    ossec-hids-2.6-15.el6.art                                                                     $   >                                  .JLh
6   >                 @  d   ?     d      d                                                	           	   Q          0          4          P          T          i          m        	                                                       W       X   W  	        W  
        W          W          W           W       \   W       !   W                 (   W                                        !     (     "1     )     "7     *     "v     +     "|     ,     "     -     "     8     "   r  9     $P   r  :     9   r  =     RS     D     R[     G     Rd   W  H     S   W  I     U   W  X     Ut     Y     U     \     U   W  ]     W   W  ^     [     b     ]B     d     ]     e     ]     f     ]     l     ]     t     ^    W  u     _\   W  v     `     w     al   W  x     b   W  y     d$          d   C ossec-hids 2.6 15.el6.art An Open Source Host-based Intrusion Detection System OSSEC is a scalable, multi-platform, open source Host-based Intrusion Detection
System (HIDS). It has a powerful correlation and analysis engine, integrating
log analysis, file integrity checking, Windows registry monitoring, centralized
policy enforcement, rootkit detection, real-time alerting and active response.
It runs on most operating systems, including Linux, OpenBSD, FreeBSD, MacOS,
Solaris and Windows.

This package contains common files required for all packages.  P,	ministry.whq.atomicorp.com   =http://www.ossec.net GPL Atomicorp <support@atomicorp.com> Applications/System http://www.ossec.net/ linux i686 if ! id -g ossec > /dev/null 2>&1; then
  groupadd -r ossec
fi
if ! id -u ossec > /dev/null 2>&1; then
  useradd -g ossec -G ossec       \
	-d /var/ossec \
	-r -s /sbin/nologin ossec
fi
if ! id -u ossecr > /dev/null 2>&1; then
  useradd -g ossec -G ossec       \
	-d /var/ossec \
	-r -s /sbin/nologin ossecr
fi              8  6     <          _   =     -         R                    ;                s      1       <     ,        c      
?    	  v      ;  |  <  4        U    '               A            O    	       {   d      (   (   <   (A큤A큤A큤A큤AhAhAhhhhhhhhhAhhhhhhhhhhhhhAhAhAA聠AAhAAAhA                                                                                                                                                                              P,P,NPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPNPP,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,P,65bec1e837d94dff7f8db551208d73aeb0dc2fef6a6407ea7c91c4ee6f430528  b697413cf6e55da97ca296ebd72cd8db53eef2c007869d389075d5d2391e14a0 e9c1d327b2e97725bbcb54f63bec73a12ec07b8d44ad17020238e84970a2d2cf 484df679efd5a5a186c40942cd2fcac511c8d3742d6a7896b4b90f59f7f581bf 92612a256f5ba0a382513b2cd6b6259e3565dccf5d91adfee1967803de50e5c4  9fe9080ce777f1a6ae7b30897d0fb608ae624bfb348ecf0c0c860ddbdf86e5f0 0ec9577297c751ff97badc51306be8111040caa25081fd2e30c0fe38e44c7f68 1e0f3d6deb94ce7081fae364891cac7758754639e4b88acccc54671eab510266  c988f19452b5542572cae3fff4f0fac802562acc315e5173aa4e083d9e369842 9d9ec8875aec0ac6117dae038f4e015d811720fe4a64b93c15d3583b1340dcf0 20cf243734164073841e9ca712d34f54db876fb5d7ebafdbdb71a9fd5c91fc92 dc0b9539ba19d3b5ddca245f8cf1e3f89a9fd345a6f6fb5dc86f7087acdb45cd 1e0f3d6deb94ce7081fae364891cac7758754639e4b88acccc54671eab510266 098c461918330df3a040ae8b3fdf06ba15ef234deeb7c8da37d9a8cc21d3af8b a81c47faa02a7cddf8962e1301f71a013cdea018cdb0975758487de252499d34 f2271e2698e78b45b32149e10600d4fd15262cbdf44e43a5a4b0d51c9f7f2e8f be8502642e5a5251a50cf8274747caa2b3aae9b819e172e5def48dd3e33e9443 ecce3956f6c2defb4033e497cf965a81ddf825964637324920d58566f6933dc8 3fa00600644e8add5af583ae9f16b64e72ae13bdf65dd5c2cbafa9cbab3e63f9 a76d2a0929c5508ddfd00a8a246c549e4d3855fd5277453d9b61c7f660e8fb48 70f89134f79532f6f642f47a2d0bdf63861d20f4b76f190711bc4e2d3dfcb892 9dfb9bdf2df6d1948877696ffb6ff8f08dbda8a3c3e1fcdead588fc44ce462ca  8ab9eb4987d590c7d1e5e7a62358c957d9d5a5c6e528f835eb2529eb751edd1c a5924d7f5fa4ecfa24bee05187fa22f432069720a914374892e9bd8d2a807d8a 4f73cb6caba37b1f399cb8e835608aa1e41dbb4ccee16ba23f6e878dd8f58899 1e1f01db9177108f64c5e561822f0a259bdfad59aebcf0fe24d0c0e9df5f9756 1e0f3d6deb94ce7081fae364891cac7758754639e4b88acccc54671eab510266 ef970afaee6fc7fa4168b1a3ccdf9808edf5df98b30c195597317e7d59c0bae1 065ae034ecc96615757d45a4af1c9f1770295131a1ead862073eb78329522d4e 1d1e66839dd778872fe2aa7275713c2ffc64486f2b2157b51d044cbfcf5ea9ee cee8fd0b3cee63ba465cf8d4d58de2e155602f678efcc54bb6a6d5a43f496a42 3668a2dd9f579512554f17443a71530e8ac867bf8c9115c53f79b301f05e7836 0458d564b9d237a720b126230bd78175da49c5a19e4e9324dcb0384302654282 785514a76800f7faf6865ba06fe6eea63cf17c2c04bd2dc65c2af5697c808070 810475207bab7ce35d0ca1f3fb2174dbad95ab50f9873a3879889674bcad9b80    c4c02e402256dfdcd58357750535ca49e191e13328eb43b5e746999153958ff1 f9a813e4e53823fc8d43a8ec1a91df67524308156eabdf63c8440086f2394260 7b870cbb4655022c0f68f97a737942d2f26b32644f43d7c38b2d8e3e74b6389c a92731e8b8ef0e0e6ac663e2ab01d92b5809a94f46858f4cbcf7dc01aa92aec1 5781e4c355eee177f8789ce242a75dde4b27f1f313e6eb4b1641227ab2767848 e736dde6929e32461fe51db100d4bff0d80ac2d316e7011aa4ac8294bb94a0a9 7b180716a51e2910f2e2595675e087bb173ba962aa61c0835990f186818704c2 a8a4b349fff82b0c8ab42a00c19289e437f0cdebbeb6b6b5c1cf575e53cbfba9  b3466df217762f4fc91bb1df77aea83c957cf0b43bce3651837700d172ad7851 1cbb5e45f98a4b872a9fe533186676ae110bb4dff25e6418589597590467e39a 44bb5b1b51a13614052f25b721cfaaee094b1a23f2048680c28dac2748c77017 d551c086b902c9192089460ab6ffe03daf15b6841119f65a22a8922e4b6d4533 53203388c00aedefb59511c4e482c0f76cb8cb22f01085d9c1d96278c232bd3d b6deef2fb3eeca969e8c4f491dedec38c80965fc7ed0caa108e48fdeedd344f8 df410bebad94ad7c3b72246240c178727a538b13afbcfd207524a34c2c9617f2 02d696911e55bf3a427f7f010d105b4d47710b2c367c94dbc93f9b5dbc340af1 24fbc3719bff6f041002db8857af4f903f82abcb5d29484b68380db178fe0dac e502a2943a7d783954f784e46dde4b90261ae6a726608c90140221b061ec5608 5df7cc5b85f2d85a5b99e98f0d25e5bd20dae24c6eede74067e0845840f4ca5e 452993375423d3d27cb78247052759d5f9fa2af425fbf239f13b4c13b2ba6713  076f8fe539b132fc462ec518ab3740c9e4e21231dce7dcb6237daa4d3de5e9ab   484b465d99d05f755034d15ed5519bf9738fbd794d8fbaf588a29e0823a6d929  9fb3b973248c76d14a814ba558235f520640d26e9f2fafac03fa2432b16e40f9 25a7f364c19adf32a092b97aa4609675237da4b5f47d17516d5068b18e033b4c aee022646c6b78507bd02bd632efc1d46e65c82589c8823190e83e4c006846d6 00897a8ee5c0159709c28c622ad5e4de85d0e596f770ea8c80be97893f85f675 43ba95564730b7265e456120cef81905316d877cc532344993987b38f1b1e008 1c87cd21a1b8e5e4fca27a2fc19868d161f15635514513586adddbdb196cec6c f97d988840ce05868f7e8eb40582354bb44f1d0e1614241d088a8c440f0fc4ba 4d4d92afaa567f36f7b7e159ea245b23873688c662380971b3f38868637fc9bd 6885d148c45a37180b3a8ee40236fc0519b87a467409e5e9167b9f4fe599054e 58d925aab330df06db3418f50d3f57c2f1f5c892f142c3d59cb9db2de1380a8d 3952a2669d9788a52c0f54d54db7954dd74129e9a34953bcf4864248fbfa5107 b8f7994193cc5fcc7a75988740e117b64462ee62a7d40cff17f72e5d39fb2736                                                                                                                                                                                                                                                                                                                                                                                                                         root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec root ossec ossec root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec-hids-2.6-15.el6.art.src.rpm    config(ossec-hids) ossec ossec-hids ossec-hids(x86-32)          @   @   @               @   @   @   
  
  
  
/bin/sh /bin/sh /bin/sh /usr/bin/env /usr/bin/perl /usr/sbin/groupadd /usr/sbin/useradd config(ossec-hids) inotify-tools perl(DBI) perl(Fcntl) perl(strict) rpmlib(CompressedFileNames) rpmlib(FileDigests) rpmlib(PayloadFilesHavePrefix) rpmlib(PayloadIsXz)        2.6-15.el6.art     3.0.4-1 4.6.0-1 4.0-1 5.2-1 4.8.0 [ -r /etc/localtime ] && cp -fpL /etc/localtime /var/ossec/etc glibc            P@OiO@OЗOЗO	O OpZ@NNS@NK@N;@N;@N6@N-ZNMMM@M@M@M?MM>MUM@MPL~L8LΫLΫLʷ@LeL@L{LL@LA@LLLzL~@@L|LvW@LmLa?@LRL4l@LT@KtK͗@KKK@K[K@K8@K@K@K@J@JJJ@JJJn@JL@JI@J2C@J2C@J/@J&eI@Io@I)@I4IܑIII@I@I&@III~@H@H|@HcHM@H2@H)GJ@GAzGV@Gm@Fޚ@F@F@FF@Fr@Fq-FIF-@EWEEySEIE
E 	DDY@D@DLSupport <support@atomicorp.com> - 2.6-15 Support <support@atomicorp.com> - 2.6-14 Support <support@atomicorp.com> - 2.6-13 Support <support@atomicorp.com> - 2.6-12 Support <support@atomicorp.com> - 2.6-11 Support <support@atomicorp.com> - 2.6-10 Support <support@atomicorp.com> - 2.6-9 Support <support@atomicorp.com> - 2.6-8 Support <support@atomicorp.com> - 2.6-7 Support <support@atomicorp.com> - 2.6-6 Support <support@atomicorp.com> - 2.6-5 Support <support@atomicorp.com> - 2.6-4 Support <support@atomicorp.com> - 2.6-3 Support <support@atomicorp.com> - 2.6-2 Support <support@atomicorp.com> - 2.6-1 Support <support@atomicorp.com> - 2.6.0-0.10 Support <support@atomicorp.com> - 2.6.0-0.9 Support <support@atomicorp.com> - 2.6.0-0.8 Support <support@atomicorp.com> - 2.6.0-0.7 Support <support@atomicorp.com> - 2.6.0-0.6 Support <support@atomicorp.com> - 2.6.0-0.5 Support <support@atomicorp.com> - 2.6.0-0.4 Support <support@atomicorp.com> - 2.6.0-0.3 Support <support@atomicorp.com> - 2.6.0-0.1 Support <support@atomicorp.com> - 2.5.1-10 Support <support@atomicorp.com> - 2.5.1-9 Support <support@atomicorp.com> - 2.5.1-8 Support <support@atomicorp.com> - 2.5.1-7 Support <support@atomicorp.com> - 2.5.1-6 Support <support@atomicorp.com> - 2.5.1-5 Support <support@atomicorp.com> - 2.5.1-4 Support <support@atomicorp.com> - 2.5.1-3 Support <support@atomicorp.com> - 2.5.1-2 Support <support@atomicorp.com> - 2.5.1-1 Support <support@atomicorp.com> - 2.5-1 Support <support@atomicorp.com> - 2.5-0.9 Support <support@atomicorp.com> - 2.5-0.8 Support <support@atomicorp.com> - 2.5-0.7 Support <support@atomicorp.com> - 2.5-0.6 Support <support@atomicorp.com> - 2.5-0.1 Support <support@atomicorp.com> - 2.4.1-11.2 Support <support@atomicorp.com> - 2.4.1-11.1 Support <support@atomicorp.com> - 2.4.1-10 Support <support@atomicorp.com> - 2.4.1-9 Support <support@atomicorp.com> - 2.4.1-8 Support <support@atomicorp.com> - 2.4.1-7 Support <support@atomicorp.com> - 2.4.1-6 Support <support@atomicorp.com> - 2.4.1-5 Support <support@atomicorp.com> - 2.4.1-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.2 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta2.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta1.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-11 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-10 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-9 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090225.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090220.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090206.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090205.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.99-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.99-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.6.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.6-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.4-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.4-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.0-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.0 Scott R. Shinn <scott@atomicrocketturtle.com> peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org - Move active response components under the common package - bugfix #xxx, correct ownership permissions on fts dir - Update to init script to suppress spurious execd output
- Add alerts queue to server package with ossec/ossec permissions - Bugfix #XXX, correct any/agentd condition - Moved agentless packages under server - Drop timeid and cat_id indexes from schema - Add new index, timeid to alerts table. - Add cmoraes patch, Adds config options for enabling/disabling rootkit/syscheck options, and agent config profiles
- Add ossec-memleaks patch
- Add agentless directories, and agent.conf
- Bugfix #XXX, ossec-hids.init will now return an exit code on status - Add prelink_cmd support - Bugfix #XXX, display multi-line events in data table correcty - Update to asl-shun.pl purge event to default to 24 hours. - Update to asl-shun.pl to change ordering of block rules
- Revert from 0805 snapshot - Update to 0805 snapshot - Update to 0801 snapshot
- Update asl-shun.pl to log to active-responses.log, blocks now go to the named chain ASL-ACTIVE-RESPONSE, and delete events are more redundant. - Update to OSSEC 2.6 Final - Update to snapshot 110711 - Update to snapshot 110613 - Update to snapshot 110609 - Update to snapshot 110606
- Moved ossecr user creation event to the ossec-hids core package - Update to snapshot 110531 - Update to snapshot 110526 - Update to snapshot 110504 - Bugfix #536, Increase the default sleep time for syscheck - Renamed to 2.6 branch - Add support for the rules/decoders dir system - Update to snapsot 110405
- Update asl-shun to support ossec alert ids - Changed asl-shun sqlite database to /var/ossec/var/blocklist3.sqlite
- asl-shun database format now stores the full alertid - Update to snapshot 101203 - Update to snapshot 101125 - Added alertid support to os_dbd, this involves a schema update - Added dst ip, src prt, and dst prt capture support to os_dbd - Bugfix #XXX, manage_agents was built in client mode for the server package. - Add clamav decoder & ruleset - Update to 2.5.1 final - Update to 2.5 final - Update to 0928 snapshot - Extended no_ar into ossec-dbd - Add no_ar option to disable active response per rule - Update to snapshot 100920 - Update snapshot to 100907 - Snapshot 100901 - Added test fix for os_dbd - Bugfix #376, ossec-control will now properly stop and reload - Update to 0809 snapshot - Relink against native mysql - Add minicon decoder from les fenison - Update to 100707 snapshot
- Feature Request #371, add ossec.log to logrotate - Updated to 100615 snapshot - Updated init and ossec-server scripts to support the new reload feature. - Update to 2.4.1 - Added zabbix reporting active response - Update to 2.4 final
- Lowered courier rule 3910 (failures) from 6 over 240 to 10 over 10
- Lowered courier rule 3911 (success) from 10 over 60 to 30 over 20 - Rebuilt for atomic repo - Update to CVS 100317 - Update to CVS 100311
- Add decoder for denyhosts
- Update asl_rules.xml to include denyhosts rules - Update to CVS 100309 - Added new decoder for smtp_auth
- Added rules to detect smtp_auth brute force attempts
- Added rules to detect imap/pop brute force attempts - Updated ossec-server.conf to be in parity with the ASL config
- Added templates dir for generating configs - Update to 2.3 release - Update to snapshot 091109 - Update to snapshot 091008 - Update to snapshot 090925
- Added timestamp field to the mysql schema
- Bugfix #XXX, for the ossec-client.init script to call the correct (renamed) ossec syscheckd/logcollector daemons
- Appologies for not updating the previous changelogs. Missed a few updates! - Update to snapshot 090827
- Feature Request #225, Added logrotate event to active-response log
- Updated system_audit_rcl.txt to look for the correct php.ini file - Update to 090824, beta 1 release - Update to 090812 snapshot - Rebuild agent daemons with -DCLIENT, added symlink trickery - update to 2.1.1 - update to 090630 snapshot, this has fixes for CentOS/RHEL 4 64-bit environments - update to 2.1 final - update to snapshot 090612 - update to snapshot 090610 - update to snapshot 090603 - Disable postgresql support, to get around an undesirable dependency on EL4 - Update to snapshot 090417 - Update to snapshot 090413 (this adds in inotify support) - Update to snapshot 090410 (this adds in inotify support) - Update to snapshot 090408 - Added authpsa rules back in, this is used to detect brute force attacks
- Added conditional building support for ASL modifications - Update to 2.0 official release - update to snapshot 090225 - update to snapshot 090220 - update to snapshot 090206 - update to snapshot 090205 - update to CVS code 090129, this is not an offical release. Its for testing only - update to CVS code 090126, this is not an offical release. Its for testing only - update to 1.6.1 - update to 1.6 - update to 1.5.1 - added mysql support - Added Stanislaw Polak's excellent ban-hackers script to manage shunning more intelligently. - update to 1.5 - fix on active-response locking bug that prevented some rules from expiring. - update to ossec 1.4 - update snapshot to ossec-hids-071011.tar.gz
- relinked C4, FC4, FC5 against mysql4 - update to snapshot ossec-hids-071006.tar.gz - update to shun blocklist tracking used by ASL
- added authpsa rules + decoder - update to 1.3 - minor adjustment in %post, to check for config file before overwriting it - v6 was first version of the patch.
- added in logging in active-response for better ASL support
- Disabled conf event in %post, to keep from overwriting config files. - changed permissions on queue/syscheck so it can be read by the ossec group (tweak for web gui) - removed the noreplace settings from decoder and the rules
- patch for a more ASL friendly client config - release -2 had a bug. 
- added ASL rules (asl_rules.xml)
- added decoder for the asl style modsecurity logging
- adjusted syslog_rules for qmail-scanner issue (BUG #ASL-18)
- Added http index in asl_rules.xml (BUG #ASL-7) - update to 1.2 - update to 1.1 - configuration change for ASL - updated to 1.0 - import into ART
- changed their naming conventions a bit, 0.9-3 to 0.9.3. Please dont be cross with me. - new version (0.9-3) - new version (0.9-2) - new version (0.9-1a) - new version (0.9-1) - new version (0.9) - some bugfixes - created /bin/sh /bin/sh                                                                                                                                                                                                                                                                                                  	   
                                                                      !   "   #   $   %   &   '   (   )   *   +   ,   -   .   /   0   1   2   3   4   5   6   7   8   9   :   ;   <   =   >   ?   @   A   B   C   D   E   F   G   H   I   J   K   L   M   N   O   P   Q   R   S   T   U   V   W                                                                                                    2.6-15.el6.art  2.6-15.el6.art 2.6-15.el6.art                                                                                                                                     	   	   	   	   	   	   	   	      
   
   
   
   
   
   
   
   
   
   
   
                                                                        ossec-hids ossec-hids-2.6 BUGS CONFIG INSTALL README doc README.config active-response-internal.txt active-response.txt br INSTALL.br README.config TRANSLATION active-response-internal.txt active-response.txt logs.txt manager.txt rootcheck.txt rule_ids.txt rules.txt logs.txt manage_agents.txt manager.txt nmap.txt pl INSTALL.pl README.config TRANSLATION active-response-internal.txt active-response.txt logs.txt manager.txt rootcheck.txt rule_ids.txt rules.txt rootcheck.txt rule_ids.txt rules.txt ossec active-response bin asl-shun.pl disable-account.sh firewall-drop.sh host-deny.sh ossec-tweeter.sh restart-ossec.sh route-null.sh zabbix-alert.sh agentless main.exp register_host.sh ssh.exp ssh_asa-fwsmconfig_diff ssh_foundry_diff ssh_generic_diff ssh_integrity_check_bsd ssh_integrity_check_linux ssh_nopass.exp ssh_pixconfig_diff sshlogin.exp su.exp bin ossec-configure etc shared agent.conf templates active-response.template apache-logs.template ar-disable-account.template ar-firewall-drop.template ar-host-deny.template ar-routenull.template pgsql-logs.template rootcheck.template rules.template snort-logs.template syscheck.template syslog-logs.template logs queue diff ossec var run /etc/logrotate.d/ /usr/share/doc/ /usr/share/doc/ossec-hids-2.6/ /usr/share/doc/ossec-hids-2.6/doc/ /usr/share/doc/ossec-hids-2.6/doc/br/ /usr/share/doc/ossec-hids-2.6/doc/pl/ /var/ /var/ossec/ /var/ossec/active-response/ /var/ossec/active-response/bin/ /var/ossec/agentless/ /var/ossec/bin/ /var/ossec/etc/ /var/ossec/etc/shared/ /var/ossec/etc/templates/ /var/ossec/queue/ /var/ossec/var/ -O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tables drpm xz 2 i686-redhat-linux-gnu                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   ASCII text ISO-8859 text POSIX shell script text executable UTF-8 Unicode text a /usr/bin/env expect script text executable a /usr/bin/perl -w script text executable directory                                                                                                                                                                                                  	   
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              R  R  	R  
R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R        ?       7zXZ  
 !   #,oC"] "k%r{"}AHگ,Wa8n}.UICS4}gJLE9y8UHrуђeEO5B
аɆ杠<bS~&sx=<N2qG=(裥7<HW~kBg33{rkWCmMg1y2asVm\;//)0ZQ殔0z#cwaI2TE~ Q4E:8u/_]n	8AL^5u|<ZfXI	~
Z
t*uҴ/4c~tY糊~n!	0;X{Iw)Cڼbe\2䘋	vIeAyVTHcc,VtBВЎ}UaǵG[oj*Po
jV HW9<ǷH5/2FI*a!`2YwcD!
c2Gß,5~ހ7;k>q89@rüBc_&q_܉zZ^
T/SJeD{Tg.g׎8\^jX#!KߺW]JMe˻/')&Ҝ/unL?tEiDy5[UE5oE96Fm!wpܝGE(n!q*G#KԖWŖ_$?<Nh>˃'X\U]ZйuOu6jׄZo\uZS~օ p} ǿA]HW9,	'+i<Ie?µ\S*2Nd#8DrN)yfm fM`t%_k28}ƏIJ2ȾOí#К.T5h7!SUХ=yNH4WokŞ\Ե2ZLndDyXDg	@7p+E	ԬalF$qSe6R:=4[ש-'']yttFʺFY7a-rzgRe胬tХbn|;G/X{!B$iP!5hՔsnGgo&<e}XgOۄr\Љ?wߋߠr7FaԅZ^R@MmQ`df\@]:HsH۩d܎5j1hYPrHvi|0q=EP2)%ac+K."ekܠflcFMj
hf	~p{93gD6~TiW9a(?0
U?){d|Z8U&0`_bpx&jFe󲪀0CҢ9w|aSsX?Q[#ބ=`M5(-OB*lOQ4va!=aʗU2GVt/vHœk (((|U# /ЬWq(bz>#O!3U5/C%f(u_g3qEtC5/$&y76[7a!})5}4
D	]G`<bKI>uu}7.ҡ$I{b3y-\gϫ}uik  ?-@q$,p\8f8q@Q@>OJݘGgm7o R"pe.'Ȇ2M>s=An1
WO@V{'K(
x(Z6gP37U!"םc&8.7Y$(
!:Ƿr~H$^屢aP}VzP#PAUGQ";Y2XNN1Pn k^\S<Ό|^u;_YʦYqrAznWźaU#5MߋwCqIS!p+YU>\kVDǊջ_+:bJsϚRQ_PtHVJ09-KMe겕ѪHJvX6G^ d\Ewj>`77n G7v偽<$:W^!ǰq~n>_v<'j\ݱzh
OYK<_4iORb(Zҁz7Z-"j/38
1	Msk=yY#Hr^'mփvOi⛵P4ޥj,xeIiw=i[:)pMť5 f6%].wvFʦƳ&Djd$rnrM>U)(݅E
ڊJ-_6u2.uYr>#4{2uNf]]$(G25ܾWFU`܋Y&œ.<7J7Ht NOsAxpU_sNX7gBn2qgG©,B)wܬE·OE5,,T<oP+wO'̠f4Օ<ŖE*ggM|-O܏rMhre1m
zK⨑'vP7z6'qMr |2}xf%,Ƞq
j$X|}0bEd̓^O"U>}$qb`nh۸`"	?u$7l#(np 2wߝhl)PUf7
0AM^xmKR~aIÕ)xce:r0Unդj&o WLua'?:Vj3kH*WuВkK)lx .gQ͜s3*yg<R7K7$IkaƬ

.<.7Yd}l83251"TOrAI1tY]VVW-)'FYm:0͡dPc,ܸ6^H<څ Ás_PdR9W}^'Ѱ{u.jܵtʶ.XqU5}3V_k1Y:JUPƈ{pז5DHO1˴q?i%Kl
y1թi{=pPۃ-w(A#wa|si9c_0~')²T{|pv+T|^<[#-Wy19DcFNltMFb-2g]SIku$.Bo
<e|kko! yXÔ}+--)ע՝1(mV*wJԾMLOvD ANGA$|S7q=KNUCu٦r<1P.l}Oϙ{AX 
yKآMVqvT^F%³גWku1TYu,ċl3}IGTX
Vrsǀh8ӳ
SRtߦkFWaW^,߽|9-5LGɬ"6MT}04>Nypɴ̤ť/Ť^MBD/@k{eG:tx@ ѱP9UQ5>0mI{u[|ecn,Y,[j5U<rC/ᝲq -z^"r^8dj|+8-|f|wX:O(:ZY>[)Cr *c6h43/2ǉ2{u6H!P̈QEv-tgXa2ЉT1{Zo7? 9FH8!Ql#*$:T7Ini
P9P
/%6Y^uĩηi1>-(DsNTBwQ@2 R3wR.@^G'µJm*tY,sXm3&ĨnAn{ub\U_ Ȣ=:< pqp;he?=;a Zf{K7	P:*4B61M?8Q!J$,-,p3hH`)Bg.~S&l˨lb}Hc$Valtİ[ݰ*dWkCIU_L<?ex:j k?@ $M*͗!'ίBW(i[=H-ԣL,|:ƌ_jڨ2ͬc.wb 9,P1)ON	uΜstZV-nS[x?'E}~و&%2ʓ48eWm&EO41pc{U(ӎlflchA"֌,+AqQ;|yJ:`(3"up6I#Kcw"G6JpjBQd>櫃t&>gՌ8ɘ͌dA{XrmZq@iY?:WðrIhM߂:ith8=skGLMƋ{фTALG;XKhc94Z19e8bRtOЋ`1S;|X[Kܾ14/fRӯtsf8ocD	|B-g;{`TMKzTJ 'v_Ga`shPdsC0yF;	`O=DAOd"tPVTCR4:pSe$E8zjMP()?#uϐ.`o[N1y߿tLںa_)CBJEcT>	
W?ߕ_wYNRg,(>3n
Dm2ƯxȷyL5; *E_anXf,J<ǴM'@U0Ű}}|rT6nI {jޕj%fڿ".VLzr=.R+
zoRBUgGs4E-?VH@}>Xz~hfl^x˻@:\>895#z-t|E1dYK~I#g7cx!rao؁8C[E8·fpplkLef̲"c@
D.VBDT#ۇ1k"o^ 7nY;I)#EŢ;
&v\˾Fn.H?ӭhXP4ۉՓ޸P0Ϣ6V_]01b!TDb(_g
v,FNE'8W(3nSfoSZj.TԙZ}%quvxYb	Sj_V۴Pn=.M'n=1]IiƢlKCph0inGf4,vN 4P%JRV>+|롁|R;/ȭd{e[MӈlhCQơ8%,]V̥V{KxMv̱![ru{vG\&L{SR
^
NCl;Ŀ /M|o%iR8ׂ|>	a	e?8۾1o\sz'RVu9̴G~
΃Ϩ6%qUv'(%4Ζ`)<EyDL"0-,/I$EF.AB%(ʰy w#QUP.`82]wcI$;34qků!tX;-oQ}'}Yk(AdNnE9=Z9vQDI![ٖWrַrAɩu0_Jwx~`øuᾷL_ˀo:cWJ!K vDX8G5#$%%@WO=oR=K8"v1TO9a$B;>&=|4C/I@p{FaGK7|t	)vs>sANxF|OxzGώ_ڧ6\Fݳ/w<evw|ٺ5NVY^m4)ݤ_VݝDdhP9Z,{e;7_}Lé^aZ|hcĆ?Nt`8odcCSJT@oh8s]:Y>CKyOD=:Hm|NtiG_]^}hvE7z/WfY1L=ٵY:')[ڼ[rS&\
^O,My6@B ٢~|NJs*j`ELR]""&\F(u-nӫ*_oLuOeA}ATRv!Wz\#ߣ'eC!tU{&	;ݐnXg{S⿧-+_r}4Pos~4&1uWlgYbf,D=VAчrֳ]'T5G©}rp/buQ,61+8jM#gdmLt_LMu_Y :@}K|Cf6wF l`p[.UUXseK'#@.SvB:Qb:ȤfKA`4Gf"ؔWF3OrV;RUrz֢rHކ2(0ber-~̺HXѡQ0ez>!ΩcMh6`M]B9+ym;{h4_E~sOjg@f'N ʺmp\B&<5:Ȑqy9
C塑쒐hD2YPHC-rI!bG<k"YG}toLI 6ys9S1xr68ҩ*cvVS3dպewm;k4MF51%fڃƗ4I<f04P}{42*9BAx5 Bc
l[<񯎽&ǛTO0@1mtd%XbjVwoPk~wWUT]Q:&>PZQ뷩pb,o{G+A
?!]i'gڅ!c^ƗLv8H
d]דu][ц_NrO4Yo̊}Ss6yB)~ߋMMr2Y-6.c{Lsƅ"28=YѵR(2Ұ߿F9$ucp?tN8RI,(d`d?|i70]䰈F՚.GɓSU8C<Ue;dZhۚ  3\{N=[3#pޅ[&1?w0}F
(ͱHAr3IZH)=qbPv5Jle==fG0Y'}?r:9W?
/Vj܀bРRHkmҗ@|.I@͑6:ӪYB7$T0FoayBd@)/jN,7
zؼ!Yʡ|t|܏w:;p"s$],pgPˡtOO/w1'|d\1i ij5J?@l1`PpRf0aB'0p.|Y'|D@^}_U27^e0ONblDR=ÐCmL5sw\g2t~PH?i}Ҵ)gFwskԙ=ΈխzUU4lfIXGěc8Mp19L@̄IƼO!a)mPh/Y9J_O  8n'uMrhXbqo;#>	!aljYc^<hH%ݵ3QXfuǌñC/l?
9$'vu4fe0POWݗǚp5[A*n(;*nMo"q%eұ=nae=!(S.	D?LCz
JXR.C{RBd7,"[>Pux{V>5/2Dsb~|_Eb~"48&m|Kʲup-P4d^J(ǱwDI:-7iޙ6R4}"pp#IݷZ+QeyڻUYtH3r(U~]«zjr&"QjKIL:&D6.pJ~Ҷ  Y佢/&8ET0(ׅ mzq]e E "L    
YZ