    ossec-hids-2.8.3-51.suse13.1.art                                                              $   >                                  ZugGO{=%   >                 >  OX   ?     OH      d                                                	   #        	   X          8          <          H          L          a          e        	                                                       :          :  	     T   :  
        :          :       J   :          :       l   :          :                    :                 T                    <     (     o     )     v     *          +          ,          -          8        o  9        o  :     (0   o  =     C/     D     C7     G     C@   :  H     D(   :  I     E   :  X     EL     Y     E\     \     E   :  ]     F   :  ^     I     b     J     d     K*     e     K/     f     K4     l     K6     u     KH   :  v     L0     w     M   :  x     N   :  y     N   C ossec-hids 2.8.3 51.suse13.1.art An Open Source Host-based Intrusion Detection System OSSEC is a scalable, multi-platform, open source Host-based Intrusion Detection
System (HIDS). It has a powerful correlation and analysis engine, integrating
log analysis, file integrity checking, Windows registry monitoring, centralized
policy enforcement, rootkit detection, real-time alerting and active response.
It runs on most operating systems, including Linux, OpenBSD, FreeBSD, MacOS,
Solaris and Windows.

This package contains common files required for all packages.   Vflatback     Dhttp://www.ossec.net GPL Atomicorp <support@atomicorp.com> Applications/System http://www.ossec.net/ linux x86_64 if ! id -g ossec > /dev/null 2>&1; then
  groupadd -r ossec
fi
if ! id -u ossec > /dev/null 2>&1; then
  useradd -g ossec -G ossec       \
	-d /var/ossec \
	-r -s /sbin/nologin ossec
fi
if ! id -u ossecr > /dev/null 2>&1; then
  useradd -g ossec -G ossec       \
	-d /var/ossec \
	-r -s /sbin/nologin ossecr
fi               #  ~  :  `       <       d           c      
?    	        }            P      '           8  A            O    	       {   d      (   (   <   (A큤AhAhAhhhhhhhhhhhAhhhhhhhhhhhhhAhAhAA聠AAhAAAhA                                                                                                                    VVV$BVV$BV$BV$BV$BV$BVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVbcd6e512c9627c6d09a2e852db43a1aa  dd96f5ec41c601c09f99252272c38aac 9e7417e6440f786de46b42cd31eee384 6bca76fa2a32b1a2bda3d06977a3b786 cd7b8fb9892087b1c734c509c5497532 426b785a1b4939418586baae90f403aa 0d7fd090a120b378bd44a18319085d88 60cc55e9654ab63ad3d7b395ff75affb    25887bdd240bc502c80c970a926132bc ac2254ffe808f2e1e6a2059f7b6b70d6 6696d5e6b1464d63569507419a7b3582 b18f166b9aa7abfbd0500b75c6ace41d 46b0e3782179474d80c2d51cc0c18ea1 91819d33fc1831c33090e6f12634c446 4cbab6aeb963b00fec11fb2c4367ff51 54265163fd59969371516ae7cf4024ee 8038838ce614839b69607b0c8d3dcd95 2eb0f40856189205d103e3116389cf54  8de9f76b53e3d931ca91b5b30e93e30d 3837e5b595795be4a4b7ab8a686419fc 151469d3db7b9984f283b3db84bd4805 c4686eb10052796a091cc2631cc26066 37bedae6ed6bb5f7b4a81b05d111110c 01998b783ae3e744910ca5fa48284e15 607f15a31477667a929b39fe93fd0ef3 5153a546ff0b249f5e5fad7336864753 3029b1c8b4452e9220e1dd0d5e3d1146 e970334d6ed40cec19ed160e0edd9503 afd8198e717c69712a39abf88d737bfd f96dec8e2bbbbba81547d8a8ca5f1f4e  0a925a9273f76d0c11923f81b3a3f166    8bbb43059e784bc7897d8afa91db4420 87a3dacc9168f4bcb24de133d93f3d25 8b01dd3679f38c62cd275c72cdf5f88d 4fb4e5adb8b146c8c1661b026c4ccec3 c305bfe360442ace1a893b033da10aba bc0ae4fa2bc3aa0359da50cfc5dc60ae 1ab23dcbf166a3d52088d6880adac31b 137905d4645eb4a91764e1fde96bdbcd 10b8dc27d937b26821fda7f91e2e281f 821a6d25c7871410bc13a1c995cfbb13 2db61ae3efd9250fe63cdac8579d005f bb55cdd41f77ea7a53c5f7b50fc2dbc7                                                                                                                                                                                                                                                                                                 root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec root ossec ossec root root root root root root root root root root root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec-hids-2.8.3-51.suse13.1.art.src.rpm   config(ossec-hids) ossec-2.8.3-51.suse13.1.art ossec-hids ossec-hids(x86-64)            @   @               
  
  
/bin/sh /bin/sh /bin/sh /usr/bin/env /usr/sbin/groupadd /usr/sbin/useradd config(ossec-hids) inotify-tools rpmlib(CompressedFileNames) rpmlib(PayloadFilesHavePrefix) rpmlib(PayloadIsLzma)       2.8.3-51.suse13.1.art  3.0.4-1 4.0-1 4.4.6-1 4.11.1 [ -r /etc/localtime ] && cp -fpL /etc/localtime /var/ossec/etc glibc         V@V{@Ux&Uv@TT@SSS[S@R@R@RʚR@R@RrF@RiRR@Q@QY@Q@@QQ@Q@Qu&@Qu&@QkQg@Q\PDPP@PP@OiO@OЗOЗO	O OpZ@NNS@NK@N;@N;@N6@N-ZNMMM@M@M@M?MM>MUM@MPL~L8LΫLΫLʷ@LeL@L{LL@LA@LLLzL~@@L|LvW@LmLa?@LRL4l@LT@KtK͗@KKK@K[K@K8@K@K@K@J@JJJ@JJJn@JL@JI@J2C@J2C@J/@J&eI@Io@I)@I4IܑISupport <support@atomicorp.com> - 2.8.3-51 Support <support@atomicorp.com> - 2.8.3-50 Support <support@atomicorp.com> - 2.8.2-49 Support <support@atomicorp.com> - 2.8.1-48 Support <support@atomicorp.com> - 2.8.1-47 Support <support@atomicorp.com> - 2.8.0-46 Support <support@atomicorp.com> - 2.8.0-45.1 Support <support@atomicorp.com> - 2.8.0-45 Support <support@atomicorp.com> - 2.7.1-44 Support <support@atomicorp.com> - 2.7.1-43 Support <support@atomicorp.com> - 2.7.1-42 Support <support@atomicorp.com> - 2.7.1-41 Support <support@atomicorp.com> - 2.7.1-40 Support <support@atomicorp.com> - 2.7.1-36 Support <support@atomicorp.com> - 2.7.1-35 Support <support@atomicorp.com> - 2.7-34 Support <support@atomicorp.com> - 2.7-33 Support <support@atomicorp.com> - 2.7-32 Support <support@atomicorp.com> - 2.7-31 Support <support@atomicorp.com> - 2.7-30 Support <support@atomicorp.com> - 2.7-29 Support <support@atomicorp.com> - 2.7-28 Support <support@atomicorp.com> - 2.7-27 Support <support@atomicorp.com> - 2.7-26 Support <support@atomicorp.com> - 2.7-25 Support <support@atomicorp.com> - 2.7-24 Support <support@atomicorp.com> - 2.7-23 Support <support@atomicorp.com> - 2.7-22 Support <support@atomicorp.com> - 2.7-21 Support <support@atomicorp.com> - 2.7-20 Support <support@atomicorp.com> - 2.7-19 Support <support@atomicorp.com> - 2.7-17 Support <support@atomicorp.com> - 2.6-16 Support <support@atomicorp.com> - 2.6-15 Support <support@atomicorp.com> - 2.6-14 Support <support@atomicorp.com> - 2.6-13 Support <support@atomicorp.com> - 2.6-12 Support <support@atomicorp.com> - 2.6-11 Support <support@atomicorp.com> - 2.6-10 Support <support@atomicorp.com> - 2.6-9 Support <support@atomicorp.com> - 2.6-8 Support <support@atomicorp.com> - 2.6-7 Support <support@atomicorp.com> - 2.6-6 Support <support@atomicorp.com> - 2.6-5 Support <support@atomicorp.com> - 2.6-4 Support <support@atomicorp.com> - 2.6-3 Support <support@atomicorp.com> - 2.6-2 Support <support@atomicorp.com> - 2.6-1 Support <support@atomicorp.com> - 2.6.0-0.10 Support <support@atomicorp.com> - 2.6.0-0.9 Support <support@atomicorp.com> - 2.6.0-0.8 Support <support@atomicorp.com> - 2.6.0-0.7 Support <support@atomicorp.com> - 2.6.0-0.6 Support <support@atomicorp.com> - 2.6.0-0.5 Support <support@atomicorp.com> - 2.6.0-0.4 Support <support@atomicorp.com> - 2.6.0-0.3 Support <support@atomicorp.com> - 2.6.0-0.1 Support <support@atomicorp.com> - 2.5.1-10 Support <support@atomicorp.com> - 2.5.1-9 Support <support@atomicorp.com> - 2.5.1-8 Support <support@atomicorp.com> - 2.5.1-7 Support <support@atomicorp.com> - 2.5.1-6 Support <support@atomicorp.com> - 2.5.1-5 Support <support@atomicorp.com> - 2.5.1-4 Support <support@atomicorp.com> - 2.5.1-3 Support <support@atomicorp.com> - 2.5.1-2 Support <support@atomicorp.com> - 2.5.1-1 Support <support@atomicorp.com> - 2.5-1 Support <support@atomicorp.com> - 2.5-0.9 Support <support@atomicorp.com> - 2.5-0.8 Support <support@atomicorp.com> - 2.5-0.7 Support <support@atomicorp.com> - 2.5-0.6 Support <support@atomicorp.com> - 2.5-0.1 Support <support@atomicorp.com> - 2.4.1-11.2 Support <support@atomicorp.com> - 2.4.1-11.1 Support <support@atomicorp.com> - 2.4.1-10 Support <support@atomicorp.com> - 2.4.1-9 Support <support@atomicorp.com> - 2.4.1-8 Support <support@atomicorp.com> - 2.4.1-7 Support <support@atomicorp.com> - 2.4.1-6 Support <support@atomicorp.com> - 2.4.1-5 Support <support@atomicorp.com> - 2.4.1-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.2 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta2.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta1.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-11 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-10 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-9 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-2 - Add logrotate for Fedora (logrotate 3.8+) - Update to 2.8.3
- Fix for Issue #642 - Update to 2.8.2, this release just inclused the -48 versions fix - Security fix for CVE-2015-3222 - Update to 2.8.1. This is identical to 2.8.0-46, the only change is the hosts.deny CVE-2014-5284 is merged in. - Revert BR#1596
- Add Bugfix for hosts.deny race condition (CVE-2014-5284) - BR #1596, Add fork limiting patch (max 10) for execd to prevent DoS conditions - Upgrade to 2.8.0 - Feature Request #1512,  speed up shuns in execd, move sqlite down - Relink against native mysql - Add ar-tracking active response - Placeholder for null exclusion rules.  Legacy support - ASL 4 version with new database format - Add support for Fedora 20
- Modify optimization flags for FORTIFY - Update to 2.7.1
- Add independent rules.d/decoders.d ossec-rules package - FR#772, add rule 3360 for postfix slow brute force
-   add dovecot-decoder.patch for cpanel dovecot
-   Update 9702, 9753 for dovecot brute force
- FR#773, add rule 11308 for pure-ftp slow brute force
- FR#1347, Update for courier v4 decoder (pop3s)
- FR#1359, Update horde decoder for v5 - Disable ossec-dbd signature table (replaced by aslw_rules). This was very slow - Break ossec-dbd into separate package
- FR#1321, update courier-imap decoder for version 4.0 - Bugfix #XXX, prevent truncating last character on ossec-dbd database inserts on the alerts/data table - Add tld column to alert table w/ index - Deprecate internal id generation in dbd
- update schema to autoincrement, increase id space to int - Add is_hidden to mysql schema - Add if exists to mysql schema - Add os_dbd-mysql-replace-query.patch to consolidate SELECT/UPDATE into REPLACE sql - Consolidate alert & data into a common table
- Add ossec-authd init script - Add sqldelete command  to execd
- Update to clear sqlite db at startup - More minor updates to GeoIP tracking - Minor update to GeoIP tracking - Bugfix on permissions for files in shared/ directory for client installs
- Add GeoIP support
- Remove dependency on perl-DBD-SQLite
- Update asl-shun to new non-perl based version.
- Deprecate firewall-drop-update.patch
- Add sqlite support to execd (/var/ossec/var/execd.sqlite) - Update to 2.7 final - Feature Request #XXX, revert duplicate detection in log events to help detect extremely fast brute force attacks
- Add FORTIFY_SOURCE, PIE, and relro (full) - Update to 2.7-rc2 - Update to 2.7-rc1 - Move active response components under the common package - bugfix #xxx, correct ownership permissions on fts dir - Update to init script to suppress spurious execd output
- Add alerts queue to server package with ossec/ossec permissions - Bugfix #XXX, correct any/agentd condition - Moved agentless packages under server - Drop timeid and cat_id indexes from schema - Add new index, timeid to alerts table. - Add cmoraes patch, Adds config options for enabling/disabling rootkit/syscheck options, and agent config profiles
- Add ossec-memleaks patch
- Add agentless directories, and agent.conf
- Bugfix #XXX, ossec-hids.init will now return an exit code on status - Add prelink_cmd support - Bugfix #XXX, display multi-line events in data table correcty - Update to asl-shun.pl purge event to default to 24 hours. - Update to asl-shun.pl to change ordering of block rules
- Revert from 0805 snapshot - Update to 0805 snapshot - Update to 0801 snapshot
- Update asl-shun.pl to log to active-responses.log, blocks now go to the named chain ASL-ACTIVE-RESPONSE, and delete events are more redundant. - Update to OSSEC 2.6 Final - Update to snapshot 110711 - Update to snapshot 110613 - Update to snapshot 110609 - Update to snapshot 110606
- Moved ossecr user creation event to the ossec-hids core package - Update to snapshot 110531 - Update to snapshot 110526 - Update to snapshot 110504 - Bugfix #536, Increase the default sleep time for syscheck - Renamed to 2.6 branch - Add support for the rules/decoders dir system - Update to snapsot 110405
- Update asl-shun to support ossec alert ids - Changed asl-shun sqlite database to /var/ossec/var/blocklist3.sqlite
- asl-shun database format now stores the full alertid - Update to snapshot 101203 - Update to snapshot 101125 - Added alertid support to os_dbd, this involves a schema update - Added dst ip, src prt, and dst prt capture support to os_dbd - Bugfix #XXX, manage_agents was built in client mode for the server package. - Add clamav decoder & ruleset - Update to 2.5.1 final - Update to 2.5 final - Update to 0928 snapshot - Extended no_ar into ossec-dbd - Add no_ar option to disable active response per rule - Update to snapshot 100920 - Update snapshot to 100907 - Snapshot 100901 - Added test fix for os_dbd - Bugfix #376, ossec-control will now properly stop and reload - Update to 0809 snapshot - Relink against native mysql - Add minicon decoder from les fenison - Update to 100707 snapshot
- Feature Request #371, add ossec.log to logrotate - Updated to 100615 snapshot - Updated init and ossec-server scripts to support the new reload feature. - Update to 2.4.1 - Added zabbix reporting active response - Update to 2.4 final
- Lowered courier rule 3910 (failures) from 6 over 240 to 10 over 10
- Lowered courier rule 3911 (success) from 10 over 60 to 30 over 20 - Rebuilt for atomic repo - Update to CVS 100317 - Update to CVS 100311
- Add decoder for denyhosts
- Update asl_rules.xml to include denyhosts rules - Update to CVS 100309 - Added new decoder for smtp_auth
- Added rules to detect smtp_auth brute force attempts
- Added rules to detect imap/pop brute force attempts - Updated ossec-server.conf to be in parity with the ASL config
- Added templates dir for generating configs - Update to 2.3 release - Update to snapshot 091109 - Update to snapshot 091008 - Update to snapshot 090925
- Added timestamp field to the mysql schema
- Bugfix #XXX, for the ossec-client.init script to call the correct (renamed) ossec syscheckd/logcollector daemons
- Appologies for not updating the previous changelogs. Missed a few updates! - Update to snapshot 090827
- Feature Request #225, Added logrotate event to active-response log
- Updated system_audit_rcl.txt to look for the correct php.ini file - Update to 090824, beta 1 release - Update to 090812 snapshot - Rebuild agent daemons with -DCLIENT, added symlink trickery - update to 2.1.1 - update to 090630 snapshot, this has fixes for CentOS/RHEL 4 64-bit environments - update to 2.1 final - update to snapshot 090612 - update to snapshot 090610 - update to snapshot 090603 - Disable postgresql support, to get around an undesirable dependency on EL4 - Update to snapshot 090417 - Update to snapshot 090413 (this adds in inotify support) - Update to snapshot 090410 (this adds in inotify support) - Update to snapshot 090408 - Added authpsa rules back in, this is used to detect brute force attacks
- Added conditional building support for ASL modifications /bin/sh /bin/sh                                                                                                                                                                                                           	   
                                                                      !   "   #   $   %   &   '   (   )   *   +   ,   -   .   /   0   1   2   3   4   5   6   7   8   9   :                                                                        2.8.3-51.suse13.1.art  2.8.3-51.suse13.1.art 2.8.3-51.suse13.1.art                                                                                                                        	   	   
   
   
   
   
   
   
   
   
   
   
   
                  ossec-hids ossec-hids BUGS CHANGELOG CONFIG CONTRIBUTORS INSTALL LICENSE README.md ossec active-response bin ar-tracking.sh asl-shun.pl disable-account.sh firewall-drop.sh host-deny.sh ip-customblock.sh ossec-tweeter.sh restart-ossec.sh route-null.sh zabbix-alert.sh agentless main.exp register_host.sh ssh.exp ssh_asa-fwsmconfig_diff ssh_foundry_diff ssh_generic_diff ssh_integrity_check_bsd ssh_integrity_check_linux ssh_nopass.exp ssh_pixconfig_diff sshlogin.exp su.exp bin ossec-configure etc shared templates active-response.template apache-logs.template ar-disable-account.template ar-firewall-drop.template ar-host-deny.template ar-routenull.template pgsql-logs.template rootcheck.template rules.template snort-logs.template syscheck.template syslog-logs.template logs queue diff ossec var run /etc/logrotate.d/ /usr/share/doc/packages/ /usr/share/doc/packages/ossec-hids/ /var/ /var/ossec/ /var/ossec/active-response/ /var/ossec/active-response/bin/ /var/ossec/agentless/ /var/ossec/bin/ /var/ossec/etc/ /var/ossec/etc/templates/ /var/ossec/queue/ /var/ossec/var/ -O2 -g -m64 -fmessage-length=0 -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables drpm lzma 5 x86_64-suse-linux                                                                                                                                                                                            ASCII text directory UTF-8 Unicode text, with very long lines UTF-8 Unicode text Pascal source, ASCII text POSIX shell script, ASCII text executable a /usr/bin/env expect script, ASCII text executable exported SGML document, ASCII text                                                                                	       
                                                                                                                                                                                                                                                                                                                                             R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R     ?       ]    "k%M{Usg`Y{
 uA%2baИi\Ii6㢺gu[h+5uzܠLL㥹O,VozPfNâ	4וǀQn\eWWCkg$U:4S|ĵKsBV	ڐGd*eqh墶SuÀCfSRk{;uy/aNpl$x9rfP;?xS`@s+
ր$tv3E2HCCuuNqtSn\flg+kr
9Y:q<@Q`n9_\PyJG??Kȋ]b3P'qA[B s>TJ ꣊^2)L5anI*:-{3_;ǳBrFZKg⑻*(T-0Q,7k	`z<c=aj|P&ƅ![:e=oK]b	ѐ79<(c:llԥx0+e={֐/c!ՕҺ5
ɲ j"^t`hc:u$FZoRTt[]`
x;Ĥ<ydS9	CkeK6?.mqTX_.)Mv~Ha<JVа&uföV jg>5kVr tٽh<7ςZ4zfhx	˵V蒼=
p5"^,XF#v<yisNɠXS}H^ A#])꺇C%-8fsJ
dхN!)NN3عt|B"$CɸY鉱V4<UHA:PgFwJjZ* 1)[4^&耴~BTne-GO
$*|JBD4VW,7w@bӮZC+&u#S۹#i<^|4摒R<ͽ7U_ꕾCN]^2Ɉ[vh<du
[ԗ;lmOoQBDo9]mQbp*cŧ6Ā_wp0'ra?s?KBԒFBd<JŜ<p{m*pԦ. I D"7BQbi|Dl`^u$1j>NL-f*34&K.$2тkO+^Z2yyɸDpbaw͝;glB#4ͦrOO0倚"a!ܡxR=`{|WaP=9_1n!JiHG(R3k
<c/8Xm <Sl7ZS--N~f=tJP	ﮭv$ /_	^3<柪Rud^uz~&~2]Cg#TҪB݈{fL8V>4$[#gY.d"F.+A:*7%(u R-3vYGj4?$;Dnl&vba~'C-sFN%Wv[ʣ*4`uOSlX
D̍mⴉ5؊b8$|i6si[\,G<40LXK	0@\$GG{}֥FӥmƮFXS