    ossec-hids-mysql-2.9.0-49.suse13.1.art                                                        $   >                                  MV@v\-;Py   >                 9  6   ?     6x      d                                                	   )        	   O           l           p                                                    	                                                            	          
                          b          d          l          v                                                  @          ,          l          p               (          8        m  9     @   m  :        m  G     4     H     4      I     4(     X     4,     Y     44     \     4`     ]     4h     ^     4     b     4     d     5'     e     5,     f     51     l     53     u     5D     v     5L     w     6     x     6      y     6(   C ossec-hids-mysql 2.9.0 49.suse13.1.art The OSSEC HIDS Server mysql connector Mysql connector for OSSEC    Xrloggerhead.atomicorp.com     0Fhttp://www.ossec.net GPL Atomicorp <support@atomicorp.com> System Environment/Daemons http://www.ossec.net/ linux i386     $Th    XrXr59346510cbee34ab0429fdd5d0c241f7 56c4c97c73c2803d1532d911213f892d           root root root root ossec-hids-2.9.0-49.suse13.1.art.src.rpm    ossec-hids-mysql ossec-hids-mysql(x86-32)     @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @      
  
  
libGeoIP.so.1 libc.so.6 libc.so.6(GLIBC_2.0) libc.so.6(GLIBC_2.1) libc.so.6(GLIBC_2.1.3) libc.so.6(GLIBC_2.2) libc.so.6(GLIBC_2.3) libc.so.6(GLIBC_2.3.4) libc.so.6(GLIBC_2.4) libc.so.6(GLIBC_2.7) libcrypto.so.1.0.0 libdl.so.2 libm.so.6 libmysqlclient.so.18 libmysqlclient.so.18(libmysqlclient_18) libpthread.so.0 libpthread.so.0(GLIBC_2.0) libpthread.so.0(GLIBC_2.2) libssl.so.1.0.0 libz.so.1 ossec-hids-server rpmlib(CompressedFileNames) rpmlib(PayloadFilesHavePrefix) rpmlib(PayloadIsLzma)                     2.9.0-49.suse13.1.art 3.0.4-1 4.0-1 4.4.6-1     ossec-hids-postgres  4.11.1 XYX@TT@SSS[S@R@R@RʚR@R@RrF@RiRR@Q@QY@Q@@QQ@Q@Qu&@Qu&@QkQg@Q\PDPP@PP@OiO@OЗOЗO	O OpZ@NNS@NK@N;@N;@N6@N-ZNMMM@M@M@M?MM>MUM@MPL~L8LΫLΫLʷ@LeL@L{LL@LA@LLLzL~@@L|LvW@LmLa?@LRL4l@LT@KtK͗@KKK@K[K@K8@K@K@K@J@JJJ@JJJn@JL@JI@J2C@J2C@J/@J&eI@Io@I)@I4IܑISupport <support@atomicorp.com> - 2.9.0-49 Support <support@atomicorp.com> - 2.9.0-48 Support <support@atomicorp.com> - 2.8.1-47 Support <support@atomicorp.com> - 2.8.0-46 Support <support@atomicorp.com> - 2.8.0-45.1 Support <support@atomicorp.com> - 2.8.0-45 Support <support@atomicorp.com> - 2.7.1-44 Support <support@atomicorp.com> - 2.7.1-43 Support <support@atomicorp.com> - 2.7.1-42 Support <support@atomicorp.com> - 2.7.1-41 Support <support@atomicorp.com> - 2.7.1-40 Support <support@atomicorp.com> - 2.7.1-36 Support <support@atomicorp.com> - 2.7.1-35 Support <support@atomicorp.com> - 2.7-34 Support <support@atomicorp.com> - 2.7-33 Support <support@atomicorp.com> - 2.7-32 Support <support@atomicorp.com> - 2.7-31 Support <support@atomicorp.com> - 2.7-30 Support <support@atomicorp.com> - 2.7-29 Support <support@atomicorp.com> - 2.7-28 Support <support@atomicorp.com> - 2.7-27 Support <support@atomicorp.com> - 2.7-26 Support <support@atomicorp.com> - 2.7-25 Support <support@atomicorp.com> - 2.7-24 Support <support@atomicorp.com> - 2.7-23 Support <support@atomicorp.com> - 2.7-22 Support <support@atomicorp.com> - 2.7-21 Support <support@atomicorp.com> - 2.7-20 Support <support@atomicorp.com> - 2.7-19 Support <support@atomicorp.com> - 2.7-17 Support <support@atomicorp.com> - 2.6-16 Support <support@atomicorp.com> - 2.6-15 Support <support@atomicorp.com> - 2.6-14 Support <support@atomicorp.com> - 2.6-13 Support <support@atomicorp.com> - 2.6-12 Support <support@atomicorp.com> - 2.6-11 Support <support@atomicorp.com> - 2.6-10 Support <support@atomicorp.com> - 2.6-9 Support <support@atomicorp.com> - 2.6-8 Support <support@atomicorp.com> - 2.6-7 Support <support@atomicorp.com> - 2.6-6 Support <support@atomicorp.com> - 2.6-5 Support <support@atomicorp.com> - 2.6-4 Support <support@atomicorp.com> - 2.6-3 Support <support@atomicorp.com> - 2.6-2 Support <support@atomicorp.com> - 2.6-1 Support <support@atomicorp.com> - 2.6.0-0.10 Support <support@atomicorp.com> - 2.6.0-0.9 Support <support@atomicorp.com> - 2.6.0-0.8 Support <support@atomicorp.com> - 2.6.0-0.7 Support <support@atomicorp.com> - 2.6.0-0.6 Support <support@atomicorp.com> - 2.6.0-0.5 Support <support@atomicorp.com> - 2.6.0-0.4 Support <support@atomicorp.com> - 2.6.0-0.3 Support <support@atomicorp.com> - 2.6.0-0.1 Support <support@atomicorp.com> - 2.5.1-10 Support <support@atomicorp.com> - 2.5.1-9 Support <support@atomicorp.com> - 2.5.1-8 Support <support@atomicorp.com> - 2.5.1-7 Support <support@atomicorp.com> - 2.5.1-6 Support <support@atomicorp.com> - 2.5.1-5 Support <support@atomicorp.com> - 2.5.1-4 Support <support@atomicorp.com> - 2.5.1-3 Support <support@atomicorp.com> - 2.5.1-2 Support <support@atomicorp.com> - 2.5.1-1 Support <support@atomicorp.com> - 2.5-1 Support <support@atomicorp.com> - 2.5-0.9 Support <support@atomicorp.com> - 2.5-0.8 Support <support@atomicorp.com> - 2.5-0.7 Support <support@atomicorp.com> - 2.5-0.6 Support <support@atomicorp.com> - 2.5-0.1 Support <support@atomicorp.com> - 2.4.1-11.2 Support <support@atomicorp.com> - 2.4.1-11.1 Support <support@atomicorp.com> - 2.4.1-10 Support <support@atomicorp.com> - 2.4.1-9 Support <support@atomicorp.com> - 2.4.1-8 Support <support@atomicorp.com> - 2.4.1-7 Support <support@atomicorp.com> - 2.4.1-6 Support <support@atomicorp.com> - 2.4.1-5 Support <support@atomicorp.com> - 2.4.1-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.2 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta2.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta1.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-11 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-10 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-9 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-2 - Update to Ossec 2.9.0 Final - Update to Ossec 2.9.0 - Update to 2.8.1. This is identical to 2.8.0-46, the only change is the hosts.deny CVE-2014-5284 is merged in. - Revert BR#1596
- Add Bugfix for hosts.deny race condition (CVE-2014-5284) - BR #1596, Add fork limiting patch (max 10) for execd to prevent DoS conditions - Upgrade to 2.8.0 - Feature Request #1512,  speed up shuns in execd, move sqlite down - Relink against native mysql - Add ar-tracking active response - Placeholder for null exclusion rules.  Legacy support - ASL 4 version with new database format - Add support for Fedora 20
- Modify optimization flags for FORTIFY - Update to 2.7.1
- Add independent rules.d/decoders.d ossec-rules package - FR#772, add rule 3360 for postfix slow brute force
-   add dovecot-decoder.patch for cpanel dovecot
-   Update 9702, 9753 for dovecot brute force
- FR#773, add rule 11308 for pure-ftp slow brute force
- FR#1347, Update for courier v4 decoder (pop3s)
- FR#1359, Update horde decoder for v5 - Disable ossec-dbd signature table (replaced by aslw_rules). This was very slow - Break ossec-dbd into separate package
- FR#1321, update courier-imap decoder for version 4.0 - Bugfix #XXX, prevent truncating last character on ossec-dbd database inserts on the alerts/data table - Add tld column to alert table w/ index - Deprecate internal id generation in dbd
- update schema to autoincrement, increase id space to int - Add is_hidden to mysql schema - Add if exists to mysql schema - Add os_dbd-mysql-replace-query.patch to consolidate SELECT/UPDATE into REPLACE sql - Consolidate alert & data into a common table
- Add ossec-authd init script - Add sqldelete command  to execd
- Update to clear sqlite db at startup - More minor updates to GeoIP tracking - Minor update to GeoIP tracking - Bugfix on permissions for files in shared/ directory for client installs
- Add GeoIP support
- Remove dependency on perl-DBD-SQLite
- Update asl-shun to new non-perl based version.
- Deprecate firewall-drop-update.patch
- Add sqlite support to execd (/var/ossec/var/execd.sqlite) - Update to 2.7 final - Feature Request #XXX, revert duplicate detection in log events to help detect extremely fast brute force attacks
- Add FORTIFY_SOURCE, PIE, and relro (full) - Update to 2.7-rc2 - Update to 2.7-rc1 - Move active response components under the common package - bugfix #xxx, correct ownership permissions on fts dir - Update to init script to suppress spurious execd output
- Add alerts queue to server package with ossec/ossec permissions - Bugfix #XXX, correct any/agentd condition - Moved agentless packages under server - Drop timeid and cat_id indexes from schema - Add new index, timeid to alerts table. - Add cmoraes patch, Adds config options for enabling/disabling rootkit/syscheck options, and agent config profiles
- Add ossec-memleaks patch
- Add agentless directories, and agent.conf
- Bugfix #XXX, ossec-hids.init will now return an exit code on status - Add prelink_cmd support - Bugfix #XXX, display multi-line events in data table correcty - Update to asl-shun.pl purge event to default to 24 hours. - Update to asl-shun.pl to change ordering of block rules
- Revert from 0805 snapshot - Update to 0805 snapshot - Update to 0801 snapshot
- Update asl-shun.pl to log to active-responses.log, blocks now go to the named chain ASL-ACTIVE-RESPONSE, and delete events are more redundant. - Update to OSSEC 2.6 Final - Update to snapshot 110711 - Update to snapshot 110613 - Update to snapshot 110609 - Update to snapshot 110606
- Moved ossecr user creation event to the ossec-hids core package - Update to snapshot 110531 - Update to snapshot 110526 - Update to snapshot 110504 - Bugfix #536, Increase the default sleep time for syscheck - Renamed to 2.6 branch - Add support for the rules/decoders dir system - Update to snapsot 110405
- Update asl-shun to support ossec alert ids - Changed asl-shun sqlite database to /var/ossec/var/blocklist3.sqlite
- asl-shun database format now stores the full alertid - Update to snapshot 101203 - Update to snapshot 101125 - Added alertid support to os_dbd, this involves a schema update - Added dst ip, src prt, and dst prt capture support to os_dbd - Bugfix #XXX, manage_agents was built in client mode for the server package. - Add clamav decoder & ruleset - Update to 2.5.1 final - Update to 2.5 final - Update to 0928 snapshot - Extended no_ar into ossec-dbd - Add no_ar option to disable active response per rule - Update to snapshot 100920 - Update snapshot to 100907 - Snapshot 100901 - Added test fix for os_dbd - Bugfix #376, ossec-control will now properly stop and reload - Update to 0809 snapshot - Relink against native mysql - Add minicon decoder from les fenison - Update to 100707 snapshot
- Feature Request #371, add ossec.log to logrotate - Updated to 100615 snapshot - Updated init and ossec-server scripts to support the new reload feature. - Update to 2.4.1 - Added zabbix reporting active response - Update to 2.4 final
- Lowered courier rule 3910 (failures) from 6 over 240 to 10 over 10
- Lowered courier rule 3911 (success) from 10 over 60 to 30 over 20 - Rebuilt for atomic repo - Update to CVS 100317 - Update to CVS 100311
- Add decoder for denyhosts
- Update asl_rules.xml to include denyhosts rules - Update to CVS 100309 - Added new decoder for smtp_auth
- Added rules to detect smtp_auth brute force attempts
- Added rules to detect imap/pop brute force attempts - Updated ossec-server.conf to be in parity with the ASL config
- Added templates dir for generating configs - Update to 2.3 release - Update to snapshot 091109 - Update to snapshot 091008 - Update to snapshot 090925
- Added timestamp field to the mysql schema
- Bugfix #XXX, for the ossec-client.init script to call the correct (renamed) ossec syscheckd/logcollector daemons
- Appologies for not updating the previous changelogs. Missed a few updates! - Update to snapshot 090827
- Feature Request #225, Added logrotate event to active-response log
- Updated system_audit_rcl.txt to look for the correct php.ini file - Update to 090824, beta 1 release - Update to 090812 snapshot - Rebuild agent daemons with -DCLIENT, added symlink trickery - update to 2.1.1 - update to 090630 snapshot, this has fixes for CentOS/RHEL 4 64-bit environments - update to 2.1 final - update to snapshot 090612 - update to snapshot 090610 - update to snapshot 090603 - Disable postgresql support, to get around an undesirable dependency on EL4 - Update to snapshot 090417 - Update to snapshot 090413 (this adds in inotify support) - Update to snapshot 090410 (this adds in inotify support) - Update to snapshot 090408 - Added authpsa rules back in, this is used to detect brute force attacks
- Added conditional building support for ASL modifications                       2.9.0-49.suse13.1.art 2.9.0-49.suse13.1.art        mysql.schema ossec-dbd /usr/share/ossec/contrib/ /var/ossec/bin/ -O2 -g -m32 -march=i486 -fmessage-length=0 -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables drpm lzma 5 i386-suse-linux         ASCII text ELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.16, BuildID[sha1]=c97c804e857445cb6f69479b3f060409fc99897f, not stripped                  R  R  R  R  R  	R  R  R  R  R  R  R  R  R   R  R  R  R  
R  R     ?   p   ]    "k%{Usgi:N-55CtAyǬԅ((4`7L2S=OD`9#Ivy/Xԓo|D/js)U#3Yg%'f2ɒSN\ܬq|&jj?
mn8ꇼ(bm$qWa!3]'"jɢzPo6cqi"lxVIBIiPΨ){QjIt>1ԟ:S)%[:P-#Uu:T\$#X0lay
`F " ĩn$QѢ1HW:?WpaXx@=j\g_@źd{5nIZϢQ{&PʹWc~|ZmjRQdIz)_)ߥ">u4t>y`-j&-H394rQP
Hwrĭůx: alxS޸aŏ4aB~&"rZ\2-	g }aB#evkښ*gt1vHZ6Xi,[\ҀFZOz{Ewg:y[!E
Q[VCVOk:¨kh+O> E^boC)!Q5U;!-㣰 a:&IP9|fIpKƁM-nEUQX1YDyvEiaszZ	-߀B~^@{yo
*d&U҉k%XF<0{ʪߟѰIvg8 0o04sr8H	B_AЪ­CPA.޺ǞWp^ײjrU2feJݕx֗A/:z|1&\y-0iot6&q>&q٫~aX.hۂ@+')_~;_邮?h<1i&Vw,Hsљ4vaU=
*U'ʹ 4]ޓva"9ޖ?r$KԿe5|KIUuIŤ}yQ8qzG_ſIDxCt"zºՎLfrKSmv[EĶN.9Dݸ#M\cY}1ʺ$k:KJ?;o6nYo}'M{ZN~CHKA%!720oUGz#4j0F88r
py{}%O?Q~Y~K]hŉr=kru_]¼}Hj$YFXXQ[-OnB(5m.(JQ.x8lgw.Ē-%,{È#x,m
ؖ+i67ó	&Ў5Lcb~ƈ.\0!|Y9G,P#y*6+:3MHOj(2'8 r'z9aʆ>+!XE*ƍ$[#P~Dp<rq4,f&FZQ	%تӿ{}ʹ7+.of5M2c}Q}V;ƈ
JyT7FNA ,>o^AcH߄ct3vUM:nĶT@.H	|0u0w\3QJS\(Ғ5Xq@#DsH*+epx/N@KiTu_1.hBc<ZeY"Pz	b
@˰J5+-{/>"9H=\Qzr t>CNWKX]rheszo{	pQY>eL	mv:IG/*Qvd&ue_N5ket|@TT_:xLԍ7|{`m0k7ϼu<_9sS^84
mZ# Bz !yG Â$(|qb>Yhr2!B1p^'X.p1Ia.OH6$X1}+(;t\j.-ٞvtgI2ӷ~o0MF2(Ik
/ҐPʿߚE[˯00cyY1p6y(	pJRɄ9RV"4ͲlGӔ|;5)^:W3-K8dJm:[y)(/;
5o3b=^KKTƸT0/{zTAg	BGQ^&-<틞/l4HM
'<:$X2CX:?ƞX7<[ybs.O8_]X;)('&M-júL_ח)nCOUmmb`AVϊ
JGA~2W|}]B>F*KX)*"%-=/Z%d3.yID%
&ښ]3l 3v#PaQu#88!BbR!`sK0@xu	^`:+ʥ8V{B+JFTe	%,\ZֲxmL3/p;{;W{5)Z0`-H3R`֛18'YQG]'LLGzl\L7nh*t5<Dz.K1,%wE}3۩,SV]p)>_xGr;j W;-:-/.|7` {c5@C99!n;yï)n$qu0D,C]awmOOQXv5S0|\U}:SsTI/"zKhZ vSv|!GʇF:]n4H
yɝ%&ĉmqOIџGQʅ]~(MrU /{-?dkm%6W:nFGJCp:d#u0b e}n,xpww??svPݣ!f",%,}m8LR跑U?#jÇȗg^jKa7sň<cDҦ֔ħyp:eMKr
6yɳ?t]kѱBGaSqXc^v*ݎ,3%tT=#jDE㿋E]%esOC󫑫7>c#7?/=f`._HV	n1P/)l&JgCmhܲ,FO@ 3q)bpP?FY? ~)ISGｽ%I22T>:k8| E6WY\K,Sӄ(K'rƂI:{}/f:_B(J̶M0>@)H	Fw\HihA0a˯6|=wFTbgq$Wg:U?tYx@He^({ho>ej{ΔÏF;)|8"qxR pQL[8hț(ѮUJc&t]~5u.	VYxpfYZ0jJi./4A>.aԫ	OeFj(zPg4ɭ(Dg\5X;J.MYhp9bmehA؂53JǏcm[O|9}P+QoЕrc0=HRy'	^9svrܧuB>(\?A^+,_dUϘ\wz1Lz}_zׁUYYٓۆz!H2C暏U/-3=PlP堮a}/*PK
!oΦ5O38c%ֹ~3򠩍=;6Rx0"эmG.>EVr+\N*e5wav܍=f+Av8NHpa7-ZʋWm|Ç{z{Yk\=z$^<ƳCDxoTWpURecMlo/e
89h7V>N\R75Ҵi6),5Ĕ}KWH:R/CN[_VN}+eڱJwCڝJ~+J4ܫ4G	'Y1CSVJBFu)hFgy/Kek[QQ,U7]"kTkmTR3U.u[|.ǔ	MǶP+M:W%:8'biM0Dmd˦HGk!|o~F,YrndN%UDvr0SʳPi)#d1QX'_բsY)~zc]>z x^@e\<7-eeG]vcyB!{9wN*ʵů~6vx_Q/4q!Cf{M:qYJnU\: