.:[ packet storm ]:.
                               
trust nothing
trust nothing

 Section:  .. / sniffers / snort  /

Snort is an excellent intrusion detection system and packet sniffer for many unix platforms. Homepage is http://www.clark.net/~roesch/security.html

Page 9 of 10
<< 1 2 3 4 5 6 7 8 9 10 >> Files 200 - 225 of 235
Currently sorted by: Last ModifiedSort By: File Name, File Size

 ///  File Name: snort-1.6-0.src.rpm
Description:
Snort 1.6.0 source rpm.
Author:Martin Roesch
Homepage:http://www.clark.net/~roesch/security.html
File Size:221679
Last Modified:Mar 29 16:04:00 2000
MD5 Checksum:eb7b1fd1ba6c49cc3401c93abd92de41

 ///  File Name: snort-1.6-0.i386.rpm
Description:
Snort 1.6.0 i386 binary rpm.
Author:Martin Roesch
Homepage:http://www.clark.net/~roesch/security.html
File Size:114939
Last Modified:Mar 28 16:04:00 2000
MD5 Checksum:1898b2e2b5d8b53d8bb48c2e7e847687

 ///  File Name: snort_rules.txt
Description:
Writing Snort Rules (Updated for Snort 1.6) - How To write Snort rules for intrusion detection and keep your sanity.
Author:Martin Roesch
Homepage:http://www.clark.net/~roesch/security.html
File Size:38811
Last Modified:Mar 28 15:26:58 2000
MD5 Checksum:e526e04c575d4373360524c66bdb103f

 ///  File Name: snort-1.6.tar.gz
Description:
Snort is a libpcap-based packet sniffer/logger which can be used as a lightweight network intrusion detection system. It features rules based logging and can perform content searching/matching in addition to being used to detect a variety of attacks and probes, such as buffer overflows, stealth port scans, CGI attacks, SMB probes, and much more. Snort has a real-time alerting capabilty, with alerts being sent to syslog, a seperate "alert" file, or as WinPopup messages via Samba's smbclient.
Author:Martin Roesch
Homepage:http://www.clark.net/~roesch/security.html
Changes:Added FlexResp (active response) plugin to fool OS fingerprinting, Added support for "stealthed" network interfaces, greatly improved the speed of the content pattern matcher, Token Ring and FDDI decoder support, Snort ported to Tru64/Alpha, IRIX 6.X, and AIX, Output plugins added (modular output system), and Snort man page now ships with the distribution.
File Size:215059
Last Modified:Mar 21 06:49:34 2000
MD5 Checksum:48193b9ff13a0ce50329ce17272eac59

 ///  File Name: Guardian.tar
Description:
Guardian watches the output from Snort, a lightweight intrustion detection system, and uses ipchains to deny any further packets from the attacker to get to the system.
Author:Anthony Stevens
Homepage:http://www.clark.net/~roesch/security.html
File Size:20480
Last Modified:Mar 1 16:06:33 2000
MD5 Checksum:ba8f89a0580e09f73cb8cbe004344863

 ///  File Name: snort2html
Description:
Snort2HTML v1.0 converts Snort Intrusion Detection System logs into nicely-formatted HTML.
Author:Daniel Swan
Homepage:http://www.clark.net/~roesch/security.html
File Size:8605
Last Modified:Mar 1 15:57:55 2000
MD5 Checksum:1e1666d5718802a2356d14d0af995d12

 ///  File Name: snort-1.5.2.tar.gz
Description:
Snort is a libpcap-based packet sniffer/logger which can be used as a lightweight network intrusion detection system. It features rules based logging and can perform content searching/matching in addition to being used to detect a variety of attacks and probes, such as buffer overflows, stealth port scans, CGI attacks, SMB probes, and much more. Snort has a real-time alerting capabilty, with alerts being sent to syslog,a seperate "alert" file, or as WinPopup messages via Samba's smbclient.
Author:Martin Roesch
Homepage:http://www.clark.net/~roesch/security.html
Changes:dded typedef checks to configure.in because Sun thought it'd be fun to define the u_int*_t variables in Solaris differently than the rest of the universe.
File Size:155462
Last Modified:Mar 1 15:52:32 2000
MD5 Checksum:d24df78a6f5b3bfb28f6f63d5736d864

 ///  File Name: snort-1.6-beta10.1.tar.gz
Description:
Snort is a libpcap-based packet sniffer/logger which can be used as a lightweight network intrusion detection system. It features rules based logging and can perform content searching/matching in addition to being used to detect a variety of attacks and probes, such as buffer overflows, stealth port scans, CGI attacks, SMB probes, and much more. Snort has a real-time alerting capabilty, with alerts being sent to syslog,a seperate "alert" file, or as WinPopup messages via Samba's smbclient.
Author:Martin Roesch
Homepage:http://www.clark.net/~roesch/security.html
Changes:Logging was broken in this mornings snort release, snort-1.6-beta10.
File Size:185811
Last Modified:Feb 28 18:35:21 2000
MD5 Checksum:3c8e29fe68bd780e9a422a7a9dc722c3

 ///  File Name: snort-1.6-beta10.tar.gz
Description:
Snort is a libpcap-based packet sniffer/logger which can be used as a lightweight network intrusion detection system. It features rules based logging and can perform content searching/matching in addition to being used to detect a variety of attacks and probes, such as buffer overflows, stealth port scans, CGI attacks, SMB probes, and much more. Snort has a real-time alerting capabilty, with alerts being sent to syslog,a seperate "alert" file, or as WinPopup messages via Samba's smbclient.
Author:Martin Roesch
Homepage:http://www.clark.net/~roesch/security.html
Changes:Modified minfrag proprocessor to only catch tiny frags, added -C command line switch to print packet payloads as ASCII only, bug/crash fixes.
File Size:185735
Last Modified:Feb 28 16:11:22 2000
MD5 Checksum:6f6d91584255c3f296c62525739110c4

 ///  File Name: address_config.sh
Description:
Sten Kalenda wrote this handy script for laptop users that change their IP address frequently. This automates the process of updating your Snort rules file.
File Size:728
Last Modified:Feb 26 21:50:44 2000
MD5 Checksum:9da2259b0d65e3ea04f989f9d1d14152

 ///  File Name: snort-1.6-beta8.tar.gz
Description:
Snort is a libpcap-based packet sniffer/logger which can be used as a lightweight network intrusion detection system. It features rules based logging and can perform content searching/matching in addition to being used to detect a variety of attacks and probes, such as buffer overflows, stealth port scans, CGI attacks, SMB probes, and much more. Snort has a real-time alerting capabilty, with alerts being sent to syslog, a seperate "alert" file, or as WinPopup messages via Samba's smbclient.
Author:Martin Roesch
Homepage:http://www.clark.net/~roesch/security.html
Changes:This is a *BETA* release. Bleeding edge users only! Added many patches, Added IPv6 counter, Added content-list rules, fixes portscan preprocessor, added time based logfile naming, Streamlined the "fast" alert printout function, new quiet mode, many bugfixes.
File Size:179468
Last Modified:Feb 8 13:06:57 2000
MD5 Checksum:732d9c44c00829d992ccc94b56a14855

 ///  File Name: vision.conf
Description:
Snort rules from the arachNIDS IDS signature database. Last updated 1/25/2000.
Author:Max Vision
Homepage:http://whitehats.com/ids/
File Size:27206
Last Modified:Jan 25 21:08:56 2000
MD5 Checksum:36f5ccc05b3b0b089f8d738e225cf0cd

 ///  File Name: snort-1.5.1.tar.gz
Description:
Snort is a libpcap-based packet sniffer/logger which can be used as a lightweight network intrusion detection system. It features rules based logging and can perform content searching/matching in addition to being used to detect a variety of attacks and probes, such as buffer overflows, stealth port scans, CGI attacks, SMB probes, and much more. Snort has a real-time alerting capabilty, with alerts being sent to syslog, a seperate "alert" file, or as WinPopup messages via Samba's smbclient.
Author:Martin Roesch
Homepage:http://www.clark.net/~roesch/security.html
Changes:fixed a problem with pass rules not being applied properly, fixed slackware 4 install problem, fixed banner output for the -V option, Added packet buffer cleanup code to all protocol decoders, and Added a Snort man page.
File Size:143583
Last Modified:Jan 25 20:47:03 2000
MD5 Checksum:fbfb89265c1a6804091191ff2bb8f626

 ///  File Name: snort-1.5.tar.gz
Description:
Snort is a libpcap-based packet sniffer/logger which can be used as a lightweight network intrusion detection system. It features rules based logging and can perform content searching/matching in addition to being used to detect a variety of attacks and probes, such as buffer overflows, stealth port scans, CGI attacks, SMB probes, and much more. Snort has a real-time alerting capabilty, with alerts being sent to syslog, a seperate "alert" file, or as WinPopup messages via Samba's smbclient.
Author:Martin Roesch
Homepage:http://www.clark.net/~roesch/security.html
Changes:detection and preprocessor plugins (think packet sniffing API), rule file variables and includes, preprocessors, TCP session logging, new detection capabilities (IP options, multiple content strings per rule), new protocol decoders (I4L-ISDN, NULL), new http preprocessor normalizes web traffic, defeating evasive web scanners like whisker.pl, faster and more accurate IP and TCP option decoders, etc.
File Size:135647
Last Modified:Dec 9 15:06:41 1999
MD5 Checksum:3272654ca7edbdf195f2532a7047ce7d

 ///  File Name: snortlog.pl
Description:
snortlog.pl is a Perl script which looks up the hostnames of machines mentioned in a snort IDS alert and outputs the relavent information in a nice list.
Author:Angelos Karageorgiou
File Size:1682
Last Modified:Dec 3 16:13:37 1999
MD5 Checksum:20ff33913adcad31119cbb49ca183939

 ///  File Name: snortpres2.ppt
Description:
PowerPoint presentation on Snort - Lightweight Intrusion Detection for Networks.
Author:Martin Roesch
Homepage:http://www.clark.net/~roesch/security.html
File Size:53760
Last Modified:Dec 3 16:13:37 1999
MD5 Checksum:6a73f235695b70f58a92193d5dbbf555

 ///  File Name: snort-1.3.1.tar.gz
Description:
Version 1.3.1 of Snort, the lightweight network intrusion detection system. Version 1.3.1 fixes an annoying crash bug, plus enhances a number of features of the program. Invalid ICMP types/codes can now be filtered or monitored, the tcpdump file playback facility can use BPF filters, and the packet payload size check keyword now accepts greater than/less than modifiers.
Author:Martin Roesch
File Size:111999
Last Modified:Oct 13 13:28:02 1999
MD5 Checksum:65de767f12998b089ad9d4c87a445b25

 ///  File Name: snort-1.3.tar.gz
Description:
Snort 1.3, the lightweight network intrusion detection system. This version has a number of new features, including four new command line switches, three new rule options, two new rule operators, performance enhancements, and bug fixes. The official Snort homepage is here
File Size:110832
Last Modified:Sep 27 17:12:56 1999
MD5 Checksum:01ccf3ec337bd4e71392376e4b78fa14

 ///  File Name: snort-1.0.1-lib
Description:
This snort-lib ruleset for the latest version of snort has over 150 rules.
Author:Martin Roesch
File Size:12165
Last Modified:Aug 16 20:13:56 1999
MD5 Checksum:3923d6f1e853f76bc202329e5d00ba72

 ///  File Name: snort-1.0.1.tar.gz
Description:
Snort 1.0.1 - Snort is a libpcap-based packet sniffer/logger which can be used as a lightweight network intrusion detection system. It features rules based logging which can perform content searching/matching and may be used to detect a variety of attacks and probes, such as buffer overflows, stealth port scans, CGI attacks, SMB probes, and much more. Snort has a real-time alerting capabilty, with alerts being sent to syslog or a seperate "alert" file.
Author:Martin Roesch
Changes:Lots of little bug fixes, plus resolved some issues on big endian hardware, fixed some bugs under Solaris to make the system compile cleanly "out of the box". Also added HP-UX and S/Linux support, new command line switch "-x" to explicitly turn on IPX decoding (such as it is) as a sanity measure for people in mixed protocol environments and added packet summary statistics upon exit.
File Size:84225
Last Modified:Aug 16 20:13:56 1999
MD5 Checksum:4a640182d941d2778707d42f7bb810cc

 ///  File Name: snort-0.99b1.tar.gz
Description:
Snort v0.99b1 is a packet logger that reads and parses packets from the link layer through the transport layer, dumping explicit header information along the way. Good logging capabilities, useful for IDS, debugging network code. It now supports rules based logging and tracks conversations better, incorporates content based logging and automatic rules sorting, includes lots of bugfixes, and has improved ICMP filenames.
Author:Martin Roesch
File Size:68489
Last Modified:Aug 16 20:13:52 1999
MD5 Checksum:c1febb075d7af9591a32c591c7b78633

 ///  File Name: snort-0.99b2.tar.gz
Description:
Snort v0.99b2 is an extremely versatile packet logger. This version features dramatic speed improvements, a more logically laid out packet header print out, packet statistics, fragment detection, and more complete IP header decoding. One of the few "5 Star, Must Have!" programs around.
Author:Martin Roesch
File Size:70749
Last Modified:Aug 16 20:13:52 1999
MD5 Checksum:fe8a945aa5094e7e6ba2590889a4986a

 ///  File Name: snort-0.99b3.tar.gz
Description:
Snort is an extremely versatile packet logger. This version features dramatic speed improvements, a more logically laid out packet header print out, packet statistics, fragment detection, and more complete IP header decoding. Improved timestamping (down to the millisecond) implemented. This release has TCP and IP option decoding, and some new rules stuff. You can now specify port ranges (or greater than/less than) and TCP flags in rules. This allows you to do things like this: alert tcp any any -> 192.168.1.0/24 :1024 {SF} <SYN FIN scan on priv ports!> which will alert on all TCP traffic below port 1024 on both SRC and DST IP or this: alert tcp any any -> 192.168.1.0/24 6000:6010 <X access attempt!> which will pick out inbound traffic going ports 6000 thru 6010. Also includes bugfixes, cleaned up fragment printout routines, truncated packet fragments get dumped in their own file, rules processor routine recoded and more flexible, much more. Several important bugfixes in this release, plus recoded IP/TCP option decoding, revised packet printout routines, and now logs illegal TCP and IP options as well in an IP_BOGUS log file.
Author:Martin Roesch
File Size:71308
Last Modified:Aug 16 20:13:52 1999
MD5 Checksum:eb9bca86631e991cc0813d3fa45f4ae3

 ///  File Name: snort-0.99rc3.tar.gz
Description:
Snort v0.99rc3 is an extremely versatile packet logger. This version features dramatic speed improvements, a more logically laid out packet header print out, packet statistics, fragment detection, and more complete IP header decoding. Improved timestamping (down to the millisecond) implemented. This release has TCP and IP option decoding, and some new rules stuff. You can now specify port ranges (or greater than/less than) and TCP flags in rules. This allows you to do things like this: alert tcp any any -> 192.168.1.0/24 :1024 {SF} <SYN FIN scan on priv ports!> which will alert on all TCP traffic below port 1024 on both SRC and DST IP or this: alert tcp any any -> 192.168.1.0/24 6000:6010 <X access attempt!> which will pick out inbound traffic going ports 6000 thru 6010. Also includes bugfixes, cleaned up fragment printout routines, truncated packet fragments get dumped in their own file, rules processor routine recoded and more flexible, much more. Several important bugfixes in this release, plus recoded IP/TCP option decoding, revised packet printout routines, and now logs illegal TCP and IP options as well in an IP_BOGUS log file.
Author:Martin Roesch
File Size:75469
Last Modified:Aug 16 20:13:52 1999
MD5 Checksum:c9682635293ea41d6a1b0c74ed63280a

 ///  File Name: snort-0.99rc5-lib
Description:
snort-0.99rc5-lib is a set of example Snort rules. It's a short one, about 43 rules total, but it gives a good overview of the basic rule types and how to use the pattern matcher properly. This version of snort-lib includes a new buffer overflow (named) and some other stuff.
Author:Martin Roesch
File Size:3482
Last Modified:Aug 16 20:13:52 1999
MD5 Checksum:37499db53c56bbcc8db438ed41e40a43