.:[ packet storm ]:.
                               
global security disclosure
global security disclosure

 Section:  .. / UNIX / audit / sara  /

Page 1 of 2
<< 1 2 >> Files 1 - 25 of 49
Currently sorted by: File NameSort By: Last Modified, File Size

 ///  File Name: sara-2.0.2.tar.gz
Description:
SARA v2.0.2 - The Security Auditor's Research Assistant (SARA) is a third generation security analysis tool that is based on the SATAN model, conforms to the Open Source model, is covered by the GNU open license, fosters a collaborative environment, and is updated on a weekly basis. The author of SAINT, Bob Todd, recently joined Advanced Research and has been working non-stop to evolve SATAN and the original SAINT concept to a community oriented product (i.e, SARA) which will be available to all. Advanced Research's philosophy relies heavily on software re-use. Rather than inventing a new module, SARA is adapted to interface to other community products. For instance, SARA interfaces with the popular NMAP package for superior "Operating System fingerprinting". Also, SARA provides a transparent interface to SAMBA for SMB security analysis. SARA's features include ( the [SARA] indicates that this is a new or improved feature when compared to SAINT or SATAN): Built-in report writer (by subnet or by database) [SARA], Built-in summary table generator [SARA], Gateway to external programs (e.g., NMAP) [SARA], CGI-BIN vulnerability testing (Unix and IIS) [SARA], SSH buffer overflow vulnerabilities [SARA], Current Sendmail vulnerabilities [SARA], IMAPD/POPD buffer overflow vulnerabilities [SARA], Current FTP and WU-FTP vulnerabilities [SARA], Tooltalk buffer overflow vulnerbilities [SARA], Netbus, Netbus-2, and Back Orifice vulnerabilities [SARA], Improved Operating System fingerprinting [SARA], Firewall-aware [SARA], Weekly updates [SARA], Probing for non-password accounts [SARA], NFS file systems exported to arbitrary hosts, NFS file systems exported to unprivileged programs, NFS file systems exported via the portmapper, NIS password file access from arbitrary hosts, REXD access from arbitrary hosts, X server access control disabled, Arbitrary files accessible via TFTP, Remote shell access from arbitrary hosts, Writable anonymous FTP home directory.
Author:Advanced Research Corporation
File Size:338271
Last Modified:Aug 16 20:04:53 1999
MD5 Checksum:e61a9f4ae20308257d7e47323633e66f

 ///  File Name: sara-2.0.3.tar.gz
Description:
SARA v2.0.3 - The Security Auditor's Research Assistant (SARA) is a third generation security analysis tool that is based on the SATAN model, conforms to the Open Source model, is covered by the GNU open license, fosters a collaborative environment, and is updated on a weekly basis. The author of SAINT, Bob Todd, recently joined Advanced Research and has been working non-stop to evolve SATAN and the original SAINT concept to a community oriented product (i.e, SARA) which will be available to all. Advanced Research's philosophy relies heavily on software re-use. Rather than inventing a new module, SARA is adapted to interface to other community products. For instance, SARA interfaces with the popular NMAP package for superior "Operating System fingerprinting". Also, SARA provides a transparent interface to SAMBA for SMB security analysis. SARA's features include ( the [SARA] indicates that this is a new or improved feature when compared to SAINT or SATAN): Built-in report writer (by subnet or by database) [SARA], Built-in summary table generator [SARA], Gateway to external programs (e.g., NMAP) [SARA], CGI-BIN vulnerability testing (Unix and IIS) [SARA], SSH buffer overflow vulnerabilities [SARA], Current Sendmail vulnerabilities [SARA], IMAPD/POPD buffer overflow vulnerabilities [SARA], Current FTP and WU-FTP vulnerabilities [SARA], Tooltalk buffer overflow vulnerbilities [SARA], Netbus, Netbus-2, and Back Orifice vulnerabilities [SARA], Improved Operating System fingerprinting [SARA], Firewall-aware [SARA], Weekly updates [SARA], Probing for non-password accounts [SARA], NFS file systems exported to arbitrary hosts, NFS file systems exported to unprivileged programs, NFS file systems exported via the portmapper, NIS password file access from arbitrary hosts, REXD access from arbitrary hosts, X server access control disabled, Arbitrary files accessible via TFTP, Remote shell access from arbitrary hosts, Writable anonymous FTP home directory.
Author:Advanced Research Corporation
File Size:340011
Last Modified:Aug 16 20:04:53 1999
MD5 Checksum:704ef00ada7bf75e622a45521b9fb7f8

 ///  File Name: sara-2.0.4.tar.gz
Description:
SARA v2.0.4 - The Security Auditor's Research Assistant (SARA) is a third generation security analysis tool that is based on the SATAN model, conforms to the Open Source model, is covered by the GNU open license, fosters a collaborative environment, and is updated on a weekly basis. The author of SAINT, Bob Todd, recently joined Advanced Research and has been working non-stop to evolve SATAN and the original SAINT concept to a community oriented product (i.e, SARA) which will be available to all. Advanced Research's philosophy relies heavily on software re-use. Rather than inventing a new module, SARA is adapted to interface to other community products. For instance, SARA interfaces with the popular NMAP package for superior "Operating System fingerprinting". Also, SARA provides a transparent interface to SAMBA for SMB security analysis. SARA's features include ( the [SARA] indicates that this is a new or improved feature when compared to SAINT or SATAN): Built-in report writer (by subnet or by database) [SARA], Built-in summary table generator [SARA], Gateway to external programs (e.g., NMAP) [SARA], CGI-BIN vulnerability testing (Unix and IIS) [SARA], SSH buffer overflow vulnerabilities [SARA], Current Sendmail vulnerabilities [SARA], IMAPD/POPD buffer overflow vulnerabilities [SARA], Current FTP and WU-FTP vulnerabilities [SARA], Tooltalk buffer overflow vulnerbilities [SARA], Netbus, Netbus-2, and Back Orifice vulnerabilities [SARA], Improved Operating System fingerprinting [SARA], Firewall-aware [SARA], Weekly updates [SARA], Probing for non-password accounts [SARA], NFS file systems exported to arbitrary hosts, NFS file systems exported to unprivileged programs, NFS file systems exported via the portmapper, NIS password file access from arbitrary hosts, REXD access from arbitrary hosts, X server access control disabled, Arbitrary files accessible via TFTP, Remote shell access from arbitrary hosts, Writable anonymous FTP home directory.
Author:Advanced Research Corporation
Changes:added ftp bounce test, added mail relay test, improved login.sara, improved timeouts for various tests, improved http.sara tests.
File Size:345512
Last Modified:Aug 16 20:04:53 1999
MD5 Checksum:d342075ff51e2770fe0aa62ae4c2f021

 ///  File Name: sara-2.0.5.tar.gz
Description:
SARA v2.0.5 - The Security Auditor's Research Assistant (SARA) is a third generation security analysis tool that is based on the SATAN model, conforms to the Open Source model, is covered by the GNU open license, fosters a collaborative environment, and is updated on a weekly basis. The author of SAINT, Bob Todd, recently joined Advanced Research and has been working non-stop to evolve SATAN and the original SAINT concept to a community oriented product (i.e, SARA) which will be available to all. Advanced Research's philosophy relies heavily on software re-use. Rather than inventing a new module, SARA is adapted to interface to other community products. For instance, SARA interfaces with the popular NMAP package for superior "Operating System fingerprinting". Also, SARA provides a transparent interface to SAMBA for SMB security analysis. SARA's features include ( the [SARA] indicates that this is a new or improved feature when compared to SAINT or SATAN): Built-in report writer (by subnet or by database) [SARA], Built-in summary table generator [SARA], Gateway to external programs (e.g., NMAP) [SARA], CGI-BIN vulnerability testing (Unix and IIS) [SARA], SSH buffer overflow vulnerabilities [SARA], Current Sendmail vulnerabilities [SARA], IMAPD/POPD buffer overflow vulnerabilities [SARA], Current FTP and WU-FTP vulnerabilities [SARA], Tooltalk buffer overflow vulnerbilities [SARA], Netbus, Netbus-2, and Back Orifice vulnerabilities [SARA], Improved Operating System fingerprinting [SARA], Firewall-aware [SARA], Weekly updates [SARA], Probing for non-password accounts [SARA], NFS file systems exported to arbitrary hosts, NFS file systems exported to unprivileged programs, NFS file systems exported via the portmapper, NIS password file access from arbitrary hosts, REXD access from arbitrary hosts, X server access control disabled, Arbitrary files accessible via TFTP, Remote shell access from arbitrary hosts, Writable anonymous FTP home directory.
Author:Advanced Research Corporation
Changes:Now compiles under Red Hat 6.0, fixed bug in login.sara.
File Size:362553
Last Modified:Aug 16 20:04:54 1999
MD5 Checksum:5dedcd00e8419aaa634b50cb1cf90da2

 ///  File Name: sara-2.0.6.tar.gz
Description:
SARA v2.0.6 - The Security Auditor's Research Assistant (SARA) is a third generation security analysis tool that is based on the SATAN model, conforms to the Open Source model, is covered by the GNU open license, fosters a collaborative environment, and is updated on a weekly basis. The author of SAINT, Bob Todd, recently joined Advanced Research and has been working non-stop to evolve SATAN and the original SAINT concept to a community oriented product (i.e, SARA) which will be available to all. Advanced Research's philosophy relies heavily on software re-use. Rather than inventing a new module, SARA is adapted to interface to other community products. For instance, SARA interfaces with the popular NMAP package for superior "Operating System fingerprinting". Also, SARA provides a transparent interface to SAMBA for SMB security analysis. SARA's features include ( the [SARA] indicates that this is a new or improved feature when compared to SAINT or SATAN): Built-in report writer (by subnet or by database) [SARA], Built-in summary table generator [SARA], Gateway to external programs (e.g., NMAP) [SARA], CGI-BIN vulnerability testing (Unix and IIS) [SARA], SSH buffer overflow vulnerabilities [SARA], Current Sendmail vulnerabilities [SARA], IMAPD/POPD buffer overflow vulnerabilities [SARA], Current FTP and WU-FTP vulnerabilities [SARA], Tooltalk buffer overflow vulnerbilities [SARA], Netbus, Netbus-2, and Back Orifice vulnerabilities [SARA], Improved Operating System fingerprinting [SARA], Firewall-aware [SARA], Weekly updates [SARA], Probing for non-password accounts [SARA], NFS file systems exported to arbitrary hosts, NFS file systems exported to unprivileged programs, NFS file systems exported via the portmapper, NIS password file access from arbitrary hosts, REXD access from arbitrary hosts, X server access control disabled, Arbitrary files accessible via TFTP, Remote shell access from arbitrary hosts, Writable anonymous FTP home directory.
Author:Advanced Research Corporation
File Size:353221
Last Modified:Aug 16 20:04:55 1999
MD5 Checksum:d3dc518777bed2aebb14870f9001ea75

 ///  File Name: sara-2.1.10.tar.gz
Description:
Security Auditor's Research Assistant (SARA) is a security analysis tool based on the SATAN model. It is updated frequently to address the latest threats. Checks for common old holes, backdoors, trust relationships, default cgi, common logins.
Author:Advanced Research Corporation
Homepage:http://www-arc.com/sara/
Changes:Added yet more http vulernability testing incl infosrch, Fixed Netscape buffer overflow detection, Fixed some of the GUI interfaces, Adding SARA Search capability, and Added Napster detection.
File Size:523220
Last Modified:Mar 13 03:27:50 2000
MD5 Checksum:0c7c601ca45fb8404f0a0bb4c8cf02cf

 ///  File Name: sara-2.1.11.tar.gz
Description:
Security Auditor's Research Assistant (SARA) is a security analysis tool based on the SATAN model. It is updated frequently to address the latest threats. Checks for common old holes, backdoors, trust relationships, default cgi, common logins.
Author:Advanced Research Corporation
Homepage:http://www-arc.com/sara/
Changes:Fixed CUI/GUI problem with Lynx and Netscape 4.72, Fixed problem with multiple reports with SNMP, Updated hosttyping database, and working on search capability.
File Size:523512
Last Modified:Mar 21 11:00:20 2000
MD5 Checksum:82ed0a159c1967cdfb6717f5c19b5f59

 ///  File Name: sara-2.1.12.tar.gz
Description:
Security Auditor's Research Assistant (SARA) is a security analysis tool based on the SATAN model. It is updated frequently to address the latest threats. Checks for common old holes, backdoors, trust relationships, default cgi, common logins.
Author:Advanced Research Corporation
Homepage:http://www-arc.com/sara/
Changes:Added test for Subseven backdoor, Fixed new CUI/GUI problem with Analysis Reporting, Supporting older Linux releases.
File Size:523163
Last Modified:Mar 23 17:20:27 2000
MD5 Checksum:a1bf6b21f12b97b21b7441ef31eb33f6

 ///  File Name: sara-2.1.13.tar.gz
Description:
Security Auditor's Research Assistant (SARA) is a security analysis tool based on the SATAN model. It is updated frequently to address the latest threats. Checks for common old holes, backdoors, trust relationships, default cgi, common logins.
Author:Advanced Research Corporation
Homepage:http://www-arc.com/sara/
Changes:Added daemon mode of SARA, Improved SMB analysis (fewer false positives), Added basic Shaft DDoS detection, Improved http.sara, fixed IRIX makefile problem, Added test for IRIX 5.x - 6.2 objectserver exploit.
File Size:452833
Last Modified:Apr 10 17:34:14 2000
MD5 Checksum:f90b1026bab5fdd05168f3496dc50b01

 ///  File Name: sara-2.1.2.tar.gz
Description:
Essentially an upgraded SATAN with a few more modern checks included. Checks for common old holes, backdoors, trust relationships, default cgi, common logins.
File Size:412191
Last Modified:Dec 11 16:02:04 1999
MD5 Checksum:2cc3b1a60b87480b04df6e40030626d9

 ///  File Name: sara-2.1.6.tar.gz
Description:
Security Auditor's Research Assistant (SARA) is a security analysis tool based on the SATAN model. It is updated frequently to address the latest threats. Checks for common old holes, backdoors, trust relationships, default cgi, common logins.
Author:Advanced Research Corporation
Homepage:http://www-arc.com/sara/
Changes:Added SARA extensions to SARA, Tweaked the documentation, and Fixed problem with mimetyping.
File Size:388022
Last Modified:Feb 2 17:46:37 2000
MD5 Checksum:65870c147d417ba03c3d9835219eaa49

 ///  File Name: sara-2.1.7.tar.gz
Description:
Security Auditor's Research Assistant (SARA) is a security analysis tool based on the SATAN model. It is updated frequently to address the latest threats. Checks for common old holes, backdoors, trust relationships, default cgi, common logins.
Author:Advanced Research Corporation
Homepage:http://www-arc.com/sara/
Changes:Distributed DOS test added, bug fixes.
File Size:487120
Last Modified:Feb 15 13:35:40 2000
MD5 Checksum:5d637056bbef5a9762eedc85f509bcce

 ///  File Name: sara-2.1.8.tar.gz
Description:
Security Auditor's Research Assistant (SARA) is a security analysis tool based on the SATAN model. It is updated frequently to address the latest threats. Checks for common old holes, backdoors, trust relationships, default cgi, common logins.
Author:Advanced Research Corporation
Homepage:http://www-arc.com/sara/
Changes:Added timing/delay command line option, Corrected minor bugs on the SARA menu, and proper credit is now given.
File Size:487053
Last Modified:Feb 23 23:47:45 2000
MD5 Checksum:4e0d43975f0a004907b7ada072866000

 ///  File Name: sara-2.1.8a.tar.gz
Description:
Security Auditor's Research Assistant (SARA) is a security analysis tool based on the SATAN model. It is updated frequently to address the latest threats. Checks for common old holes, backdoors, trust relationships, default cgi, common logins.
Author:Advanced Research Corporation
Homepage:http://www-arc.com/sara/
Changes:Windows Trinoo detection.
File Size:487853
Last Modified:Mar 2 00:24:04 2000
MD5 Checksum:76cf262b5dd0cbff6a919540479f5cb1

 ///  File Name: sara-2.1.9.tar.gz
Description:
Security Auditor's Research Assistant (SARA) is a security analysis tool based on the SATAN model. It is updated frequently to address the latest threats. Checks for common old holes, backdoors, trust relationships, default cgi, common logins.
Author:Advanced Research Corporation
Homepage:http://www-arc.com/sara/
Changes:Added the trojan_trinoo DDOS test, Added test for the sgi_fam buffer overflow vulnerability, Fixed false alarms from Web cache manager, Updated snmp reporting, and Added support for hpux 11.x.
File Size:546229
Last Modified:Mar 2 23:28:35 2000
MD5 Checksum:90118276af80170f3848b9771d9f47e0

 ///  File Name: sara-3.0.1.tar.gz
Description:
Security Auditor's Research Assistant (SARA) is a security analysis tool based on the SATAN model. It is updated frequently to address the latest threats. Checks for common old holes, backdoors, trust relationships, default cgi, common logins.
Author:Advanced Research Corporation
Homepage:http://www-arc.com/sara/
Changes:Added Search to SARA, Added sgi_pmcd vulnerability test, Added Solaris nisd vulnerability test, Added Compaq CIM server vulnerability test, Added numerous new cgi vulnerability tests, fixed bugs.
File Size:542636
Last Modified:Apr 25 16:39:44 2000
MD5 Checksum:9949f53709cea38044ea97328418b382

 ///  File Name: sara-3.0.2.tar.gz
Description:
Security Auditor's Research Assistant (SARA) is a security analysis tool based on the SATAN model. This release addresses the pirahna attack and the mstream DDOS detection. Added pirahna test (password vulnerability in Linux Web server), Updated http.sara to reduce false alarms on non 404 servers, updated sara.cf to avoid answerbook2 inadvertent denial of service, Added test for pcanywhere, Added test for mstream DDOS agents.
Author:Advanced Research Corporation
Homepage:http://www-arc.com/sara
File Size:553784
Last Modified:May 2 16:22:12 2000
MD5 Checksum:2320f69222dc0bbac465060dac0fb9b9

 ///  File Name: sara-3.0.3.tar.gz
Description:
Security Auditor's Research Assistant (SARA) is a security analysis tool based on the SATAN model. It is updated frequently to address the latest threats. Checks for common old holes, backdoors, trust relationships, default cgi, common logins.
Author:Advanced Research Corporation
Homepage:http://www-arc.com/sara
Changes:Fixed mstream test (PONG vs pong), Added test for timbuktu, Added tutorial for pcanywhere and timbuktu, and Incorporated Steve Rader's new relay.sara (many more tests).
File Size:480604
Last Modified:May 11 04:08:13 2000
MD5 Checksum:2255ff1bc3da9d7678c0ab8e64064f14

 ///  File Name: sara-3.0.4.tar.gz
Description:
Security Auditor's Research Assistant (SARA) is a security analysis tool based on the SATAN model. It is updated frequently to address the latest threats. Checks for common old holes, backdoors, trust relationships, default cgi, common logins.
Author:Advanced Research Corporation
Homepage:http://www-arc.com/sara
Changes:Added test for SunOS netpr vulnerability, Added test for counter http vulnerability, Added a range argument to target spec, and incorporated target specs in interactive mode.
File Size:481009
Last Modified:May 16 21:39:29 2000
MD5 Checksum:bce209252d9402ce9aeb389a230790e8

 ///  File Name: sara-3.0.5.tar.gz
Description:
Security Auditor's Research Assistant (SARA) is a security analysis tool based on the SATAN model. It is updated frequently to address the latest threats. Checks for common old holes, backdoors, trust relationships, default cgi, common logins.
Author:Advanced Research Corporation
Homepage:http://www-arc.com/sara
Changes:Addded depends.sara to minimize OS oriented false positives, Fixed login.sara to minimize false positives with JetDirect, Fixed multiple subnet scanning in firewall mode, Mitigated lockups in SARA daemon mode, Added new mode (vulnerabilities) to SARA Search, Updated http.sara to minimize FrontPage vulnerabilities, Added eight new tests to http.sara, and added test for kerberos.
File Size:483040
Last Modified:May 24 23:23:01 2000
MD5 Checksum:a1781be6dfb34e490946131f86c211c6

 ///  File Name: sara-3.1.0.tar.gz
Description:
Security Auditor's Research Assistant (SARA) is a security analysis tool based on the SATAN model. It is updated frequently to address the latest threats. Checks for common old holes, backdoors, trust relationships, default cgi, common logins.
Author:Advanced Research Corporation
Homepage:http://www-arc.com/sara
Changes:Included SARAPRO report writer into SARA, provided report writer to SATAN and SAINT users, added SANS-10 top vulnerability filter to report writer, corrected tutorial problem with pcanywhere and kerberos, and fixed man page to include the "-n" option.
File Size:606057
Last Modified:Jun 2 15:10:54 2000
MD5 Checksum:3bed9cf7e0c6cb4e94738e7f43fc654c

 ///  File Name: sara-3.1.1.tar.gz
Description:
Security Auditor's Research Assistant (SARA) is a security analysis tool based on the SATAN model. It is updated frequently to address the latest threats. Checks for common old holes, backdoors, trust relationships, default cgi, common logins.
Author:Advanced Research Corporation
Homepage:http://www-arc.com/sara
Changes:Fixed FrontPage test, Added more rpc program checking, Added test for tacacs server, Added test for Sub 7 backdoor, Added test for JetAdmin directory traversal, Added test for QPOP 3.53 vulnerability, Added test for Cisco Catalyst Vulnerability, Added test for Suse imap server, and bug fixes and performance updates.
File Size:571502
Last Modified:Jun 13 12:12:43 2000
MD5 Checksum:33375b51813c48fad56ed77eeb718b73

 ///  File Name: sara-3.1.2.tar.gz
Description:
Security Auditor's Research Assistant (SARA) is a security analysis tool based on the SATAN model. It is updated frequently to address the latest threats. Checks for common old holes, backdoors, trust relationships, default cgi, common logins.
Author:Advanced Research Corporation
Homepage:http://www-arc.com/sara
Changes:Added switch to slow the scan to minimize impact to slower networks, Added custom and multiple hosts on GUI (Target Mgt), Added test for INN 2.x.x vulnerability, Improved JetAdmin logic in http.sara, Improved the Custom attack level (see config/sara.cf), Improved printer logic in depends.sara, Fixed ftp.sara to properly report MS FTP status.
File Size:572245
Last Modified:Jun 18 23:17:19 2000
MD5 Checksum:1bd66108ad15d7be9fdebb33fe0d189d

 ///  File Name: sara-3.1.3.tar.gz
Description:
Security Auditor's Research Assistant (SARA) is a security analysis tool based on the SATAN model. It is updated frequently to address the latest threats. Checks for common old holes, backdoors, trust relationships, default cgi, common logins.
Author:Advanced Research Corporation
Homepage:http://www-arc.com/sara
Changes:Incorporated SANS recommended additions to SANS/SARA Top 10, test for vulnerability in wu-ftpd 2.6.0, bug fixes.
File Size:694656
Last Modified:Jul 6 02:11:36 2000
MD5 Checksum:0c8eba413a5e30f45c458cafe536392c

 ///  File Name: sara-3.1.4.tar.gz
Description:
Security Auditor's Research Assistant (SARA) is a security analysis tool based on the SATAN model. It is updated frequently to address the latest threats. Checks for common old holes, backdoors, trust relationships, default cgi, common logins.
Author:Advanced Research Corporation
Homepage:http://www-arc.com/sara
Changes:Improved SMB logic for Windows 9X, Improved processing for nfs exports for non world access, Corrected numerous typos in tutorial links (thanks to Walt Jones), Fixed corrupted udpscan.sara file, Fixed more problems with relay.sara, Updated tutorials and FAQ, Updated X Server logic to reduce false positives, Changed default start-up mode, and added Big Brother test.
File Size:542941
Last Modified:Jul 13 01:15:43 2000
MD5 Checksum:e69373c563d693f6b028273593d83d7e