Section: .. / UNIX / audit /
| /// File Name: |
aexpl-1.0.tar.gz |
Description:
|
AntiExploit is a small Perl script that scans for well known exploit files. It currently recognizes over 1400 suspicious files, and the database is updated weekly. Useful for a system that has a lot of shell accounts being used.
| | Author: | Enrico Kern | | Homepage: | http://www.h07.org | | File Size: | 134985 | | Last Modified: | May 1 13:00:58 2004 |
| MD5 Checksum: | 233a203d625b8756342c708530248d4e |
|
| /// File Name: |
aexpl-1.2.tar.gz |
Description:
|
AntiExploit is a small Perl script that scans for well known exploit files. It currently recognizes over 1400 suspicious files, and the database is updated weekly. Useful for a system that has a lot of shell accounts being used.
| | Author: | Enrico Kern | | Homepage: | http://www.h07.org | | Changes: | Added a grsecurity exec log analyzer, last Perl release 1.3 will use dazuko and do realtime checks. | | File Size: | 166782 | | Last Modified: | May 25 19:17:40 2004 |
| MD5 Checksum: | 68c15fb75e8a9a2f183d5b09fae444d6 |
|
| /// File Name: |
AntiExploit-1.3b2-hotfix.tar.gz |
Description:
|
AntiExploit is an exploit scanner to detect local intruders. It scans for over 3900 suspicious files, has daily database updates, and will act if a file is accessed. It uses the dazuko kernel module, which is also used by clamAV, Amavis, and other virus scanners.
| | Author: | Enrico Kern | | Homepage: | http://www.hzeroseven.org/projects/aexpl/ | | Changes: | Skipping zero length files, Log shows real exploit count without dups, Fixed double kill of the main thread. | | File Size: | 256133 | | Last Modified: | Sep 9 01:28:41 2004 |
| MD5 Checksum: | abb91ef52cec0a634fe4c1f4ce0e8d95 |
|
| /// File Name: |
AntiExploit-1.3b2.tar.gz |
Description:
|
AntiExploit is an exploit scanner to detect local intruders. It scans for over 3900 suspicious files, has daily database updates, and will act if a file is accessed. It uses the dazuko kernel module, which is also used by clamAV, Amavis, and other virus scanners.
| | Author: | Enrico Kern | | Homepage: | http://www.hzeroseven.org/projects/aexpl/ | | File Size: | 255606 | | Last Modified: | Aug 24 04:03:34 2004 |
| MD5 Checksum: | 065703dd544a43a820597f5e83313916 |
|
| /// File Name: |
AntiExploit-1.3b3.tar.gz |
Description:
|
AntiExploit is an exploit scanner to detect local intruders. It scans for over 3900 suspicious files, has daily database updates, and will act if a file is accessed. It uses the dazuko kernel module, which is also used by clamAV, Amavis, and other virus scanners.
| | Author: | Enrico Kern | | Homepage: | http://www.hzeroseven.org/projects/aexpl/ | | Changes: | Added proxy support, SSL support to the update function, and various other enhancements. | | File Size: | 268841 | | Last Modified: | Sep 17 02:10:12 2004 |
| MD5 Checksum: | 7f9b4827fbcb8d7c98816888e3b9da8c |
|
| /// File Name: |
AntiExploit-1.3b5.tar.gz |
Description:
|
AntiExploit is an exploit scanner to detect local intruders. It scans for over 3900 suspicious files, has daily database updates, and will act if a file is accessed. It uses the dazuko kernel module, which is also used by clamAV, Amavis, and other virus scanners.
| | Author: | Enrico Kern | | Homepage: | http://www.hzeroseven.org/projects/aexpl/ | | Changes: | Various bug fixes and feature improvements. | | File Size: | 274728 | | Last Modified: | Oct 13 03:21:43 2004 |
| MD5 Checksum: | 8710cf7990fd876bce108402cb735e0a |
|
| /// File Name: |
AntiExploit-1.3b6.tar.gz |
Description:
|
AntiExploit is an exploit scanner to detect local intruders. It scans for over 3900 suspicious files, has daily database updates, and will act if a file is accessed. It uses the dazuko kernel module, which is also used by clamAV, Amavis, and other virus scanners.
| | Author: | Enrico Kern | | Homepage: | http://www.hzeroseven.org/projects/aexpl/ | | Changes: | Various bug fixes and feature improvements. | | File Size: | 265732 | | Last Modified: | Aug 24 03:32:26 2005 |
| MD5 Checksum: | 514fb2703a69df699ff342fc469c8c8f |
|
| /// File Name: |
argus-1.7.beta.1e.tar.gz |
Description:
|
Argus v1.7.beta.1e - Argus is a generic IP network transaction auditing tool; it enables a site to generate comprehensive network transaction audit logs, allowing user to perform extensive analysis of network traffic.
| | Author: | Carnegie Mellon University's Software Engineering Institute | | File Size: | 249085 | | Last Modified: | Aug 16 20:04:47 1999 |
| MD5 Checksum: | e39be3326791ded525cc33bb0314e95b |
|
| /// File Name: |
asax.tgz |
Description:
|
The Advanced Security audit trail Analyzer on uniX.
| | File Size: | 732779 | | Last Modified: | Aug 16 20:04:42 1999 |
| MD5 Checksum: | 89258443ee9f3924ef06c67d88b1c595 |
|
| /// File Name: |
audit-0.2.tar.gz |
Description:
|
audit v0.2 - The audit program recursively searches through directories looking for files that may not be needed by checking permissions, names, sizes, types, ownership, links, and timestamps. 12k.
| | Author: | Jeff Tranter | | File Size: | 11779 | | Last Modified: | Aug 16 20:04:49 1999 |
| MD5 Checksum: | aa0a2b706857531334fa3b9aad3c2857 |
|
| /// File Name: |
auditd-1.11.tar.gz |
Description:
|
auditd v1.11 for linux - Auditd is part of the linux kernel auditing toolkit. It will capture auditing trails created by the kernel auditing facility from /proc/audit, filter them, and save them in specific log files. Make sure you get the PGP signature and HERT PGP key from the HERT web site.
| | Author: | HERT | | File Size: | 15949 | | Last Modified: | Aug 16 20:04:48 1999 |
| MD5 Checksum: | 9ab900b5dfdab7c608285d632b26a810 |
|
| /// File Name: |
auditd-1.20.tar.gz |
Description:
|
auditd is part of the Linux Kernel Auditing Facility (KAD). It will capture auditing trails created by the kernel auditing facility from /proc/audit, filter them, and save them in specific log files. Either a kernel patch or loadable module must be installed for the daemon to be useful, both of which are included.
| | Homepage: | http://www.hert.org | | Changes: | This release includes a kernel module (modkaf) which replaces the previously used patches. Also included is a library (libaudit) which enables you to write applications which emit debugging trails under certain trust-related conditions, and can also be used as a ld.preload object to hook syslog calls. | | File Size: | 39423 | | Last Modified: | Jan 8 16:15:08 2001 |
| MD5 Checksum: | 5cf24931b5d522eb2e3a5825d6d7a993 |
|
| /// File Name: |
bindinfo.c |
Description:
|
Bindinfo v1.01: allows root to make DNS queries behind firewalls. Works on Solaris, OpenBSD.
| | Author: | Joshua James Drake | | File Size: | 10890 | | Last Modified: | Sep 29 16:06:53 1999 |
| MD5 Checksum: | 063e41e6f5018c2d3112340138f20628 |
|
| /// File Name: |
bsign_0.1.7.tar.gz |
Description:
|
bsign v0.1.7 - bsign embeds hash and/or digital signature in ELF files, helping to confirm data integrity. This is a preliminary release.
| | Author: | Oscar Levi | | File Size: | 53565 | | Last Modified: | Aug 16 20:04:48 1999 |
| MD5 Checksum: | 89f71906fa2c413a35e855871d17e181 |
|
| /// File Name: |
bsqlbf.pl.txt |
Description:
|
Proof of concept tool to be used for blind SQL injection attacks.
| | Author: | Alejandro Ramos | | Homepage: | http://www.unsec.net | | File Size: | 12164 | | Last Modified: | Feb 13 23:37:46 2006 |
| MD5 Checksum: | b35af1cf6570aa23440513c412e1577b |
|
| /// File Name: |
bsyrin1.zip |
Description:
|
Buffer Syringe is a tool for checking servers/daemons (e.g. ftp) for buffer overflow(s) on given parameter(s) (a stress tool if you may). It has a flexible configuration file where you input the parameters needed to run the program and it logs sessions to textfile for easy viewing and printing.
| | Author: | Digital Monkey | | File Size: | 24821 | | Last Modified: | Apr 17 17:48:54 2000 |
| MD5 Checksum: | 7c18e001b401c47b2eb6f113cc730c42 |
|
| /// File Name: |
bug-exploit.tar.bz2 |
Description:
|
bug-exploit is a utility designed to go through a list of setuid and setgid files and will assist a coder in figuring out whether or not a buffer overflow exists in the command line arguments fed to the binary.
| | Author: | Bugghy | | Homepage: | http://vaida.bogdan.googlepages.com/ | | File Size: | 13111 | | Last Modified: | Apr 29 23:22:05 2003 |
| MD5 Checksum: | b734014c1b42f8ded0b07b2c39d31d0e |
|
| /// File Name: |
check.pl |
Description:
|
Check.pl 1.0 runs through all of the files and directories that it is given as arguments and determines the permissions. It then sends a list of "dangerous" files to stdout which can be redirected to a file. This program should be run as a regular user to check for writeable directories, suid, guid, and writeable files. Helps admins sniff out files that have incorrect permissions.
| | Author: | David Allen | | Changes: | Changes in reporting for first public release, runs slightly faster, added limits to depth of directory recursion so as to avoid the GNOME circular symlink problem in home directories. | | File Size: | 3864 | | Last Modified: | Aug 16 20:04:53 1999 |
| MD5 Checksum: | fc89fa873b32f999dcacd3651153c1c4 |
|
| /// File Name: |
chklastlog.c |
Description:
|
chklastlog.c v1.3 checks lastlog and wtmp for signs of tampering. It will detect most log wiping programs, such as z2 and zap.
| | Changes: | Linux/FreeBSD port, new Red Hat compatibility. | | File Size: | 2171 | | Last Modified: | Jul 4 02:21:47 2000 |
| MD5 Checksum: | ec7e4916679ab5a52db61c032fe711af |
|
| /// File Name: |
chkrootkit-0.15.tgz |
Description:
|
chkrootkit V. 0.15 locally checks for signs of a rootkit. Includes ifpromisc.c to check and see if the interface is in promisc mode, chklastlog.c to check lastlog for deletions, and chkwtmp.c to check wtmp for deletions. Tested on Linux 2.0.x, 2.2.x and FreeBSD 2.2.x, 3.x and 4.0.
| | Author: | Nelson Murilo | | Homepage: | ftp://ftp.pangeia.com.br/pub/seg/pac/ | | Changes: | lrk5 detection, Sun/Solaris support, and Red Hat fixes. | | File Size: | 8468 | | Last Modified: | Jul 4 02:37:50 2000 |
| MD5 Checksum: | 918d81248d226f08f3d96f0f27fde3d4 |
|
| /// File Name: |
chkrootkit-0.16.tar.gz |
Description:
|
chkrootkit V. 0.16 locally checks for signs of a rootkit. Includes ifpromisc.c to check and see if the interface is in promisc mode, chklastlog.c to check lastlog for deletions, and chkwtmp.c to check wtmp for deletions. Tested on Linux 2.0.x, 2.2.x and FreeBSD 2.2.x, 3.x and 4.0.
| | Author: | Nelson Murilo | | Homepage: | ftp://ftp.pangeia.com.br/pub/seg/pac/ | | Changes: | Add tests for new and popular variations of rootkits, better port for Solaris and performance patches. | | File Size: | 9536 | | Last Modified: | Jul 17 18:37:08 2000 |
| MD5 Checksum: | eb14969d932d3bfa502fd40ecdc9ce35 |
|
| /// File Name: |
chkrootkit-0.17.tar.gz |
Description:
|
chkrootkit V. 0.17 locally checks for signs of a rootkit. Includes detection of LKM rootkits, ifpromisc.c to check and see if the interface is in promisc mode, chklastlog.c to check lastlog for deletions, and chkwtmp.c to check wtmp for deletions. Tested on Linux, FreeBSD, and Solaris.
| | Author: | Nelson Murilo | | Homepage: | ftp://ftp.pangeia.com.br/pub/seg/pac/ | | Changes: | Add tests for new and popular variations of rootkits, including Tornkit. Now attempts to identify LKM rootkits. | | File Size: | 10833 | | Last Modified: | Sep 20 18:14:26 2000 |
| MD5 Checksum: | c5e3bb37172ce1b2a605fa53064dac0d |
|
| /// File Name: |
chkrootkit-0.19.tar.gz |
Description:
|
chkrootkit locally checks for signs of a rootkit. Includes detection of LKM rootkits, ifpromisc.c to check and see if the interface is in promisc mode, chklastlog.c to check lastlog for deletions, and chkwtmp.c to check wtmp for deletions. Tested on Linux, FreeBSD, Solaris, and OpenBSD.
| | Author: | Nelson Murilo | | Homepage: | ftp://ftp.pangeia.com.br/pub/seg/pac/ | | Changes: | Ambient's Rootkit for Linux (ARK) detection, OpenBSD support, xinetd support, new command line options, and bug fixes. | | File Size: | 13837 | | Last Modified: | Dec 27 00:40:40 2000 |
| MD5 Checksum: | b8557bcfc5dae6d0c3579783596fe450 |
|
| /// File Name: |
chkrootkit-0.21.tar.gz |
Description:
|
chkrootkit locally checks for signs of a rootkit. Includes detection of LKM rootkits, ifpromisc.c to check and see if the interface is in promisc mode, chklastlog.c to check lastlog for deletions, and chkwtmp.c to check wtmp for deletions. Tested on Linux, FreeBSD, Solaris, and OpenBSD.
| | Author: | Nelson Murilo | | Homepage: | http://www.chkrootkit.org | | Changes: | Detects the Ramen worm, latest t0rnkit, and bug fixes. | | File Size: | 14744 | | Last Modified: | Jan 24 17:06:51 2001 |
| MD5 Checksum: | a9d741f3d952a4fb4129194677da93a8 |
|
| /// File Name: |
chkrootkit-0.23.tar.gz |
Description:
|
chkrootkit locally checks for signs of a rootkit. Includes detection of LKM rootkits, ifpromisc.c to check and see if the interface is in promisc mode, chklastlog.c to check lastlog for deletions, and chkwtmp.c to check wtmp for deletions. Tested on Linux, FreeBSD, Solaris, and OpenBSD.
| | Author: | Nelson Murilo | | Homepage: | http://www.chkrootkit.org | | Changes: | Lrk6 detection, rh[67]-shaper detection, RSHA detection, Romanian rootkit detection, test for shell history file anomalies, and a better bindshell test. | | File Size: | 15991 | | Last Modified: | Mar 15 20:47:33 2001 |
| MD5 Checksum: | 989001de68edd7104baa50287d246c2c |
|
|
|
|
|