iptables is the new packet alteration framework (firewall utility) for Linux 2.4. It is an enhancement on ipchains, and is used to control packet filtering, Network Address Translation (masquerading, port forwarding, transparent proxying), and special effects.
424f666dc4060b83dec77d7e5a13b381ee2e7d7c8731ed52d4ee5509e3815197
redir-httpd is an ultra-minimalist, non-RFC-compliant HTTP server that will ONLY issue redirects to another site. It's good for running on home systems that have permanent connectivity (i.e. DSL and cable-modem subscribers). It should be short enough to be easily understood (and thus audited for potential security issues), and still fairly robust.
f9d88a4cd09ef7c39dc3301fb37e374a6aa58d621506ed6948a2aef19eb42d95
Flitz is a DDOS tool which features spoofed ip/tcp/udp flood, flooding in parallel, distributed smurf attack and status report of the slave. With one stop command, you can stop all the slaves at once.
9346b94e8f0ca0ba742335190ffba0de3a9812e72964aefb7757767c7f553e0f
Wu-ftpd 2.6.0 mass scanner.
aa2dc9d24e9555a64b9794199e3fb1801e88083d39017b468c5588cbcd4b3c41
GNU tar follows symlinks blindly, a problem if you untar as root.
941d4baa8400f1fbed234f9bd2533ce2860e8137e6ad91ba30b49a049594c4f6
Redhat rpc.statdx mass exploit - scans for vulnerable hosts and implants a bindshell.
1b45bfc55a0f485af901ce8bd6d9f5e43c1bd304911f3aba1fa66a0b50409fd0
IPA is highly configurable IP accounting software for Free and Open BSD. It allows to make IP accounting based on IP Firewall and/or IP Filter accounting rules. In most cases IP Accounting Daemon is run on public servers, software routers, etc. It uses powerful IP Firewall and/or IP Filter accounting rules and based on its configuration allows to escape from writing scripts to manage network accounting.
563b0649befc9c9aa73a5dc18205c7cefadacb7078a25a04e71219dd156f6b8f
Netsed v0.01b brings sed functionality to the network layer, allowing you to change the contents of packets traveling through your network on the fly and in a completely transparent manner. It features basic expressions and dynamic filtering, and cooperates with ipfwadm/ipchains transparent proxy rules to pick specific packets.
a04f6b235d787b1efd96ecdb398e6c8456301dbf965840e6fcbad36c68372dce
auditd is part of the Linux Kernel Auditing Facility (KAD). It will capture auditing trails created by the kernel auditing facility from /proc/audit, filter them, and save them in specific log files. Either a kernel patch or loadable module must be installed for the daemon to be useful, both of which are included.
6c5c09a62ccddf426fb43c09643ad20d8cd4c7c49e0c9348d53259249bcbb305
fwlogwatch analyzes the ipchains, netfilter, or iptables packet filter logfiles and generates text and HTML summaries. Features realtime anomaly alerting capability, an interactive report generator, and the ability to cut off attacks by adding firewall rules.
05ef7d6d6322de7a8721e7a368a05759a63e3ae1beed75f0f8794322abd7243e
Logtool is a syslog file parser, report generator, and monitoring utility. It takes syslog (and syslog compatible) logfiles as input from stdin, and depending on command line switches and/or config file settings, will parse and filter out unwanted messages from the logfile accordingly, and generate output in ANSI color, formatted ASCII, CSV (for spreadsheets), or HTML format. It is very handy for use in automated nightly reports, and online monitoring of logfile activity. It comes with some simple example scripts and documentation.
51269d444ab0a4ca6c3fb0275db05ab7bf72991eb58b375b908cb07b99386e25
Knetfilter is a KDE gui application designed to manage the netfilter functionalities that will come with the new kernel 2.4.x. In Principal, all standard firewall system administration activities can be done just using knetfilter. But there is not just a GUI to iptables command line, it is possible also some monitoring via a tcpdump interface.
4a732257225576206dbb9a67e2f9818f0f814b0e9e93ea2d122c0620a53bd98d
SubNetwork Explorer is a network scanning tool that checks subnets of a network for anonymous FTP, CUPS, Netbios, and SunRPC ports. It uses 'fork()' to scan all of the subnets at the same time.
128526167796733d82ded38f9d72649acd500dee160a084d02f60c3e62710b6d