Section: .. / UNIX / IDS /
| /// File Name: |
securelib.tar.gz |
Description:
|
Protect your RPC daemons against unauthorized access. Shared library for SunOS 4.1 and later.
| | File Size: | 9766 | | Last Modified: | Aug 16 20:02:15 1999 |
| MD5 Checksum: | 2d149f795d1dbcabd85e29225fcac6a3 |
|
| /// File Name: |
secureworx0_7-B1.sh |
Description:
|
Secure Worx (TM) Network Intrusion Detection System - The intrusion detection system is a network based system that performs high-speed traffic analysis of the content and context of a network packet to detect unauthorized traffic in real-time. It has inexpensive hardware and OS requirements. The intrusion detection system runs on a Intel Pentium class compatible processor with a 10/100 Ethernet card running the Linux OS with kernel 2.2 and above with a configured TCP/IP stack. The installation process involves running an installation script that asks a few simple questions. It is then a simple matter of starting the software and your network is then searched for anomalous activity.
| | Author: | Secure Worx | | Homepage: | http://secureworx.homestead.com | | File Size: | 107122 | | Last Modified: | May 2 19:35:35 2000 |
| MD5 Checksum: | a4743d99fc1ca09beb0fcf86ef7f7579 |
|
| /// File Name: |
sensorTrends-0.6.tar.gz |
Description:
|
sensorTrends is a GPL web-based application that displays a high-level view of the ports that are being scanned over the course of time. The display is similar to the look and feel of Internet Storm Center (incidents.org). Supported log formats are Cisco router Access Control Lists (ACLs) syslog output, Cisco PIX firewall syslog output, Snort's portscan.log files and NetScreen syslog output, and more. Demonstration page available here.
| | Author: | John Weidley | | Homepage: | http://www.packetshack.org/index.php?page=sensorTrends | | File Size: | 17499 | | Last Modified: | Oct 30 14:00:05 2003 |
| MD5 Checksum: | e038e47abfe3838a0ae230d2465c1cf1 |
|
| /// Directory: |
/ sentinel / |
Description:
|
The Sentinel project is designed to be a portable, accurate implementation of all publicly known promiscuous detection techniques.
| | Total Files: | 5 | | Last Modified: | Sep 5 21:21:00 2007 |
|
| /// File Name: |
sentinel-1.2.0.tar.gz |
Description:
|
Sentinel is a fast file/drive scanning utility similar to the Tripwire and Viper.pl utilities available. It uses a database similar to Tripwire, but uses a RIPEMD-160bit MAC checksumming algorithm (no patents) which is more secure than the patented MD5 128 bit checksum. It should run on most unixes (tested on redhat linux v6.0 & v5.2, slackware linux v3.x & 4.xb and IRIX (v5.2 and v6.x). Several other utilities which are used for Sentinel development are also posted here. Most utilities are included with the sentinel tarball. gSentinel is a graphical front-end to sentinel. Newbies should download gSentinel as it comes with a very simple rpm based installation and offers a friendly interface. Beware that gSentinel is currently under development and may be fairly crude compared to most GUI packages.
| | Homepage: | http://zurk.netpedia.net/zfile.html | | File Size: | 395168 | | Last Modified: | Jan 24 19:55:33 2000 |
| MD5 Checksum: | 6c7adcd611c90494db94c4e3f9b579cc |
|
| /// File Name: |
sentinel-1.2.1.tar.gz |
Description:
|
Sentinel is a fast file integrity checker similar to Tripwire or ViperDB with built in authentication using the RIPEMD 160 bit MAC hashing function. It uses a single database similar to Tripwire, maintains file integrity using the RIPEMD algorithm and also produces secure, signed logfiles. Its main design goal is to detect intruders modifying files. It also prevents intruders with root/superuser permissions from tampering with its log files and database.
| | Homepage: | http://zurk.sourceforge.net/zfile.html | | Changes: | A -fullcheck option has been added which allows you to check for files added to the drive even if they are not in the database. The efficiency and speed of the algorithms for checking and database creation have also been improved, allowing it to work at or near a hard disk's max throughput limits. | | File Size: | 407678 | | Last Modified: | Mar 21 17:11:09 2001 |
| MD5 Checksum: | 1dd56b8670f857d7f1299bbe7dd3ced7 |
|
| /// File Name: |
sentinel-1.2.1c.tar.gz |
Description:
|
Sentinel is a fast file integrity checker similar to Tripwire or ViperDB with built in authentication using the RIPEMD 160 bit MAC hashing function. It uses a single database similar to Tripwire, maintains file integrity using the RIPEMD algorithm and also produces secure, signed logfiles. Its main design goal is to detect intruders modifying files. It also prevents intruders with root/superuser permissions from tampering with its log files and database.
| | Homepage: | http://zurk.sourceforge.net/zfile.html | | Changes: | Sentinel-user for individual users has been added. The copyright has been changed to the FSF. This release also contains minor makefile updates. | | File Size: | 443155 | | Last Modified: | Apr 24 21:24:03 2001 |
| MD5 Checksum: | 87a55fcb020303d4d8efe60317948c3a |
|
| /// File Name: |
servme.tar |
Description:
|
Servme is a small daemon that listens on a port and logs the contents of all incoming connections to a file. New release allows emulation of ssh, Apache, VS-FTPD, telnetd, and generic open ports.
| | Author: | Chris | | Homepage: | http://www.cr-secure.net | | File Size: | 20480 | | Last Modified: | Aug 7 16:18:37 2004 |
| MD5 Checksum: | c317394522eebf8b04cb1b4ff4cfe6b5 |
|
| /// File Name: |
sf-0.1b.tgz |
Description:
|
Secure Files 0.1b is a security tool that checks system integrity by comparing the MD5 checksums of flagged files against their earlier recorded checksums.
| | Author: | Venomous | | Homepage: | http://www.rdcrew.com.ar | | File Size: | 3645 | | Last Modified: | Aug 28 22:19:23 2000 |
| MD5 Checksum: | cae75ec5225047150b2055ad309208b8 |
|
| /// File Name: |
sfck.tar.gz |
Description:
|
Sfck is a program that locates file changes on your linux system. It keeps a database which you can put on a read-only disk to make sure no changes take place from a hacker/intruder. When a file change is detected it mails root.
| | Author: | Vision | | File Size: | 3027 | | Last Modified: | Aug 16 20:02:40 1999 |
| MD5 Checksum: | 059733c5a98c11ca907f0160ee6b3a74 |
|
| /// File Name: |
shadow.setup.readme |
Description:
|
SHADOW setup and intro file.
| | File Size: | 86483 | | Last Modified: | Aug 16 20:02:20 1999 |
| MD5 Checksum: | 0066298039a8b9f491cf44e65d888295 |
|
| /// File Name: |
SHADOW.tar.gz |
Description:
|
Traffic analysis and Intrusion Detection System developed by The SANS Institute, The Naval Surface Warfare Center, the Lawrence Berkeley Research Center, and the US Dept of Energy. This package includes tcpdump, tcpslice, libpcap, and the SHADOW code. Check out the Instruction file before you download it. Requires SSH and Apache web server
| | File Size: | 3854366 | | Last Modified: | Aug 16 20:02:20 1999 |
| MD5 Checksum: | 9048a80d7f705efa73a4ba5aa7488fb5 |
|
| /// File Name: |
sherpa-0.1.3.tar.gz |
Description:
|
sherpa is a tool for configuring and then checking system security via the console. Written in perl, it allows an admin to maintain a custom database of file and directory permissions and ownership attributes as local needs dictate. Any changes from the prescribed layout will be detected each time sherpa is run. Also, sherpa does some basic system checks (world-writable files, .rhosts and hosts.equiv files, etc.) that help the busy admin keep on top of a system.
| | Author: | Rick Crelia | | Homepage: | http://sherpa.lavamonkeys.com/ | | File Size: | 43362 | | Last Modified: | Oct 20 15:21:54 1999 |
| MD5 Checksum: | 8bbb31cc9de6a094556aef48cb9d2410 |
|
| /// File Name: |
sherpa-0.1.4.tar.gz |
Description:
|
sherpa is a tool for configuring and then checking system security via the console. Written in perl, it allows an admin to maintain a custom database of file and directory permissions and ownership attributes as local needs dictate. Any changes from the prescribed layout will be detected each time sherpa is run. Also, sherpa does some basic system checks (world-writable files, .rhosts and hosts.equiv files, etc.) that help the busy admin keep on top of a system.
| | Author: | Rick Crelia | | Homepage: | http://sherpa.lavamonkeys.com/ | | Changes: | Sherpa now checks for shadow passwords, parses inetd.conf to look for use of tcp_wrappers, and verifies perms.lst for RedHat 6.1. | | File Size: | 44170 | | Last Modified: | Feb 3 16:25:20 2000 |
| MD5 Checksum: | 333b6e7a425c99017bcbd4ce6c229504 |
|
| /// File Name: |
sherpa-0.1.8.tgz |
Description:
|
sherpa is a tool for configuring and then checking system security via the console. Written in perl, it allows an admin to maintain a custom database of file and directory permissions and ownership attributes as local needs dictate. Any changes from the prescribed layout will be detected each time sherpa is run. Also, sherpa does some basic system checks (world-writable files, .rhosts and hosts.equiv files, etc.) that help the busy admin keep on top of a system.
| | Author: | Rick Crelia | | Homepage: | http://sherpa.lavamonkeys.com/ | | Changes: | Bug fixes and some optimizations. | | File Size: | 72308 | | Last Modified: | Nov 4 23:22:23 2004 |
| MD5 Checksum: | f19a47d6634f4ccea7dedef052a1b7c8 |
|
| /// File Name: |
shoki-0.08.2.tar.gz |
Description:
|
Shoki is a collection of IDS tools, scripts, and so forth. All the bits together can collect data from sensors, schlep it to a central location for storage, run signature-based and statistical analysis on the data, and load the data into a SQL database. Shoki provides a framework for a distributed system for network traffic analysis among untrusted peers.
| | Homepage: | http://www.meshuggeneh.net/shoki | | File Size: | 149000 | | Last Modified: | Oct 21 04:26:57 2000 |
| MD5 Checksum: | 20d43922b0415cedf1de6af12fbbeca6 |
|
| /// File Name: |
shoneypot-0.2-3.tar.gz |
Description:
|
Single Honeypot simulates many services - SMTP, HTTP, shell, and FTP. It can pretend to be many OS's, such as Windows FTP systems, Windows SMTP systems, different Linux distributions, and some Posix distributions.
| | Homepage: | http://sourceforge.net/projects/single-honeypot | | Changes: | Pop3 target added and commands of the SMTP target have been added and modified. | | File Size: | 13302 | | Last Modified: | Sep 20 12:04:59 2002 |
| MD5 Checksum: | d449ea1d6be95ffea39501e2f044361e |
|
| /// File Name: |
shoneypot-0.2-7.tar.gz |
Description:
|
Single Honeypot simulates many services - SMTP, HTTP, shell, and FTP. It can pretend to be many OS's, such as Windows FTP systems, Windows SMTP systems, different Linux distributions, and some Posix distributions.
| | Homepage: | http://sourceforge.net/projects/single-honeypot | | File Size: | 18651 | | Last Modified: | Apr 5 16:11:00 2004 |
| MD5 Checksum: | 7396dfe31a9485dcd5bb023c7dfb93bd |
|
| /// File Name: |
shoneypot-0.2.tar.gz |
Description:
|
Single Honeypot simulates many services - SMTP, HTTP, shell, and FTP. It can pretend to be many OS's, such as Windows FTP systems, Windows SMTP systems, different Linux distributions, and some Posix distributions.
| | Homepage: | http://sourceforge.net/projects/single-honeypot | | Changes: | Added install script, and added more responses to the SMTP target. | | File Size: | 12140 | | Last Modified: | Aug 14 02:06:59 2002 |
| MD5 Checksum: | 12b81eaafcaad1dde6291f4c1b79823c |
|
| /// File Name: |
sid-0.3.10.tar.gz |
Description:
|
SID is a Shell Intrusion Detection system. The kernel part plugs into a terminal-processing subsystem and logs hashed terminal lines. The user part reads log entries (hashes), consults a list of allowed entries, and takes appropriate action upon unexpected log entries. Currently supported are Solaris and Linux.
| | Author: | belpo | | Homepage: | http://sid.sourceforge.net | | Changes: | Various updates. | | File Size: | 49491 | | Last Modified: | Sep 21 04:16:43 2004 |
| MD5 Checksum: | 21f8d67b76623b7587ec469d2a3d141d |
|
| /// File Name: |
sid-0.3.3.tar.gz |
Description:
|
SID is a Shell Intrusion Detection system. The kernel part plugs into a terminal-processing subsystem and logs hashed terminal lines. The user part reads log entries (hashes), consults a list of allowed entries, and takes appropriate action upon unexpected log entries. Currently supported are Solaris and Linux.
| | Author: | belpo | | Homepage: | http://sid.sourceforge.net | | File Size: | 41017 | | Last Modified: | Apr 10 12:06:00 2004 |
| MD5 Checksum: | cec3a3f4fec35389049ac63d4df66efe |
|
| /// File Name: |
sid-0.3.4.tar.gz |
Description:
|
SID is a Shell Intrusion Detection system. The kernel part plugs into a terminal-processing subsystem and logs hashed terminal lines. The user part reads log entries (hashes), consults a list of allowed entries, and takes appropriate action upon unexpected log entries. Currently supported are Solaris and Linux.
| | Author: | belpo | | Homepage: | http://sid.sourceforge.net | | Changes: | Various updates. | | File Size: | 41665 | | Last Modified: | Apr 20 08:02:00 2004 |
| MD5 Checksum: | 56b27dbe49befdd875de879144c968c0 |
|
| /// File Name: |
sid-0.3.5.tar.gz |
Description:
|
SID is a Shell Intrusion Detection system. The kernel part plugs into a terminal-processing subsystem and logs hashed terminal lines. The user part reads log entries (hashes), consults a list of allowed entries, and takes appropriate action upon unexpected log entries. Currently supported are Solaris and Linux.
| | Author: | belpo | | Homepage: | http://sid.sourceforge.net | | Changes: | Various updates. | | File Size: | 43346 | | Last Modified: | Jun 7 23:44:57 2004 |
| MD5 Checksum: | 40ede1091f7a36800078a85259ff3a1b |
|
| /// File Name: |
sid-0.3.7.tar.gz |
Description:
|
SID is a Shell Intrusion Detection system. The kernel part plugs into a terminal-processing subsystem and logs hashed terminal lines. The user part reads log entries (hashes), consults a list of allowed entries, and takes appropriate action upon unexpected log entries. Currently supported are Solaris and Linux.
| | Author: | belpo | | Homepage: | http://sid.sourceforge.net | | Changes: | Various updates. | | File Size: | 49564 | | Last Modified: | Aug 9 23:30:41 2004 |
| MD5 Checksum: | c9a3a9d58f24491cd8e8dd674a575eb3 |
|
| /// File Name: |
sid-0.3.tar.gz |
Description:
|
SID is a Shell Intrusion Detection system. The kernel part plugs into a terminal-processing subsystem and logs hashed terminal lines. The user part reads log entries (hashes), consults a list of allowed entries, and takes appropriate action upon unexpected log entries. Currently supported are Solaris and Linux.
| | Author: | belpo | | Homepage: | http://sid.sourceforge.net | | File Size: | 37889 | | Last Modified: | Feb 22 21:52:00 2004 |
| MD5 Checksum: | f1edd0767a8217958f1048b4aeb66fd3 |
|
|
|
|
|