    ossec-hids-hybrid-0:3.3.0-7006.el6.art                                                        $   >                                  4mW^W   >                 8  j   ?     j|      d                                                   (        	   ,        	   I                                                                        	  0          K          a          g           l             M          M  	        M  
     D   M       x   M          M       T   M          M          M                    M                                                   8          <          M     (     N     8     T     9     !     :     <     >     ^     G     ^   M  H     _   M  I     `   M  X     aD     Y     aL     \     ax   M  ]     b   M  ^     h9     b     i     d     jX     e     j]     f     j`     l     jb          jx   C ossec-hids-hybrid 3.3.0 7006.el6.art      The OSSEC HIDS hybrid client The ossec-hids-hybrid package contains the agent component of the
OSSEC HIDS for systems running in hierarchical server configurations.    \=scanner.prometheusglobal.com      http://www.ossec.net AGPL https://www.atomicorp.com System Environment/Daemons http://www.ossec.net/ linux i686 if [ ! -f /var/ossec/ossec-agent/etc/localtime ]; then
	cp -fpL /etc/localtime /var/ossec/ossec-agent/etc
fi      	       k  p           d    I  	l  &    x    c  $  +    f    F P        W         *A  n  /    4    'R        D2  t  A  P   R q  l5   yI 3  & '    >  a  !*      '                                     AhhhhhhhhhhhhhhhhhhhAAhAhAhAAAAhCAhA                                                                                                                                                          \=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=q\=q\=q\=g\=r\=r\=r\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g\=g2f34bc2e1a86e1a61595ab123245bf6ccc69e4b93fc0fc2778e97c56f83b2b82  a420190cdc9a1e252cf15145be0e3bd560ee4e6169b3b59e27d6a1adde768387 629db0bcd01893c6f9b8191dc3b156323cd2e41c11c3c8a64c1f31759a32f4ff bfa6537b9c271bb7180d163f9f837f3576dd9f0325effdda715972d0858f0f1c 838c4422e6468fe7fab97f49d1f7b4dfc72975c18b981506845feded0a4f031b b8b77ad5d1cf487a6f707b41058a081f5408b130438b42505896c14db49f03cc ad3a1960d461563223ef0b1b1f97a653104d426513eb24c09d6463eec433f7a9 a6789d184e207e5bf1bab81cf99acb94f31e1e7ebd0e5ad12fbbbce0f6caa055 365aa94a72f38faeedc5a473a6598b19ef28536f7f1db168be7c16eb45c07ea6 e736dde6929e32461fe51db100d4bff0d80ac2d316e7011aa4ac8294bb94a0a9 fb32ed79d97a1a9c6ab12fc86dc6678c5500d2ecd21192d5e5fd13277173a584 dbfc71e6af8b288eb468bacdba8a02569671224e6f65bbf01fb461d40eb9ed40 5029207a9255c4e0df67db772a500694dae75a96cb9f0326916b21fc94c0d317 67308a684121b063b3f2afae6374de1d7ff4a39d8293073ce701e0814890b912 4d63380f28bbd789138ef6396cbf8421a59cd45cf8abb9e3a2ac813d2b11cafb 04a2c084b43acb1f9d91c6f84bdaca5d6816e43f2d5937fcb19a45bc8da6aaec 35a9a511eb0a40adbfb9e5f1a2a7734a923b2e9ebfcd28896e8fa2bf4f2445b5 779a5cec11b6f3d2dcc996ecd09d5f641c82fe0e26dad8b3dbcee76f2c592e27 fa49d3f7210f6d16eceb372353010ca1619886febf528cbc7c3f8d3dbcf931da 8546f15dafe30ce45e3284803bbe01e261c9ce0b763a53418c15a0047d06065f f6ecb3c4400cb1e531e4768429b1b86e06f33b89e495d0549d10e5adbae476b8 e0d30dec6a4271badf289a8fe44d19be4d4bb0f4dfb90ae7aea6930658abb45d 255a26c4e816582e6979b950effa43d850ddcaac8421080b492ab18d0921185c 83cd186d1ab2ce3a7fa1dbcd2d19f1e4a5dadb277f3585c93ebef8cba2e0e130 f5b31a3b37dd23257c002459417316028c845a4c0071b2a219fa744b2ac70d0c 8bf836dbfd89c452ad107d0d8b8f1aa4797dc5fbfb51fdf0d3ac5c49b6345d5d 6768610521bf4f23310a5a283fea842266e7514fc137f8a8796cc22877c1ae2c 82f1f509a898498ddbff327b9702f949979da7e25373f59d452454362ecb587d 820d5d7b42023bed2fc15e07aaae0ab6d0697a8db15db00a517d7a652ea55609 f5dfc5850552db9581d6bb313462199983eeddb4754c0099b26d1dd4cc898519 1ddbd17440eb68334eecd14ffcf062f0fd6082220a781decfd1d46b3105c2226 077b95902dc35fd2e4c4a01ce08250d2b5109577a316f32044970eaa54fca094 7da476d9f782f26360fdf764800c512a016ff028db713dec4226466bb72d5ca8 c1030b917aba0bc42b21ebb829eaa3cafb9081d55f533c676bf8708c0376bbeb 606d523f646921a6cbb0e8bce30d03072c69186025ba48bb288e580f377876d6 79322c236ceba006a93fa98b2eccfd7c7a8e8950d79ee47ede838ffabd85a9d4 7d8bf39b94dee07d419b1be477492af9c96b286703ef28966fa462049cfb66b9 aa416fbbac58650e86b603e8daeb857179a268fe390cab9e3eaefa5df589db5a d11c6bee007203a88fc95b5d8efd363e8ca85b2563aa0848a612206cb2aed6cd fb91113c7718e1b888c1acb828aa3c1762b81c994604fc3bcc9afa791d685a18 fcead21e9169e3eac8382c19ca68203b0fd420e1c8493c4861c6985acc956388 ff7d84b1bc9e99e5fbfd8863212d641482277f2507f77ca64808d42f13f82e1a f834fb3cc9734c2fb8423703374abff2503ca812c53d1e9d1dcc4f3dd7756337 de661cd1fcdfd7aedc77747ec1ebbbb3c0a4c742235d417f4a7c243bdc79fcee cee436359b8c46705cf53999ee1c0d1c170b9b519a1c2143b7ee7cedc8a5ecd1 2d01fd0b9e5b3ac2dcc10f8e28ca38ff124eb533556ddf8e44c7053fc06b59af cfb430514099645b7509dc280890c235d950dcd1a1d8a70699336b4fa2cdb96d 08898b80b1668086047e4e06300e0ebc37c09c3ae29abdaba7fb40df7a7be713 590c23b4d79498c44391c62180558dae05492f57cd335bc943572e63aae70aaa 573e96835fb298a92b2efc5fdade2123083ba31a79b93d1fd6e11d07887a4414 705f5a7821e50ea431a46af7be478fe6e643dd1d4363fa5780667fc36094c23b dc06a958a7aeb301bde892d09eaad121adacc42ab751d4e98101b592d36534ca 47e92f3a901c071be1e7b8cffa1dc5d49ab813f7362383ba302355ab2a37f204 b3f5d0ef8d77b92c79c2aed07946b794f3dc7e75080c04411cb488def839c71e 4171d412b3e27779d853387dbcf5b9daf17adf9dc59012d5b9d75f4bbfd8c7d0 37c5737f18af8a1f99a176e97bad241fb6226ea449863c7e638c3f0e4f8e30b6 28bd6aa363f94d1f3b138b413b1c558eb2f850968ca8d9b22d29b452beaa68cc 06a0d126959af0d58b01a0f6e983d98e3b27a48046e16cb848b0ba137adfb34e 42adab23d378a6805197a8bcb77d91e061ebdfb6bf1ca4018be88070e2afc18c 7c41bef367f249e432edebf6769d34a34ae30cf96bd523f2b7330042a38a4ea1 48e5400dd103802599776a05739494155f10298cb5b321a8d893f529a1838946 067bdbfaa05b45c727a25e20a17409b06ef0e2db5059456a0abcc2e48581b820 b95ca2bec018f3bca0fe2932ac7ef017b89e1694ebe9e0266496b97e3f168dd3 6739a7000c32d0266a97db6b459701918dd884aefbdd7dbc874f7b4bf531ecbe 30cde09311c089e8c7efd2f18aa0f60fd084549ecb38e2fecc6d84835511a7f7                                                                                                                                                                                                                                                                                                                                                                                                            root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root ossec root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root ossec root root root ossec ossec root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root ossec root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root ossec root root ossec ossec ossec ossec ossec ossec ossec ossec ossec-hids-3.3.0-7006.el6.art.src.rpm   ossec-hids-hybrid ossec-hids-hybrid(x86-32)                     
  
  
  @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   @   
ossec-hids /sbin/chkconfig /sbin/chkconfig /sbin/service /sbin/service /bin/sh rpmlib(FileDigests) rpmlib(PayloadFilesHavePrefix) rpmlib(CompressedFileNames) /bin/bash /bin/sh /usr/bin/env libcrypto.so.10 libcrypto.so.10(libcrypto.so.10) libc.so.6 libc.so.6(GLIBC_2.0) libc.so.6(GLIBC_2.1) libc.so.6(GLIBC_2.1.3) libc.so.6(GLIBC_2.2) libc.so.6(GLIBC_2.3) libc.so.6(GLIBC_2.3.4) libc.so.6(GLIBC_2.4) libc.so.6(GLIBC_2.7) libm.so.6 libpcre2-8.so.0 libpthread.so.0 libpthread.so.0(GLIBC_2.0) libpthread.so.0(GLIBC_2.2) libssl.so.10 libssl.so.10(libssl.so.10) libz.so.1 rpmlib(PayloadIsXz) 0:3.3.0-7006.el6.art      4.6.0-1 4.0-1 3.0.4-1                       5.2-1       ossec-hids-agent  4.8.0 \@\R@XXYX@TT@SSS[S@R@R@RʚR@R@RrF@RiRR@Q@QY@Q@@QQ@Q@Qu&@Qu&@QkQg@Q\PDPP@PP@OiO@OЗOЗO	O OpZ@NNS@NK@N;@N;@N6@N-ZNMMM@M@M@M?MM>MUM@MPL~L8LΫLΫLʷ@LeL@L{LL@LA@LLLzL~@@L|LvW@LmLa?@LRL4l@LT@KtK͗@KKK@K[K@K8@K@K@K@J@JJJ@JJJn@JL@JI@J2C@J2C@J/@J&eI@Io@I)@I4IܑIII@I@I&@III~@H@H|@HcHM@H2@H)GJ@GAzGV@Gm@Fޚ@F@F@FF@Fr@Fq-FIF-@EWEEySEIE
E 	DDY@D@DLSupport <support@atomicorp.com> - 3.3.0 Support <support@atomicorp.com> - 3.2.0 Support <support@atomicorp.com> - 2.9.0-50 Support <support@atomicorp.com> - 2.9.0-49 Support <support@atomicorp.com> - 2.9.0-48 Support <support@atomicorp.com> - 2.8.1-47 Support <support@atomicorp.com> - 2.8.0-46 Support <support@atomicorp.com> - 2.8.0-45.1 Support <support@atomicorp.com> - 2.8.0-45 Support <support@atomicorp.com> - 2.7.1-44 Support <support@atomicorp.com> - 2.7.1-43 Support <support@atomicorp.com> - 2.7.1-42 Support <support@atomicorp.com> - 2.7.1-41 Support <support@atomicorp.com> - 2.7.1-40 Support <support@atomicorp.com> - 2.7.1-36 Support <support@atomicorp.com> - 2.7.1-35 Support <support@atomicorp.com> - 2.7-34 Support <support@atomicorp.com> - 2.7-33 Support <support@atomicorp.com> - 2.7-32 Support <support@atomicorp.com> - 2.7-31 Support <support@atomicorp.com> - 2.7-30 Support <support@atomicorp.com> - 2.7-29 Support <support@atomicorp.com> - 2.7-28 Support <support@atomicorp.com> - 2.7-27 Support <support@atomicorp.com> - 2.7-26 Support <support@atomicorp.com> - 2.7-25 Support <support@atomicorp.com> - 2.7-24 Support <support@atomicorp.com> - 2.7-23 Support <support@atomicorp.com> - 2.7-22 Support <support@atomicorp.com> - 2.7-21 Support <support@atomicorp.com> - 2.7-20 Support <support@atomicorp.com> - 2.7-19 Support <support@atomicorp.com> - 2.7-17 Support <support@atomicorp.com> - 2.6-16 Support <support@atomicorp.com> - 2.6-15 Support <support@atomicorp.com> - 2.6-14 Support <support@atomicorp.com> - 2.6-13 Support <support@atomicorp.com> - 2.6-12 Support <support@atomicorp.com> - 2.6-11 Support <support@atomicorp.com> - 2.6-10 Support <support@atomicorp.com> - 2.6-9 Support <support@atomicorp.com> - 2.6-8 Support <support@atomicorp.com> - 2.6-7 Support <support@atomicorp.com> - 2.6-6 Support <support@atomicorp.com> - 2.6-5 Support <support@atomicorp.com> - 2.6-4 Support <support@atomicorp.com> - 2.6-3 Support <support@atomicorp.com> - 2.6-2 Support <support@atomicorp.com> - 2.6-1 Support <support@atomicorp.com> - 2.6.0-0.10 Support <support@atomicorp.com> - 2.6.0-0.9 Support <support@atomicorp.com> - 2.6.0-0.8 Support <support@atomicorp.com> - 2.6.0-0.7 Support <support@atomicorp.com> - 2.6.0-0.6 Support <support@atomicorp.com> - 2.6.0-0.5 Support <support@atomicorp.com> - 2.6.0-0.4 Support <support@atomicorp.com> - 2.6.0-0.3 Support <support@atomicorp.com> - 2.6.0-0.1 Support <support@atomicorp.com> - 2.5.1-10 Support <support@atomicorp.com> - 2.5.1-9 Support <support@atomicorp.com> - 2.5.1-8 Support <support@atomicorp.com> - 2.5.1-7 Support <support@atomicorp.com> - 2.5.1-6 Support <support@atomicorp.com> - 2.5.1-5 Support <support@atomicorp.com> - 2.5.1-4 Support <support@atomicorp.com> - 2.5.1-3 Support <support@atomicorp.com> - 2.5.1-2 Support <support@atomicorp.com> - 2.5.1-1 Support <support@atomicorp.com> - 2.5-1 Support <support@atomicorp.com> - 2.5-0.9 Support <support@atomicorp.com> - 2.5-0.8 Support <support@atomicorp.com> - 2.5-0.7 Support <support@atomicorp.com> - 2.5-0.6 Support <support@atomicorp.com> - 2.5-0.1 Support <support@atomicorp.com> - 2.4.1-11.2 Support <support@atomicorp.com> - 2.4.1-11.1 Support <support@atomicorp.com> - 2.4.1-10 Support <support@atomicorp.com> - 2.4.1-9 Support <support@atomicorp.com> - 2.4.1-8 Support <support@atomicorp.com> - 2.4.1-7 Support <support@atomicorp.com> - 2.4.1-6 Support <support@atomicorp.com> - 2.4.1-5 Support <support@atomicorp.com> - 2.4.1-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.2 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta2.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta1.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-11 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-10 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-9 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090225.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090220.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090206.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0.0-0.090205.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.99-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.99-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.6.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.6-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.5-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.4-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.4-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.3-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.2-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.0-2 Scott R. Shinn <scott@atomicrocketturtle.com> - 1.0 Scott R. Shinn <scott@atomicrocketturtle.com> peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org peter.pramberger@member.fsf.org - Update to 3.3.0 - Update to 3.2.0 - Change labels in alert mail headers to "ASL" - Update to Ossec 2.9.0 Final - Update to Ossec 2.9.0 - Update to 2.8.1. This is identical to 2.8.0-46, the only change is the hosts.deny CVE-2014-5284 is merged in. - Revert BR#1596
- Add Bugfix for hosts.deny race condition (CVE-2014-5284) - BR #1596, Add fork limiting patch (max 10) for execd to prevent DoS conditions - Upgrade to 2.8.0 - Feature Request #1512,  speed up shuns in execd, move sqlite down - Relink against native mysql - Add ar-tracking active response - Placeholder for null exclusion rules.  Legacy support - ASL 4 version with new database format - Add support for Fedora 20
- Modify optimization flags for FORTIFY - Update to 2.7.1
- Add independent rules.d/decoders.d ossec-rules package - FR#772, add rule 3360 for postfix slow brute force
-   add dovecot-decoder.patch for cpanel dovecot
-   Update 9702, 9753 for dovecot brute force
- FR#773, add rule 11308 for pure-ftp slow brute force
- FR#1347, Update for courier v4 decoder (pop3s)
- FR#1359, Update horde decoder for v5 - Disable ossec-dbd signature table (replaced by aslw_rules). This was very slow - Break ossec-dbd into separate package
- FR#1321, update courier-imap decoder for version 4.0 - Bugfix #XXX, prevent truncating last character on ossec-dbd database inserts on the alerts/data table - Add tld column to alert table w/ index - Deprecate internal id generation in dbd
- update schema to autoincrement, increase id space to int - Add is_hidden to mysql schema - Add if exists to mysql schema - Add os_dbd-mysql-replace-query.patch to consolidate SELECT/UPDATE into REPLACE sql - Consolidate alert & data into a common table
- Add ossec-authd init script - Add sqldelete command  to execd
- Update to clear sqlite db at startup - More minor updates to GeoIP tracking - Minor update to GeoIP tracking - Bugfix on permissions for files in shared/ directory for client installs
- Add GeoIP support
- Remove dependency on perl-DBD-SQLite
- Update asl-shun to new non-perl based version.
- Deprecate firewall-drop-update.patch
- Add sqlite support to execd (/var/ossec/var/execd.sqlite) - Update to 2.7 final - Feature Request #XXX, revert duplicate detection in log events to help detect extremely fast brute force attacks
- Add FORTIFY_SOURCE, PIE, and relro (full) - Update to 2.7-rc2 - Update to 2.7-rc1 - Move active response components under the common package - bugfix #xxx, correct ownership permissions on fts dir - Update to init script to suppress spurious execd output
- Add alerts queue to server package with ossec/ossec permissions - Bugfix #XXX, correct any/agentd condition - Moved agentless packages under server - Drop timeid and cat_id indexes from schema - Add new index, timeid to alerts table. - Add cmoraes patch, Adds config options for enabling/disabling rootkit/syscheck options, and agent config profiles
- Add ossec-memleaks patch
- Add agentless directories, and agent.conf
- Bugfix #XXX, ossec-hids.init will now return an exit code on status - Add prelink_cmd support - Bugfix #XXX, display multi-line events in data table correcty - Update to asl-shun.pl purge event to default to 24 hours. - Update to asl-shun.pl to change ordering of block rules
- Revert from 0805 snapshot - Update to 0805 snapshot - Update to 0801 snapshot
- Update asl-shun.pl to log to active-responses.log, blocks now go to the named chain ASL-ACTIVE-RESPONSE, and delete events are more redundant. - Update to OSSEC 2.6 Final - Update to snapshot 110711 - Update to snapshot 110613 - Update to snapshot 110609 - Update to snapshot 110606
- Moved ossecr user creation event to the ossec-hids core package - Update to snapshot 110531 - Update to snapshot 110526 - Update to snapshot 110504 - Bugfix #536, Increase the default sleep time for syscheck - Renamed to 2.6 branch - Add support for the rules/decoders dir system - Update to snapsot 110405
- Update asl-shun to support ossec alert ids - Changed asl-shun sqlite database to /var/ossec/var/blocklist3.sqlite
- asl-shun database format now stores the full alertid - Update to snapshot 101203 - Update to snapshot 101125 - Added alertid support to os_dbd, this involves a schema update - Added dst ip, src prt, and dst prt capture support to os_dbd - Bugfix #XXX, manage_agents was built in client mode for the server package. - Add clamav decoder & ruleset - Update to 2.5.1 final - Update to 2.5 final - Update to 0928 snapshot - Extended no_ar into ossec-dbd - Add no_ar option to disable active response per rule - Update to snapshot 100920 - Update snapshot to 100907 - Snapshot 100901 - Added test fix for os_dbd - Bugfix #376, ossec-control will now properly stop and reload - Update to 0809 snapshot - Relink against native mysql - Add minicon decoder from les fenison - Update to 100707 snapshot
- Feature Request #371, add ossec.log to logrotate - Updated to 100615 snapshot - Updated init and ossec-server scripts to support the new reload feature. - Update to 2.4.1 - Added zabbix reporting active response - Update to 2.4 final
- Lowered courier rule 3910 (failures) from 6 over 240 to 10 over 10
- Lowered courier rule 3911 (success) from 10 over 60 to 30 over 20 - Rebuilt for atomic repo - Update to CVS 100317 - Update to CVS 100311
- Add decoder for denyhosts
- Update asl_rules.xml to include denyhosts rules - Update to CVS 100309 - Added new decoder for smtp_auth
- Added rules to detect smtp_auth brute force attempts
- Added rules to detect imap/pop brute force attempts - Updated ossec-server.conf to be in parity with the ASL config
- Added templates dir for generating configs - Update to 2.3 release - Update to snapshot 091109 - Update to snapshot 091008 - Update to snapshot 090925
- Added timestamp field to the mysql schema
- Bugfix #XXX, for the ossec-client.init script to call the correct (renamed) ossec syscheckd/logcollector daemons
- Appologies for not updating the previous changelogs. Missed a few updates! - Update to snapshot 090827
- Feature Request #225, Added logrotate event to active-response log
- Updated system_audit_rcl.txt to look for the correct php.ini file - Update to 090824, beta 1 release - Update to 090812 snapshot - Rebuild agent daemons with -DCLIENT, added symlink trickery - update to 2.1.1 - update to 090630 snapshot, this has fixes for CentOS/RHEL 4 64-bit environments - update to 2.1 final - update to snapshot 090612 - update to snapshot 090610 - update to snapshot 090603 - Disable postgresql support, to get around an undesirable dependency on EL4 - Update to snapshot 090417 - Update to snapshot 090413 (this adds in inotify support) - Update to snapshot 090410 (this adds in inotify support) - Update to snapshot 090408 - Added authpsa rules back in, this is used to detect brute force attacks
- Added conditional building support for ASL modifications - Update to 2.0 official release - update to snapshot 090225 - update to snapshot 090220 - update to snapshot 090206 - update to snapshot 090205 - update to CVS code 090129, this is not an offical release. Its for testing only - update to CVS code 090126, this is not an offical release. Its for testing only - update to 1.6.1 - update to 1.6 - update to 1.5.1 - added mysql support - Added Stanislaw Polak's excellent ban-hackers script to manage shunning more intelligently. - update to 1.5 - fix on active-response locking bug that prevented some rules from expiring. - update to ossec 1.4 - update snapshot to ossec-hids-071011.tar.gz
- relinked C4, FC4, FC5 against mysql4 - update to snapshot ossec-hids-071006.tar.gz - update to shun blocklist tracking used by ASL
- added authpsa rules + decoder - update to 1.3 - minor adjustment in post, to check for config file before overwriting it - v6 was first version of the patch.
- added in logging in active-response for better ASL support
- Disabled conf event in post, to keep from overwriting config files. - changed permissions on queue/syscheck so it can be read by the ossec group (tweak for web gui) - removed the noreplace settings from decoder and the rules
- patch for a more ASL friendly client config - release -2 had a bug. 
- added ASL rules (asl_rules.xml)
- added decoder for the asl style modsecurity logging
- adjusted syslog_rules for qmail-scanner issue (BUG #ASL-18)
- Added http index in asl_rules.xml (BUG #ASL-7) - update to 1.2 - update to 1.1 - configuration change for ASL - updated to 1.0 - import into ART
- changed their naming conventions a bit, 0.9-3 to 0.9.3. Please dont be cross with me. - new version (0.9-3) - new version (0.9-2) - new version (0.9-1a) - new version (0.9-1) - new version (0.9) - some bugfixes - created /bin/sh                                                                                                                                                                                                                                                                    	   
                                                                      !   "   #   $   %   &   '   (   )   *   +   ,   -   .   /   0   1   2   3   4   5   6   7   8   9   :   ;   <   =   >   ?   @   A   B   C   D   E   F   G   H   I   J   K   L   M                                                                                      0:3.3.0-7006.el6.art 0:3.3.0-7006.el6.art                                                                                                                                                                                                                      	   	   	   	   	   
      ossec-hids-hybrid bin disable-account.sh firewall-drop.sh firewalld-drop.sh host-deny.sh ip-customblock.sh ossec-pagerduty.sh ossec-slack.sh ossec-tweeter.sh restart-ossec.sh route-null.sh main.exp register_host.sh ssh.exp ssh_asa-fwsmconfig_diff ssh_foundry_diff ssh_generic_diff ssh_integrity_check_bsd ssh_integrity_check_linux ssh_nopass.exp ssh_pixconfig_diff sshlogin.exp su.exp agent-auth manage_agent ossec-agentd ossec-control ossec-execd ossec-logcollector ossec-syscheckd internal_options.conf ossec.conf acsc_office2016_rcl.txt agent.conf cis_apache2224_rcl.txt cis_debian_linux_rcl.txt cis_debianlinux7-8_L1_rcl.txt cis_debianlinux7-8_L2_rcl.txt cis_mysql5-6_community_rcl.txt cis_mysql5-6_enterprise_rcl.txt cis_rhel5_linux_rcl.txt cis_rhel6_linux_rcl.txt cis_rhel7_linux_rcl.txt cis_rhel_linux_rcl.txt cis_sles11_linux_rcl.txt cis_sles12_linux_rcl.txt cis_solaris11_rcl.txt cis_win10_enterprise_L1_rcl.txt cis_win10_enterprise_L2_rcl.txt cis_win2012r2_domainL1_rcl.txt cis_win2012r2_domainL2_rcl.txt cis_win2012r2_memberL1_rcl.txt cis_win2012r2_memberL2_rcl.txt cis_win2016_domainL1_rcl.txt cis_win2016_domainL2_rcl.txt cis_win2016_memberL1_rcl.txt cis_win2016_memberL2_rcl.txt rootkit_files.txt rootkit_trojans.txt system_audit_pw.txt system_audit_rcl.txt system_audit_ssh.txt win_applications_rcl.txt win_audit_rcl.txt win_malware_rcl.txt logs compiled native alerts diff ossec rids syscheck tmp var run /etc/rc.d/init.d/ /var/ossec/ossec-agent/active-response/ /var/ossec/ossec-agent/active-response/bin/ /var/ossec/ossec-agent/agentless/ /var/ossec/ossec-agent/bin/ /var/ossec/ossec-agent/etc/ /var/ossec/ossec-agent/etc/shared/ /var/ossec/ossec-agent/ /var/ossec/ossec-agent/lua/ /var/ossec/ossec-agent/queue/ /var/ossec/ossec-agent/ /var/ossec/ossec-agent/ /var/ossec/ossec-agent/var/ -O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tables drpm xz 2 i686-redhat-linux-gnu       ?      7zXZ  
 !   #,?] "k%{lyMieh2&Bү
Xa׈L73:j+?ؕu?NPcbaQa0=k	w"ybn|1ȥ/Y#Ԣө(Ŏ꒨2( O[Zw#+]%{TMoYG.;xoki{ SvydoAí=lMhU\7VO*y cq0OʼPl<M,<Z4qڐܟ܉XE%\&g4\0Gc*$$qҮ\'~u}X<@	^\m̄ so\55bL[M٤S'K4>B}/1q%PAY`-Z]^s3@TKC]pNcC)m*
ҤKtԞ@d$:G0'oWL]S!ch][;BeTS2Rsc䞀txӢY+\ 0s}9esIDFω	[jL$1Ӏd9hmN|'y$
Dlïxp՚+:j;gMA u[%jAmk7QM(E<
$k檭_,ܸߙGho#P}woJpo"u'7WFA)~ǎ&ӛ^̷4:4Nk5  :}bgi
4 nփ0U0sTQ9MC|`M>wHZ%"e<c$\
-'>|D/v8`o\zE{q`=XƬP_L|*aaZX[{I5*˃$VI}4(w1%@TvV[ =A*	U$;^|{GKy-"T4_/YQL]&Yx( 9m8}9f ii,
3%FOc6m5Sˁ=@1x2+r	zNR$%+<WC]E	H\]̫=)f5>_ttd@ȪB'g亵lFYG0cKSTB=BpaH F)G[sk3Řᦾ\d1L)]_
x>%=[9Q^XNcw\?^x\
6[+¹WZ>9*{A@XfaH,ǚQp5qٻ6a	T?7\`H $yP1k7Ybu$	yVܳ.K99y1siOd,2f^_0T;v[3aq	$1ē,	qvZQakH3FlU{Bm-!6~7;ԇ	sj[Вpv?goYK!PH fRDȫ2%Zuwz/gDG46Hzdi/Xį3^me1+4I_rʋ~gXDUEmg={5L9ADKeiG*q2nZF!g#8dLe78#"]j]"?Ƅfj"~>m|mT[ Lð1{QGsXUcbg&xϽ38U0/$E<rzUX$FPAUTHH5J3ml7}:=:Zɻ4:rԦPtgBEvm7AdJJ޷P +r	"l\6fVGrMn6]+~d.C8<0ߴ<¯Vx1_Eq9U8ceŮlj`<Sm#ݝ%GI 4^4;Ĵmc/@H&9D%m?T̀EʵF1D(<SCdg.PzMVZч,Ftnyvr\A өin4
΀.g_JˆրdXpYGr"t v!]7+|^]@	<)Tﰳ.ڈT
^?9'+ҴG/W︲&	k,grc+R)_$HgD0߭NߧHs3;FM%hw3cxuɐVm_]'+~9@%AxUn_+n>V@y]ٳ)5h*U ڗeZb6Ӌ#GGgՊS<ܰhBS{@zRIsX`!x&=zs Wޜ|pZa4cm+/fi9D%k+?$N`hgeG,\&ȾnRTRbwDQA*sDqv݆O(ăN
lؑ^u1m;TF
)kM+.sP]tr735!vikjyhg}<^H=d=u\)TSe͙moE4Mod,F_=s=A3N!g$22+xl.:Zu(JqT$^_,n´!޾!p1+mX>ao_(:|~#Ąv}W8h{2IxJSOZL'\Ak`%p@cݿ!vnrN2um:5v?Ґ-B0|	輗?K-ijj;5􎥗|c|l:)t|nw>LR_]JȣJMD"D4_2Tu4'>E>Sv5|@9}UēCK[yc=H-ז0.MKI0TvA-$\/DUyrSJ1B] _7ҟOUQhE[]0@Z}HG`R;5sovכܨe҉Kx>uca0~89w'@@mZƧ=Xo
+ 0ݻ;Z9t8Ik;CuIYٖ!57שrW.QaiT+Ǿ,@  1Kt9-&Uq%S[墧S6`1DU%LŞ"ײ0>ŬPU׬	\c 'Y}K?l[Y	sGDǒQIv9u3# pu	XeRBjZ*i12FFBj-cWT[θȖ%RpJzRzz)OG{nT_٧LP~4_FEl(-'ԮMVrPPfN_s^V.zA,!$H۵#T&TEqgw?vO7._FcO\\TNTOzJ\/;Ki;s{蹝f-e 4 P&S6V]CPx$3""a.[Y i)+kMlW.ޯk;nݏm{ f=˷jਔnɶmNMh
J4>qZɪO.4sR1ihqH=?Ct'4T@0JB `.!jC,;υts0ITaܫ;Kv]8.Kʴa
ǼEeDYD.֍׻v`)Z =ѵ
))ZҬh<1~GWvvrRFDI)`";{Ud:7d]	8FwܖV`般!i2&`c/?+#o7R!M3rŶC%	-Z?:<`mK%JV=!w*tL# S~sMX`z>X_[,-u0+.q\봠bsQ@)L~N<H=gS!?8{ZK2WBB j;}NWwJe!f3Cu#*<=HfM0Y'	J[/;3v+SsȥJZ&qIZ%DsQ2BM2BCVv<HB5PT ta%ߡ`'9xN)mC@Oʰaa-[#j0KY[KMZl@Hө2J<'&FKh7.,}=vز0݅SeoFɦCՕ-[S9k! {LD:C"|shKD/6DE	~aR]iUo䘅}hRaL_O1,Su=?W8CB?fļ6v 2A}R@ ءZǭ5JuȘayRG7^G(,1d>z N@y6"5n(V9n0qD1E;Eb;]li5w_cw6Ę+QĄqzsA!HJ̺L E#IBnO?z&M; t^|?SqL\nyۜ=I	 <k=]!GlSKW YL3}# Y39z;k\1rv "AZJ8+KsS
RHi>r2n8X e(v !fN_;P      2Z'U] M )  ?Ol    
YZ