Section: .. / UNIX / IDS /
| /// Directory: |
/ nidsbench / |
Description:
|
nidsbench is a network intrusion detection system test suite. nidsbench is being published in the hopes that a more precise testing methodology might be applied to network intrusion detection, which is still a black art at best. This release of nidsbench includes: fragrouter: Implement all IP fragmentation attacks outlined in T. Ptacek and T. Newsham's "Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection" paper of January, 1998. tcpreplay: Replay saved tcpdump(8) dumpfiles at arbitrary speeds. nidsbench is published under a BSD-style license, and has been tested on the following platforms: OpenBSD 2.x, FreeBSD 3.x, BSD/OS 2.x, Linux (2.x kernels), Solaris 2.x (tcpreplay only).
| | Author: | Anzen Computing | | Total Files: | 18 | | Last Modified: | Sep 5 21:20:54 2007 |
|
| /// Directory: |
/ lsof / |
Description:
|
Unavailable.
| | Total Files: | 35 | | Last Modified: | Sep 5 21:20:51 2007 |
|
| /// Directory: |
/ cpm / |
Description:
|
Tool for checking network nterfaces in promisc mode.
| | Total Files: | 8 | | Last Modified: | Sep 5 21:20:48 2007 |
|
| /// Directory: |
/ L6 / |
Description:
|
L6 is a file data integrity checker using both the MD5 and SHA-1 hash algorithms. This tool can detect file tampering based on hashes generated by both algorithms and other inode information. It also provides a useful, lightweight and flexible interface (written in perl) to verify file data integrity, and the output and functionality resembles that of L5.
| | Author: | Programmaton | | Total Files: | 6 | | Last Modified: | Sep 5 21:20:45 2007 |
|
| /// File Name: |
radmind-1.10.0.tar.gz |
Description:
|
radmind is a suite of Unix command-line tools and a server designed to remotely administer the file systems of multiple Unix machines. Radmind operates as a tripwire which is able to detect changes to any managed filesystem object, e.g. files, directories, links, etc. However, radmind goes further than just integrity checking: once a change is detected, radmind can optionally reverse the change.
| | Homepage: | http://rsug.itd.umich.edu/software/radmind | | Changes: | Added a couple of options and various tweaks. | | File Size: | 397065 | | Last Modified: | Sep 1 00:07:46 2007 |
| MD5 Checksum: | ade8dd2e2ef68f29f105611e793bd393 |
|
| /// File Name: |
prelude-manager-0.9.9.tar.gz |
Description:
|
Prelude Manager is the main program of the Prelude Hybrid IDS suite. It is able to register local or remote sensors, let the operator configure them remotely, receive alerts, and store alerts in a database or any format supported by reporting plugins, thus providing centralized logging and analysis.
| | Homepage: | http://prelude.sourceforge.net | | Changes: | Updated configuration template, added documentation for Prelude generic TCP options. Various other tweaks and changes. | | File Size: | 647696 | | Last Modified: | Aug 8 01:34:13 2007 |
| MD5 Checksum: | ca9258faadb7306863dffeac8f855161 |
|
| /// File Name: |
samhain-2.3.5.tar.gz |
Description:
|
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
| | Author: | Rainer Wichmann | | Homepage: | http://samhain.sourceforge.net | | Changes: | Various updates. | | File Size: | 1726134 | | Last Modified: | Jun 21 15:49:55 2007 |
| MD5 Checksum: | 0351a6baee5d177432c6b7200b096105 |
|
| /// File Name: |
beltane-1.0.13.tar.gz |
Description:
|
Beltane is a web-based central management console for the Samhain file integrity / intrusion detection system. It enables the administrator to browse client messages, acknowledge them, and update centrally stored file signature databases. Beltane requires a Samhain (version 1.6.0 or higher) client/server installation, with file signature databases stored on the central server, and logging to a SQL database enabled.
| | Homepage: | http://la-samhna.de/beltane | | Changes: | Bug fixes. | | File Size: | 178761 | | Last Modified: | Jun 7 02:39:53 2007 |
| MD5 Checksum: | 44bbc7af1ffb0417b6dc2d6d5d07ee9f |
|
| /// File Name: |
integrit-4.1.tar.gz |
Description:
|
Integrit is an alternative to file integrity verification programs like tripwire and aide. It helps you determine whether an intruder has modified a computer system. integrit's major advantages are a small memory footprint and simplicity. It works by creating a database that is a snapshot of the most essential parts of your computer system. You put the database somewhere safe, and you can then use it to make sure that no one has made any illicit modifications to the computer system. In the case of a break in, you know exactly which files have been modified, added, or removed.
| | Homepage: | http://integrit.sourceforge.net | | Changes: | Fixed exit status, considering missing files correctly as a change. | | File Size: | 271626 | | Last Modified: | Jun 6 18:30:51 2007 |
| MD5 Checksum: | f51a5b558981a5d90e7d6f4e7e269a46 |
|
| /// File Name: |
radmind-1.8.1.tar.gz |
Description:
|
radmind is a suite of Unix command-line tools and a server designed to remotely administer the file systems of multiple Unix machines. Radmind operates as a tripwire which is able to detect changes to any managed filesystem object, e.g. files, directories, links, etc. However, radmind goes further than just integrity checking: once a change is detected, radmind can optionally reverse the change.
| | Homepage: | http://rsug.itd.umich.edu/software/radmind | | Changes: | lapply doesn't attempt to report when run with -n, some other changes. | | File Size: | 387410 | | Last Modified: | May 23 22:14:01 2007 |
| MD5 Checksum: | 77687b759a05cc34a8611469ded5c667 |
|
| /// File Name: |
samhain-2.3.4.tar.gz |
Description:
|
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
| | Author: | Rainer Wichmann | | Homepage: | http://samhain.sourceforge.net | | Changes: | Various updates. | | File Size: | 1725798 | | Last Modified: | May 2 22:04:33 2007 |
| MD5 Checksum: | da5d5be7e0fe3e198d6fe4ed5277cab1 |
|
| /// File Name: |
prelude-manager-0.9.8.tar.gz |
Description:
|
Prelude Manager is the main program of the Prelude Hybrid IDS suite. It is able to register local or remote sensors, let the operator configure them remotely, receive alerts, and store alerts in a database or any format supported by reporting plugins, thus providing centralized logging and analysis.
| | Homepage: | http://prelude.sourceforge.net | | Changes: | Various bug fixes and some updates. | | File Size: | 617261 | | Last Modified: | May 2 22:02:02 2007 |
| MD5 Checksum: | be73ee46a7279200c5b9fcc4a2f9b7ad |
|
| /// File Name: |
samhain-2.3.3.tar.gz |
Description:
|
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
| | Author: | Rainer Wichmann | | Homepage: | http://samhain.sourceforge.net | | Changes: | Various updates. | | File Size: | 1719870 | | Last Modified: | Apr 2 20:18:34 2007 |
| MD5 Checksum: | ebde568b6067dc5ce2c1346265caf3dc |
|
| /// File Name: |
prelude-manager-0.9.7.2.tar.gz |
Description:
|
Prelude Manager is the main program of the Prelude Hybrid IDS suite. It is able to register local or remote sensors, let the operator configure them remotely, receive alerts, and store alerts in a database or any format supported by reporting plugins, thus providing centralized logging and analysis.
| | Homepage: | http://prelude.sourceforge.net | | Changes: | Various bug fixes and some updates. | | File Size: | 596874 | | Last Modified: | Mar 20 00:10:09 2007 |
| MD5 Checksum: | 7f32b6fb176d9f91d98f341928e0802e |
|
| /// File Name: |
samhain-2.3.2.tar.gz |
Description:
|
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
| | Author: | Rainer Wichmann | | Homepage: | http://samhain.sourceforge.net | | Changes: | Various updates. | | File Size: | 1555549 | | Last Modified: | Feb 5 23:39:14 2007 |
| MD5 Checksum: | 19d6a199ec52e1c812309d33808df542 |
|
| /// File Name: |
samhain-2.3.1a.tar.gz |
Description:
|
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
| | Author: | Rainer Wichmann | | Homepage: | http://samhain.sourceforge.net | | Changes: | Various updates. | | File Size: | 1555161 | | Last Modified: | Jan 26 22:12:56 2007 |
| MD5 Checksum: | 4b349359955f607f9842963f8afcbe60 |
|
| /// File Name: |
prelude-manager-0.9.7.1.tar.gz |
Description:
|
Prelude Manager is the main program of the Prelude Hybrid IDS suite. It is able to register local or remote sensors, let the operator configure them remotely, receive alerts, and store alerts in a database or any format supported by reporting plugins, thus providing centralized logging and analysis.
| | Homepage: | http://prelude.sourceforge.net | | Changes: | Fix compilation issue on system where ferror is not declared as a function. | | File Size: | 565882 | | Last Modified: | Dec 21 22:23:32 2006 |
| MD5 Checksum: | 4af593e21b41faa220d9dc9648df4a85 |
|
| /// File Name: |
samhain-2.3.0a.tar.gz |
Description:
|
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
| | Author: | Rainer Wichmann | | Homepage: | http://samhain.sourceforge.net | | Changes: | Various updates. | | File Size: | 1572372 | | Last Modified: | Nov 2 10:27:47 2006 |
| MD5 Checksum: | 02d616b597f07a1ff97c873e0b69a69f |
|
| /// File Name: |
samhain-2.2.5.tar.gz |
Description:
|
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
| | Author: | Rainer Wichmann | | Homepage: | http://samhain.sourceforge.net | | Changes: | Various updates. | | File Size: | 1525739 | | Last Modified: | Oct 18 19:58:35 2006 |
| MD5 Checksum: | 8171f55efc1531fde591fda0649d6c1d |
|
| /// File Name: |
radmind-1.7.1.tar.gz |
Description:
|
radmind is a suite of Unix command-line tools and a server designed to remotely administer the file systems of multiple Unix machines. Radmind operates as a tripwire which is able to detect changes to any managed filesystem object, e.g. files, directories, links, etc. However, radmind goes further than just integrity checking: once a change is detected, radmind can optionally reverse the change.
| | Homepage: | http://rsug.itd.umich.edu/software/radmind | | Changes: | fsdiff does not checksum files that are going to be deleted. Added additional wildcard patterns for config file. Using updated DNSServiceDiscovery APIs. | | File Size: | 378163 | | Last Modified: | Oct 5 00:09:04 2006 |
| MD5 Checksum: | cdc83d33a111bdf883ca8291129c81fc |
|
| /// File Name: |
bubblegum-1.12.tar.gz |
Description:
|
Bubblegum is a daemon written in C which watches a file's access, modification, and inode change times, logging the changes. It can run an external command, read files from a filelist, and more.
| | Homepage: | http://cyclic.sourceforge.net/bubblegum | | Changes: | Build fix for RedHat. Support for directory recursion. Port to Solaris. | | File Size: | 111091 | | Last Modified: | Oct 4 23:51:52 2006 |
| MD5 Checksum: | b0cea809735aa3ab85cbc3a577ef8aeb |
|
| /// File Name: |
nepenthes-0.1.7.tar.bz2 |
Description:
|
Nepenthes is a low interaction honeypot like honeyd or mwcollect. Low Interaction Honeypots emulate _known_ vulnerabilities to collect information about potential attacks. Nepenthes is designed to emulate vulnerabilities worms use to spread, and to capture these worms. As there are many possible ways for worms to spread, Nepenthes is modular.
| | Homepage: | http://nepenthes.mwcollect.org/ | | File Size: | 514301 | | Last Modified: | Sep 21 20:20:23 2006 |
| MD5 Checksum: | 7eb9fa1e3f819d5aa3c9ac81a572a724 |
|
| /// File Name: |
samhain-2.2.4.tar.gz |
Description:
|
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
| | Author: | Rainer Wichmann | | Homepage: | http://samhain.sourceforge.net | | Changes: | Various updates. | | File Size: | 1525691 | | Last Modified: | Sep 13 04:13:01 2006 |
| MD5 Checksum: | 66b81869578b1295ed8cc0d811457173 |
|
| /// File Name: |
samhain-2.2.3.tar.gz |
Description:
|
Samhain is a file system integrity checker that can be used as a client/server application for centralized monitoring of networked hosts. Databases and configuration files can be stored on the server. Databases, logs, and config files can be signed for tamper resistance. In addition to forwarding reports to the log server via authenticated TCP/IP connections, several other logging facilities (e-mail, console, and syslog) are available. Tested on Linux, AIX, HP-UX, Unixware, Sun and Solaris.
| | Author: | Rainer Wichmann | | Homepage: | http://samhain.sourceforge.net | | Changes: | Various updates. | | File Size: | 1518903 | | Last Modified: | Aug 17 02:27:53 2006 |
| MD5 Checksum: | 254933757f61b63022d4a454e35eed87 |
|
| /// File Name: |
integrit-4.0.tar.gz |
Description:
|
Integrit is an alternative to file integrity verification programs like tripwire and aide. It helps you determine whether an intruder has modified a computer system. integrit's major advantages are a small memory footprint and simplicity. It works by creating a database that is a snapshot of the most essential parts of your computer system. You put the database somewhere safe, and you can then use it to make sure that no one has made any illicit modifications to the computer system. In the case of a break in, you know exactly which files have been modified, added, or removed.
| | Homepage: | http://integrit.sourceforge.net | | Changes: | Updated output format for "new" file checksums to match "removed". | | File Size: | 266001 | | Last Modified: | Aug 17 02:26:02 2006 |
| MD5 Checksum: | 2f6a7e28e48b0cbc8214648e3224703b |
|
|
|
|
|