    ossec-hids-2.7-23.fc15.art                                                                    $   >                                  oan]k"\O.   >                 @  f   ?     f      d                                                	           	   R          0          4          P          T          i          m        	                                                        V       X   V  	        V  
        V          V       ^   V          V          V          V                    V        $           \                     !Z     (     !     )     !     *     !     +     !     ,     !     -     !     8     !   y  9     #   y  :     :T   y  =     U'     D     U/     G     U8   V  H     V   V  I     W   V  X     X@     Y     XP     \     X   V  ]     Y   V  ^     ^|     b     _     d     `d     l     `i     t     `   V  u     a   V  v     c4     w     c   V  x     e8   V  y     f          f     e     f     f     f   C ossec-hids 2.7 23.fc15.art An Open Source Host-based Intrusion Detection System OSSEC is a scalable, multi-platform, open source Host-based Intrusion Detection
System (HIDS). It has a powerful correlation and analysis engine, integrating
log analysis, file integrity checking, Windows registry monitoring, centralized
policy enforcement, rootkit detection, real-time alerting and active response.
It runs on most operating systems, including Linux, OpenBSD, FreeBSD, MacOS,
Solaris and Windows.

This package contains common files required for all packages. Ql hloggerhead.atomicorp.com     {http://www.ossec.net GPL Atomicorp <support@atomicorp.com> Applications/System http://www.ossec.net/ linux x86_64 if ! id -g ossec > /dev/null 2>&1; then
  groupadd -r ossec
fi
if ! id -u ossec > /dev/null 2>&1; then
  useradd -g ossec -G ossec       \
	-d /var/ossec \
	-r -s /sbin/nologin ossec
fi
if ! id -u ossecr > /dev/null 2>&1; then
  useradd -g ossec -G ossec       \
	-d /var/ossec \
	-r -s /sbin/nologin ossecr
fi            !  !  8  6     <          _   =     -         R                    ;                s      1       <             c      
?    	        }            P      '           8  A            O    
       {   d      (   (   <   (A큤A큤A큤A큤AhAhAhhhhhhhhhAhhhhhhhhhhhhhAhAhAA聠AAhAAAhA                                                                                                                                                                            Ql fQl gPiwPiwPiwPiwPrUPiwPiwPiwPrUPiwPiwPiwPiwPiwPiwPiwPiwPiwPiwPiwPiwPiwPiwPrUPiwPiwPiwPiwPiwPiwPiwPiwPiwPiwPiwPiwPiwQl eQl eQl fQl fQl fQl fQl fQl fQl fQl fQl fQl fQl fQl fQl fQl fQl fQl fQl fQl fQl fQl fQl fQl fQl gQl fQl fQl fQl fQl fQl fQl fQl fQl fQl fQl fQl fQl fQl fQl fQl fQl eQl eQl eQl eQl eQl e65bec1e837d94dff7f8db551208d73aeb0dc2fef6a6407ea7c91c4ee6f430528  5724e1febc0e096bd10f7b60e053d35cdcff1081d79641aa8c2e224b4d25564b ab992180ccba57356947dafa66fee78705d3193cb5a0aeb06746e29c171fece3 5ba0d1e9c28d5fbac69da4d4c5aa661d3b36043f91db79d0d24e065f64eaf5d9 873997ee9e481e8ec70717ccb9cfd4586bfc206de7bfcf4d9e4ee2362b51984d  9fe9080ce777f1a6ae7b30897d0fb608ae624bfb348ecf0c0c860ddbdf86e5f0 0ec9577297c751ff97badc51306be8111040caa25081fd2e30c0fe38e44c7f68 1e0f3d6deb94ce7081fae364891cac7758754639e4b88acccc54671eab510266  c988f19452b5542572cae3fff4f0fac802562acc315e5173aa4e083d9e369842 9d9ec8875aec0ac6117dae038f4e015d811720fe4a64b93c15d3583b1340dcf0 20cf243734164073841e9ca712d34f54db876fb5d7ebafdbdb71a9fd5c91fc92 dc0b9539ba19d3b5ddca245f8cf1e3f89a9fd345a6f6fb5dc86f7087acdb45cd 1e0f3d6deb94ce7081fae364891cac7758754639e4b88acccc54671eab510266 098c461918330df3a040ae8b3fdf06ba15ef234deeb7c8da37d9a8cc21d3af8b a81c47faa02a7cddf8962e1301f71a013cdea018cdb0975758487de252499d34 f2271e2698e78b45b32149e10600d4fd15262cbdf44e43a5a4b0d51c9f7f2e8f be8502642e5a5251a50cf8274747caa2b3aae9b819e172e5def48dd3e33e9443 ecce3956f6c2defb4033e497cf965a81ddf825964637324920d58566f6933dc8 3fa00600644e8add5af583ae9f16b64e72ae13bdf65dd5c2cbafa9cbab3e63f9 a76d2a0929c5508ddfd00a8a246c549e4d3855fd5277453d9b61c7f660e8fb48 70f89134f79532f6f642f47a2d0bdf63861d20f4b76f190711bc4e2d3dfcb892 9dfb9bdf2df6d1948877696ffb6ff8f08dbda8a3c3e1fcdead588fc44ce462ca  8ab9eb4987d590c7d1e5e7a62358c957d9d5a5c6e528f835eb2529eb751edd1c a5924d7f5fa4ecfa24bee05187fa22f432069720a914374892e9bd8d2a807d8a 4f73cb6caba37b1f399cb8e835608aa1e41dbb4ccee16ba23f6e878dd8f58899 1e1f01db9177108f64c5e561822f0a259bdfad59aebcf0fe24d0c0e9df5f9756 1e0f3d6deb94ce7081fae364891cac7758754639e4b88acccc54671eab510266 ef970afaee6fc7fa4168b1a3ccdf9808edf5df98b30c195597317e7d59c0bae1 065ae034ecc96615757d45a4af1c9f1770295131a1ead862073eb78329522d4e 1d1e66839dd778872fe2aa7275713c2ffc64486f2b2157b51d044cbfcf5ea9ee cee8fd0b3cee63ba465cf8d4d58de2e155602f678efcc54bb6a6d5a43f496a42 3668a2dd9f579512554f17443a71530e8ac867bf8c9115c53f79b301f05e7836 0458d564b9d237a720b126230bd78175da49c5a19e4e9324dcb0384302654282 785514a76800f7faf6865ba06fe6eea63cf17c2c04bd2dc65c2af5697c808070 810475207bab7ce35d0ca1f3fb2174dbad95ab50f9873a3879889674bcad9b80    27c6d28abb5b4d45e99b42ff42431cf20b9960e2aeb3624846866e8c8ddd822d f9a813e4e53823fc8d43a8ec1a91df67524308156eabdf63c8440086f2394260 5c48ccea0bedb4854aee80f5c371e3a00f9f7b3e5aa097a3e76d77fc4c682eb9 a92731e8b8ef0e0e6ac663e2ab01d92b5809a94f46858f4cbcf7dc01aa92aec1 5781e4c355eee177f8789ce242a75dde4b27f1f313e6eb4b1641227ab2767848 e736dde6929e32461fe51db100d4bff0d80ac2d316e7011aa4ac8294bb94a0a9 7b180716a51e2910f2e2595675e087bb173ba962aa61c0835990f186818704c2 a8a4b349fff82b0c8ab42a00c19289e437f0cdebbeb6b6b5c1cf575e53cbfba9  5714dd884065a61ba76e2ea64b5e34cd772b05f1236cca1b1560453859c51b7a 17259074c474eeb4ce681de22d537df841878e16afe18ebc5395136952fd4409 5c7c776bd51ea5278df7c61683c07043d6ff8ae275fa4ae491605e7e7efa374b 8db328d8b0d2983b2a15ca437de8cdba77c3fd9baf5a7cf3de7ef964d4cc12d8 5a71febacae4f138f9ec10024a12cf575cc1e8d1c0acd75bba23d8a4b1ae7c97 6f34bc106944b14f45afcb983ecff32260e65d767b7d0ddf04b55dd62d31f99d 7add0c3b7abe86dfb0a2e29b01a6c6d90c4753232187961cd433ebd03a826755 1662ad5b46a0a66592c4d8b035d890340867ab25eb5a0f508c51edbac2bbc24a 1e93338483db73bb9571fbc05565b81f9695937709698510d40ad78a9e2c1973 41ae7d35f1ee0240c58808f3138c21322c577495dfe2de13219e4274c55722a9 00f8187f0435b42ce4b9b07fbf1df73502a5dd22329c6b5070786e137d5a3f97 38e0d5d61620a94b3fc552a822e40d27bd6add5cb354dab8779b2c180e5f692e  076f8fe539b132fc462ec518ab3740c9e4e21231dce7dcb6237daa4d3de5e9ab    9fb3b973248c76d14a814ba558235f520640d26e9f2fafac03fa2432b16e40f9 738d6767a0d76f8732f9afb869b5b7533b0342989ff6754fbc9fc023a37b0c1c aee022646c6b78507bd02bd632efc1d46e65c82589c8823190e83e4c006846d6 00897a8ee5c0159709c28c622ad5e4de85d0e596f770ea8c80be97893f85f675 43ba95564730b7265e456120cef81905316d877cc532344993987b38f1b1e008 1c87cd21a1b8e5e4fca27a2fc19868d161f15635514513586adddbdb196cec6c f97d988840ce05868f7e8eb40582354bb44f1d0e1614241d088a8c440f0fc4ba 4d4d92afaa567f36f7b7e159ea245b23873688c662380971b3f38868637fc9bd bab6f4daa755da05205517d885939b1880703b271958789962fb92b83df9ee59 58d925aab330df06db3418f50d3f57c2f1f5c892f142c3d59cb9db2de1380a8d 3952a2669d9788a52c0f54d54db7954dd74129e9a34953bcf4864248fbfa5107 b8f7994193cc5fcc7a75988740e117b64462ee62a7d40cff17f72e5d39fb2736                                                                                                                                                                                                                                                                                                                                                                                                                  root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec root ossec ossec root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec-hids-2.7-23.fc15.art.src.rpm   config(ossec-hids) ossec ossec-hids ossec-hids(x86-64)          @   @               
  
  
  
/bin/sh /bin/sh /bin/sh /usr/bin/env /usr/sbin/groupadd /usr/sbin/useradd config(ossec-hids) inotify-tools rpmlib(CompressedFileNames) rpmlib(FileDigests) rpmlib(PayloadFilesHavePrefix) rpmlib(PayloadIsXz)       2.7-23.fc15.art  3.0.4-1 4.6.0-1 4.0-1 5.2-1 4.9.1.3 [ -r /etc/localtime ] && cp -fpL /etc/localtime /var/ossec/etc glibc          QkQg@Q\PDPP@PP@OiO@OЗOЗO	O OpZ@NNS@NK@N;@N;@N6@N-ZNMMM@M@M@M?MM>MUM@MPL~L8LΫLΫLʷ@LeL@L{LL@LA@LLLzL~@@L|LvW@LmLa?@LRL4l@LT@KtK͗@KKK@K[K@K8@K@K@K@J@JJJ@JJJn@JL@JI@J2C@J2C@J/@J&eI@Io@I)@I4IܑIII@I@I&@III~@H@H|@HcHM@H2@H)GJ@GAzGV@Gm@Fޚ@F@F@FF@Fr@Fq-FIF-@EWEEySEIE
E 	DDY@D@DLSupport <support@atomicorp.com> - 2.7-23 Support <support@atomicorp.com> - 2.7-22 Support <support@atomicorp.com> - 2.7-21 Support <support@atomicorp.com> - 2.7-20 Support <support@atomicorp.com> - 2.7-19 Support <support@atomicorp.com> - 2.7-17 Support <support@atomicorp.com> - 2.6-16 Support <support@atomicorp.com> - 2.6-15 Support <support@atomicorp.com> - 2.6-14 Support <support@atomicorp.com> - 2.6-13 Support <support@atomicorp.com> - 2.6-12 Support <support@atomicorp.com> - 2.6-11 Support <support@atomicorp.com> - 2.6-10 Support <support@atomicorp.com> - 2.6-9 Support <support@atomicorp.com> - 2.6-8 Support <support@atomicorp.com> - 2.6-7 Support <support@atomicorp.com> - 2.6-6 Support <support@atomicorp.com> - 2.6-5 Support <support@atomicorp.com> - 2.6-4 Support <support@atomicorp.com> - 2.6-3 Support <support@atomicorp.com> - 2.6-2 Support <support@atomicorp.com> - 2.6-1 Support <support@atomicorp.com> - 2.6.0-0.10 Support <support@atomicorp.com> - 2.6.0-0.9 Support <support@atomicorp.com> - 2.6.0-0.8 Support <support@atomicorp.com> - 2.6.0-0.7 Support <support@atomicorp.com> - 2.6.0-0.6 Support <support@atomicorp.com> - 2.6.0-0.5 Support <support@atomicorp.com> - 2.6.0-0.4 Support <support@atomicorp.com> - 2.6.0-0.3 Support <support@atomicorp.com> - 2.6.0-0.1 Support <support@atomicorp.com> - 2.5.1-10 Support <support@atomicorp.com> - 2.5.1-9 Support <support@atomicorp.com> - 2.5.1-8 Support <support@atomicorp.com> - 2.5.1-7 Support <support@atomicorp.com> - 2.5.1-6 Support <support@atomicorp.com> - 2.5.1-5 Support <support@atomicorp.com> - 2.5.1-4 Support <support@atomicorp.com> - 2.5.1-3 Support <support@atomicorp.com> - 2.5.1-2 Support <support@atomicorp.com> - 2.5.1-1 Support <support@atomicorp.com> - 2.5-1 Support <support@atomicorp.com> - 2.5-0.9 Support <support@atomicorp.com> - 2.5-0.8 Support <support@atomicorp.com> - 2.5-0.7 Support <support@atomicorp.com> - 2.5-0.6 Support <support@atomicorp.com> - 2.5-0.1 Support <support@atomicorp.com> - 2.4.1-11.2 Support <support@atomicorp.com> - 2.4.1-11.1 Support <support@atomicorp.com> - 2.4.1-10 Support <support@atomicorp.com> - 2.4.1-9 Support <support@atomicorp.com> - 2.4.1-8 Support <support@atomicorp.com> - 2.4.1-7 Support <support@atomicorp.com> - 2.4.1-6 Support <support@atomicorp.com> - 2.4.1-5 Support <support@atomicorp.com> - 2.4.1-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.2 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta2.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta1.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-11 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-10 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-9 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090225.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090220.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090206.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090205.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.99-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.99-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.6.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.6-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.4-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.4-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.0-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.0 Scott R. Shinn <scott@atomicrocketturtle.com> peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org - More minor updates to GeoIP tracking - Minor update to GeoIP tracking - Bugfix on permissions for files in shared/ directory for client installs
- Add GeoIP support
- Remove dependency on perl-DBD-SQLite
- Update asl-shun to new non-perl based version.
- Deprecate firewall-drop-update.patch
- Add sqlite support to execd (/var/ossec/var/execd.sqlite) - Update to 2.7 final - Feature Request #XXX, revert duplicate detection in log events to help detect extremely fast brute force attacks
- Add FORTIFY_SOURCE, PIE, and relro (full) - Update to 2.7-rc2 - Update to 2.7-rc1 - Move active response components under the common package - bugfix #xxx, correct ownership permissions on fts dir - Update to init script to suppress spurious execd output
- Add alerts queue to server package with ossec/ossec permissions - Bugfix #XXX, correct any/agentd condition - Moved agentless packages under server - Drop timeid and cat_id indexes from schema - Add new index, timeid to alerts table. - Add cmoraes patch, Adds config options for enabling/disabling rootkit/syscheck options, and agent config profiles
- Add ossec-memleaks patch
- Add agentless directories, and agent.conf
- Bugfix #XXX, ossec-hids.init will now return an exit code on status - Add prelink_cmd support - Bugfix #XXX, display multi-line events in data table correcty - Update to asl-shun.pl purge event to default to 24 hours. - Update to asl-shun.pl to change ordering of block rules
- Revert from 0805 snapshot - Update to 0805 snapshot - Update to 0801 snapshot
- Update asl-shun.pl to log to active-responses.log, blocks now go to the named chain ASL-ACTIVE-RESPONSE, and delete events are more redundant. - Update to OSSEC 2.6 Final - Update to snapshot 110711 - Update to snapshot 110613 - Update to snapshot 110609 - Update to snapshot 110606
- Moved ossecr user creation event to the ossec-hids core package - Update to snapshot 110531 - Update to snapshot 110526 - Update to snapshot 110504 - Bugfix #536, Increase the default sleep time for syscheck - Renamed to 2.6 branch - Add support for the rules/decoders dir system - Update to snapsot 110405
- Update asl-shun to support ossec alert ids - Changed asl-shun sqlite database to /var/ossec/var/blocklist3.sqlite
- asl-shun database format now stores the full alertid - Update to snapshot 101203 - Update to snapshot 101125 - Added alertid support to os_dbd, this involves a schema update - Added dst ip, src prt, and dst prt capture support to os_dbd - Bugfix #XXX, manage_agents was built in client mode for the server package. - Add clamav decoder & ruleset - Update to 2.5.1 final - Update to 2.5 final - Update to 0928 snapshot - Extended no_ar into ossec-dbd - Add no_ar option to disable active response per rule - Update to snapshot 100920 - Update snapshot to 100907 - Snapshot 100901 - Added test fix for os_dbd - Bugfix #376, ossec-control will now properly stop and reload - Update to 0809 snapshot - Relink against native mysql - Add minicon decoder from les fenison - Update to 100707 snapshot
- Feature Request #371, add ossec.log to logrotate - Updated to 100615 snapshot - Updated init and ossec-server scripts to support the new reload feature. - Update to 2.4.1 - Added zabbix reporting active response - Update to 2.4 final
- Lowered courier rule 3910 (failures) from 6 over 240 to 10 over 10
- Lowered courier rule 3911 (success) from 10 over 60 to 30 over 20 - Rebuilt for atomic repo - Update to CVS 100317 - Update to CVS 100311
- Add decoder for denyhosts
- Update asl_rules.xml to include denyhosts rules - Update to CVS 100309 - Added new decoder for smtp_auth
- Added rules to detect smtp_auth brute force attempts
- Added rules to detect imap/pop brute force attempts - Updated ossec-server.conf to be in parity with the ASL config
- Added templates dir for generating configs - Update to 2.3 release - Update to snapshot 091109 - Update to snapshot 091008 - Update to snapshot 090925
- Added timestamp field to the mysql schema
- Bugfix #XXX, for the ossec-client.init script to call the correct (renamed) ossec syscheckd/logcollector daemons
- Appologies for not updating the previous changelogs. Missed a few updates! - Update to snapshot 090827
- Feature Request #225, Added logrotate event to active-response log
- Updated system_audit_rcl.txt to look for the correct php.ini file - Update to 090824, beta 1 release - Update to 090812 snapshot - Rebuild agent daemons with -DCLIENT, added symlink trickery - update to 2.1.1 - update to 090630 snapshot, this has fixes for CentOS/RHEL 4 64-bit environments - update to 2.1 final - update to snapshot 090612 - update to snapshot 090610 - update to snapshot 090603 - Disable postgresql support, to get around an undesirable dependency on EL4 - Update to snapshot 090417 - Update to snapshot 090413 (this adds in inotify support) - Update to snapshot 090410 (this adds in inotify support) - Update to snapshot 090408 - Added authpsa rules back in, this is used to detect brute force attacks
- Added conditional building support for ASL modifications - Update to 2.0 official release - update to snapshot 090225 - update to snapshot 090220 - update to snapshot 090206 - update to snapshot 090205 - update to CVS code 090129, this is not an offical release. Its for testing only - update to CVS code 090126, this is not an offical release. Its for testing only - update to 1.6.1 - update to 1.6 - update to 1.5.1 - added mysql support - Added Stanislaw Polak's excellent ban-hackers script to manage shunning more intelligently. - update to 1.5 - fix on active-response locking bug that prevented some rules from expiring. - update to ossec 1.4 - update snapshot to ossec-hids-071011.tar.gz
- relinked C4, FC4, FC5 against mysql4 - update to snapshot ossec-hids-071006.tar.gz - update to shun blocklist tracking used by ASL
- added authpsa rules + decoder - update to 1.3 - minor adjustment in post, to check for config file before overwriting it - v6 was first version of the patch.
- added in logging in active-response for better ASL support
- Disabled conf event in post, to keep from overwriting config files. - changed permissions on queue/syscheck so it can be read by the ossec group (tweak for web gui) - removed the noreplace settings from decoder and the rules
- patch for a more ASL friendly client config - release -2 had a bug. 
- added ASL rules (asl_rules.xml)
- added decoder for the asl style modsecurity logging
- adjusted syslog_rules for qmail-scanner issue (BUG #ASL-18)
- Added http index in asl_rules.xml (BUG #ASL-7) - update to 1.2 - update to 1.1 - configuration change for ASL - updated to 1.0 - import into ART
- changed their naming conventions a bit, 0.9-3 to 0.9.3. Please dont be cross with me. - new version (0.9-3) - new version (0.9-2) - new version (0.9-1a) - new version (0.9-1) - new version (0.9) - some bugfixes - created /bin/sh /bin/sh     #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   #   # i% i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i i$ i$ i$ i% i%p i%q i%r i%s i%t i%u i% i$ i% i% i% i% i% i% i% i% i% i% i% i% i$ i% i$ i$ i$ i%H i%I i%J i%K i%L i%M i%N i%O i%P i%Q i%R i%S i$ i$ i$ i$ i$ i$                                                                                                    2.7-23.fc15.art  2.7-23.fc15.art 2.7-23.fc15.art                                                                                                                                      	   	   	   	   	   	   	   	      
   
   
   
   
   
   
   
   
   
   
   
                                                                     ossec-hids ossec-hids-2.7 BUGS CONFIG INSTALL README doc README.config active-response-internal.txt active-response.txt br INSTALL.br README.config TRANSLATION active-response-internal.txt active-response.txt logs.txt manager.txt rootcheck.txt rule_ids.txt rules.txt logs.txt manage_agents.txt manager.txt nmap.txt pl INSTALL.pl README.config TRANSLATION active-response-internal.txt active-response.txt logs.txt manager.txt rootcheck.txt rule_ids.txt rules.txt rootcheck.txt rule_ids.txt rules.txt ossec active-response bin asl-shun.pl disable-account.sh firewall-drop.sh host-deny.sh ossec-tweeter.sh restart-ossec.sh route-null.sh zabbix-alert.sh agentless main.exp register_host.sh ssh.exp ssh_asa-fwsmconfig_diff ssh_foundry_diff ssh_generic_diff ssh_integrity_check_bsd ssh_integrity_check_linux ssh_nopass.exp ssh_pixconfig_diff sshlogin.exp su.exp bin ossec-configure etc shared templates active-response.template apache-logs.template ar-disable-account.template ar-firewall-drop.template ar-host-deny.template ar-routenull.template pgsql-logs.template rootcheck.template rules.template snort-logs.template syscheck.template syslog-logs.template logs queue diff ossec var run /etc/logrotate.d/ /usr/share/doc/ /usr/share/doc/ossec-hids-2.7/ /usr/share/doc/ossec-hids-2.7/doc/ /usr/share/doc/ossec-hids-2.7/doc/br/ /usr/share/doc/ossec-hids-2.7/doc/pl/ /var/ /var/ossec/ /var/ossec/active-response/ /var/ossec/active-response/bin/ /var/ossec/agentless/ /var/ossec/bin/ /var/ossec/etc/ /var/ossec/etc/templates/ /var/ossec/queue/ /var/ossec/var/ -O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m64 -mtune=generic drpm x86_64-redhat-linux-gnu                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               ASCII text ISO-8859 text POSIX shell script, ASCII text executable UTF-8 Unicode text a expect script, ASCII text executable directory exported SGML document, ASCII text                                                                                                                                                                                                             	   
                                                                                                                                                                                                                                                                                                                                                                                                                                                         R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R     xz 2    ?       7zXZ  
 !   #,,] "k%w!q{"}AHڱ,"a	!6R+FZL4޾$ϜpBb\,.ɧU̻UR11h4`$80zQ[	 rQ\@}G(G7HB*k_^j۽/u1hPmH76tȹDճ܎T! l@\[;jkbo2R} _	HnTnEy|\_ 
_&F,8ٰ4_Dc@/NxԌCXytWӂpΑ⍴Cm;jc1ؿU;*U)ҋw%G8X1:0gTc՗嘴Ol:oVFȥ/`Sݐ
edPjM8;B䈠MOauyN ތ<+DwyX5fN3%{%!Q|UUA* G Tؾ?QQ
_1J/툮`Ϡ<19(2\:8KL,6Q]o<Mͷ|zz;gB"m\g?ëb]c@XzH
7ЭJƤҖŵu L‬1'(39`-id7,fpCJt7#r=7AQ3a.7ZH_BV6n|CIzo~nd}bkd02 /`(ôxO}ޜM#Qp}P;Z'(BetfW5CIJHgx&?v߾@Ε.=-qc&4`{8'sf䈬<6zq;eIHXi˚I)"1Xa ffܳ[)˯[b`}ԣ#̟~֋   MO	3UdL2ǣQ/Zy! 
  gy[    
YZ