Categories

Visit BadVista.org Visit PlayOgg.org Visit DefectiveByDesign.org

scanlogd

'scanlogd' is a TCP port scan detection tool which attempts to log all portscans of a host to the syslog, in a secure fashion. It was designed to illustrate various attacks an IDS developer has to deal with; thus, unlike some other port scan detection tools, 'scanlogd' is designed to be totally safe to use. The current released can be built with support for one of several packet capture interfaces. In addition to the raw socket interface on Gnu/Linux, scanlogd is now aware of libnids and libpcap.

The author discourages the use of libpcap. If you're on a system other than GNU/Linux and/or want to monitor the traffic of an entire network at once, he suggests using libnids in order to handle fragmented IP packets.

Last updated 3 Jun, 2004


User level: Submit a level

User Rating:

Homepage

License(s) :

SimplePermissiveNoNonWarranty

Rate it!

 

About

Leadership
Requirements
  • libnids (Weak Prerequisite)
  • libpcap (Weak Prerequisite)
Related Projects

AIDE, Firestorm, Gtk-nocker, Knocker, Multiscan, Port Scan Attack Detector, SNORT, TCP Re-engineering, Tiger, Tripwire

Versions

2.2.4

2.2.4 stable released 2004-06-02

User Community and Support

User manpage included and available in HTML format from http://www.openwall.com/scanlogd/scanlogd.8.shtml

General Resources
Support Resources

Development

Developer Resources
Bug Tracking Resources
 

Please send comments on these web pages to bug-directory@fsf.org, send other questions to info@fsf.org.

Copyright © 2000 - 2008 Free Software Foundation, Inc., 51 Franklin Street, 5th Floor, Boston, MA 02110-1301, USA

The copyright licensing notice below applies to this text. Any software described in this text has its own copyright notice and license, which can usually be found in the distribution itself.

Permission is granted to copy, distribute, and/or modify this document under the terms of the GNU Free Documentation License, Version 1.2 or any later version published by the Free Software Foundation; with no Invariant Sections, with no Front-Cover Texts, and with no Back-Cover Texts.