atomicorp.com> - 2.6.0-0.6 Support <support@atomicorp.com> - 2.6.0-0.5 Support <support@atomicorp.com> - 2.6.0-0.4 Support <support@atomicorp.com> - 2.6.0-0.3 Support <support@atomicorp.com> - 2.6.0-0.1 Support <support@atomicorp.com> - 2.5.1-10 Support <support@atomicorp.com> - 2.5.1-9 Support <support@atomicorp.com> - 2.5.1-8 Support <support@atomicorp.com> - 2.5.1-7 Support <support@atomicorp.com> - 2.5.1-6 Support <support@atomicorp.com> - 2.5.1-5 Support <support@atomicorp.com> - 2.5.1-4 Support <support@atomicorp.com> - 2.5.1-3 Support <support@atomicorp.com> - 2.5.1-2 Support <support@atomicorp.com> - 2.5.1-1 Support <support@atomicorp.com> - 2.5-1 Support <support@atomicorp.com> - 2.5-0.9 Support <support@atomicorp.com> - 2.5-0.8 Support <support@atomicorp.com> - 2.5-0.7 Support <support@atomicorp.com> - 2.5-0.6 Support <support@atomicorp.com> - 2.5-0.1 Support <support@atomicorp.com> - 2.4.1-11.2 Support <support@atomicorp.com> - 2.4.1-11.1 Support <support@atomicorp.com> - 2.4.1-10 Support <support@atomicorp.com> - 2.4.1-9 Support <support@atomicorp.com> - 2.4.1-8 Support <support@atomicorp.com> - 2.4.1-7 Support <support@atomicorp.com> - 2.4.1-6 Support <support@atomicorp.com> - 2.4.1-5 Support <support@atomicorp.com> - 2.4.1-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.2 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta2.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta1.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-11 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-10 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-9 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090225.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090220.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090206.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090205.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.99-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.99-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.6.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.6-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.4-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.4-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.0-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.0 Scott R. Shinn <scott@atomicrocketturtle.com> peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org - Update to 3.2.0 - Change labels in alert mail headers to "ASL" - Update to Ossec 2.9.0 Final - Update to Ossec 2.9.0 - Update to 2.8.1. This is identical to 2.8.0-46, the only change is the hosts.deny CVE-2014-5284 is merged in. - Revert BR#1596
- Add Bugfix for hosts.deny race condition (CVE-2014-5284) - BR #1596, Add fork limiting patch (max 10) for execd to prevent DoS conditions - Upgrade to 2.8.0 - Feature Request #1512,  speed up shuns in execd, move sqlite down - Relink against native mysql - Add ar-tracking active response - Placeholder for null exclusion rules.  Legacy support - ASL 4 version with new database format - Add support for Fedora 20
- Modify optimization flags for FORTIFY - Update to 2.7.1
- Add independent rules.d/decoders.d ossec-rules package - FR#772, add rule 3360 for postfix slow brute force
-   add dovecot-decoder.patch for cpanel dovecot
-   Update 9702, 9753 for dovecot brute force
- FR#773, add rule 11308 for pure-ftp slow brute force
- FR#1347, Update for courier v4 decoder (pop3s)
- FR#1359, Update horde decoder for v5 - Disable ossec-dbd signature table (replaced by aslw_rules). This was very slow - Break ossec-dbd into separate package
- FR#1321, update courier-imap decoder for version 4.0 - Bugfix #XXX, prevent truncating last character on ossec-dbd database inserts on the alerts/data table - Add tld column to alert table w/ index - Deprecate internal id generation in dbd
- update schema to autoincrement, increase id space to int - Add is_hidden to mysql schema - Add if exists to mysql schema - Add os_dbd-mysql-replace-query.patch to consolidate SELECT/UPDATE into REPLACE sql - Consolidate alert & data into a common table
- Add ossec-authd init script - Add sqldelete command  to execd
- Update to clear sqlite db at startup - More minor updates to GeoIP tracking - Minor update to GeoIP tracking - Bugfix on permissions for files in shared/ directory for client installs
- Add GeoIP support
- Remove dependency on perl-DBD-SQLite
- Update asl-shun to new non-perl based version.
- Deprecate firewall-drop-update.patch
- Add sqlite support to execd (/var/ossec/var/execd.sqlite) - Update to 2.7 final - Feature Request #XXX, revert duplicate detection in log events to help detect extremely fast brute force attacks
- Add FORTIFY_SOURCE, PIE, and relro (full) - Update to 2.7-rc2 - Update to 2.7-rc1 - Move active response components under the common package - bugfix #xxx, correct ownership permissions on fts dir - Update to init script to suppress spurious execd output
- Add alerts queue to server package with ossec/ossec permissions - Bugfix #XXX, correct any/agentd condition - Moved agentless packages under server - Drop timeid and cat_id indexes from schema - Add new index, timeid to alerts table. - Add cmoraes patch, Adds config options for enabling/disabling rootkit/syscheck options, and agent config profiles
- Add ossec-memleaks patch
- Add agentless directories, and agent.conf
- Bugfix #XXX, ossec-hids.init will now return an exit code on status - Add prelink_cmd support - Bugfix #XXX, display multi-line events in data table correcty - Update to asl-shun.pl purge event to default to 24 hours. - Update to asl-shun.pl to change ordering of block rules
- Revert from 0805 snapshot - Update to 0805 snapshot - Update to 0801 snapshot
- Update asl-shun.pl to log to active-responses.log, blocks now go to the named chain ASL-ACTIVE-RESPONSE, and delete events are more redundant. - Update to OSSEC 2.6 Final - Update to snapshot 110711 - Update to snapshot 110613 - Update to snapshot 110609 - Update to snapshot 110606
- Moved ossecr user creation event to the ossec-hids core package - Update to snapshot 110531 - Update to snapshot 110526 - Update to snapshot 110504 - Bugfix #536, Increase the default sleep time for syscheck - Renamed to 2.6 branch - Add support for the rules/decoders dir system - Update to snapsot 110405
- Update asl-shun to support ossec alert ids - Changed asl-shun sqlite database to /var/ossec/var/blocklist3.sqlite
- asl-shun database format now stores the full alertid - Update to snapshot 101203 - Update to snapshot 101125 - Added alertid support to os_dbd, this involves a schema update - Added dst ip, src prt, and dst prt capture support to os_dbd - Bugfix #XXX, manage_agents was built in client mode for the server package. - Add clamav decoder & ruleset - Update to 2.5.1 final - Update to 2.5 final - Update to 0928 snapshot - Extended no_ar into ossec-dbd - Add no_ar option to disable active response per rule - Update to snapshot 100920 - Update snapshot to 100907 - Snapshot 100901 - Added test fix for os_dbd - Bugfix #376, ossec-control will now properly stop and reload - Update to 0809 snapshot - Relink against native mysql - Add minicon decoder from les fenison - Update to 100707 snapshot
- Feature Request #371, add ossec.log to logrotate - Updated to 100615 snapshot - Updated init and ossec-server scripts to support the new reload feature. - Update to 2.4.1 - Added zabbix reporting active response - Update to 2.4 final
- Lowered courier rule 3910 (failures) from 6 over 240 to 10 over 10
- Lowered courier rule 3911 (success) from 10 over 60 to 30 over 20 - Rebuilt for atomic repo - Update to CVS 100317 - Update to CVS 100311
- Add decoder for denyhosts
- Update asl_rules.xml to include denyhosts rules - Update to CVS 100309 - Added new decoder for smtp_auth
- Added rules to detect smtp_auth brute force attempts
- Added rules to detect imap/pop brute force attempts - Updated ossec-server.conf to be in parity with the ASL config
- Added templates dir for generating configs - Update to 2.3 release - Update to snapshot 091109 - Update to snapshot 091008 - Update to snapshot 090925
- Added timestamp field to the mysql schema
- Bugfix #XXX, for the ossec-client.init script to call the correct (renamed) ossec syscheckd/logcollector daemons
- Appologies for not updating the previous changelogs. Missed a few updates! - Update to snapshot 090827
- Feature Request #225, Added logrotate event to active-response log
- Updated system_audit_rcl.txt to look for the correct php.ini file - Update to 090824, beta 1 release - Update to 090812 snapshot - Rebuild agent daemons with -DCLIENT, added symlink trickery - update to 2.1.1 - update to 090630 snapshot, this has fixes for CentOS/RHEL 4 64-bit environments - update to 2.1 final - update to snapshot 090612 - update to snapshot 090610 - update to snapshot 090603 - Disable postgresql support, to get around an undesirable dependency on EL4 - Update to snapshot 090417 - Update to snapshot 090413 (this adds in inotify support) - Update to snapshot 090410 (this adds in inotify support) - Update to snapshot 090408 - Added authpsa rules back in, this is used to detect brute force attacks
- Added conditional building support for ASL modifications - Update to 2.0 official release - update to snapshot 090225 - update to snapshot 090220 - update to snapshot 090206 - update to snapshot 090205 - update to CVS code 090129, this is not an offical release. Its for testing only - update to CVS code 090126, this is not an offical release. Its for testing only - update to 1.6.1 - update to 1.6 - update to 1.5.1 - added mysql support - Added Stanislaw Polak's excellent ban-hackers script to manage shunning more intelligently. - update to 1.5 - fix on active-response locking bug that prevented some rules from expiring. - update to ossec 1.4 - update snapshot to ossec-hids-071011.tar.gz
- relinked C4, FC4, FC5 against mysql4 - update to snapshot ossec-hids-071006.tar.gz - update to shun blocklist tracking used by ASL
- added authpsa rules + decoder - update to 1.3 - minor adjustment in post, to check for config file before overwriting it - v6 was first version of the patch.
- added in logging in active-response for better ASL support
- Disabled conf event in post, to keep from overwriting config files. - changed permissions on queue/syscheck so it can be read by the ossec group (tweak for web gui) - removed the noreplace settings from decoder and the rules
- patch for a more ASL friendly client config - release -2 had a bug. 
- added ASL rules (asl_rules.xml)
- added decoder for the asl style modsecurity logging
- adjusted syslog_rules for qmail-scanner issue (BUG #ASL-18)
- Added http index in asl_rules.xml (BUG #ASL-7) - update to 1.2 - update to 1.1 - configuration change for ASL - updated to 1.0 - import into ART
- changed their naming conventions a bit, 0.9-3 to 0.9.3. Please dont be cross with me. - new version (0.9-3) - new version (0.9-2) - new version (0.9-1a) - new version (0.9-1) - new version (0.9) - some bugfixes - created /bin/sh /bin/sh ossec-hids-client                                                                                                                                                                             	   
                                                                      !   "   #   $   %   &   '   (   )   *   +   ,   -   .   /   0                                                      0:3.2.0-6132.amzn1.art 0:3.2.0-6132.amzn1.art                                                                                                                                                            ossec-init.conf ossec-hids agent-auth client-logcollector client-syscheckd manage_agent ossec-agentd ossec-client.sh ossec-execd internal_options.conf ossec-agent.conf ossec.conf.sample agent.conf acsc_office2016_rcl.txt cis_apache2224_rcl.txt cis_debian_linux_rcl.txt cis_debianlinux7-8_L1_rcl.txt cis_debianlinux7-8_L2_rcl.txt cis_mysql5-6_community_rcl.txt cis_mysql5-6_enterprise_rcl.txt cis_rhel5_linux_rcl.txt cis_rhel6_linux_rcl.txt cis_rhel7_linux_rcl.txt cis_rhel_linux_rcl.txt cis_sles11_linux_rcl.txt cis_sles12_linux_rcl.txt cis_solaris11_rcl.txt cis_win10_enterprise_L1_rcl.txt cis_win10_enterprise_L2_rcl.txt cis_win2012r2_domainL1_rcl.txt cis_win2012r2_domainL2_rcl.txt cis_win2012r2_memberL1_rcl.txt cis_win2012r2_memberL2_rcl.txt cis_win2016_domainL1_rcl.txt cis_win2016_domainL2_rcl.txt cis_win2016_memberL1_rcl.txt cis_win2016_memberL2_rcl.txt rootkit_files.txt rootkit_trojans.txt system_audit_pw.txt system_audit_rcl.txt system_audit_ssh.txt win_applications_rcl.txt win_audit_rcl.txt win_malware_rcl.txt alerts rids syscheck /etc/ /etc/rc.d/init.d/ /var/ossec/bin/ /var/ossec/etc/ /var/ossec/etc/shared/ /var/ossec/ossec-agent/etc/shared/ /var/ossec/queue/ -O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m64 -mtune=generic drpm gzip 9 x86_64-amazon-linux-gnu    ?   0        Z	xڞ. E؅&iҍBSm
nta-I2i&3qfæW\@EE@@e/\P(^D^
$MJ[Q<9gs̜ 9AjmdŊ	&^5sӐD}O_vǅgٴi=}>vuՍvnGhAD'Dn7 ~cAVD߭!$Jc Ek}#<ӕBm:B<BPW*2c2O%/?'xX(ԊHڭ̫k;VƩLh[-K=rq89'mx9	U^FH,kU-7ϭqhuGg;ys1eA't{n#^{\s';c{k/z4ˏu_vzg)sct77-Ũ5_+)O޹DՆm`Z?'>y}?^|3Ldm-ל[CAW^?q%Orjkf3}#9?o].s5mBO 1# OVj3*zHmw>Ix6_ۺѴ=޹$|3cxo}IYGSmam/>sf~u',g=xw_\}j_'G9_f؅ȾsKyog=mnV34mUUO,8w~GE=<tqgg4˗#c&9~#?lmg*>oj8MȜ79$*[,T^Px}Br5nOI'Xʭ^lUN{7.s}ΨS؅Oe:hsc;]M3<lXKO_-uUᧂ^9^jrRFw<3ōbts,u;/)7,Ǥ5-;EXB2iEb{ٶxrD5\3\t˷Ug]E={z䐔gߨ]Ɵw|)[_r7kVq=U)	ؿ2۟t]gquSȯJ_vDtwyfX+o}ygqM;33<hT9ࡍ}'u,;Ʀz<o]zb{dA/vݜF99gԥ>RŴԔ~m/_Uz]nĿ[lXNOn룣j{dɷD?~V;z_ED̙ᇧ ;]fɍs?m}АO/khqukׯ9rpROQ-R{2q*[..:Lximm<%4UBރRJmWSe,x6x򄲞_+2PCA x.b2
yJg(CI JmWzww\~P2tSz*|p彻K)=Y{OpoxbۈT(:(wsL8)|x4hrM@=J)nf͂Dy6gD׫DeCD=c7ԕHw)=->uyXsK>-V!PvB|-@7%ʯDC W'Ӝ%O%GCbRDשmf1TqCE[z;e5Xzi֥Gݼݑ;\{45gvst(ʯ~mI+co\LiPE$QC5jz$8t!y公㓋kCV]ylCnB:)KC&CmDNjزr2:-#h#!	[%-_
~CR tJXΟy"MۋOAqOPy^Җgj.dóMviGO~1@x.Goy*tՒ6W<-\13s:	}Q7ZG_@u鈤+o}rqgzf՝2#C##"efw4χC;f/h%y4cAw"ihZ:Sc<]݂?*$7`^affdq﷜VMnUODDX&SIȷu#b+?̞m:mԣ
vݾoSc}篞ۤ^'k?ZFt|.yo|>`$oo%ى.l5ݹiJz}яóD#&|v`*^Pd굯[c^:38bPST_Ws٭f|4o~zHִZYGdVҴ7C'E~t_w	E4/z3$=cOq=aWJ=z|֑fvG[F}U"9U<&fЖ[|voq;1._v/c?r̆o5@[t)rqLUi2G7^x³qQm]b9K8vW%ov~y3
V~woSON߼QV[>jVg{Z>pQ?vŮԢH"^¯A;zwuk*wfimNdf2G"$¢<CtPeMb#YCdd**Fx]jYY1s.XA7j=e,M1he6m $@RbF[e棼bT_1.BY9&*vPFI7#"GyÃ- RT0Mr9q9)1?0:D_RIn8D'#v܌Y( YCP-:)ʖ"4fH;)lJ
HtЬNYES-P ٕ!|BV-"ڎ87rCKdhLegb8n"3w):@Pp+H)jT*`7vU	`1y	\Cp}DCBr|  d%t;_^	AiYI\OjHEV
v4t[xX⑝眈,x`[6*.B+Г`C.)|a a-4A ebITzdP2* OAmh90tx(I<!4l0VE[DC(. Hj6(?ŋX.c9h9\sPzEɘ@_]N:(DD.T!=X ),bp4¬@wuú_PzR)Tɹ(?i0&S^vC0(ێRqJ>(''(9'8<nRxS
Z!sxp?RPg"Cv-84*YrB6K4P~NO	da0Yd/x^BY$$1>rf&+K&Fpz[H3^*d*YarII~Rl'e83kQ91F6{@e<v5,͒gYipkR>4JO^v7XLbV?_q1d5$ s<U
<2:`!&ASL+e,<I'%|PԠ̋F!}mx:(ox^$ܿ?
cz
,]D`)P&HcExQ7ZRV8h@`d`7Hbb)&Up i#(:NWCp_zXp\)/!yhZ'X_cqVl!O`(/0i
gMz (G)jBIdD)҆-LAF` JĦ&^G\$MR| 3c)2V +3xL|<7&]YH TyئqAeHXn20eq!okGt*XMZuUN1C/q`"HHz
AnDѰVIY$Q)UiԲhLl&nA<Bn6OkT8//aL@
Pb"'`YT?M%=@5gdX5Jk5NkV!m;]Lڽ Ar&^E	 ФMD
&Hcf
d/2OF-rf{Y$#@R)f%ӵ04B')^+)fO`fJs0%%'ˍKrbsRf&4+)VR40%QzůЭj8lv 3ʭrPul<Rr!=x*̤FuWErWlZ3oe4b% ߇%	`Yi;(&	㬻ܼp)MA0-~rpҤw|89."ݗþ|CBV+ìm)?!֩TNVd&Rf>r5\FY8Tw%wt^NrOJ&uҩBIّ rZx!1YJWUH-BXDO]TlS*rӧhOCfCBfQҽoq2%]$^K<LE""]N肄*K.,~%1S>7Ӵw	'Moqt*yD݀pvM{4߬.Ubm5+*mTx(诊D6vJ7a&mJ8QP.1I:1%%Ֆ2.M+y&Ήe/-2t*6]/9TuCڇz{Vڴ
5>QR2/5rRb뺡~'r	Ch B8IQƻܒJaFސ#]&1~9pjP|-͂ۃS1p|Kq`{mo|vF
OuTeҟ-wjmyم}<UFiJ&kb<GbԒ8-9mPl<||PeW ɭH5"o]P)I5LoB}dof&!X%8DRب%:u[ƖB9#s3+"r&ԅ7KSSnr Ad
o@aLkP]*QV؄Lh@}]uQ&5>]>"؀jBmHIe:moXEjCRPԨ~߬
jلgw&OSP?Иi,6V8[P.źJ&]v-Xp9Dc{Xmu8w;|SbedB3-т4ZZ/xy;}æc9ט14;TZ3Q4qqJ-h6wIP0?s6?(Xh{FJd%;ȗ~LE6clϘC)rV~_lSsJDdt1 \F|c
63'7Խ#`҅n`UWR'kT+.p< VăpısM]"
drl(s©x L_R<Q_#sK39'Iҿܔ^/U(5ngd47Wruۏm&So^_ ࢤ"mV:  