    ossec-hids-2.8-46.suse13.1.art                                                                $   >                                  Y*bGǋ3   >                 >  M(   ?     M      d                                                	   !        	   V          4          8          D          H          ]          a        	                                                       :          :  	     P   :  
        :          :       F   :          :       h   :          :                    :                 H          t          0     (     a     )     h     *          +          ,          -          8        j  9     `   j  :     '9   j  =     A     D     A	     G     A   :  H     A   :  I     B   :  X     C      Y     C0     \     Cp   :  ]     DX   :  ^     Gy     b     H     d     H     e     H     f     I     l     I     u     I   :  v     J      w     J   :  x     K   :  y     L   C ossec-hids 2.8 46.suse13.1.art An Open Source Host-based Intrusion Detection System OSSEC is a scalable, multi-platform, open source Host-based Intrusion Detection
System (HIDS). It has a powerful correlation and analysis engine, integrating
log analysis, file integrity checking, Windows registry monitoring, centralized
policy enforcement, rootkit detection, real-time alerting and active response.
It runs on most operating systems, including Linux, OpenBSD, FreeBSD, MacOS,
Solaris and Windows.

This package contains common files required for all packages. Tflatback     0http://www.ossec.net GPL Atomicorp <support@atomicorp.com> Applications/System http://www.ossec.net/ linux x86_64 if ! id -g ossec > /dev/null 2>&1; then
  groupadd -r ossec
fi
if ! id -u ossec > /dev/null 2>&1; then
  useradd -g ossec -G ossec       \
	-d /var/ossec \
	-r -s /sbin/nologin ossec
fi
if ! id -u ossecr > /dev/null 2>&1; then
  useradd -g ossec -G ossec       \
	-d /var/ossec \
	-r -s /sbin/nologin ossecr
fi               !  |  8  `       <       d           c      
?    	        }            P      '           8  A            O    	       {   d      (   (   <   (A큤AhAhAhhhhhhhhhhhAhhhhhhhhhhhhhAhAhAA聠AAhAAAhA                                                                                                                    TTS}aTS}aS}aS}aS}aS}aTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTbcd6e512c9627c6d09a2e852db43a1aa  dd96f5ec41c601c09f99252272c38aac 9e7417e6440f786de46b42cd31eee384 f18762365fcf687764a89f4126dd7a9d b4318998d4d34431f536824bee4dc766 3a3fca440e5142141f75613396dc55be 0d7fd090a120b378bd44a18319085d88 620bb7958e0665fa9dd3a544ae944a15    25887bdd240bc502c80c970a926132bc ac2254ffe808f2e1e6a2059f7b6b70d6 6696d5e6b1464d63569507419a7b3582 b18f166b9aa7abfbd0500b75c6ace41d c4f4e6d48605c3df168c5f78b9164eda 91819d33fc1831c33090e6f12634c446 4cbab6aeb963b00fec11fb2c4367ff51 54265163fd59969371516ae7cf4024ee 8038838ce614839b69607b0c8d3dcd95 2eb0f40856189205d103e3116389cf54  8de9f76b53e3d931ca91b5b30e93e30d 3837e5b595795be4a4b7ab8a686419fc 151469d3db7b9984f283b3db84bd4805 c4686eb10052796a091cc2631cc26066 37bedae6ed6bb5f7b4a81b05d111110c 01998b783ae3e744910ca5fa48284e15 607f15a31477667a929b39fe93fd0ef3 5153a546ff0b249f5e5fad7336864753 3029b1c8b4452e9220e1dd0d5e3d1146 e970334d6ed40cec19ed160e0edd9503 afd8198e717c69712a39abf88d737bfd f96dec8e2bbbbba81547d8a8ca5f1f4e  0a925a9273f76d0c11923f81b3a3f166    8bbb43059e784bc7897d8afa91db4420 87a3dacc9168f4bcb24de133d93f3d25 8b01dd3679f38c62cd275c72cdf5f88d 4fb4e5adb8b146c8c1661b026c4ccec3 c305bfe360442ace1a893b033da10aba bc0ae4fa2bc3aa0359da50cfc5dc60ae 1ab23dcbf166a3d52088d6880adac31b 137905d4645eb4a91764e1fde96bdbcd 10b8dc27d937b26821fda7f91e2e281f 821a6d25c7871410bc13a1c995cfbb13 2db61ae3efd9250fe63cdac8579d005f bb55cdd41f77ea7a53c5f7b50fc2dbc7                                                                                                                                                                                                                                                                                                 root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec root ossec ossec root root root root root root root root root root root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec-hids-2.8-46.suse13.1.art.src.rpm config(ossec-hids) ossec-2.8-46.suse13.1.art ossec-hids ossec-hids(x86-64)          @   @               
  
  
/bin/sh /bin/sh /bin/sh /usr/bin/env /usr/sbin/groupadd /usr/sbin/useradd config(ossec-hids) inotify-tools rpmlib(CompressedFileNames) rpmlib(PayloadFilesHavePrefix) rpmlib(PayloadIsLzma)       2.8-46.suse13.1.art  3.0.4-1 4.0-1 4.4.6-1 4.11.1 [ -r /etc/localtime ] && cp -fpL /etc/localtime /var/ossec/etc glibc           T@SSS[S@R@R@RʚR@R@RrF@RiRR@Q@QY@Q@@QQ@Q@Qu&@Qu&@QkQg@Q\PDPP@PP@OiO@OЗOЗO	O OpZ@NNS@NK@N;@N;@N6@N-ZNMMM@M@M@M?MM>MUM@MPL~L8LΫLΫLʷ@LeL@L{LL@LA@LLLzL~@@L|LvW@LmLa?@LRL4l@LT@KtK͗@KKK@K[K@K8@K@K@K@J@JJJ@JJJn@JL@JI@J2C@J2C@J/@J&eI@Io@I)@I4IܑISupport <support@atomicorp.com> - 2.8.0-46 Support <support@atomicorp.com> - 2.8.0-45.1 Support <support@atomicorp.com> - 2.8.0-45 Support <support@atomicorp.com> - 2.7.1-44 Support <support@atomicorp.com> - 2.7.1-43 Support <support@atomicorp.com> - 2.7.1-42 Support <support@atomicorp.com> - 2.7.1-41 Support <support@atomicorp.com> - 2.7.1-40 Support <support@atomicorp.com> - 2.7.1-36 Support <support@atomicorp.com> - 2.7.1-35 Support <support@atomicorp.com> - 2.7-34 Support <support@atomicorp.com> - 2.7-33 Support <support@atomicorp.com> - 2.7-32 Support <support@atomicorp.com> - 2.7-31 Support <support@atomicorp.com> - 2.7-30 Support <support@atomicorp.com> - 2.7-29 Support <support@atomicorp.com> - 2.7-28 Support <support@atomicorp.com> - 2.7-27 Support <support@atomicorp.com> - 2.7-26 Support <support@atomicorp.com> - 2.7-25 Support <support@atomicorp.com> - 2.7-24 Support <support@atomicorp.com> - 2.7-23 Support <support@atomicorp.com> - 2.7-22 Support <support@atomicorp.com> - 2.7-21 Support <support@atomicorp.com> - 2.7-20 Support <support@atomicorp.com> - 2.7-19 Support <support@atomicorp.com> - 2.7-17 Support <support@atomicorp.com> - 2.6-16 Support <support@atomicorp.com> - 2.6-15 Support <support@atomicorp.com> - 2.6-14 Support <support@atomicorp.com> - 2.6-13 Support <support@atomicorp.com> - 2.6-12 Support <support@atomicorp.com> - 2.6-11 Support <support@atomicorp.com> - 2.6-10 Support <support@atomicorp.com> - 2.6-9 Support <support@atomicorp.com> - 2.6-8 Support <support@atomicorp.com> - 2.6-7 Support <support@atomicorp.com> - 2.6-6 Support <support@atomicorp.com> - 2.6-5 Support <support@atomicorp.com> - 2.6-4 Support <support@atomicorp.com> - 2.6-3 Support <support@atomicorp.com> - 2.6-2 Support <support@atomicorp.com> - 2.6-1 Support <support@atomicorp.com> - 2.6.0-0.10 Support <support@atomicorp.com> - 2.6.0-0.9 Support <support@atomicorp.com> - 2.6.0-0.8 Support <support@atomicorp.com> - 2.6.0-0.7 Support <support@atomicorp.com> - 2.6.0-0.6 Support <support@atomicorp.com> - 2.6.0-0.5 Support <support@atomicorp.com> - 2.6.0-0.4 Support <support@atomicorp.com> - 2.6.0-0.3 Support <support@atomicorp.com> - 2.6.0-0.1 Support <support@atomicorp.com> - 2.5.1-10 Support <support@atomicorp.com> - 2.5.1-9 Support <support@atomicorp.com> - 2.5.1-8 Support <support@atomicorp.com> - 2.5.1-7 Support <support@atomicorp.com> - 2.5.1-6 Support <support@atomicorp.com> - 2.5.1-5 Support <support@atomicorp.com> - 2.5.1-4 Support <support@atomicorp.com> - 2.5.1-3 Support <support@atomicorp.com> - 2.5.1-2 Support <support@atomicorp.com> - 2.5.1-1 Support <support@atomicorp.com> - 2.5-1 Support <support@atomicorp.com> - 2.5-0.9 Support <support@atomicorp.com> - 2.5-0.8 Support <support@atomicorp.com> - 2.5-0.7 Support <support@atomicorp.com> - 2.5-0.6 Support <support@atomicorp.com> - 2.5-0.1 Support <support@atomicorp.com> - 2.4.1-11.2 Support <support@atomicorp.com> - 2.4.1-11.1 Support <support@atomicorp.com> - 2.4.1-10 Support <support@atomicorp.com> - 2.4.1-9 Support <support@atomicorp.com> - 2.4.1-8 Support <support@atomicorp.com> - 2.4.1-7 Support <support@atomicorp.com> - 2.4.1-6 Support <support@atomicorp.com> - 2.4.1-5 Support <support@atomicorp.com> - 2.4.1-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.2 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta2.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta1.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-11 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-10 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-9 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-2 - Revert BR#1596
- Add Bugfix for hosts.deny race condition - BR #1596, Add fork limiting patch (max 10) for execd to prevent DoS conditions - Upgrade to 2.8.0 - Feature Request #1512,  speed up shuns in execd, move sqlite down - Relink against native mysql - Add ar-tracking active response - Placeholder for null exclusion rules.  Legacy support - ASL 4 version with new database format - Add support for Fedora 20
- Modify optimization flags for FORTIFY - Update to 2.7.1
- Add independent rules.d/decoders.d ossec-rules package - FR#772, add rule 3360 for postfix slow brute force
-   add dovecot-decoder.patch for cpanel dovecot
-   Update 9702, 9753 for dovecot brute force
- FR#773, add rule 11308 for pure-ftp slow brute force
- FR#1347, Update for courier v4 decoder (pop3s)
- FR#1359, Update horde decoder for v5 - Disable ossec-dbd signature table (replaced by aslw_rules). This was very slow - Break ossec-dbd into separate package
- FR#1321, update courier-imap decoder for version 4.0 - Bugfix #XXX, prevent truncating last character on ossec-dbd database inserts on the alerts/data table - Add tld column to alert table w/ index - Deprecate internal id generation in dbd
- update schema to autoincrement, increase id space to int - Add is_hidden to mysql schema - Add if exists to mysql schema - Add os_dbd-mysql-replace-query.patch to consolidate SELECT/UPDATE into REPLACE sql - Consolidate alert & data into a common table
- Add ossec-authd init script - Add sqldelete command  to execd
- Update to clear sqlite db at startup - More minor updates to GeoIP tracking - Minor update to GeoIP tracking - Bugfix on permissions for files in shared/ directory for client installs
- Add GeoIP support
- Remove dependency on perl-DBD-SQLite
- Update asl-shun to new non-perl based version.
- Deprecate firewall-drop-update.patch
- Add sqlite support to execd (/var/ossec/var/execd.sqlite) - Update to 2.7 final - Feature Request #XXX, revert duplicate detection in log events to help detect extremely fast brute force attacks
- Add FORTIFY_SOURCE, PIE, and relro (full) - Update to 2.7-rc2 - Update to 2.7-rc1 - Move active response components under the common package - bugfix #xxx, correct ownership permissions on fts dir - Update to init script to suppress spurious execd output
- Add alerts queue to server package with ossec/ossec permissions - Bugfix #XXX, correct any/agentd condition - Moved agentless packages under server - Drop timeid and cat_id indexes from schema - Add new index, timeid to alerts table. - Add cmoraes patch, Adds config options for enabling/disabling rootkit/syscheck options, and agent config profiles
- Add ossec-memleaks patch
- Add agentless directories, and agent.conf
- Bugfix #XXX, ossec-hids.init will now return an exit code on status - Add prelink_cmd support - Bugfix #XXX, display multi-line events in data table correcty - Update to asl-shun.pl purge event to default to 24 hours. - Update to asl-shun.pl to change ordering of block rules
- Revert from 0805 snapshot - Update to 0805 snapshot - Update to 0801 snapshot
- Update asl-shun.pl to log to active-responses.log, blocks now go to the named chain ASL-ACTIVE-RESPONSE, and delete events are more redundant. - Update to OSSEC 2.6 Final - Update to snapshot 110711 - Update to snapshot 110613 - Update to snapshot 110609 - Update to snapshot 110606
- Moved ossecr user creation event to the ossec-hids core package - Update to snapshot 110531 - Update to snapshot 110526 - Update to snapshot 110504 - Bugfix #536, Increase the default sleep time for syscheck - Renamed to 2.6 branch - Add support for the rules/decoders dir system - Update to snapsot 110405
- Update asl-shun to support ossec alert ids - Changed asl-shun sqlite database to /var/ossec/var/blocklist3.sqlite
- asl-shun database format now stores the full alertid - Update to snapshot 101203 - Update to snapshot 101125 - Added alertid support to os_dbd, this involves a schema update - Added dst ip, src prt, and dst prt capture support to os_dbd - Bugfix #XXX, manage_agents was built in client mode for the server package. - Add clamav decoder & ruleset - Update to 2.5.1 final - Update to 2.5 final - Update to 0928 snapshot - Extended no_ar into ossec-dbd - Add no_ar option to disable active response per rule - Update to snapshot 100920 - Update snapshot to 100907 - Snapshot 100901 - Added test fix for os_dbd - Bugfix #376, ossec-control will now properly stop and reload - Update to 0809 snapshot - Relink against native mysql - Add minicon decoder from les fenison - Update to 100707 snapshot
- Feature Request #371, add ossec.log to logrotate - Updated to 100615 snapshot - Updated init and ossec-server scripts to support the new reload feature. - Update to 2.4.1 - Added zabbix reporting active response - Update to 2.4 final
- Lowered courier rule 3910 (failures) from 6 over 240 to 10 over 10
- Lowered courier rule 3911 (success) from 10 over 60 to 30 over 20 - Rebuilt for atomic repo - Update to CVS 100317 - Update to CVS 100311
- Add decoder for denyhosts
- Update asl_rules.xml to include denyhosts rules - Update to CVS 100309 - Added new decoder for smtp_auth
- Added rules to detect smtp_auth brute force attempts
- Added rules to detect imap/pop brute force attempts - Updated ossec-server.conf to be in parity with the ASL config
- Added templates dir for generating configs - Update to 2.3 release - Update to snapshot 091109 - Update to snapshot 091008 - Update to snapshot 090925
- Added timestamp field to the mysql schema
- Bugfix #XXX, for the ossec-client.init script to call the correct (renamed) ossec syscheckd/logcollector daemons
- Appologies for not updating the previous changelogs. Missed a few updates! - Update to snapshot 090827
- Feature Request #225, Added logrotate event to active-response log
- Updated system_audit_rcl.txt to look for the correct php.ini file - Update to 090824, beta 1 release - Update to 090812 snapshot - Rebuild agent daemons with -DCLIENT, added symlink trickery - update to 2.1.1 - update to 090630 snapshot, this has fixes for CentOS/RHEL 4 64-bit environments - update to 2.1 final - update to snapshot 090612 - update to snapshot 090610 - update to snapshot 090603 - Disable postgresql support, to get around an undesirable dependency on EL4 - Update to snapshot 090417 - Update to snapshot 090413 (this adds in inotify support) - Update to snapshot 090410 (this adds in inotify support) - Update to snapshot 090408 - Added authpsa rules back in, this is used to detect brute force attacks
- Added conditional building support for ASL modifications /bin/sh /bin/sh                                                                                                                                                                                                             	   
                                                                      !   "   #   $   %   &   '   (   )   *   +   ,   -   .   /   0   1   2   3   4   5   6   7   8   9   :                                                                        2.8-46.suse13.1.art  2.8-46.suse13.1.art 2.8-46.suse13.1.art                                                                                                                          	   	   
   
   
   
   
   
   
   
   
   
   
   
                  ossec-hids ossec-hids BUGS CHANGELOG CONFIG CONTRIBUTORS INSTALL LICENSE README.md ossec active-response bin ar-tracking.sh asl-shun.pl disable-account.sh firewall-drop.sh host-deny.sh ip-customblock.sh ossec-tweeter.sh restart-ossec.sh route-null.sh zabbix-alert.sh agentless main.exp register_host.sh ssh.exp ssh_asa-fwsmconfig_diff ssh_foundry_diff ssh_generic_diff ssh_integrity_check_bsd ssh_integrity_check_linux ssh_nopass.exp ssh_pixconfig_diff sshlogin.exp su.exp bin ossec-configure etc shared templates active-response.template apache-logs.template ar-disable-account.template ar-firewall-drop.template ar-host-deny.template ar-routenull.template pgsql-logs.template rootcheck.template rules.template snort-logs.template syscheck.template syslog-logs.template logs queue diff ossec var run /etc/logrotate.d/ /usr/share/doc/packages/ /usr/share/doc/packages/ossec-hids/ /var/ /var/ossec/ /var/ossec/active-response/ /var/ossec/active-response/bin/ /var/ossec/agentless/ /var/ossec/bin/ /var/ossec/etc/ /var/ossec/etc/templates/ /var/ossec/queue/ /var/ossec/var/ -O2 -g -m64 -fmessage-length=0 -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables drpm lzma 5 x86_64-suse-linux                                                                                                                                                                                            ASCII text directory UTF-8 Unicode text, with very long lines UTF-8 Unicode text Pascal source, ASCII text POSIX shell script, ASCII text executable a /usr/bin/env expect script, ASCII text executable exported SGML document, ASCII text                                                                                	       
                                                                                                                                                                                                                                                                                                                                             R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R     ?       ]    "k%Gnpv|g^ZL6nfmxKZ<Enؖ%IAϤMg- aXEPI7 =Lj
 dȳee+kGQAG'oοwz)Kֲ 	I1-<UKߠWHg$n^:|+^pKr`ۤŵq|y'q6/QPNe쭦)JȊaymH%Ɵ8B9nq..\#>)H/ij\ǎtA}{f ڧ3uph$y+ol^C/Lߺ"-nz˗pVo.Rl<LybdZa:MZ-9ų#7Z]u]=7p#I(s-@֡ ;OiZ>VCI=.?fP@_2'`aSy#J.]-5T56;d U^yM+ODkmKql'b1Bipg+@3+^>/~F<zg𛘚ĊBֱHֈYaX|m$r|ͧUAjHmQ-r2<S%jjp)B<Qb E?AVm˳0R	£@Q$oFeTm36N%Y +	6Ͱup͹]*,̡BH֌mgȍ6:~7è7W=IX9rjsRCwVY:x=2m^U>pgzMD0	|Nr5*̈ 6W)dh%uPXXAj<. 6,K!V$a,>B~A<q*"ʊ]-}PóA -qNȳiqdX	SEr(HzgM+Pi`vtPh0{|'I _I\~%	L>Ǜp^3Ff]ĩuV h]ؤtREH~`xsaZI$t}~kDMR+VS^<}JQ8Mx={|(.=-{D`%<KWZyޭtפIz('R|Ѡt:ƛ5JR )*xpɫb#N=,%02-tG9#/dAPk: Օ?bxJf bMNևNMU،*3n?;$^ib9^!J֯קj"kxfy.67࢞44"Мt<8	aW!@kwɼRS@:õߩp$ڳgg^
kRL |~'$IlQ6zar!YaNuASJ-#5SqZ+ۃ{~g-~~vɈPUJI&Jlӆh{[Lf;T
!8tyO5h/0 !3	h!U)rI']N״<I:5rчsI#"`65L1Y%NeCЖl{S0:Տc\;&0ǆ'{-;NNA	z~eq&h6n<ryZGgs"d=	8[!~2'``epGû'Yv}~}D߭l"	 X |U˱)}D1N}FF8R_nFw79f*7CӲ䶳	SWO#7G;w,i̙e&v[KRYvG9#t>usPMcY?.|7ƍ	ib<R'u̈́JƂ94#+ܙCeun 