Top > All Packages in Directory > scanlogd

scanlogd - TCP port scan detection tool

'scanlogd' is a TCP port scan detection tool which attempts to log all portscans of a host to the syslog, in a secure fashion. It was designed to illustrate various attacks an IDS developer has to deal with; thus, unlike some other port scan detection tools, 'scanlogd' is designed to be totally safe to use. The current released can be built with support for one of several packet capture interfaces. In addition to the raw socket interface on Gnu/Linux, scanlogd is now aware of libnids and libpcap.

The author discourages the use of libpcap. If you're on a system other than GNU/Linux and/or want to monitor the traffic of an entire network at once, he suggests using libnids in order to handle fragmented IP packets.

Obtaining

Web pagehttp://www.openwall.com/scanlogd/
Source tarballhttp://www.openwall.com/scanlogd/scanlogd-2.2.4.tar.gz
Version 2.2.4 (stable) released on 2004-06-02
Licensed under SimplePerissiveNoNonWarranty.
This is not a GNU package.

Documentation

User manpage included and available in HTML format from http://www.openwall.com/scanlogd/scanlogd.8.shtml
Support contacts

Help List<solar@openwall.com>
Developer List<solar@openwall.com>
Bug List<solar@openwall.com>
SupportPaid consulting and system administration available from Openwall, Inc at

Project contacts

Maintainers
Developers

Related information

Interfacesdaemon
Source languagesC
Weak prerequisiteslibnids, libpcap
Related programsSNORT, Port Scan Attack Detector, Tiger, Gtk-nocker, Knocker, AIDE, Firestorm, Multiscan, Tripwire

Entry information

License verified byJanet Casey <jcasey@gnu.org> on 2004-06-03
Entry compiled byJanet Casey <jcasey@gnu.org>

Categories



The copyright licensing notice below applies to this text. The software described in this text has its own copyright notice and license, which can usually be found in the distribution itself.

Copyright © 2000, 2001, 2002, 2003, 2004 Free Software Foundation, Inc.

Permission is granted to copy, distribute, and/or modify this document under the terms of the GNU Free Documentation License, Version 1.1 or any later version published by the Free Software Foundation; with no Invariant Sections, with no Front-Cover Texts, and with no Back-Cover Texts. A copy of this license is included in the file COPYING.DOC.

Please report any problems in this page to bug-directory@gnu.org, or find out how you can help fix them.

The FSF provides this directory as a service to the free software community. Please consider donating to the FSF to help support this project.