    ossec-hids-postgres-2.9.0-49.suse12.3.art                                                     $   >                                  LR9k;PP$+Cd   >                 ;  6   ?     6      d                                                	   ,        	   U           t           x                                                    	                                  
                     T          \     	     `     
     d          l                                                                                 0                    5          t          x               (          8        m  9     H   m  :        m  >     4      G     4(     H     40     I     48     X     4<     Y     4D     \     4p     ]     4x     ^     4     b     4     d     5B     e     5G     f     5L     l     5N     u     5`     v     5h     w     6@     x     6H     y     6P   C ossec-hids-postgres 2.9.0 49.suse12.3.art The OSSEC HIDS Server postgres connector Postgresql connector for OSSEC Xrleatherback.atomicorp.com    =http://www.ossec.net GPL Atomicorp <support@atomicorp.com> System Environment/Daemons http://www.ossec.net/ linux i386 ln -sf /var/ossec/bin/ossec-pgsql-dbd /var/ossec/bin/ossec-dbd || :     h    XrXr54914fd444e8232948eafe99f0398224 7e861ba315135b00cff36d171c1767a8           root root root root ossec-hids-2.9.0-49.suse12.3.art.src.rpm    ossec-hids-postgres ossec-hids-postgres(x86-32)      @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @      
  
  
/bin/sh libGeoIP.so.1 libc.so.6 libc.so.6(GLIBC_2.0) libc.so.6(GLIBC_2.1) libc.so.6(GLIBC_2.1.3) libc.so.6(GLIBC_2.2) libc.so.6(GLIBC_2.3) libc.so.6(GLIBC_2.3.4) libc.so.6(GLIBC_2.4) libc.so.6(GLIBC_2.7) libcrypto.so.1.0.0 libm.so.6 libpq.so.5 libpthread.so.0 libpthread.so.0(GLIBC_2.0) libpthread.so.0(GLIBC_2.2) libssl.so.1.0.0 ossec-hids-server rpmlib(CompressedFileNames) rpmlib(PayloadFilesHavePrefix) rpmlib(PayloadIsLzma)                   2.9.0-49.suse12.3.art 3.0.4-1 4.0-1 4.4.6-1      ossec-hids-mysql  4.10.2    XYX@TT@SSS[S@R@R@RʚR@R@RrF@RiRR@Q@QY@Q@@QQ@Q@Qu&@Qu&@QkQg@Q\PDPP@PP@OiO@OЗOЗO	O OpZ@NNS@NK@N;@N;@N6@N-ZNMMM@M@M@M?MM>MUM@MPL~L8LΫLΫLʷ@LeL@L{LL@LA@LLLzL~@@L|LvW@LmLa?@LRL4l@LT@KtK͗@KKK@K[K@K8@K@K@K@J@JJJ@JJJn@JL@JI@J2C@J2C@J/@J&eI@Io@I)@I4IܑISupport <support@atomicorp.com> - 2.9.0-49 Support <support@atomicorp.com> - 2.9.0-48 Support <support@atomicorp.com> - 2.8.1-47 Support <support@atomicorp.com> - 2.8.0-46 Support <support@atomicorp.com> - 2.8.0-45.1 Support <support@atomicorp.com> - 2.8.0-45 Support <support@atomicorp.com> - 2.7.1-44 Support <support@atomicorp.com> - 2.7.1-43 Support <support@atomicorp.com> - 2.7.1-42 Support <support@atomicorp.com> - 2.7.1-41 Support <support@atomicorp.com> - 2.7.1-40 Support <support@atomicorp.com> - 2.7.1-36 Support <support@atomicorp.com> - 2.7.1-35 Support <support@atomicorp.com> - 2.7-34 Support <support@atomicorp.com> - 2.7-33 Support <support@atomicorp.com> - 2.7-32 Support <support@atomicorp.com> - 2.7-31 Support <support@atomicorp.com> - 2.7-30 Support <support@atomicorp.com> - 2.7-29 Support <support@atomicorp.com> - 2.7-28 Support <support@atomicorp.com> - 2.7-27 Support <support@atomicorp.com> - 2.7-26 Support <support@atomicorp.com> - 2.7-25 Support <support@atomicorp.com> - 2.7-24 Support <support@atomicorp.com> - 2.7-23 Support <support@atomicorp.com> - 2.7-22 Support <support@atomicorp.com> - 2.7-21 Support <support@atomicorp.com> - 2.7-20 Support <support@atomicorp.com> - 2.7-19 Support <support@atomicorp.com> - 2.7-17 Support <support@atomicorp.com> - 2.6-16 Support <support@atomicorp.com> - 2.6-15 Support <support@atomicorp.com> - 2.6-14 Support <support@atomicorp.com> - 2.6-13 Support <support@atomicorp.com> - 2.6-12 Support <support@atomicorp.com> - 2.6-11 Support <support@atomicorp.com> - 2.6-10 Support <support@atomicorp.com> - 2.6-9 Support <support@atomicorp.com> - 2.6-8 Support <support@atomicorp.com> - 2.6-7 Support <support@atomicorp.com> - 2.6-6 Support <support@atomicorp.com> - 2.6-5 Support <support@atomicorp.com> - 2.6-4 Support <support@atomicorp.com> - 2.6-3 Support <support@atomicorp.com> - 2.6-2 Support <support@atomicorp.com> - 2.6-1 Support <support@atomicorp.com> - 2.6.0-0.10 Support <support@atomicorp.com> - 2.6.0-0.9 Support <support@atomicorp.com> - 2.6.0-0.8 Support <support@atomicorp.com> - 2.6.0-0.7 Support <support@atomicorp.com> - 2.6.0-0.6 Support <support@atomicorp.com> - 2.6.0-0.5 Support <support@atomicorp.com> - 2.6.0-0.4 Support <support@atomicorp.com> - 2.6.0-0.3 Support <support@atomicorp.com> - 2.6.0-0.1 Support <support@atomicorp.com> - 2.5.1-10 Support <support@atomicorp.com> - 2.5.1-9 Support <support@atomicorp.com> - 2.5.1-8 Support <support@atomicorp.com> - 2.5.1-7 Support <support@atomicorp.com> - 2.5.1-6 Support <support@atomicorp.com> - 2.5.1-5 Support <support@atomicorp.com> - 2.5.1-4 Support <support@atomicorp.com> - 2.5.1-3 Support <support@atomicorp.com> - 2.5.1-2 Support <support@atomicorp.com> - 2.5.1-1 Support <support@atomicorp.com> - 2.5-1 Support <support@atomicorp.com> - 2.5-0.9 Support <support@atomicorp.com> - 2.5-0.8 Support <support@atomicorp.com> - 2.5-0.7 Support <support@atomicorp.com> - 2.5-0.6 Support <support@atomicorp.com> - 2.5-0.1 Support <support@atomicorp.com> - 2.4.1-11.2 Support <support@atomicorp.com> - 2.4.1-11.1 Support <support@atomicorp.com> - 2.4.1-10 Support <support@atomicorp.com> - 2.4.1-9 Support <support@atomicorp.com> - 2.4.1-8 Support <support@atomicorp.com> - 2.4.1-7 Support <support@atomicorp.com> - 2.4.1-6 Support <support@atomicorp.com> - 2.4.1-5 Support <support@atomicorp.com> - 2.4.1-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.2 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta2.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta1.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-11 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-10 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-9 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-2 - Update to Ossec 2.9.0 Final - Update to Ossec 2.9.0 - Update to 2.8.1. This is identical to 2.8.0-46, the only change is the hosts.deny CVE-2014-5284 is merged in. - Revert BR#1596
- Add Bugfix for hosts.deny race condition (CVE-2014-5284) - BR #1596, Add fork limiting patch (max 10) for execd to prevent DoS conditions - Upgrade to 2.8.0 - Feature Request #1512,  speed up shuns in execd, move sqlite down - Relink against native mysql - Add ar-tracking active response - Placeholder for null exclusion rules.  Legacy support - ASL 4 version with new database format - Add support for Fedora 20
- Modify optimization flags for FORTIFY - Update to 2.7.1
- Add independent rules.d/decoders.d ossec-rules package - FR#772, add rule 3360 for postfix slow brute force
-   add dovecot-decoder.patch for cpanel dovecot
-   Update 9702, 9753 for dovecot brute force
- FR#773, add rule 11308 for pure-ftp slow brute force
- FR#1347, Update for courier v4 decoder (pop3s)
- FR#1359, Update horde decoder for v5 - Disable ossec-dbd signature table (replaced by aslw_rules). This was very slow - Break ossec-dbd into separate package
- FR#1321, update courier-imap decoder for version 4.0 - Bugfix #XXX, prevent truncating last character on ossec-dbd database inserts on the alerts/data table - Add tld column to alert table w/ index - Deprecate internal id generation in dbd
- update schema to autoincrement, increase id space to int - Add is_hidden to mysql schema - Add if exists to mysql schema - Add os_dbd-mysql-replace-query.patch to consolidate SELECT/UPDATE into REPLACE sql - Consolidate alert & data into a common table
- Add ossec-authd init script - Add sqldelete command  to execd
- Update to clear sqlite db at startup - More minor updates to GeoIP tracking - Minor update to GeoIP tracking - Bugfix on permissions for files in shared/ directory for client installs
- Add GeoIP support
- Remove dependency on perl-DBD-SQLite
- Update asl-shun to new non-perl based version.
- Deprecate firewall-drop-update.patch
- Add sqlite support to execd (/var/ossec/var/execd.sqlite) - Update to 2.7 final - Feature Request #XXX, revert duplicate detection in log events to help detect extremely fast brute force attacks
- Add FORTIFY_SOURCE, PIE, and relro (full) - Update to 2.7-rc2 - Update to 2.7-rc1 - Move active response components under the common package - bugfix #xxx, correct ownership permissions on fts dir - Update to init script to suppress spurious execd output
- Add alerts queue to server package with ossec/ossec permissions - Bugfix #XXX, correct any/agentd condition - Moved agentless packages under server - Drop timeid and cat_id indexes from schema - Add new index, timeid to alerts table. - Add cmoraes patch, Adds config options for enabling/disabling rootkit/syscheck options, and agent config profiles
- Add ossec-memleaks patch
- Add agentless directories, and agent.conf
- Bugfix #XXX, ossec-hids.init will now return an exit code on status - Add prelink_cmd support - Bugfix #XXX, display multi-line events in data table correcty - Update to asl-shun.pl purge event to default to 24 hours. - Update to asl-shun.pl to change ordering of block rules
- Revert from 0805 snapshot - Update to 0805 snapshot - Update to 0801 snapshot
- Update asl-shun.pl to log to active-responses.log, blocks now go to the named chain ASL-ACTIVE-RESPONSE, and delete events are more redundant. - Update to OSSEC 2.6 Final - Update to snapshot 110711 - Update to snapshot 110613 - Update to snapshot 110609 - Update to snapshot 110606
- Moved ossecr user creation event to the ossec-hids core package - Update to snapshot 110531 - Update to snapshot 110526 - Update to snapshot 110504 - Bugfix #536, Increase the default sleep time for syscheck - Renamed to 2.6 branch - Add support for the rules/decoders dir system - Update to snapsot 110405
- Update asl-shun to support ossec alert ids - Changed asl-shun sqlite database to /var/ossec/var/blocklist3.sqlite
- asl-shun database format now stores the full alertid - Update to snapshot 101203 - Update to snapshot 101125 - Added alertid support to os_dbd, this involves a schema update - Added dst ip, src prt, and dst prt capture support to os_dbd - Bugfix #XXX, manage_agents was built in client mode for the server package. - Add clamav decoder & ruleset - Update to 2.5.1 final - Update to 2.5 final - Update to 0928 snapshot - Extended no_ar into ossec-dbd - Add no_ar option to disable active response per rule - Update to snapshot 100920 - Update snapshot to 100907 - Snapshot 100901 - Added test fix for os_dbd - Bugfix #376, ossec-control will now properly stop and reload - Update to 0809 snapshot - Relink against native mysql - Add minicon decoder from les fenison - Update to 100707 snapshot
- Feature Request #371, add ossec.log to logrotate - Updated to 100615 snapshot - Updated init and ossec-server scripts to support the new reload feature. - Update to 2.4.1 - Added zabbix reporting active response - Update to 2.4 final
- Lowered courier rule 3910 (failures) from 6 over 240 to 10 over 10
- Lowered courier rule 3911 (success) from 10 over 60 to 30 over 20 - Rebuilt for atomic repo - Update to CVS 100317 - Update to CVS 100311
- Add decoder for denyhosts
- Update asl_rules.xml to include denyhosts rules - Update to CVS 100309 - Added new decoder for smtp_auth
- Added rules to detect smtp_auth brute force attempts
- Added rules to detect imap/pop brute force attempts - Updated ossec-server.conf to be in parity with the ASL config
- Added templates dir for generating configs - Update to 2.3 release - Update to snapshot 091109 - Update to snapshot 091008 - Update to snapshot 090925
- Added timestamp field to the mysql schema
- Bugfix #XXX, for the ossec-client.init script to call the correct (renamed) ossec syscheckd/logcollector daemons
- Appologies for not updating the previous changelogs. Missed a few updates! - Update to snapshot 090827
- Feature Request #225, Added logrotate event to active-response log
- Updated system_audit_rcl.txt to look for the correct php.ini file - Update to 090824, beta 1 release - Update to 090812 snapshot - Rebuild agent daemons with -DCLIENT, added symlink trickery - update to 2.1.1 - update to 090630 snapshot, this has fixes for CentOS/RHEL 4 64-bit environments - update to 2.1 final - update to snapshot 090612 - update to snapshot 090610 - update to snapshot 090603 - Disable postgresql support, to get around an undesirable dependency on EL4 - Update to snapshot 090417 - Update to snapshot 090413 (this adds in inotify support) - Update to snapshot 090410 (this adds in inotify support) - Update to snapshot 090408 - Added authpsa rules back in, this is used to detect brute force attacks
- Added conditional building support for ASL modifications /bin/sh                       2.9.0-49.suse12.3.art 2.9.0-49.suse12.3.art        postgresql.schema ossec-pgsql-dbd /usr/share/ossec/contrib/ /var/ossec/bin/ -O2 -g -m32 -march=i486 -fmessage-length=0 -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables drpm lzma 5 i386-suse-linux          ASCII text ELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.16, BuildID[sha1]=0xe6bc8141b87d96ec0abf039cb52ef1bbf7ad9f7f, not stripped directory                 R  R  R  R  R  R  R  R  R  	R  
R  R  R  R  R  R  R     ?   P   ]    "k%{Usgi!#=$9zS}\H[*2[VLosZaa$ 1)MokX&b˳spqIV癣=;`#ԲIAC79?xp*dҗkp}2I7Xmj]Cwӕ߳E}kH-,[ ^;q\ww"*`UG+ڝ]0m{TI$H'35$b
yA{a;ͩoO~3N;A2bvܸn,6~YERVQ)Y:h?%$\2߹ 3pI?TDя}'hkR6GWZn&g㭰z kSSmŃWV[/mo	تe)d"C?Sp:<;;)Hd%e]
	VVvfvB>~@ ]Hm~'ۃID#ptU\;=ro6[@ȝ~[}B<:̢C&yïu_/K09 ed;r+ -?<
4o1LFaˏa(ӹ*bVYuWz3gͺy-QB\e|ҁ(,nm1`P۪x~ړ9tJ0De.Ѩ|[]`y#';/@#]`c^<g!9Bˏ>o:4:HpdlM{}T#8۰AuqWaؤ~5ڳ\rl`h,38bs={8;-1K9>x;撽Q_t[9bqqݝ12*$_-Ub߼v~U{3CK yZDw < rgK>mZ`T#m7ƦR+GP+&[4>4ozsܙ]󚅐*d	Nwdk<&¡]'兂aVحՃK*![l4K>
V3){ԑN9B-ř+kTD&\bi'oXLYz,EY9!~|@ЈD-_gn9uN'	>?eٛk͚6 ɥ)3T(Hn':S}bd?z]x4OH(^]tC'8`ETd浺`^hJV~3nL*c,K-4#&2ڿXcfPPSϛe]kX}O	PÎS3'2!^o	RsB~~:_̔Y	Eb~	 `nEsV)KVt~6M1[@i`E& B0NV¬奉]I҉la88<%pe;yqu6"0it
|ƣ	}(Gcn=EI/Ė<ï!R+KvU}2VόQZͅ!ۡfOc"cj<Pz+]v('_b%U.[
˅73}Do Ʈ{yX5b$lۃ4/̕ UyELGb'hX".AS?0$I`
!@܍ܪ4VehS̏?Ii@\qW;RN2P>Eգvj!j(MM5Z)DBlDDg˄mD,l7D`C( th Hp]́,]Iy OkgWrmN+ ك(13Q~H&R] XGw)aO@ʺt=
sUې$CA{hoc#qXFZ$ZК!nsͻ^Iى)+`u<cG_
-0߹}}59`cTm)+gpVe5[;qU)ɂ\ʲ4?ԟ%:ajh&U@]Wx?5g#nZ^W,2;51WDNѺlC);o;2bedkd;+
%PYXqoToK6_IN)@rV:cTjH"z[OtW*ŚP!rtLӰAPm]J?~mTi)l;(h |ewY,wy.;L֤! 

`!dI*!|K3NCnN!tEf,G9];EZ&t}4D7B]4hEBdfOU.keXܷrb!JS@6\#pNU#CfD|D|ԊΑudCD>UF׼bU!|}\SIzJtçJj15Qg2r-
13:)gb[lK7^K.k׆xu
r'lߪd4?m?EmNWoE:lU@1CX	}B|Yl)XnȄU-ê`"i!U[2Jjc=+*R	c9י4PKJPev{Fv٧?Ie$gzR 	؃R"Ӟ9#iz;dܑ^jrixTU. EgrԳ`*dҸnr>;V[iu|CXrf	&E[a,Uߚw>G'^Q}-mF}-Bb`.⫊KN-ѮWq(Kscx˼|E9<L`N<(Zi.8꣍,˔N0ArZkU0
'Ǘ3p'28T@_Wr؝e-~fonLTFeANB:i
6	`yD],K6Xkuj+GėW6oo26WJC,KoHviqx@h$SEm^w<ޫF3DB D^^3?|Lqtgo'wPS8zm0D͋'LSs3Η܈T/(;@4\<4D\8;0<
C3O6\8)YtSӡsx}z}e.BfGmZ<+=_-
^Щv.j];|;eݞV]7`'hڗᒱ:`=-]Ǘ9]wKx8)'(9VtHA.Y]7?_A$w'GZ^
_qy; IV0܎CٗDXPqaD#;O_!^L*!!5Mݕ[..~NQ	8#(XOt3oΈpvm+v<65;LU @FimI
4mUlXܫ!kҟ`Tm:B7fLnKBFr
u&ߤjҰ[{
ܦNUKrK$3^z:ra*pnP~Tddޕ7A_"0d~XBZ. { ډsp
䙣r#Գv;Cxɯ]۴͒F3zw/8jqv/G:e8)R	6~-^gv9G#YO%$J%{2?gےys|}6"֙BK>tRiVtmqPݾi4pױnoIrq'םYvn#7@ztRi|	\[ՠkl P@1HȜWq,"G˲}K{M h<gV1"BIYuJ#NзDnJ*|Fڂ`v3mQQ	>Wj8b.kmXjpRXPHyZ**Ԃݨ&,m-Wl+Fn7G@C5/<;&9Xo_0\+ƶN
3D X٩B{-I4^U	8`1ReUd՛+1zkC7pD&Ҡ.+}<qc!@gxXm+lio$slbu8XGE,7oDzmzǞ)~oHB>rĭV CSc 