Skip to content

Instantly share code, notes, and snippets.

@ddpbsd
ddpbsd / alpine_buildlog.txt
Created July 8, 2019 14:08
alpine ossec build log
cc -I./external/compat -g -DMAX_AGENTS=2048 -DOSSECHIDS -DDEFAULTDIR=\"/var/ossec\" -DUSER=\"ossec\" -DREMUSER=\"ossecr\" -DGROUPGLOBAL=\"ossec\" -DMAILUSER=\"ossecm\" -DLinux -DINOTIFY_ENABLED -DZLIB_SYSTEM -DLIBOPENSSL_ENABLED -DCLIENT -Wall -Wextra -I./ -I./headers/ -c external/cJSON/cJSON.c -o external/cJSON/cJSON.o
ar -crs libcJSON.a external/cJSON/cJSON.o
ranlib libcJSON.a
cc -I./external/compat -g -DMAX_AGENTS=2048 -DOSSECHIDS -DDEFAULTDIR=\"/var/ossec\" -DUSER=\"ossec\" -DREMUSER=\"ossecr\" -DGROUPGLOBAL=\"ossec\" -DMAILUSER=\"ossecm\" -DLinux -DINOTIFY_ENABLED -DZLIB_SYSTEM -DLIBOPENSSL_ENABLED -DCLIENT -Wall -Wextra -I./ -I./headers/ -I./client-agent -DARGV0=\"ossec-agentd\" -c client-agent/notify.c -o client-agent/notify.o
client-agent/notify.c: In function 'run_notify':
client-agent/notify.c:124:58: warning: '%s' directive output may be truncated writing up to 1023 bytes into a region of size between 984 and 1016 [-Wformat-truncation=]
snprintf(tmp_msg, OS_SIZE_1024, "#!-%s / %s\n%s\n%s"
Verifying that +ddpbsd is my blockchain ID. https://onename.com/ddpbsd
@ddpbsd
ddpbsd / local_decoder.xml
Created March 16, 2016 11:41
nginx syslog decoder
<decoder name="nginx-syslog">
<program_name>^nginx</program_name>
<type>web-log</type>
</decoder>
<decoder name="nginx-syslog-2">
<parent>nginx-syslog</parent>
<regex>^(\S+) (\S+) - [\d\d/\S\S\S/\d\d\d\d:\d\d:\d\d:\d\d \S\d\d\d\d] "(\S+) (\S+) HTTP\S+" (\d\d\d) </regex>
<order>extra_data, srcip, action, url, status</order>
</decoder>

Keybase proof

I hereby claim:

  • I am ddpbsd on github.
  • I am ddpbsd (https://keybase.io/ddpbsd) on keybase.
  • I have a public key whose fingerprint is E16E E8BB AADA 6E8C 4F08 6260 DF02 7B6C 80E6 A369

To claim this, I am signing this object: