what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 526 - 550 of 907 RSS Feed

Intrusion Detection Files

lsof_4.61.tar.gz
Posted Jan 31, 2002
Authored by Vic Abell

Lsof is an extremely powerful unix diagnostic tool. Its name stands for LiSt Open Files, and it does just that. It lists information about any files that are open by processes currently running on the system. It easily pinpoints which process is using each network connection / open port. FAQ available here.

Changes: Adds support for FreeBSD 4.5 and 5, makes Linux lsof handle file sizes greater than 32 bits, supports Solaris 9 BETA-Refresh, and permits NetBSD and OpenBSD lsof compilation when system sources are absent.
tags | tool, intrusion detection
systems | unix
SHA-256 | c998f200faef5821fde15c1b767260fa0f25665a10da539bf14771e058498261
monitord-4.0beta.tar.gz
Posted Dec 18, 2001
Site sourceforge.net

The Network Security Monitor Daemon is a lightweight (distributed?) network security monitor for TCP/IP LANs which will capture certain network events and record them in a relational database. The recorded data is then made available for analysis via a CGI-based interface.

Changes: Improved security - No threads run as root. Added a new statistical thread and an HTTP server thread (which serves statistics in XML/XSL).
tags | tool, cgi, tcp, intrusion detection
systems | unix
SHA-256 | 848342a5d5417eb00d5a2621a8ecd05922765397c2559d33af29be18b511c60c
lsof_4.60_W.tar.gz
Posted Nov 17, 2001
Authored by Vic Abell

Lsof is an extremely powerful unix diagnostic tool. Its name stands for LiSt Open Files, and it does just that. It lists information about any files that are open by processes currently running on the system. It easily pinpoints which process is using each network connection / open port. FAQ available here.

Changes: Adds better handling of IPv6 selectors; makes safer lsof's ending of its child process; adds options to affect -v output; makes big_brother.perl5 run on SCO OSR; avoids an SCCS escape sequence in 00DCACHE and 00FAQ; makes 32 bit HP-UX 11 Makefile more portable; enables use of gcc to build a 64 bit HP-UX 11.00 executable.
tags | tool, intrusion detection
systems | unix
SHA-256 | 1d84dc2e46d728cf93b300eaeb662aa2808635a33821cde826d23f41b1df0a60
swatch-3.0.4.tar.gz
Posted Nov 14, 2001
Authored by Todd Atkins | Site stanford.edu

Swatch, the Simple Watch Daemon is a program for UNIX system logging, originally written to actively monitor messages as they are written to a log file via the UNIX syslog utility. Swatch was designed to keep system administrators from being overwhelmed by large quantities of log data. It monitors log files and acts to filter out unwanted data and take one or more simple user specified actions based upon patterns in the log. Swatch can monitor information as it is being appended to the log file and alert system administrators immediately to serious system problems as they occur.

Changes: Fixed a big bug involving key value assignment when throttling.
tags | tool, intrusion detection
systems | unix
SHA-256 | 3f3225f58781b125ec0025ae69ddac82e9e8a2e0b1b3bb4b116021812053dfd7
lsof_4.59_W.tar.gz
Posted Oct 23, 2001
Authored by Vic Abell

Lsof is an extremely powerful unix diagnostic tool. Its name stands for LiSt Open Files, and it does just that. It lists information about any files that are open by processes currently running on the system. It easily pinpoints which process is using each network connection / open port. FAQ available here.

Changes: Fixes for FreeBSD 5.0-CURRENT and Linux. Added new output field for raw device number in hex. Added support for OpenUNIX 8. Added an IP version selector to the -i option parameters.
tags | tool, intrusion detection
systems | unix
SHA-256 | 1e39c392e1016b61346c7830245b6b687bbb0fe67fc1d4576878af2447c25ac0
Samhain File Integrity Checker
Posted Oct 23, 2001
Authored by Rainer Wichmann | Site samhain.sourceforge.net

Samhain (stable branch) is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, tamper-resistant log file, and syslog) are available. Tested on Linux, AIX 4.1, HP-UX 10.20, Unixware 7.1.0, and Solaris 2.6.

Changes: Added MD5 and SHA1, fixed bugs.
tags | tool, tcp, intrusion detection
systems | linux, unix, solaris, aix, hpux, unixware
SHA-256 | 92952b60551212215a3ff7938055c795c0c7cf7520c9ecfa02d8165549e7e816
sentinel-1.0.tar.gz
Posted Oct 11, 2001
Authored by Bind | Site packetfactory.net

The Sentinel project is designed to be a portable, accurate, and effective implementation of all publicly known promiscuous detection techniques. Sentinel currently supports 3 methods of remote promiscuous detection: The DNS test, icmp etherping test, and ARP test. Tested on OpenBSD-3.0beta, FreeBSD 4.0, Netbsd 1.5.2, and Linux 2.4.x.

Changes: Bug fixes, updated documentation.
tags | tool, remote, intrusion detection
systems | linux, netbsd, unix, freebsd, openbsd
SHA-256 | ba808bc62d2d43d00e7abd9c078c366ef0e6f689e632ec39c75f19a573034883
Samhain File Integrity Checker
Posted Oct 5, 2001
Authored by Rainer Wichmann | Site samhain.sourceforge.net

Samhain (stable branch) is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, tamper-resistant log file, and syslog) are available. Tested on Linux, AIX 4.1, HP-UX 10.20, Unixware 7.1.0, and Solaris 2.6.

Changes: Better detection of kernel module rootkits (Linux only) to detect 'stealth' syscall redirection, the server can listen for syslog reports from remote hosts, logfiles can be written in XML format, the default install paths comply with the Filesystem Hierarchy Standard, minor bugs have been fixed, and added support for Mac OS X.
tags | tool, tcp, intrusion detection
systems | linux, unix, solaris, aix, hpux, unixware
SHA-256 | 0ff014554ff5f6e52c2fcc3638ee710af2c7053143a3f95659761f0aa510a287
firestorm-0.2.2.tar.gz
Posted Sep 27, 2001
Site scaramanga.co.uk

Firestorm is a Network Intrusion Detection sensor which is multi-threaded, fast, and is pluggable at almost every point.

Changes: Many snort compatibility fixes were made. All the snort 1.7 rules work. Most of the snort 1.8 rules work. Lots of bugs were fixed.
tags | tool, intrusion detection
systems | unix
SHA-256 | 25d1a40d6e0adbf5ed62b143d1f7a0e416617b5b67d9c4f0e55d11e094db97b4
netl-1.09.tar.gz
Posted Sep 20, 2001
Authored by Graham Ollis | Site netl.org

netl v1.09 is a network logger/sniffer suitable for TCP/IP over Ethernet and loopback which provides functionality not found in similar programs. netl is capable of logging everything from pings to telnet, including low level IP like SYNs and RSTs.

Changes: Added perl/Tk interface, fixed some bugs.
tags | tool, tcp, intrusion detection
systems | unix
SHA-256 | 5c0f37cb666914e50b01575f936c4800c589f5a6b7f0052d172debf882e961f7
LaBrea.tgz
Posted Sep 19, 2001
Authored by Tom Liston | Site hackbusters.net

LaBrea v2.0 is a program that creates a tarpit or, as some have called it, a "sticky honeypot". LaBrea takes over unused IP addresses on a network and creates "virtual machines" that answer to connection attempts. LaBrea answers those connection attempts in a way that causes the machine at the other end to get "stuck", sometimes for a very long time.

Changes: New command line option -p to keep tcp connections in the "persist" state, which can hold on to threads for a long time.
tags | tool, intrusion detection
systems | unix
SHA-256 | 23b2e7cad2a4578ea03587998eac0e122e2899f608739aa1a517864514a77f26
lsof_4.58_W.tar.gz
Posted Sep 15, 2001
Authored by Vic Abell

Lsof is an extremely powerful unix diagnostic tool. Its name stands for LiSt Open Files, and it does just that. It lists information about any files that are open by processes currently running on the system. It easily pinpoints which process is using each network connection / open port. FAQ available here.

Changes: Better error reporting, Enabled and tested on FreeBSD 4.4, and fixed some bugs.
tags | tool, intrusion detection
systems | unix
SHA-256 | 9bfb02d6c59ccd6b30cc793cca18bdf2b0e7a65aa3de8a99ae9c5f251be31293
swatch-3.0.2.tar.gz
Posted Sep 6, 2001
Authored by Todd Atkins | Site oit.ucsb.edu

Swatch, the Simple Watch Daemon is a program for UNIX system logging, originally written to actively monitor messages as they are written to a log file via the UNIX syslog utility. Swatch was designed to keep system administrators from being overwhelmed by large quantities of log data. It monitors log files and acts to filter out unwanted data and take one or more simple user specified actions based upon patterns in the log. Swatch can monitor information as it is being appended to the log file and alert system administrators immediately to serious system problems as they occur.

Changes: Defaults to /var/adm/messages now. Lots of bugs were fixed.
tags | tool, intrusion detection
systems | unix
SHA-256 | ecc3023e0c1b71e7b0f3d0122473ddd13694810fdb850d77557ebd05c57c6b2d
firestorm-0.2.1.tar.gz
Posted Sep 5, 2001
Site scaramanga.co.uk

Firestorm is a Network Intrusion Detection sensor which is multi-threaded, fast, and is pluggable at almost every point.

Changes: Sensors can now send data out to a central server over the Internet. Some bugs were fixed, and work on a firestorm daemon was started.
tags | tool, intrusion detection
systems | unix
SHA-256 | 8e8b5c43e13c843370f225ff1003f6b0f2483791e95265a9dc7a0a465faa5d17
prelude-0.4.2.tar.gz
Posted Aug 30, 2001
Site prelude.sourceforge.net

Prelude is a Network Intrusion Detection system which captures packets and performs data analysis and reporting. Important and current features of Prelude include an IP defragmentation stack and detection plugins with persistent state.

Changes: Fixes for people with dynamic IP addresses, a fix for a bug where inversed tests were wrongly reported, a fix for a crash on startup, and other bug fixes.
tags | tool, intrusion detection
systems | unix
SHA-256 | 63fae34c63a02a698038fed5ba22a17cc1df64e3d97358d6bc6910d171ec75af
prelude-0.4.1.tar.gz
Posted Aug 19, 2001
Site prelude.sourceforge.net

Prelude is a Network Intrusion Detection system which captures packets and performs data analysis and reporting. Important and current features of Prelude include an IP defragmentation stack and detection plugins with persistent state.

Changes: Better configuration, a new Arpspoof detection plugin which detects several ARP attacks, and bug fixes.
tags | tool, intrusion detection
systems | unix
SHA-256 | be3c8779ddf9c567462e5553bf2d7d2a4d4a289fcd18d68930b531d67360f039
prelude-0.4.0.tar.gz
Posted Aug 17, 2001
Site prelude.sourceforge.net

Prelude is a Network Intrusion Detection system which captures packets and performs data analysis and reporting. Important and current features of Prelude include an IP defragmentation stack and detection plugins with persistent state.

Changes: Includes a new signature engine which can can read Snort rulesets. The protocol plugins telnet (Handle telnet/FTP negotiation character), rpc (Handle the rpc protocol, provide the RPC key used in several Snort rulesets), http (Handle the uricontent key used in the Snort ruleset) have been added. There is a new XML reporting plugin, and lots of bugfixes.
tags | tool, intrusion detection
systems | unix
SHA-256 | 07e1bbaca0c98a435b7f8322276d2ac7c9c7fd73c04776f2db926169a885801c
lsof_4.57_W.tar.gz
Posted Aug 15, 2001
Authored by Vic Abell

Lsof is an extremely powerful unix diagnostic tool. Its name stands for LiSt Open Files, and it does just that. It lists information about any files that are open by processes currently running on the system. It easily pinpoints which process is using each network connection / open port.

Changes: Help now links to the new FAQ, fixed bugs for old linux kernels, improved HP-UX support, added OpenBSD 2.6, 2.9, and FreeBSD 5.0-CURRENT support, and fixed some bugs.
tags | tool, intrusion detection
systems | unix
SHA-256 | 0af199f2e17c821efb6810cf7e3ff308e165e9e3a88dbc63c59e90c2b9093df2
coderedwarn0_0b2.tar.gz
Posted Aug 11, 2001
Authored by Jonathan Hayward | Site JonathansCorner.com

Code Red Warn is a perl script which runs as a daemon and watches apache logs to notify you each time you are scanned with code red.

Changes: The recipient list has been adjusted to be more SMTP-compliant. A suggested way to run without keeping bounce messages in queue has been provided. SMTP connections are tested on the remote host before sending, and the 404 on home page download has been fixed.
tags | tool, perl, intrusion detection
systems | unix
SHA-256 | fae00696b98d72d39d852cfaf643db6cda13a657fa477e73854249eb09f8dd1a
coderedwarn0.0b.tar.gz
Posted Aug 11, 2001
Authored by Jonathan Hayward | Site JonathansCorner.com

Code Red Warn is a perl script which runs as a daemon and watches apache logs to notify you each time you are scanned with code red.

tags | tool, perl, intrusion detection
systems | unix
SHA-256 | f69297ae0b8f1068f19470d74cfedc384e601a7657fe6aacbe7c236a3db523c0
acid-0.9.6b12.tar.gz
Posted Aug 4, 2001
Site acidlab.sourceforge.net

The Analysis Console for Intrusion Databases (ACID) is a PHP-based analysis engine to search and process a database of incidents generated by security software such as IDS's and firewalls (e.g., Snort or ipchains). It provides a search interface for finding alerts matching practically any criteria, including arrival time, signature time, source/dest address/port, flags, payload, etc. ACID also provides the ability to annotate and logically group related events, delete false positives, or archive alerts among databases. A variety of statistics and graphs can be generated based on time, IP address, ports, alert classification, and sensor.

tags | tool, php, intrusion detection
systems | unix
SHA-256 | e08027b7d330a234c53242f9b733a6fe8846e0ef01641717de2b9f123754d1c6
Samhain File Integrity Checker
Posted Aug 4, 2001
Authored by Rainer Wichmann | Site samhain.sourceforge.net

Samhain (stable branch) is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, tamper-resistant log file, and syslog) are available. Tested on Linux, AIX 4.1, HP-UX 10.20, Unixware 7.1.0, and Solaris 2.6.

Changes: New files in monitored directories are now automatically included in the monitoring. More info and examples for paging is included in the manual. Several minor bugs have been fixed.
tags | tool, tcp, intrusion detection
systems | linux, unix, solaris, aix, hpux, unixware
SHA-256 | 65f57e2ad7b7c22483a3f42e9807ae6c22bd831ac181beed6eacdac7a7fdd282
firestorm-0.2.0.tar.gz
Posted Jul 25, 2001
Site scaramanga.co.uk

Firestorm is a Network Intrusion Detection sensor which is multi-threaded, fast, and is pluggable at almost every point.

Changes: Re-Designed packet encode engine which supports encapsulation. A final few issues in the snort parser have been resolved. A log target (logs to tcpdump files) was added. Bugs were fixed,
tags | tool, intrusion detection
systems | unix
SHA-256 | d77c1d52b7ede8d864490d563f7de3841605942ac9922a458ccce1868d830305
petrovich-1.0.0.tar.gz
Posted Jul 21, 2001
Authored by T. Kinch | Site sourceforge.net

Petrovich is a GPLed filesystem integrity checker similar to Tripwire. It is written in Perl using standard perl modules available from www.cpan.org. It currently supports Base64 MD2, MD5, and SHA1 hashes. Petrovich has been tested on windows 2000, OpenBSD 2.6 - 2.8, and RedHat Linux 7.1.

tags | tool, perl, intrusion detection
systems | linux, redhat, windows, unix, openbsd
SHA-256 | f6d1536844bda3897c7a7ee1beafa6a618fa8544f48798df61fb93e8e5a76663
portsentry-1.1.tar.gz
Posted Jul 17, 2001
Authored by Craig Rowland | Site psionic.com

PortSentry is a program designed to detect and respond to port scans against a target host in real-time. It runs on TCP and UDP sockets and works on most UNIX systems. Advanced stealth detection modes are available under Linux only and detect SYN, FIN, NULL, XMAS, and Oddball packet scans. All modes support real-time blocking and reporting of violations. All modes support real time alerting and blocking.

Changes: Added netmask ignoring support, a toggle for DNS lookups, and can prioritize response/external commands. The Linux 2.4 CPU usage bug has been fixed.
tags | tool, udp, tcp, intrusion detection
systems | linux, unix
SHA-256 | eb06f3c328614365a9fe61b8878acb76cbf364cb695dda37536a3b0e07a13f1f
Page 22 of 37
Back2021222324Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close