    ossec-hids-1:3.2.0-6132.el7.art                                                               $   >                                  vTlЛb>   >                 ;  al   ?     a\      d                                                            	   $        	   Y          8          <          `          d          y          ~        	                                                       ?          ?  	        ?  
        ?          ?          ?          ?          ?          ?       z             ?                                          (           )          *          +          ,          -          8          9          :     6     =     X     D     X     G     X   ?  H     Y   ?  I     Z   ?  X     Z     Y     [      \     [,   ?  ]     \(   ?  ^     _     b     `     d     a5     e     a:     f     a=     l     a?          aX   C ossec-hids 3.2.0 6132.el7.art    An Open Source Host-based Intrusion Detection System OSSEC is a scalable, multi-platform, open source Host-based Intrusion Detection
System (HIDS). It has a powerful correlation and analysis engine, integrating
log analysis, file integrity checking, Windows registry monitoring, centralized
policy enforcement, rootkit detection, real-time alerting and active response.
It runs on most operating systems, including Linux, OpenBSD, FreeBSD, MacOS,
Solaris and Windows.

This package contains common files required for all packages.  \SEI43e77533019f46d8a86540a5ea53f08b     http://www.ossec.net AGPL Atomicorp <support@atomicorp.com> Applications/System http://www.ossec.net/ linux x86_64 if ! id -g ossec > /dev/null 2>&1; then
  groupadd -r ossec
fi
if ! id -u ossec > /dev/null 2>&1; then
  useradd -g ossec -G ossec       \
	-d /var/ossec \
	-r -s /sbin/nologin ossec
fi
if ! id -u ossecr > /dev/null 2>&1; then
  useradd -g ossec -G ossec       \
	-d /var/ossec \
	-r -s /sbin/nologin ossecr
fi           I  L   )    :  `                 k  p           d    I  
?     	l  &    x    c  $  +    f    F     '             8  A            O  (  	       {                           A큤AhAhAhhhhhhhhhhhhhAhhhhhhhhhhhhhAhAhAA聠AAhAhAhAAAhAhA                                                                                                                              \SE3\SE=\S!~\S!~\S!~\S!~\S!~\S!~\S!~\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE<\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3b80f8f94f7447c9f4d1f98c635a96977fca2003ff101fbf98f1e583e399614ab  f44612342e9830a31cec6c0ae70b322be62b1eeac919fd42d54617a2ba8f0516 dcdaa02ebcb144f73caaa9e5c29186a8fc80e1890d4db282821dc29a1a947e5f 251ac7ccf4522c78bc62f18d0e60557fcf05c43a80d6caeb3db3f1eabd8085d1 b4785605349422d9bbefbac4511df428aca5fdfcb1b20dd8461521702b9e5a1b a84cb71737980acf3f967456d2e30b696be557d445d2e360525713545e0dc50e e5e87cc49099b4a68cb524904e4dffc56fa5d1b9cf2394c871fdeba3eb73adda cf4e876597c8366647d2f54d8e0b76598e2d3cdb01d4bd47f88825e8a4929892    a600f753530ed55d66e7585b6be640063ce343626d5335f0ed72f81187b00c5e f9a813e4e53823fc8d43a8ec1a91df67524308156eabdf63c8440086f2394260 629db0bcd01893c6f9b8191dc3b156323cd2e41c11c3c8a64c1f31759a32f4ff bfa6537b9c271bb7180d163f9f837f3576dd9f0325effdda715972d0858f0f1c 838c4422e6468fe7fab97f49d1f7b4dfc72975c18b981506845feded0a4f031b b8b77ad5d1cf487a6f707b41058a081f5408b130438b42505896c14db49f03cc ad3a1960d461563223ef0b1b1f97a653104d426513eb24c09d6463eec433f7a9 a6789d184e207e5bf1bab81cf99acb94f31e1e7ebd0e5ad12fbbbce0f6caa055 365aa94a72f38faeedc5a473a6598b19ef28536f7f1db168be7c16eb45c07ea6 e736dde6929e32461fe51db100d4bff0d80ac2d316e7011aa4ac8294bb94a0a9 fb32ed79d97a1a9c6ab12fc86dc6678c5500d2ecd21192d5e5fd13277173a584 a8a4b349fff82b0c8ab42a00c19289e437f0cdebbeb6b6b5c1cf575e53cbfba9  dbfc71e6af8b288eb468bacdba8a02569671224e6f65bbf01fb461d40eb9ed40 5029207a9255c4e0df67db772a500694dae75a96cb9f0326916b21fc94c0d317 67308a684121b063b3f2afae6374de1d7ff4a39d8293073ce701e0814890b912 4d63380f28bbd789138ef6396cbf8421a59cd45cf8abb9e3a2ac813d2b11cafb 04a2c084b43acb1f9d91c6f84bdaca5d6816e43f2d5937fcb19a45bc8da6aaec 35a9a511eb0a40adbfb9e5f1a2a7734a923b2e9ebfcd28896e8fa2bf4f2445b5 779a5cec11b6f3d2dcc996ecd09d5f641c82fe0e26dad8b3dbcee76f2c592e27 fa49d3f7210f6d16eceb372353010ca1619886febf528cbc7c3f8d3dbcf931da 8546f15dafe30ce45e3284803bbe01e261c9ce0b763a53418c15a0047d06065f f6ecb3c4400cb1e531e4768429b1b86e06f33b89e495d0549d10e5adbae476b8 e0d30dec6a4271badf289a8fe44d19be4d4bb0f4dfb90ae7aea6930658abb45d 255a26c4e816582e6979b950effa43d850ddcaac8421080b492ab18d0921185c  076f8fe539b132fc462ec518ab3740c9e4e21231dce7dcb6237daa4d3de5e9ab    9fb3b973248c76d14a814ba558235f520640d26e9f2fafac03fa2432b16e40f9 738d6767a0d76f8732f9afb869b5b7533b0342989ff6754fbc9fc023a37b0c1c aee022646c6b78507bd02bd632efc1d46e65c82589c8823190e83e4c006846d6 00897a8ee5c0159709c28c622ad5e4de85d0e596f770ea8c80be97893f85f675 43ba95564730b7265e456120cef81905316d877cc532344993987b38f1b1e008 1c87cd21a1b8e5e4fca27a2fc19868d161f15635514513586adddbdb196cec6c f97d988840ce05868f7e8eb40582354bb44f1d0e1614241d088a8c440f0fc4ba ec23980e084d9e878b33c29b38a58f91873629275f6e9802970d074ae8fb490b f10d1482c86ef799205c84eea9e258616952fc495052bc1e64bf07d7adf8c129 58d925aab330df06db3418f50d3f57c2f1f5c892f142c3d59cb9db2de1380a8d f20b3a42c0106d46e810ddf37fee88edf7a629fc9f622c5acd2cd211ba2e5a5f b8f7994193cc5fcc7a75988740e117b64462ee62a7d40cff17f72e5d39fb2736                                                                                                                                                                                                                                                                                                                               root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec root root root ossec ossec root root root root root root root root root root root root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec root root ossec ossec ossec ossec ossec ossec ossec-hids-3.2.0-6132.el7.art.src.rpm ossec-3.2.0-6132.el7.art ossec-hids ossec-hids(x86-64)                          
  
  
  @   @   @   
/usr/sbin/groupadd /usr/sbin/useradd openssl /bin/cat GeoIP /bin/sh /bin/sh rpmlib(FileDigests) rpmlib(PayloadFilesHavePrefix) rpmlib(CompressedFileNames) /bin/bash /bin/sh /usr/bin/env rpmlib(PayloadIsXz)        4.6.0-1 4.0-1 3.0.4-1    5.2-1 4.11.3 [ -r /etc/localtime ] && cp -fpL /etc/localtime /var/ossec/etc
if [ -f /var/ossec/ossec-agent/etc ]; then
	cp -fpL /etc/localtime /var/ossec/ossec-agent/etc
fi glibc           \R@XXYX@TT@SSS[S@R@R@RʚR@R@RrF@RiRR@Q@QY@Q@@QQ@Q@Qu&@Qu&@QkQg@Q\PDPP@PP@OiO@OЗOЗO	O OpZ@NNS@NK@N;@N;@N6@N-ZNMMM@M@M@M?MM>MUM@MPL~L8LΫLΫLʷ@LeL@L{LL@LA@LLLzL~@@L|LvW@LmLa?@LRL4l@LT@KtK͗@KKK@K[K@K8@K@K@K@J@JJJ@JJJn@JL@JI@J2C@J2C@J/@J&eI@Io@I)@I4IܑIII@I@I&@III~@H@H|@HcHM@H2@H)GJ@GAzGV@Gm@Fޚ@F@F@FF@Fr@Fq-FIF-@EWEEySEIE
E 	DDY@D@DLSupport <support@atomicorp.com> - 3.2.0 Support <support@atomicorp.com> - 2.9.0-50 Support <support@atomicorp.com> - 2.9.0-49 Support <support@atomicorp.com> - 2.9.0-48 Support <support@atomicorp.com> - 2.8.1-47 Support <support@atomicorp.com> - 2.8.0-46 Support <support@atomicorp.com> - 2.8.0-45.1 Support <support@atomicorp.com> - 2.8.0-45 Support <support@atomicorp.com> - 2.7.1-44 Support <support@atomicorp.com> - 2.7.1-43 Support <support@atomicorp.com> - 2.7.1-42 Support <support@atomicorp.com> - 2.7.1-41 Support <support@atomicorp.com> - 2.7.1-40 Support <support@atomicorp.com> - 2.7.1-36 Support <support@atomicorp.com> - 2.7.1-35 Support <support@atomicorp.com> - 2.7-34 Support <support@atomicorp.com> - 2.7-33 Support <support@atomicorp.com> - 2.7-32 Support <support@atomicorp.com> - 2.7-31 Support <support@atomicorp.com> - 2.7-30 Support <support@atomicorp.com> - 2.7-29 Support <support@atomicorp.com> - 2.7-28 Support <support@atomicorp.com> - 2.7-27 Support <support@atomicorp.com> - 2.7-26 Support <support@atomicorp.com> - 2.7-25 Support <support@atomicorp.com> - 2.7-24 Support <support@atomicorp.com> - 2.7-23 Support <support@atomicorp.com> - 2.7-22 Support <support@atomicorp.com> - 2.7-21 Support <support@atomicorp.com> - 2.7-20 Support <support@atomicorp.com> - 2.7-19 Support <support@atomicorp.com> - 2.7-17 Support <support@atomicorp.com> - 2.6-16 Support <support@atomicorp.com> - 2.6-15 Support <support@atomicorp.com> - 2.6-14 Support <support@atomicorp.com> - 2.6-13 Support <support@atomicorp.com> - 2.6-12 Support <support@atomicorp.com> - 2.6-11 Support <support@atomicorp.com> - 2.6-10 Support <support@atomicorp.com> - 2.6-9 Support <support@atomicorp.com> - 2.6-8 Support <support@atomicorp.com> - 2.6-7 Support <support@atomicorp.com> - 2.6-6 Support <support@atomicorp.com> - 2.6-5 Support <support@atomicorp.com> - 2.6-4 Support <support@atomicorp.com> - 2.6-3 Support <support@atomicorp.com> - 2.6-2 Support <support@atomicorp.com> - 2.6-1 Support <support@atomicorp.com> - 2.6.0-0.10 Support <support@atomicorp.com> - 2.6.0-0.9 Support <support@atomicorp.com> - 2.6.0-0.8 Support <support@atomicorp.com> - 2.6.0-0.7 Support <support@atomicorp.com> - 2.6.0-0.6 Support <support@atomicorp.com> - 2.6.0-0.5 Support <support@atomicorp.com> - 2.6.0-0.4 Support <support@atomicorp.com> - 2.6.0-0.3 Support <support@atomicorp.com> - 2.6.0-0.1 Support <support@atomicorp.com> - 2.5.1-10 Support <support@atomicorp.com> - 2.5.1-9 Support <support@atomicorp.com> - 2.5.1-8 Support <support@atomicorp.com> - 2.5.1-7 Support <support@atomicorp.com> - 2.5.1-6 Support <support@atomicorp.com> - 2.5.1-5 Support <support@atomicorp.com> - 2.5.1-4 Support <support@atomicorp.com> - 2.5.1-3 Support <support@atomicorp.com> - 2.5.1-2 Support <support@atomicorp.com> - 2.5.1-1 Support <support@atomicorp.com> - 2.5-1 Support <support@atomicorp.com> - 2.5-0.9 Support <support@atomicorp.com> - 2.5-0.8 Support <support@atomicorp.com> - 2.5-0.7 Support <support@atomicorp.com> - 2.5-0.6 Support <support@atomicorp.com> - 2.5-0.1 Support <support@atomicorp.com> - 2.4.1-11.2 Support <support@atomicorp.com> - 2.4.1-11.1 Support <support@atomicorp.com> - 2.4.1-10 Support <support@atomicorp.com> - 2.4.1-9 Support <support@atomicorp.com> - 2.4.1-8 Support <support@atomicorp.com> - 2.4.1-7 Support <support@atomicorp.com> - 2.4.1-6 Support <support@atomicorp.com> - 2.4.1-5 Support <support@atomicorp.com> - 2.4.1-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.2 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta2.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta1.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-11 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-10 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-9 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090225.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090220.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090206.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090205.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.99-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.99-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.6.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.6-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.4-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.4-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.0-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.0 Scott R. Shinn <scott@atomicrocketturtle.com> peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org - Update to 3.2.0 - Change labels in alert mail headers to "ASL" - Update to Ossec 2.9.0 Final - Update to Ossec 2.9.0 - Update to 2.8.1. This is identical to 2.8.0-46, the only change is the hosts.deny CVE-2014-5284 is merged in. - Revert BR#1596
- Add Bugfix for hosts.deny race condition (CVE-2014-5284) - BR #1596, Add fork limiting patch (max 10) for execd to prevent DoS conditions - Upgrade to 2.8.0 - Feature Request #1512,  speed up shuns in execd, move sqlite down - Relink against native mysql - Add ar-tracking active response - Placeholder for null exclusion rules.  Legacy support - ASL 4 version with new database format - Add support for Fedora 20
- Modify optimization flags for FORTIFY - Update to 2.7.1
- Add independent rules.d/decoders.d ossec-rules package - FR#772, add rule 3360 for postfix slow brute force
-   add dovecot-decoder.patch for cpanel dovecot
-   Update 9702, 9753 for dovecot brute force
- FR#773, add rule 11308 for pure-ftp slow brute force
- FR#1347, Update for courier v4 decoder (pop3s)
- FR#1359, Update horde decoder for v5 - Disable ossec-dbd signature table (replaced by aslw_rules). This was very slow - Break ossec-dbd into separate package
- FR#1321, update courier-imap decoder for version 4.0 - Bugfix #XXX, prevent truncating last character on ossec-dbd database inserts on the alerts/data table - Add tld column to alert table w/ index - Deprecate internal id generation in dbd
- update schema to autoincrement, increase id space to int - Add is_hidden to mysql schema - Add if exists to mysql schema - Add os_dbd-mysql-replace-query.patch to consolidate SELECT/UPDATE into REPLACE sql - Consolidate alert & data into a common table
- Add ossec-authd init script - Add sqldelete command  to execd
- Update to clear sqlite db at startup - More minor updates to GeoIP tracking - Minor update to GeoIP tracking - Bugfix on permissions for files in shared/ directory for client installs
- Add GeoIP support
- Remove dependency on perl-DBD-SQLite
- Update asl-shun to new non-perl based version.
- Deprecate firewall-drop-update.patch
- Add sqlite support to execd (/var/ossec/var/execd.sqlite) - Update to 2.7 final - Feature Request #XXX, revert duplicate detection in log events to help detect extremely fast brute force attacks
- Add FORTIFY_SOURCE, PIE, and relro (full) - Update to 2.7-rc2 - Update to 2.7-rc1 - Move active response components under the common package - bugfix #xxx, correct ownership permissions on fts dir - Update to init script to suppress spurious execd output
- Add alerts queue to server package with ossec/ossec permissions - Bugfix #XXX, correct any/agentd condition - Moved agentless packages under server - Drop timeid and cat_id indexes from schema - Add new index, timeid to alerts table. - Add cmoraes patch, Adds config options for enabling/disabling rootkit/syscheck options, and agent config profiles
- Add ossec-memleaks patch
- Add agentless directories, and agent.conf
- Bugfix #XXX, ossec-hids.init will now return an exit code on status - Add prelink_cmd support - Bugfix #XXX, display multi-line events in data table correcty - Update to asl-shun.pl purge event to default to 24 hours. - Update to asl-shun.pl to change ordering of block rules
- Revert from 0805 snapshot - Update to 0805 snapshot - Update to 0801 snapshot
- Update asl-shun.pl to log to active-responses.log, blocks now go to the named chain ASL-ACTIVE-RESPONSE, and delete events are more redundant. - Update to OSSEC 2.6 Final - Update to snapshot 110711 - Update to snapshot 110613 - Update to snapshot 110609 - Update to snapshot 110606
- Moved ossecr user creation event to the ossec-hids core package - Update to snapshot 110531 - Update to snapshot 110526 - Update to snapshot 110504 - Bugfix #536, Increase the default sleep time for syscheck - Renamed to 2.6 branch - Add support for the rules/decoders dir system - Update to snapsot 110405
- Update asl-shun to support ossec alert ids - Changed asl-shun sqlite database to /var/ossec/var/blocklist3.sqlite
- asl-shun database format now stores the full alertid - Update to snapshot 101203 - Update to snapshot 101125 - Added alertid support to os_dbd, this involves a schema update - Added dst ip, src prt, and dst prt capture support to os_dbd - Bugfix #XXX, manage_agents was built in client mode for the server package. - Add clamav decoder & ruleset - Update to 2.5.1 final - Update to 2.5 final - Update to 0928 snapshot - Extended no_ar into ossec-dbd - Add no_ar option to disable active response per rule - Update to snapshot 100920 - Update snapshot to 100907 - Snapshot 100901 - Added test fix for os_dbd - Bugfix #376, ossec-control will now properly stop and reload - Update to 0809 snapshot - Relink against native mysql - Add minicon decoder from les fenison - Update to 100707 snapshot
- Feature Request #371, add ossec.log to logrotate - Updated to 100615 snapshot - Updated init and ossec-server scripts to support the new reload feature. - Update to 2.4.1 - Added zabbix reporting active response - Update to 2.4 final
- Lowered courier rule 3910 (failures) from 6 over 240 to 10 over 10
- Lowered courier rule 3911 (success) from 10 over 60 to 30 over 20 - Rebuilt for atomic repo - Update to CVS 100317 - Update to CVS 100311
- Add decoder for denyhosts
- Update asl_rules.xml to include denyhosts rules - Update to CVS 100309 - Added new decoder for smtp_auth
- Added rules to detect smtp_auth brute force attempts
- Added rules to detect imap/pop brute force attempts - Updated ossec-server.conf to be in parity with the ASL config
- Added templates dir for generating configs - Update to 2.3 release - Update to snapshot 091109 - Update to snapshot 091008 - Update to snapshot 090925
- Added timestamp field to the mysql schema
- Bugfix #XXX, for the ossec-client.init script to call the correct (renamed) ossec syscheckd/logcollector daemons
- Appologies for not updating the previous changelogs. Missed a few updates! - Update to snapshot 090827
- Feature Request #225, Added logrotate event to active-response log
- Updated system_audit_rcl.txt to look for the correct php.ini file - Update to 090824, beta 1 release - Update to 090812 snapshot - Rebuild agent daemons with -DCLIENT, added symlink trickery - update to 2.1.1 - update to 090630 snapshot, this has fixes for CentOS/RHEL 4 64-bit environments - update to 2.1 final - update to snapshot 090612 - update to snapshot 090610 - update to snapshot 090603 - Disable postgresql support, to get around an undesirable dependency on EL4 - Update to snapshot 090417 - Update to snapshot 090413 (this adds in inotify support) - Update to snapshot 090410 (this adds in inotify support) - Update to snapshot 090408 - Added authpsa rules back in, this is used to detect brute force attacks
- Added conditional building support for ASL modifications - Update to 2.0 official release - update to snapshot 090225 - update to snapshot 090220 - update to snapshot 090206 - update to snapshot 090205 - update to CVS code 090129, this is not an offical release. Its for testing only - update to CVS code 090126, this is not an offical release. Its for testing only - update to 1.6.1 - update to 1.6 - update to 1.5.1 - added mysql support - Added Stanislaw Polak's excellent ban-hackers script to manage shunning more intelligently. - update to 1.5 - fix on active-response locking bug that prevented some rules from expiring. - update to ossec 1.4 - update snapshot to ossec-hids-071011.tar.gz
- relinked C4, FC4, FC5 against mysql4 - update to snapshot ossec-hids-071006.tar.gz - update to shun blocklist tracking used by ASL
- added authpsa rules + decoder - update to 1.3 - minor adjustment in post, to check for config file before overwriting it - v6 was first version of the patch.
- added in logging in active-response for better ASL support
- Disabled conf event in post, to keep from overwriting config files. - changed permissions on queue/syscheck so it can be read by the ossec group (tweak for web gui) - removed the noreplace settings from decoder and the rules
- patch for a more ASL friendly client config - release -2 had a bug. 
- added ASL rules (asl_rules.xml)
- added decoder for the asl style modsecurity logging
- adjusted syslog_rules for qmail-scanner issue (BUG #ASL-18)
- Added http index in asl_rules.xml (BUG #ASL-7) - update to 1.2 - update to 1.1 - configuration change for ASL - updated to 1.0 - import into ART
- changed their naming conventions a bit, 0.9-3 to 0.9.3. Please dont be cross with me. - new version (0.9-3) - new version (0.9-2) - new version (0.9-1a) - new version (0.9-1) - new version (0.9) - some bugfixes - created /bin/sh /bin/sh                                                                                                                                                                                                                            	   
                                                                      !   "   #   $   %   &   '   (   )   *   +   ,   -   .   /   0   1   2   3   4   5   6   7   8   9   :   ;   <   =   >   ?                                                                           1:3.2.0-6132.el7.art 1:3.2.0-6132.el7.art                                                                                                                              	   	   
   
   
   
   
   
   
   
   
   
   
   
                           ossec-hids ossec-hids-3.2.0 BUGS CHANGELOG CONFIG CONTRIBUTORS INSTALL LICENSE README.md ossec active-response bin ar-tracking.sh disable-account.sh firewall-drop.sh firewalld-drop.sh host-deny.sh ip-customblock.sh ossec-pagerduty.sh ossec-slack.sh ossec-tweeter.sh restart-ossec.sh route-null.sh zabbix-alert.sh agentless main.exp register_host.sh ssh.exp ssh_asa-fwsmconfig_diff ssh_foundry_diff ssh_generic_diff ssh_integrity_check_bsd ssh_integrity_check_linux ssh_nopass.exp ssh_pixconfig_diff sshlogin.exp su.exp bin ossec-configure etc shared templates active-response.template apache-logs.template ar-disable-account.template ar-firewall-drop.template ar-host-deny.template ar-routenull.template pgsql-logs.template rootcheck.template rules.template snort-logs.template syscheck.template syslog-logs.template logs compiled native queue diff ossec tmp var run /etc/logrotate.d/ /usr/share/doc/ /usr/share/doc/ossec-hids-3.2.0/ /var/ /var/ossec/ /var/ossec/active-response/ /var/ossec/active-response/bin/ /var/ossec/agentless/ /var/ossec/bin/ /var/ossec/etc/ /var/ossec/etc/templates/ /var/ossec/lua/ /var/ossec/queue/ /var/ossec/var/ -O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches   -m64 -mtune=generic drpm xz 2 x86_64-redhat-linux-gnu        ?   P   7zXZ  
 !   #,!w,] "k%G{lsIP@뀖	|_FSn|`e1\85mWYs8lFrǙ˼
X(mtB8J)mLyMɣ7Dp^8j+)D7A	Ӗẅԥv,=m`{\t)UuS4DO7VۭOo$嚳BјtՕX!/8=Ai`xMAwĕDlI՝[xa	&3	\e =Ŭt@1mn`J2ÏVV4B/P|lӁ͕V"-m3J/lmgO)Fd]Mf<#}}%Cⷰ|4EF	pqiu{2˙_O/LNJ}[N2h_/mkg7e*9Y9ևElh'^VL~ڬ Ffrg!|q;D6*#2CF+T2cʝSAk#bk~kb,Opz?W=D(u̱ F^;UCZ:m)V\(QH5 efQf1`@۹	hMc*[]tY!?*\%)B7'̝t<:ĞM%ХM7*l87-Z"޾8ȩi	fmzխV+RB^=`]=2*h'B{ʱZ`y%21]Joк5P藡@U="*?{F~8@#'C 0Ii{j]vn,y3 6Z$+7kcJpXa-хNTӄX(3E> zj}L%	3Yj\( !k+|:hUX֎ޝ1"d☇MSic]f9radC'4#in	UCg@&?k 4$6/B*& vM,a37۝[.4_U>"U $х-uV Ǚd#Tf`		Lt_6!YoA-),G,Q9/@r؇535n=4muDf;e-@)c?>̇N.#@*i;ro%btD4Avqc3<)m1|30_b2ʥ}̐rN~S#'*\ڇvײ{-A~|YXX-"bFSCßvUd[^rJĎluCt6 s˝\W ꑣCG5PNCZNE,eи/c?TycqqBH RmsK>PImɘ8һX
^>5[D'l_s9'E+TIϘNq<W%'7rVy9b׸O%[y׵D{Jw'5:$Wi]΅qHf$H	|>saڢNpnڔAMt)HR_y?B7u)^z?\چ`r:|za fXlv?1CyQ\v[{A-3i[2KM>]!7ɒMm8lJ  Ktf9k. uYQoRy(C ryf\D*̲MW58&w$O$K/nrǛ#JhvtoT6/O%v[IǃDPgBys&V`E~ƚ.C[T(uoSfT1mJ
_*EABy
2Qi]ee]OGfgRW`I/2s{1R_\@D@Si^tN23o8$aQ_ǒ?;
bGMu(c~}~`IWux{IxE:%Z-"?YTu]T+ )TS}՜Ccd]xNHmlzzV[kGL;Kg5rO74"ݽf3-7	jge<7tmbVTEo|3P+<]SYxi"`JkC $6,?	IEܷ##!)Tqq2_r[imLeu n<`*k%賃gX󾣶4=DrA/1׺~};8	Y`DV\ZusKq 05܋cmlǸ2|54#HW/|?kk-K~Wcji!'9G)YZW@enofhUck&譎I>%zp!i8f 6]gqwEif_fsʗR6:HNmR[=i`dqaJwJb\r%?FxЩMj]=Ф(MlwWfZW6..S	?4v$r)Z54q$O Aɚf:
	nvR=䕦7X83-nA[hzA(D2eĠq#N"vjԯue1UdYTg"fJTAC
?`Ӑd6 C^?Fx_]9`w{bd;?0>v9\3t➟U r菲o-}w$JT1ie6"n$o}֜#csP!m&ҪڝXϡn>s`6NTab8j矪2'189!v_bhp9Eu	KG+d:m+D:%Y/K':kzG8qynMynӅU;"c \drYd$,[O<-+Lo`Չ@cuRCXu` UY
+X$k_w;YHom
X^G2&/wUW\d0,d#@0jIՇyz)ࡾWM(}ĂBYKۛ\u$Z6Ntاj,{SwmpSuo|H/$
CjL
W5ތRmVͶJE`U/$wx/
ƅ-{|PǥN}	E3Ix!-8t+)RɛӐfYnEcA?,ih	$G9H^IJϬ 	Zjܖnb
^@{(pns4W)WVǹЍN`BgL*Dt2I<CDFa9/ZUazdKlq$?FiƕKvO\1Oeߪ5,*մRI$:,&t9`ǟKbXk#C90֢1I]I.!9y)(f
ԽT|1)bO	j\Nq2?jʪs-{IOŅGsR
^C6uqW`fT*G{"'[8:+iWJA so4L[g]rHb{9+L'V"\aKF|~WCXlhRgHI+OeHWEXnzE~ކ0ą7gWؘVƛp0b8a h|qd<kaTήq5A'$N0ϼOIڕ؇3l[@5%GLxUt9ňWM	L'<;8M`=ɜAPg{OkATutit}l3M[;0UЃt'wJyM;ы+Čb,`B
fFz!lH<޿z0WjZF)#emZ7Ċ#?g׺ OJEzLy̼G65O1~ynҞ_r*)|mG)?(oA>XV,S&Lߎr\Pfc  dU"+1&5.C0v"`h|hjh֡
 "B  ^    
YZ