    ossec-hids-2.8.2-49.suse12.3.art                                                              $   >                                  ZG)B=$`1vtr4   >                 >  N   ?     N      d                                                	   #        	   X          8          <          X          \          q          u        	                                                       :          :  	     `   :  
        :          :       V   :          :       x   :          :                 (   :                 `                    H     (     {     )          *          +          ,          -          8        m  9        m  :     '   m  =     B     D     B     G     B   :  H     C   :  I     Dl   :  X     D     Y     D     \     D   :  ]     E   :  ^     I     b     J     d     J     e     J     f     J     l     J     u     J   :  v     K   	  w     L   :  x     Mp   :  y     NX   C ossec-hids 2.8.2 49.suse12.3.art An Open Source Host-based Intrusion Detection System OSSEC is a scalable, multi-platform, open source Host-based Intrusion Detection
System (HIDS). It has a powerful correlation and analysis engine, integrating
log analysis, file integrity checking, Windows registry monitoring, centralized
policy enforcement, rootkit detection, real-time alerting and active response.
It runs on most operating systems, including Linux, OpenBSD, FreeBSD, MacOS,
Solaris and Windows.

This package contains common files required for all packages.   Uxleatherback.atomicorp.com    <http://www.ossec.net GPL Atomicorp <support@atomicorp.com> Applications/System http://www.ossec.net/ linux i386 if ! id -g ossec > /dev/null 2>&1; then
  groupadd -r ossec
fi
if ! id -u ossec > /dev/null 2>&1; then
  useradd -g ossec -G ossec       \
	-d /var/ossec \
	-r -s /sbin/nologin ossec
fi
if ! id -u ossecr > /dev/null 2>&1; then
  useradd -g ossec -G ossec       \
	-d /var/ossec \
	-r -s /sbin/nologin ossecr
fi             !  |  8  `               d           c      
?     	        }            P       '             8  A            O    	       {                  A큤AhAhAhhhhhhhhhhhAhhhhhhhhhhhhhAhAhAA聠AAhAAAhA                                                                                                                    UxUxUxYUxUxYUxYUxYUxYUxYUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxUxbcd6e512c9627c6d09a2e852db43a1aa  dd96f5ec41c601c09f99252272c38aac 9e7417e6440f786de46b42cd31eee384 f18762365fcf687764a89f4126dd7a9d b4318998d4d34431f536824bee4dc766 3a3fca440e5142141f75613396dc55be 0d7fd090a120b378bd44a18319085d88 620bb7958e0665fa9dd3a544ae944a15    25887bdd240bc502c80c970a926132bc ac2254ffe808f2e1e6a2059f7b6b70d6 6696d5e6b1464d63569507419a7b3582 b18f166b9aa7abfbd0500b75c6ace41d 46b0e3782179474d80c2d51cc0c18ea1 91819d33fc1831c33090e6f12634c446 4cbab6aeb963b00fec11fb2c4367ff51 54265163fd59969371516ae7cf4024ee 8038838ce614839b69607b0c8d3dcd95 2eb0f40856189205d103e3116389cf54  8de9f76b53e3d931ca91b5b30e93e30d 3837e5b595795be4a4b7ab8a686419fc 151469d3db7b9984f283b3db84bd4805 c4686eb10052796a091cc2631cc26066 37bedae6ed6bb5f7b4a81b05d111110c 01998b783ae3e744910ca5fa48284e15 607f15a31477667a929b39fe93fd0ef3 5153a546ff0b249f5e5fad7336864753 3029b1c8b4452e9220e1dd0d5e3d1146 e970334d6ed40cec19ed160e0edd9503 afd8198e717c69712a39abf88d737bfd f96dec8e2bbbbba81547d8a8ca5f1f4e  0a925a9273f76d0c11923f81b3a3f166    8bbb43059e784bc7897d8afa91db4420 87a3dacc9168f4bcb24de133d93f3d25 8b01dd3679f38c62cd275c72cdf5f88d 4fb4e5adb8b146c8c1661b026c4ccec3 c305bfe360442ace1a893b033da10aba bc0ae4fa2bc3aa0359da50cfc5dc60ae 1ab23dcbf166a3d52088d6880adac31b 137905d4645eb4a91764e1fde96bdbcd 10b8dc27d937b26821fda7f91e2e281f 821a6d25c7871410bc13a1c995cfbb13 2db61ae3efd9250fe63cdac8579d005f bb55cdd41f77ea7a53c5f7b50fc2dbc7                                                                                                                                                                                                                                                                                                 root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec root ossec ossec root root root root root root root root root root root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec-hids-2.8.2-49.suse12.3.art.src.rpm   config(ossec-hids) ossec-2.8.2-49.suse12.3.art ossec-hids ossec-hids(x86-32)            @   @               
  
  
/bin/sh /bin/sh /bin/sh /usr/bin/env /usr/sbin/groupadd /usr/sbin/useradd config(ossec-hids) inotify-tools rpmlib(CompressedFileNames) rpmlib(PayloadFilesHavePrefix) rpmlib(PayloadIsLzma)       2.8.2-49.suse12.3.art  3.0.4-1 4.0-1 4.4.6-1 4.10.2 [ -r /etc/localtime ] && cp -fpL /etc/localtime /var/ossec/etc glibc         Ux&Uv@TT@SSS[S@R@R@RʚR@R@RrF@RiRR@Q@QY@Q@@QQ@Q@Qu&@Qu&@QkQg@Q\PDPP@PP@OiO@OЗOЗO	O OpZ@NNS@NK@N;@N;@N6@N-ZNMMM@M@M@M?MM>MUM@MPL~L8LΫLΫLʷ@LeL@L{LL@LA@LLLzL~@@L|LvW@LmLa?@LRL4l@LT@KtK͗@KKK@K[K@K8@K@K@K@J@JJJ@JJJn@JL@JI@J2C@J2C@J/@J&eI@Io@I)@I4IܑISupport <support@atomicorp.com> - 2.8.2-49 Support <support@atomicorp.com> - 2.8.1-48 Support <support@atomicorp.com> - 2.8.1-47 Support <support@atomicorp.com> - 2.8.0-46 Support <support@atomicorp.com> - 2.8.0-45.1 Support <support@atomicorp.com> - 2.8.0-45 Support <support@atomicorp.com> - 2.7.1-44 Support <support@atomicorp.com> - 2.7.1-43 Support <support@atomicorp.com> - 2.7.1-42 Support <support@atomicorp.com> - 2.7.1-41 Support <support@atomicorp.com> - 2.7.1-40 Support <support@atomicorp.com> - 2.7.1-36 Support <support@atomicorp.com> - 2.7.1-35 Support <support@atomicorp.com> - 2.7-34 Support <support@atomicorp.com> - 2.7-33 Support <support@atomicorp.com> - 2.7-32 Support <support@atomicorp.com> - 2.7-31 Support <support@atomicorp.com> - 2.7-30 Support <support@atomicorp.com> - 2.7-29 Support <support@atomicorp.com> - 2.7-28 Support <support@atomicorp.com> - 2.7-27 Support <support@atomicorp.com> - 2.7-26 Support <support@atomicorp.com> - 2.7-25 Support <support@atomicorp.com> - 2.7-24 Support <support@atomicorp.com> - 2.7-23 Support <support@atomicorp.com> - 2.7-22 Support <support@atomicorp.com> - 2.7-21 Support <support@atomicorp.com> - 2.7-20 Support <support@atomicorp.com> - 2.7-19 Support <support@atomicorp.com> - 2.7-17 Support <support@atomicorp.com> - 2.6-16 Support <support@atomicorp.com> - 2.6-15 Support <support@atomicorp.com> - 2.6-14 Support <support@atomicorp.com> - 2.6-13 Support <support@atomicorp.com> - 2.6-12 Support <support@atomicorp.com> - 2.6-11 Support <support@atomicorp.com> - 2.6-10 Support <support@atomicorp.com> - 2.6-9 Support <support@atomicorp.com> - 2.6-8 Support <support@atomicorp.com> - 2.6-7 Support <support@atomicorp.com> - 2.6-6 Support <support@atomicorp.com> - 2.6-5 Support <support@atomicorp.com> - 2.6-4 Support <support@atomicorp.com> - 2.6-3 Support <support@atomicorp.com> - 2.6-2 Support <support@atomicorp.com> - 2.6-1 Support <support@atomicorp.com> - 2.6.0-0.10 Support <support@atomicorp.com> - 2.6.0-0.9 Support <support@atomicorp.com> - 2.6.0-0.8 Support <support@atomicorp.com> - 2.6.0-0.7 Support <support@atomicorp.com> - 2.6.0-0.6 Support <support@atomicorp.com> - 2.6.0-0.5 Support <support@atomicorp.com> - 2.6.0-0.4 Support <support@atomicorp.com> - 2.6.0-0.3 Support <support@atomicorp.com> - 2.6.0-0.1 Support <support@atomicorp.com> - 2.5.1-10 Support <support@atomicorp.com> - 2.5.1-9 Support <support@atomicorp.com> - 2.5.1-8 Support <support@atomicorp.com> - 2.5.1-7 Support <support@atomicorp.com> - 2.5.1-6 Support <support@atomicorp.com> - 2.5.1-5 Support <support@atomicorp.com> - 2.5.1-4 Support <support@atomicorp.com> - 2.5.1-3 Support <support@atomicorp.com> - 2.5.1-2 Support <support@atomicorp.com> - 2.5.1-1 Support <support@atomicorp.com> - 2.5-1 Support <support@atomicorp.com> - 2.5-0.9 Support <support@atomicorp.com> - 2.5-0.8 Support <support@atomicorp.com> - 2.5-0.7 Support <support@atomicorp.com> - 2.5-0.6 Support <support@atomicorp.com> - 2.5-0.1 Support <support@atomicorp.com> - 2.4.1-11.2 Support <support@atomicorp.com> - 2.4.1-11.1 Support <support@atomicorp.com> - 2.4.1-10 Support <support@atomicorp.com> - 2.4.1-9 Support <support@atomicorp.com> - 2.4.1-8 Support <support@atomicorp.com> - 2.4.1-7 Support <support@atomicorp.com> - 2.4.1-6 Support <support@atomicorp.com> - 2.4.1-5 Support <support@atomicorp.com> - 2.4.1-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.2 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta2.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta1.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-11 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-10 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-9 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-2 - Update to 2.8.2, this release just inclused the -48 versions fix - Security fix for CVE-2015-3222 - Update to 2.8.1. This is identical to 2.8.0-46, the only change is the hosts.deny CVE-2014-5284 is merged in. - Revert BR#1596
- Add Bugfix for hosts.deny race condition (CVE-2014-5284) - BR #1596, Add fork limiting patch (max 10) for execd to prevent DoS conditions - Upgrade to 2.8.0 - Feature Request #1512,  speed up shuns in execd, move sqlite down - Relink against native mysql - Add ar-tracking active response - Placeholder for null exclusion rules.  Legacy support - ASL 4 version with new database format - Add support for Fedora 20
- Modify optimization flags for FORTIFY - Update to 2.7.1
- Add independent rules.d/decoders.d ossec-rules package - FR#772, add rule 3360 for postfix slow brute force
-   add dovecot-decoder.patch for cpanel dovecot
-   Update 9702, 9753 for dovecot brute force
- FR#773, add rule 11308 for pure-ftp slow brute force
- FR#1347, Update for courier v4 decoder (pop3s)
- FR#1359, Update horde decoder for v5 - Disable ossec-dbd signature table (replaced by aslw_rules). This was very slow - Break ossec-dbd into separate package
- FR#1321, update courier-imap decoder for version 4.0 - Bugfix #XXX, prevent truncating last character on ossec-dbd database inserts on the alerts/data table - Add tld column to alert table w/ index - Deprecate internal id generation in dbd
- update schema to autoincrement, increase id space to int - Add is_hidden to mysql schema - Add if exists to mysql schema - Add os_dbd-mysql-replace-query.patch to consolidate SELECT/UPDATE into REPLACE sql - Consolidate alert & data into a common table
- Add ossec-authd init script - Add sqldelete command  to execd
- Update to clear sqlite db at startup - More minor updates to GeoIP tracking - Minor update to GeoIP tracking - Bugfix on permissions for files in shared/ directory for client installs
- Add GeoIP support
- Remove dependency on perl-DBD-SQLite
- Update asl-shun to new non-perl based version.
- Deprecate firewall-drop-update.patch
- Add sqlite support to execd (/var/ossec/var/execd.sqlite) - Update to 2.7 final - Feature Request #XXX, revert duplicate detection in log events to help detect extremely fast brute force attacks
- Add FORTIFY_SOURCE, PIE, and relro (full) - Update to 2.7-rc2 - Update to 2.7-rc1 - Move active response components under the common package - bugfix #xxx, correct ownership permissions on fts dir - Update to init script to suppress spurious execd output
- Add alerts queue to server package with ossec/ossec permissions - Bugfix #XXX, correct any/agentd condition - Moved agentless packages under server - Drop timeid and cat_id indexes from schema - Add new index, timeid to alerts table. - Add cmoraes patch, Adds config options for enabling/disabling rootkit/syscheck options, and agent config profiles
- Add ossec-memleaks patch
- Add agentless directories, and agent.conf
- Bugfix #XXX, ossec-hids.init will now return an exit code on status - Add prelink_cmd support - Bugfix #XXX, display multi-line events in data table correcty - Update to asl-shun.pl purge event to default to 24 hours. - Update to asl-shun.pl to change ordering of block rules
- Revert from 0805 snapshot - Update to 0805 snapshot - Update to 0801 snapshot
- Update asl-shun.pl to log to active-responses.log, blocks now go to the named chain ASL-ACTIVE-RESPONSE, and delete events are more redundant. - Update to OSSEC 2.6 Final - Update to snapshot 110711 - Update to snapshot 110613 - Update to snapshot 110609 - Update to snapshot 110606
- Moved ossecr user creation event to the ossec-hids core package - Update to snapshot 110531 - Update to snapshot 110526 - Update to snapshot 110504 - Bugfix #536, Increase the default sleep time for syscheck - Renamed to 2.6 branch - Add support for the rules/decoders dir system - Update to snapsot 110405
- Update asl-shun to support ossec alert ids - Changed asl-shun sqlite database to /var/ossec/var/blocklist3.sqlite
- asl-shun database format now stores the full alertid - Update to snapshot 101203 - Update to snapshot 101125 - Added alertid support to os_dbd, this involves a schema update - Added dst ip, src prt, and dst prt capture support to os_dbd - Bugfix #XXX, manage_agents was built in client mode for the server package. - Add clamav decoder & ruleset - Update to 2.5.1 final - Update to 2.5 final - Update to 0928 snapshot - Extended no_ar into ossec-dbd - Add no_ar option to disable active response per rule - Update to snapshot 100920 - Update snapshot to 100907 - Snapshot 100901 - Added test fix for os_dbd - Bugfix #376, ossec-control will now properly stop and reload - Update to 0809 snapshot - Relink against native mysql - Add minicon decoder from les fenison - Update to 100707 snapshot
- Feature Request #371, add ossec.log to logrotate - Updated to 100615 snapshot - Updated init and ossec-server scripts to support the new reload feature. - Update to 2.4.1 - Added zabbix reporting active response - Update to 2.4 final
- Lowered courier rule 3910 (failures) from 6 over 240 to 10 over 10
- Lowered courier rule 3911 (success) from 10 over 60 to 30 over 20 - Rebuilt for atomic repo - Update to CVS 100317 - Update to CVS 100311
- Add decoder for denyhosts
- Update asl_rules.xml to include denyhosts rules - Update to CVS 100309 - Added new decoder for smtp_auth
- Added rules to detect smtp_auth brute force attempts
- Added rules to detect imap/pop brute force attempts - Updated ossec-server.conf to be in parity with the ASL config
- Added templates dir for generating configs - Update to 2.3 release - Update to snapshot 091109 - Update to snapshot 091008 - Update to snapshot 090925
- Added timestamp field to the mysql schema
- Bugfix #XXX, for the ossec-client.init script to call the correct (renamed) ossec syscheckd/logcollector daemons
- Appologies for not updating the previous changelogs. Missed a few updates! - Update to snapshot 090827
- Feature Request #225, Added logrotate event to active-response log
- Updated system_audit_rcl.txt to look for the correct php.ini file - Update to 090824, beta 1 release - Update to 090812 snapshot - Rebuild agent daemons with -DCLIENT, added symlink trickery - update to 2.1.1 - update to 090630 snapshot, this has fixes for CentOS/RHEL 4 64-bit environments - update to 2.1 final - update to snapshot 090612 - update to snapshot 090610 - update to snapshot 090603 - Disable postgresql support, to get around an undesirable dependency on EL4 - Update to snapshot 090417 - Update to snapshot 090413 (this adds in inotify support) - Update to snapshot 090410 (this adds in inotify support) - Update to snapshot 090408 - Added authpsa rules back in, this is used to detect brute force attacks
- Added conditional building support for ASL modifications /bin/sh /bin/sh                                                                                                                                                                                                            	   
                                                                      !   "   #   $   %   &   '   (   )   *   +   ,   -   .   /   0   1   2   3   4   5   6   7   8   9   :                                                                        2.8.2-49.suse12.3.art  2.8.2-49.suse12.3.art 2.8.2-49.suse12.3.art                                                                                                                        	   	   
   
   
   
   
   
   
   
   
   
   
   
                  ossec-hids ossec-hids BUGS CHANGELOG CONFIG CONTRIBUTORS INSTALL LICENSE README.md ossec active-response bin ar-tracking.sh asl-shun.pl disable-account.sh firewall-drop.sh host-deny.sh ip-customblock.sh ossec-tweeter.sh restart-ossec.sh route-null.sh zabbix-alert.sh agentless main.exp register_host.sh ssh.exp ssh_asa-fwsmconfig_diff ssh_foundry_diff ssh_generic_diff ssh_integrity_check_bsd ssh_integrity_check_linux ssh_nopass.exp ssh_pixconfig_diff sshlogin.exp su.exp bin ossec-configure etc shared templates active-response.template apache-logs.template ar-disable-account.template ar-firewall-drop.template ar-host-deny.template ar-routenull.template pgsql-logs.template rootcheck.template rules.template snort-logs.template syscheck.template syslog-logs.template logs queue diff ossec var run /etc/logrotate.d/ /usr/share/doc/packages/ /usr/share/doc/packages/ossec-hids/ /var/ /var/ossec/ /var/ossec/active-response/ /var/ossec/active-response/bin/ /var/ossec/agentless/ /var/ossec/bin/ /var/ossec/etc/ /var/ossec/etc/templates/ /var/ossec/queue/ /var/ossec/var/ -O2 -g -m32 -march=i486 -fmessage-length=0 -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables drpm lzma 5 i386-suse-linux                                                                                                                                                                                  ASCII text POSIX shell script, ASCII text executable Pascal source, ASCII text UTF-8 Unicode text UTF-8 Unicode text, with very long lines a /usr/bin/env expect script, ASCII text executable directory exported SGML document, ASCII text                                                                                   	       
                                                                                                                                                                                                                                                                                                                                             R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R     ?       ]    "k%M{Usg`Y{
 e[_kkG,9st=5$ Pi"NBgOr}\ˉÏd̌(%w:yQ"@-##.ѢFCo+WvlU
kQ B/mym HO^oLo&aC'EOݜѴy >ݛeKOX@	KХm<ޣ2ӫ2dMG Pڋ9٤tPN ry,rؑ
v=pjsz<Kso*uGPOFhTQ;SԀOUW31Oy|6o"Vk+G4nՌeԍb{FU\{tD>`I~UzK#bq daί@F2sFP>wLau&F{D. @O30s/jhX/Và\k>jqV$ntǚsXPE5A	@iAwN$HPBVrCer8 <*R9mg$ %&.v[H9gtpW-hS@*Qc^+1m`O.zTŨXtQ"&>EXf/ZwYG:3:ӄ)h71ky}.A:o:jUR7wz#!Ocw>o4D'Vt|2}%	a޴bWoSkI\9M.KM0Ls٬iVÝH¥YQ?)=].A_!]Þ{Ѳx}J|P#h>kLTf}hyCH|{t,e+T;U f|JGn#~#g~Q9ӫnqJ_DU1>pTa;%J/^!ȬQsȤk?#K?Gi/{3Sș
uQX tT- cڷW=qTgI&wZ2reȉZTBJw(Ymo !z5*}.fyoՃ#:SY;Rk6ZG ΅vODsAd r:^9"ӄ+o
fTb̫#&?jR#U)e-Q*sը,>d,-tS~GM-*ğE':%8D.],7k^bvb$ JzKRdǍ8ި3E^%TbǴv\?[>oF%f *phxZvxߧ-5iv ^w&V%dǅ+CBP]6rSA41<F?ï&<AYڋU!MQ3`bp<)QϬ<~}uILtktְF}5d?MRn,@.2N|n"˧BcZzg&KԼ\j:gu)4NAE?1(Rw!tziMnX=qH!}U:<19&\mV^dba`wz5LlfTwb{h}P%ƘzMퟅ7ns{e4a>{4tgcWp <)f؞v(o|ߔ 1RZ_Np/FhXw"QEjM5C=8}:eeH