Network Promiscuous Ethernet Detector, rewriten with Libnet/libpcap so it works on FreeBSD, OpenBSD, and linux, possibly more. neped scans your subnet and detects promiscuous boxes that might be running sniffers or similar applications, using hacked ARPs (non broadcast), only listened by promiscuous ethernets.
ee928946f9d5187fe8a5c6224ad7ebf4Based on my neped-libnet source, just figures out what boxens in your lan run IP stack and are in the same subnet with you.
e1dbafbd87c7a076abc08ef5c3f09e67Named version scanner. Due to several vulneriabilities found in BIND daemon, it's always good to know what bind versions you're running.
91698f940780ed317b1bd33c56b5a4b3Unix backdoor which pretends to be a http daemon.
620e6dc8e252318465de768315e7f8beSimplified Restricted Shell 0.1.3. Major purpose of this shell is to maintain 'not permitted explictly then not allowed' policy on machines which provide shell access to users, which can not be trusted, while trying to keep KISS rule. Of course you should carefully check up and configure applications, which you allow your users to run, otherwise it still would be trivial to break your policy with badly configured pine or lynx for example. Some day this will be a full-fledged user tracking system.
946a141076b90d4fa4c42f766fdded35The foundation for a "Windows Deception Toolkit". This package contains "fake" telnet and sendmail daemons, coded in Perl, runs on Windows. Cool concept!
7af6c15c79e3bdd0eced2daaf99e7253spoof v0.0 - TCP packet spoofing library (alpha code).
e0615cee970538b934743a439172dea1Latest release of Spoof Library project by Fyodor, now supports IP/UDP/TCP spoofing.
7e54fbdac4bbb5cbd22bac2d190e9ef4Sample code showing how to send spoofed packets (for Linux with BSd compatibility in mind).
979e7fd6e6c05531e657a73dc51fa9c2Sample for very simple sniffer.
7b50b9c717f2609dd207a1fbeb4b8babtcplogd is a stealth-scan detector (TCP only). Configurable. 15k.
baf8a0fa54e27de371f53dfec78ee7b2tcplogd is a stealth-scan detector (TCP only). Configurable. 15k.
696d26b61c7ef65d41130da7b3f3795ctcplogd is a stealth-scan detector (TCP only). Configurable. 15k.
07070bb2a2c8cace49a450bcaddae3f1tcplogd v0.1.4 is a stealth-scan detecting daemon that is designed to detect most nmap sX/sN/sS scans, queso and other network scanners. This release includes fixes for the port range bugs.
24e3d3179645e3d05f0432435bcff939tcplogd is a stealth-scan detector (TCP only). Configurable. 15k.
1260c11424dfbae48f54794098c66cc7tcplogd is a stealth-scan detector (TCP only). Configurable. 15k.
bdc1c88c5d082d561cf1f457750ced90tcplogd v0.1.5pre1 is a stealth-scan detecting daemon that is designed to detect most nmap sX/sN/sS scans, queso and other network scanners. "trusted hosts" feature added in this release.
e21ce321839a92c555a43f0e96e103a1tcplogd v0.1 is a stealth-scan detecting daemon that is designed to detect most nmap sX/sN/sS scans, queso and other network scanners.
2789fdec90c42eaaeb46b976d28d80e9tcplogd v0.0 is a stealth-scan detector (TCP only). Configurable. 15k.
4aa8e83e36457d4800eb2bd71e7286faicmpmon will show you all ICMP packets reaching your box, which could be useful in detecting attacks/portscans sometimes.
d5afe56be732dcec59d8890f134620f6Snippet of code that will tell you whether remote device is a cisco router or not using cisco's indent port (1999).
6989be7342b251d6a0e411bed93fae94Squid_connect : shows the way to exploit squid proxy servers to hide your identity.
44276857394487c6a40bea5886c5486dRetrives netbios name from remote Windog (as described in Hobbit'sdocument cifs.txt).
9bd89a4c42958c2fa6cac594551cf171Sample daemon, which hooks on the UDP ports, listens and records all incomming packets. (could play ping/pong with them as well).
2aaf763fdf805c915e6d94187aa8e42fRetrieves netbios name from remote Windog (as described in Hobbit's document cifs.txt). Several bugfixes in this release, including timeouts.
645a6354746400aba046534273f6b376