|
(Page 1 of 4) 1 2 3 4 Next > Category: System Security Management » Monitoring ASDIC Added 2006-10-13 ASDIC is a system for advanced traffic and log analysis. It helps you to determine what traffic there is in your network. You can look at ASDIC as a reverse firewall. Input unstructured traffic information and output a rule set. ASDIC can analyze logs from any firewall or router, or sniff the network by itself. JAAScois PC Monitor v1.0 Added 2006-09-10 » Protecting system and windows startup » Protecting internet explorer from hijacks & spyware » Preventing access to computer settings » Internet filtering for web sites , chat rooms and e-mail Log 2 Google Earth Added 2006-07-26 Visualize any logfile (firewall / apache you name it) in near realtime on Google Earth. See where you traffic is coming and going to. Astral III Added 2006-06-11 This version of Astral is easy to use and equipped to contribute to the process of tap and trace. Capable of correlating the dump by frame id, sequence number, protocol, ethertype, IP address, or simply view the entire capture. Record each step of the trace, in order to preserve the most accurate timeline possible. Set a unique username and password, in order to deny unauthorised access to the trace logs. Take a snapshot of all local traffic using a dialup, ethernet, or wireless network adapter. Developed for the Microsoft Windows NT platform. WinPcap 3.1 or better is required. Aeer Ports Statistics Viewer (Open Source) Added 2006-05-25 Aeer Ports Statistics Viewer Aeer is name of a Tree in Persian Country ( Egypt ) Introduction =========== Ports statistics is utility that shows protocol statistics and current TCP/IP - UDP/IP network connections. This tool shows all open ports found on the current machine. Each open port represents a service/application; if one of these services can be 'exploited', the hacker could gain access to that machine. Therefore, it's important to close any port that is not needed. Ports statistics shows these properties fields including: Pid (Global process identifier that you can use to identify a process. The value is valid from the time a process is created until it is terminated. ) Port Number (Local port number connections.) Port Type (TCP/UDP) Processes (Contains Processes Names.) Host Address (Host IP Address.) Remote Port (Remote port number.) Status Port Processes File (Show Path to the executable file of the process. Example: C:\WINDOWS\EXPLORER.EXE. ) File Length (This is the length of Processes file names. This method Block the windows file spoofing (WFS) trick. For more see http://www.rootkit.com/newsread_print.php?newsid=486.) Processes Start Time (obtains timing information about a specified process.) Processes Running Level (Returns the user name and the domain name under the owner of this process.) SID (Returns the security identifier descriptor for this process.) Processes Command Line (Command line used to start a specific process, if applicable. This property is new for Windows XP. For example if attacker exactable telnet process like this: Telnet 127.0.0.1 12345.) Aeers Download Link: https://www.rootkit.com/vault/neocrackr/Aeer.rar E-mail: Thecrackers_group <>at<> yahoo <>dot<> ca THE CRACKERS GROUP INC 2006 (C) , Nima Bagheri SwitchSniffer Added 2006-05-20 >>> Overview SwitchSniffer is a program that can scan your switched LAN for up hosts and can reroute and collect all packets without the target users' recognition. It can also detect the arpspoofer program running on the network and block user definable sessions like firewall. If you use this program in tandem with any sniffer program, you can capture and see the users IDs and passwords on a switched network. That is, SwitchSniffer enables you to monitor all the packets and all the hosts on a switch network. >>> SwitchSniffer has the following features: SwitchSniffer can poll and collect all the packets on the switched LAN. SwitchSniffer can scan and display the active hosts on the LAN quickly, and automatically. While spoofing ARP tables, SwitchSniffer can act as another gateway (or ip-forwarder) without other users' recognition on the LAN.' It can collect and forward packets by selecting inbound, outbound, and both to be sent to the Internet. An ARP table is recovered automatically in about 30 seconds. But, SwitchSniffer can keep spoofing continuously by updating the target computers ARP table more frequently. If one or more network interface cards are installed on a computer, you can choose which NIC you would like SwitchSniffer to scan and spoof through. SwitchSniffer can display information about the amount of data transferred to and from the internet. SwitchSniffer can detect if any computer on the LAN is running an arpspoofer program. SwitchSniffer can filter: sessions, local hosts, and remote hosts. The installation of the winpcap driver is not necessary for SwitchSniffer. SwitchSniffer can manage the local hosts based on MAC Address. SwitchSniffer can act as a plug-and-played router. SwitchSniffer can export the data of view into an excel file. >>> SwitchSniffer has the following benefits: SwitchSniffer can find the hidden hosts on the LAN, which is not found by IP-Scanners. SwitchSniffer can find if abnormal hosts are connected to your wireless network. SwitchSniffer protects your network from abnormal users. SwitchSniffer can check if there are abnormal packets on the LAN. SwitchSniffer allows you to capture user IDs, passwords, chat sessions and web sessions etc., on the switched network through the use of a sniffer application. SwitchSniffer can block the local hosts based on MAC Address. SwitchSniffer can resolve the problem of IP Collision. SwitchSniffer can find out the country name by ip address on remote. SwitchSniffer enables you to monitor all the packets on a switch network. arpcheck-1.8 Added 2006-05-19 arpcheck checks /proc/net/arp for MAC/IP combinations and compares them to a static or dynamic MAC list. If something does not fit, you'll get an alarm which will also be logged. You can also run custom scripts/commands like adding iptables rules and so on. This is very useful, if you're using the tool on a router with multiple interfaces (e.g. WAN, LAN, DMZ) and want to check if anyone from your clients is evil and does some arpspoofing (mitm) or changes his IP. OSSEC Added 2006-05-12 OSSEC HIDS is an Open Source Host-based Intrusion Detection System. It performs log analysis and correlation, integrity checking, rootkit detection, time-based alerting and active response. It runs on most operating systems, including Linux, OpenBSD, FreeBSD, Solaris and Windows. FileMonService Added 2006-05-10 Windows File Monitor Service : created, changed, deleted, renamed and created-auto-removed on DotNet(.NET) darc - Distributed Aide Runtime Controller Added 2006-04-24 darc is a multi-threaded Python application designed for managing AIDE installations in large heterogeneous networks. It provides centralized database management, unified reporting, and eliminates the need to maintain Aide databases and binaries on read-only media. Browse by category |
|
|
Privacy Statement |