    ossec-hids-agent-1:3.2.0-6132.el7.art                                                         $   >                                  |<;kt<.H   >                 =  ad   ?     aT      d                                                   (        	   ,        	   B                                                                        	  (          C          Y          _           f                       0          0  	     ,   0  
        0       L   0          0          0          0          0                    0       x                                                              2     (     3     8     <     9          :     7[     >     Y-     ?     Y5     B     Y=     G     YP   0  H     Z   0  I     Z   0  X     [      Y     [     Z     [4     [     [8     \     [<   0  ]     [   0  ^     `     b     `     d     a.     e     a3     f     a6     l     a8          aP   C ossec-hids-agent 3.2.0 6132.el7.art      The OSSEC HIDS Client The ossec-hids-agent package contains the agent part of the
OSSEC HIDS. Install this package on every system to be
monitored. \SEI43e77533019f46d8a86540a5ea53f08b     $,http://www.ossec.net AGPL Atomicorp <support@atomicorp.com> System Environment/Daemons http://www.ossec.net/ linux x86_64 if [ $1 = 1 ]; then
	/bin/systemctl daemon-reload >/dev/null 2>&1 || :
fi

echo "TYPE=\"agent\"" >> /etc/ossec-init.conf

if [ ! -f  /var/ossec/etc/ossec.conf ]; then
  ln -sf ossec-agent.conf /var/ossec/etc/ossec.conf
fi

ln -sf /var/ossec/bin/ossec-client.sh /var/ossec/bin/ossec-control

# daemon trickery
ln -sf /var/ossec/bin/client-logcollector  /var/ossec/bin/ossec-logcollector 
ln -sf /var/ossec/bin/client-syscheckd  /var/ossec/bin/ossec-syscheckd 

touch /var/ossec/logs/ossec.log
chown ossec:ossec /var/ossec/logs/ossec.log
chmod 0664 /var/ossec/logs/ossec.log


#/sbin/service ossec-hids restart || : if [ $1 = 0 ]; then
  /sbin/chkconfig ossec-hids off
  /sbin/chkconfig --del ossec-hids

  /sbin/service ossec-hids stop || :

  rm -f /var/ossec/etc/localtime
  rm -f /var/ossec/etc/ossec.conf
  rm -f /var/ossec/bin/ossec-control
  rm -f /var/ossec/bin/ossec-logcollector 
  rm -f /var/ossec/bin/ossec-syscheckd 
fi       K  	 p m   0     ۨ      b  *A     n  /    4    'R        D2  t  A  P   R q  l5   3  & &    >  a  !*      '             hhhhhhhAhAAh                                                                                                \SE3\SE3\SE6\SE<\SE9\SE6\SE8\SE3\SE5\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE3\SE36bc2a85c9951bd0ab935cebb683419bd1d3c95d01734cf8f9eaaa1f17134bbdd 21630d0d8054768ffe6cb4463be91bb22a434cf8cecca98ac17506b0cb36b4cb 6863df4a3d0aad9384832ad0408af6845eea4248382dbf803465d751ab6b32c1 51bd14aa5c0a7056caf8c9bce487787d5f1444efa80ce3b0dfec554a0ab68114 05a521effba9579cbdcaf7c7d66e903cbab814bf91077cb0a6745a95b5723d28 104108f774c36a5d9cde21fd492e90a8de72fe98517212baaf9483072c42db75 c2e60074c19a7d75df0c42744b68d4c3a4b603d3b9e06311ac3a4c8a4c3e0798 e9ed6b61a9d803ff66d0bbb097135f076a5656664a485986c41915c07261ff36 95ceee00d5006e86c6cf02e58ed8127d2e868e97436f31f5d62135aee713042d 4bea16845c8e076f47d04c77b1aa1ed98dfb60870246014db53f7a5be2ea0a86 31aabae3bfdebd4bb15344d2fde8a4397749d03f291d49c0dddb51fb0a22c5c7 bce9f3aa161d62308a080985269e4b46c3966bfbbb93b3708a3e2cb264e4b749 c1030b917aba0bc42b21ebb829eaa3cafb9081d55f533c676bf8708c0376bbeb 7da476d9f782f26360fdf764800c512a016ff028db713dec4226466bb72d5ca8 606d523f646921a6cbb0e8bce30d03072c69186025ba48bb288e580f377876d6 79322c236ceba006a93fa98b2eccfd7c7a8e8950d79ee47ede838ffabd85a9d4 7d8bf39b94dee07d419b1be477492af9c96b286703ef28966fa462049cfb66b9 aa416fbbac58650e86b603e8daeb857179a268fe390cab9e3eaefa5df589db5a d11c6bee007203a88fc95b5d8efd363e8ca85b2563aa0848a612206cb2aed6cd fb91113c7718e1b888c1acb828aa3c1762b81c994604fc3bcc9afa791d685a18 fcead21e9169e3eac8382c19ca68203b0fd420e1c8493c4861c6985acc956388 ff7d84b1bc9e99e5fbfd8863212d641482277f2507f77ca64808d42f13f82e1a f834fb3cc9734c2fb8423703374abff2503ca812c53d1e9d1dcc4f3dd7756337 de661cd1fcdfd7aedc77747ec1ebbbb3c0a4c742235d417f4a7c243bdc79fcee cee436359b8c46705cf53999ee1c0d1c170b9b519a1c2143b7ee7cedc8a5ecd1 2d01fd0b9e5b3ac2dcc10f8e28ca38ff124eb533556ddf8e44c7053fc06b59af cfb430514099645b7509dc280890c235d950dcd1a1d8a70699336b4fa2cdb96d f1fe077b0ae542e125c4e6899232639d5da03325be76f352a374594bb8e22f1c 590c23b4d79498c44391c62180558dae05492f57cd335bc943572e63aae70aaa 1df4b00f400fd1b0a8144d51d78e6048c906c2587961362a0a6d2e9163408d73 705f5a7821e50ea431a46af7be478fe6e643dd1d4363fa5780667fc36094c23b 4271355d227fba0da96772ee7f67f7b052df2a70d149e3aff8dd9f647807dd53 5e0fb408fd057de938d8881d2040473c9892b698fbca38d377786e0014f55877 9159967ffcd0e20fc2b30d47a2ca11b44665a4ee3c801c43d0ef4cd96a9261c4 4171d412b3e27779d853387dbcf5b9daf17adf9dc59012d5b9d75f4bbfd8c7d0 64769f6c942f38099c06d78e6f6a3c62666ac1bfb36e35dd8851bbbccf469499 28bd6aa363f94d1f3b138b413b1c558eb2f850968ca8d9b22d29b452beaa68cc 06a0d126959af0d58b01a0f6e983d98e3b27a48046e16cb848b0ba137adfb34e 42adab23d378a6805197a8bcb77d91e061ebdfb6bf1ca4018be88070e2afc18c 7c41bef367f249e432edebf6769d34a34ae30cf96bd523f2b7330042a38a4ea1 48e5400dd103802599776a05739494155f10298cb5b321a8d893f529a1838946 067bdbfaa05b45c727a25e20a17409b06ef0e2db5059456a0abcc2e48581b820 b95ca2bec018f3bca0fe2932ac7ef017b89e1694ebe9e0266496b97e3f168dd3 6739a7000c32d0266a97db6b459701918dd884aefbdd7dbc874f7b4bf531ecbe 30cde09311c089e8c7efd2f18aa0f60fd084549ecb38e2fecc6d84835511a7f7                                                                                                                                                                                                                                                 root root root root root root root root root root root root ossec root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root ossec root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root ossec ossec ossec ossec-hids-3.2.0-6132.el7.art.src.rpm  ossec-hids-agent ossec-hids-agent(x86-64)                       	   
  
  
  @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   
ossec-hids /sbin/chkconfig /sbin/chkconfig /sbin/service /sbin/service /bin/sh /bin/sh rpmlib(FileDigests) rpmlib(PayloadFilesHavePrefix) rpmlib(CompressedFileNames) /bin/bash /bin/sh libcrypto.so.10()(64bit) libcrypto.so.10(libcrypto.so.10)(64bit) libc.so.6()(64bit) libc.so.6(GLIBC_2.14)(64bit) libc.so.6(GLIBC_2.15)(64bit) libc.so.6(GLIBC_2.2.5)(64bit) libc.so.6(GLIBC_2.3.4)(64bit) libc.so.6(GLIBC_2.3)(64bit) libc.so.6(GLIBC_2.4)(64bit) libc.so.6(GLIBC_2.7)(64bit) libdl.so.2()(64bit) libGeoIP.so.1()(64bit) libm.so.6()(64bit) libpthread.so.0()(64bit) libpthread.so.0(GLIBC_2.2.5)(64bit) libssl.so.10()(64bit) libssl.so.10(libssl.so.10)(64bit) libz.so.1()(64bit) rpmlib(PayloadIsXz) 1:3.2.0-6132.el7.art       4.6.0-1 4.0-1 3.0.4-1                     5.2-1      ossec-hids-server  4.11.3   \R@XXYX@TT@SSS[S@R@R@RʚR@R@RrF@RiRR@Q@QY@Q@@QQ@Q@Qu&@Qu&@QkQg@Q\PDPP@PP@OiO@OЗOЗO	O OpZ@NNS@NK@N;@N;@N6@N-ZNMMM@M@M@M?MM>MUM@MPL~L8LΫLΫLʷ@LeL@L{LL@LA@LLLzL~@@L|LvW@LmLa?@LRL4l@LT@KtK͗@KKK@K[K@K8@K@K@K@J@JJJ@JJJn@JL@JI@J2C@J2C@J/@J&eI@Io@I)@I4IܑIII@I@I&@III~@H@H|@HcHM@H2@H)GJ@GAzGV@Gm@Fޚ@F@F@FF@Fr@Fq-FIF-@EWEEySEIE
E 	DDY@D@DLSupport <support@atomicorp.com> - 3.2.0 Support <support@atomicorp.com> - 2.9.0-50 Support <support@atomicorp.com> - 2.9.0-49 Support <support@atomicorp.com> - 2.9.0-48 Support <support@atomicorp.com> - 2.8.1-47 Support <support@atomicorp.com> - 2.8.0-46 Support <support@atomicorp.com> - 2.8.0-45.1 Support <support@atomicorp.com> - 2.8.0-45 Support <support@atomicorp.com> - 2.7.1-44 Support <support@atomicorp.com> - 2.7.1-43 Support <support@atomicorp.com> - 2.7.1-42 Support <support@atomicorp.com> - 2.7.1-41 Support <support@atomicorp.com> - 2.7.1-40 Support <support@atomicorp.com> - 2.7.1-36 Support <support@atomicorp.com> - 2.7.1-35 Support <support@atomicorp.com> - 2.7-34 Support <support@atomicorp.com> - 2.7-33 Support <support@atomicorp.com> - 2.7-32 Support <support@atomicorp.com> - 2.7-31 Support <support@atomicorp.com> - 2.7-30 Support <support@atomicorp.com> - 2.7-29 Support <support@atomicorp.com> - 2.7-28 Support <support@atomicorp.com> - 2.7-27 Support <support@atomicorp.com> - 2.7-26 Support <support@atomicorp.com> - 2.7-25 Support <support@atomicorp.com> - 2.7-24 Support <support@atomicorp.com> - 2.7-23 Support <support@atomicorp.com> - 2.7-22 Support <support@atomicorp.com> - 2.7-21 Support <support@atomicorp.com> - 2.7-20 Support <support@atomicorp.com> - 2.7-19 Support <support@atomicorp.com> - 2.7-17 Support <support@atomicorp.com> - 2.6-16 Support <support@atomicorp.com> - 2.6-15 Support <support@atomicorp.com> - 2.6-14 Support <support@atomicorp.com> - 2.6-13 Support <support@atomicorp.com> - 2.6-12 Support <support@atomicorp.com> - 2.6-11 Support <support@atomicorp.com> - 2.6-10 Support <support@atomicorp.com> - 2.6-9 Support <support@atomicorp.com> - 2.6-8 Support <support@atomicorp.com> - 2.6-7 Support <support@atomicorp.com> - 2.6-6 Support <support@atomicorp.com> - 2.6-5 Support <support@atomicorp.com> - 2.6-4 Support <support@atomicorp.com> - 2.6-3 Support <support@atomicorp.com> - 2.6-2 Support <support@atomicorp.com> - 2.6-1 Support <support@atomicorp.com> - 2.6.0-0.10 Support <support@atomicorp.com> - 2.6.0-0.9 Support <support@atomicorp.com> - 2.6.0-0.8 Support <support@atomicorp.com> - 2.6.0-0.7 Support <support@atomicorp.com> - 2.6.0-0.6 Support <support@atomicorp.com> - 2.6.0-0.5 Support <support@atomicorp.com> - 2.6.0-0.4 Support <support@atomicorp.com> - 2.6.0-0.3 Support <support@atomicorp.com> - 2.6.0-0.1 Support <support@atomicorp.com> - 2.5.1-10 Support <support@atomicorp.com> - 2.5.1-9 Support <support@atomicorp.com> - 2.5.1-8 Support <support@atomicorp.com> - 2.5.1-7 Support <support@atomicorp.com> - 2.5.1-6 Support <support@atomicorp.com> - 2.5.1-5 Support <support@atomicorp.com> - 2.5.1-4 Support <support@atomicorp.com> - 2.5.1-3 Support <support@atomicorp.com> - 2.5.1-2 Support <support@atomicorp.com> - 2.5.1-1 Support <support@atomicorp.com> - 2.5-1 Support <support@atomicorp.com> - 2.5-0.9 Support <support@atomicorp.com> - 2.5-0.8 Support <support@atomicorp.com> - 2.5-0.7 Support <support@atomicorp.com> - 2.5-0.6 Support <support@atomicorp.com> - 2.5-0.1 Support <support@atomicorp.com> - 2.4.1-11.2 Support <support@atomicorp.com> - 2.4.1-11.1 Support <support@atomicorp.com> - 2.4.1-10 Support <support@atomicorp.com> - 2.4.1-9 Support <support@atomicorp.com> - 2.4.1-8 Support <support@atomicorp.com> - 2.4.1-7 Support <support@atomicorp.com> - 2.4.1-6 Support <support@atomicorp.com> - 2.4.1-5 Support <support@atomicorp.com> - 2.4.1-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.2 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta2.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta1.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-11 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-10 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-9 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090225.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090220.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090206.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090205.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.99-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.99-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.6.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.6-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.4-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.4-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.0-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.0 Scott R. Shinn <scott@atomicrocketturtle.com> peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org - Update to 3.2.0 - Change labels in alert mail headers to "ASL" - Update to Ossec 2.9.0 Final - Update to Ossec 2.9.0 - Update to 2.8.1. This is identical to 2.8.0-46, the only change is the hosts.deny CVE-2014-5284 is merged in. - Revert BR#1596
- Add Bugfix for hosts.deny race condition (CVE-2014-5284) - BR #1596, Add fork limiting patch (max 10) for execd to prevent DoS conditions - Upgrade to 2.8.0 - Feature Request #1512,  speed up shuns in execd, move sqlite down - Relink against native mysql - Add ar-tracking active response - Placeholder for null exclusion rules.  Legacy support - ASL 4 version with new database format - Add support for Fedora 20
- Modify optimization flags for FORTIFY - Update to 2.7.1
- Add independent rules.d/decoders.d ossec-rules package - FR#772, add rule 3360 for postfix slow brute force
-   add dovecot-decoder.patch for cpanel dovecot
-   Update 9702, 9753 for dovecot brute force
- FR#773, add rule 11308 for pure-ftp slow brute force
- FR#1347, Update for courier v4 decoder (pop3s)
- FR#1359, Update horde decoder for v5 - Disable ossec-dbd signature table (replaced by aslw_rules). This was very slow - Break ossec-dbd into separate package
- FR#1321, update courier-imap decoder for version 4.0 - Bugfix #XXX, prevent truncating last character on ossec-dbd database inserts on the alerts/data table - Add tld column to alert table w/ index - Deprecate internal id generation in dbd
- update schema to autoincrement, increase id space to int - Add is_hidden to mysql schema - Add if exists to mysql schema - Add os_dbd-mysql-replace-query.patch to consolidate SELECT/UPDATE into REPLACE sql - Consolidate alert & data into a common table
- Add ossec-authd init script - Add sqldelete command  to execd
- Update to clear sqlite db at startup - More minor updates to GeoIP tracking - Minor update to GeoIP tracking - Bugfix on permissions for files in shared/ directory for client installs
- Add GeoIP support
- Remove dependency on perl-DBD-SQLite
- Update asl-shun to new non-perl based version.
- Deprecate firewall-drop-update.patch
- Add sqlite support to execd (/var/ossec/var/execd.sqlite) - Update to 2.7 final - Feature Request #XXX, revert duplicate detection in log events to help detect extremely fast brute force attacks
- Add FORTIFY_SOURCE, PIE, and relro (full) - Update to 2.7-rc2 - Update to 2.7-rc1 - Move active response components under the common package - bugfix #xxx, correct ownership permissions on fts dir - Update to init script to suppress spurious execd output
- Add alerts queue to server package with ossec/ossec permissions - Bugfix #XXX, correct any/agentd condition - Moved agentless packages under server - Drop timeid and cat_id indexes from schema - Add new index, timeid to alerts table. - Add cmoraes patch, Adds config options for enabling/disabling rootkit/syscheck options, and agent config profiles
- Add ossec-memleaks patch
- Add agentless directories, and agent.conf
- Bugfix #XXX, ossec-hids.init will now return an exit code on status - Add prelink_cmd support - Bugfix #XXX, display multi-line events in data table correcty - Update to asl-shun.pl purge event to default to 24 hours. - Update to asl-shun.pl to change ordering of block rules
- Revert from 0805 snapshot - Update to 0805 snapshot - Update to 0801 snapshot
- Update asl-shun.pl to log to active-responses.log, blocks now go to the named chain ASL-ACTIVE-RESPONSE, and delete events are more redundant. - Update to OSSEC 2.6 Final - Update to snapshot 110711 - Update to snapshot 110613 - Update to snapshot 110609 - Update to snapshot 110606
- Moved ossecr user creation event to the ossec-hids core package - Update to snapshot 110531 - Update to snapshot 110526 - Update to snapshot 110504 - Bugfix #536, Increase the default sleep time for syscheck - Renamed to 2.6 branch - Add support for the rules/decoders dir system - Update to snapsot 110405
- Update asl-shun to support ossec alert ids - Changed asl-shun sqlite database to /var/ossec/var/blocklist3.sqlite
- asl-shun database format now stores the full alertid - Update to snapshot 101203 - Update to snapshot 101125 - Added alertid support to os_dbd, this involves a schema update - Added dst ip, src prt, and dst prt capture support to os_dbd - Bugfix #XXX, manage_agents was built in client mode for the server package. - Add clamav decoder & ruleset - Update to 2.5.1 final - Update to 2.5 final - Update to 0928 snapshot - Extended no_ar into ossec-dbd - Add no_ar option to disable active response per rule - Update to snapshot 100920 - Update snapshot to 100907 - Snapshot 100901 - Added test fix for os_dbd - Bugfix #376, ossec-control will now properly stop and reload - Update to 0809 snapshot - Relink against native mysql - Add minicon decoder from les fenison - Update to 100707 snapshot
- Feature Request #371, add ossec.log to logrotate - Updated to 100615 snapshot - Updated init and ossec-server scripts to support the new reload feature. - Update to 2.4.1 - Added zabbix reporting active response - Update to 2.4 final
- Lowered courier rule 3910 (failures) from 6 over 240 to 10 over 10
- Lowered courier rule 3911 (success) from 10 over 60 to 30 over 20 - Rebuilt for atomic repo - Update to CVS 100317 - Update to CVS 100311
- Add decoder for denyhosts
- Update asl_rules.xml to include denyhosts rules - Update to CVS 100309 - Added new decoder for smtp_auth
- Added rules to detect smtp_auth brute force attempts
- Added rules to detect imap/pop brute force attempts - Updated ossec-server.conf to be in parity with the ASL config
- Added templates dir for generating configs - Update to 2.3 release - Update to snapshot 091109 - Update to snapshot 091008 - Update to snapshot 090925
- Added timestamp field to the mysql schema
- Bugfix #XXX, for the ossec-client.init script to call the correct (renamed) ossec syscheckd/logcollector daemons
- Appologies for not updating the previous changelogs. Missed a few updates! - Update to snapshot 090827
- Feature Request #225, Added logrotate event to active-response log
- Updated system_audit_rcl.txt to look for the correct php.ini file - Update to 090824, beta 1 release - Update to 090812 snapshot - Rebuild agent daemons with -DCLIENT, added symlink trickery - update to 2.1.1 - update to 090630 snapshot, this has fixes for CentOS/RHEL 4 64-bit environments - update to 2.1 final - update to snapshot 090612 - update to snapshot 090610 - update to snapshot 090603 - Disable postgresql support, to get around an undesirable dependency on EL4 - Update to snapshot 090417 - Update to snapshot 090413 (this adds in inotify support) - Update to snapshot 090410 (this adds in inotify support) - Update to snapshot 090408 - Added authpsa rules back in, this is used to detect brute force attacks
- Added conditional building support for ASL modifications - Update to 2.0 official release - update to snapshot 090225 - update to snapshot 090220 - update to snapshot 090206 - update to snapshot 090205 - update to CVS code 090129, this is not an offical release. Its for testing only - update to CVS code 090126, this is not an offical release. Its for testing only - update to 1.6.1 - update to 1.6 - update to 1.5.1 - added mysql support - Added Stanislaw Polak's excellent ban-hackers script to manage shunning more intelligently. - update to 1.5 - fix on active-response locking bug that prevented some rules from expiring. - update to ossec 1.4 - update snapshot to ossec-hids-071011.tar.gz
- relinked C4, FC4, FC5 against mysql4 - update to snapshot ossec-hids-071006.tar.gz - update to shun blocklist tracking used by ASL
- added authpsa rules + decoder - update to 1.3 - minor adjustment in post, to check for config file before overwriting it - v6 was first version of the patch.
- added in logging in active-response for better ASL support
- Disabled conf event in post, to keep from overwriting config files. - changed permissions on queue/syscheck so it can be read by the ossec group (tweak for web gui) - removed the noreplace settings from decoder and the rules
- patch for a more ASL friendly client config - release -2 had a bug. 
- added ASL rules (asl_rules.xml)
- added decoder for the asl style modsecurity logging
- adjusted syslog_rules for qmail-scanner issue (BUG #ASL-18)
- Added http index in asl_rules.xml (BUG #ASL-7) - update to 1.2 - update to 1.1 - configuration change for ASL - updated to 1.0 - import into ART
- changed their naming conventions a bit, 0.9-3 to 0.9.3. Please dont be cross with me. - new version (0.9-3) - new version (0.9-2) - new version (0.9-1a) - new version (0.9-1) - new version (0.9) - some bugfixes - created /bin/sh /bin/sh ossec-hids-client                                                                                                                                                                             	   
                                                                      !   "   #   $   %   &   '   (   )   *   +   ,   -   .   /   0                                                      1:3.2.0-6132.el7.art 1:3.2.0-6132.el7.art                                                                                                                                                            ossec-init.conf ossec-hids agent-auth client-logcollector client-syscheckd manage_agent ossec-agentd ossec-client.sh ossec-execd internal_options.conf ossec-agent.conf ossec.conf.sample agent.conf acsc_office2016_rcl.txt cis_apache2224_rcl.txt cis_debian_linux_rcl.txt cis_debianlinux7-8_L1_rcl.txt cis_debianlinux7-8_L2_rcl.txt cis_mysql5-6_community_rcl.txt cis_mysql5-6_enterprise_rcl.txt cis_rhel5_linux_rcl.txt cis_rhel6_linux_rcl.txt cis_rhel7_linux_rcl.txt cis_rhel_linux_rcl.txt cis_sles11_linux_rcl.txt cis_sles12_linux_rcl.txt cis_solaris11_rcl.txt cis_win10_enterprise_L1_rcl.txt cis_win10_enterprise_L2_rcl.txt cis_win2012r2_domainL1_rcl.txt cis_win2012r2_domainL2_rcl.txt cis_win2012r2_memberL1_rcl.txt cis_win2012r2_memberL2_rcl.txt cis_win2016_domainL1_rcl.txt cis_win2016_domainL2_rcl.txt cis_win2016_memberL1_rcl.txt cis_win2016_memberL2_rcl.txt rootkit_files.txt rootkit_trojans.txt system_audit_pw.txt system_audit_rcl.txt system_audit_ssh.txt win_applications_rcl.txt win_audit_rcl.txt win_malware_rcl.txt alerts rids syscheck /etc/ /etc/rc.d/init.d/ /var/ossec/bin/ /var/ossec/etc/ /var/ossec/etc/shared/ /var/ossec/ossec-agent/etc/shared/ /var/ossec/queue/ -O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches   -m64 -mtune=generic drpm xz 2 x86_64-redhat-linux-gnu       ?   0   7zXZ  
 !   #,:] "k%l{ls&ԥ=^ }WXrJBw5:/CxrZn-Y pdy]|꛹9t[NѸ;.%%mr}eӰm1n^xR8m#'ucya^Io`Jfc޴]kkYu¼Q㠯#W	7Tηᶘ;s87)\ۅv!1g(cHr~ReRi#zٓNj{#$}њǂҘSh1;W1plfBo/
qcD]$8=`) _i7/֔b入3<]=˃OgS1wh,EHI|Kե2xtB^P>Hх8Vz#0,_xSk}R6CLc^xW
|DQ£]5Z$֒2dI/Gm(YOn)_7ԥ!-vx[saP1nlP

=I+6h$(	ܪ+\+kL'|vp.!M۝uFsD`[k[nəY6LC(79׍С|>/q׺qǉdr
kB݅FRy0%\mn<\Aՙ_6wdEanN²72`؅?,N3Sl[V2 h" Wꛜ~>P@TMyy:7/0o]˛t9Dp Fl&fgݨ7%~9NgdsLM>It-pz6#	13+gAc!٥1$Jwxqu T(]{S3XSfIo0Ke>TKO0i7Ǖ7J~ڝ$X+s}~ˢ)rNGXxWXQ1%{N T?.4Rz1$#OH0Xr?N˸9͚\AG#Hc&Vz_>A|SopϢSs_ -,A /hΆqsƷCAjGАi*uqsHO#S%3! !+>VXMs?hpݟx|^mƩ{5ꤵ\u}!ƞ3Q6ЙV~itDעD_*N0~Mw'FiՍXrMEj6{٭s͵X'red5fO(<3oY,n/ˉ5vN%$YE3Lq,ȐG31tOK{Z[75w$AXՖèL0Kq	t7+w7d8'Ka;Ȏ4#^Y`Z!jѹެ,ZZXޙ;~,HTt%|T꒽tӔeF˒LNj ~u1Hv≓w8Gɭ-Ѹ$!kS~^䎫MS4ہE}x fGXig&B)xy%Cۨ~ƬbZۺ96
2|MS=6r:^zeіu.ޟJoQ97>*1.$[O턿Lvfyߦ"NZL+~X[UVp=[v9>8qb[^9ndRD̔9||W	++d,|G
H~GVkiG()|Θ~	wа@P4WοE*N+<k4[ccb!Z2A5i3Լjh<K
P,[:
'l*H@kҐ	/K@yO3	$bM^%r-Ola6_XQxmYkbf]Hh.A1xD\~\{j}o̀yZ CO%G-9.Ii9Ydw
A;1-}YCH%原ݢ'\!w˹GkL6⤄bd2Յą]y)_&c*IaYPAdbf3heC$meoU?>
 #r`fyUj
+[H_xm5S!8N'9.SM?\sn9{,X Afz.GIZnqpّ]mAbIM"'+Q(.6G_fj!H[jNNb@_Aq8Jc#sUv"&9Ў~
X/8|޷>1(5P`,aۯqq/;<-xZ}NYKZom^( W>b=u_[3ѫbe},Y]j9ͩ[k{-9EL#بxM.3qYQ=TdF|E=4nyMkl(FK2z)ڠM!RaYF_1S*Gi0\xvkSyl){r@>pڱ@5E꽂ש;sb\De6μk&$ZW5	!+:QJ@6Z\ j?YWK~-
NOq(6'IOȈS3i/Yh |hk97GD	% 1kOX4*m|k_vOS;tg3'	.f|x`t
DPwF8ҩ"Pيٽ~EMvn&e6]w,jSC;r,"p7~Qau]Aƀ`9WJH(s/V*,hhV"O~u\3a4 
*f^f>/(_tJ`	Rdg[6.4UBBwŐMc^1(Uq45esmU|mP|Ǖxq'+	N֜[8?	Es<O,OfqY%4b;$UեˢҀi"6\ݧҚ
8H	fdoOv$](UhkW1CТ%HvЭd\!<: %Oξ»-ˏu_k`TN~5 DYJo-G>$y,soĎm]9@F3|t.`?0z.Dl&lQu'*WΗKCYۡYz6$Z;KZ8eG&"?`C9*JMWɰ0nѱcL)]CAJ%о0|@/^Fao`Xj;b?˭j'N9eԐR٤yp 'kL.|\쐣4 aTgږi:{5n2`/n9}"Dlg&ݺP!$v?Y$&w'jU
ZP2Pe"A ;r"g;3%k7hs:)W3I=pAUc8י鋓*(0~0ȉ[ґT7ͨ>$i
kFt?_ZS/wn#Riz^pS7+#]=ڤǍ*fޮ:Z)=K:gp}z"3q7K!GJfAdp1&gwyCy"_+cec㶺.hڭWSB%({Xbm	G`
B@2N0s5Ď5Z.A|:ΙٽT!k]p[sұC!N[*8
+e3d&U]0iÁ d佚ǛzU82QJ'*}Mk^ 4+5G+|j$!BzVw"<l%/?HU% 0@jf9ږKuj
>vugjHl|49vRw@e~7*sצspZ0#σwN~mCRۗUր9ˌ.?&.SV;lxу/䨯PD|e9(i%X1 ғ5fw¢֨;åP<
O)*<OHr%rg{tX63uڒ¢)C/Ce@3a_]ݙzm'|9NX8l"q0!?I:YF
V,JkkEЫ2@ELD9I'PFĽyiCZбvZF{<`W]=$HSս{
Τ#ܼm%[{WB]:L) ba8No- 9~F!Pr\._( #=LtzFAtdj|ARYIHR	)iShl4;/Z4QwB"Rk0mɋq汧nayD6h9CGJCEO\784։d#h|id=
H"C@BJ:l)tZo3-xHU^_wVW1bSH2*ApɰizuÛIyz$XKtْx}p*j?&o+s;to#,0cWg]Mq;|),zMIaE?:;lUhC[lFex,I#)+i9WFZl՞?If&p0qF~b٫%cl?Y/%-tǂ"mɨbk3^4T,z)gSm#ܭe諤䌗<;,mΔ>7w6yCݹ⑏΁|{يP
>uaJ ]->JIҮ>j$v"BY&YmNt?֐daESP? R`Ƿ .gn.>A:4wD/hv*Vb.=P7x
}&/fgޡGy e@ཀྵ-Bk]uyjCL9m %<]OtndV`cyXe+*`iv|V&wN:ǞOΑW Y@.!Τay5˚uܱ_=9ZL!nN|N# hKT`R5B![#\nĉKA: d=CQAN{jY.*nks#5.^t-$n~uW1׳f8Ag_7{A1	ƜFt:=T,	}gT+39y ]bS
/w&ն4)S%I     (='iYHLj 	G}Q\O -u  ,    
YZ