SEARCH
NEW RPMS
DIRECTORIES
ABOUT
FAQ
VARIOUS
BLOG

 
 

psad rpm build for : Mandrake 10.X. For other distributions click psad.

Name : psad
Version : 1.4.1 Vendor : MandrakeSoft
Release : 2mdk Date : 2005-03-15 11:22:30
Group : System/Servers Source RPM : psad-1.4.1-2mdk.src.rpm
Size : 1.28 MB
Packager : Lenny Cartier < lenny_mandrakesoft_com>
Summary : Psad analyzses iptables log messages for suspect traffic
Description :
Port Scan Attack Detector (psad) is a collection of four lightweight
system daemons written in Perl and C that are designed to work with
Linux firewalling code (iptables in the 2.4.x kernels, and ipchains
in the 2.2.x kernels) to detect port scans. It features a set of highly
configurable danger thresholds (with sensible defaults provided),
verbose alert messages that include the source, destination, scanned
port range, begin and end times, TCP flags and corresponding nmap
options (Linux 2.4.x kernels only), email alerting, and automatic
blocking of offending IP addresses via dynamic configuration of
ipchains/iptables firewall rulesets. In addition, for the 2.4.x kernels
psad incorporates many of the TCP, UDP, and ICMP signatures included in
Snort to detect highly suspect scans for various backdoor programs
(e.g. EvilFTP, GirlFriend, SubSeven), DDoS tools (mstream, shaft), and
advanced port scans (syn, fin, Xmas) which are easily leveraged against
a machine via nmap. Psad also uses packet TTL, IP id, TOS, and TCP
window sizes to passively fingerprint the remote operating system from
which scans originate.

RPM found in directory: /vol/rzm6/linux-mandriva/official/10.2/i586/media/contrib

Content of RPM  Changelog  Provides Requires

Download
ftp.icm.edu.pl  psad-1.4.1-2mdk.i586.rpm
     Search for other platforms
psad-1.4.1-2mdk.sparc.rpm
psad-1.4.1-2mdk.alpha.rpm
psad-1.4.1-2mdk.ppc.rpm
psad-1.4.1-2mdk.ia64.rpm
psad-1.4.1-2mdk.s390.rpm

Provides :
perl(Psad)
psad

Requires :
perl(Getopt::Long)
perl(POSIX)
perl(Exporter)
bash
perl(Unix::Syslog)
perl(Socket)
rpm-helper
perl-Unix-Syslog
perl(IO::Handle)
perl-base
perl(Carp)
perl(Data::Dumper)
perl(IPTables::ChainMgr)
smtpdaemon
perl(Psad)
perl-Bit-Vector
libc.so.6(GLIBC_2.0)
perl-Net-IPv4Addr
perl(Date::Calc)
perl(Net::IPv4Addr)
/bin/sh
rpmlib(PayloadFilesHavePrefix) <= 4.0-1
perl-IPTables-Parse
libc.so.6(GLIBC_2.3)
perl(File::Path)
perl(IPTables::Parse)
rpmlib(CompressedFileNames) <= 3.0.4-1
rpmlib(VersionedDependencies) <= 3.0.3-1
perl-Date-Calc
libc.so.6(GLIBC_2.1)
perl(File::Copy)
libc.so.6
userspace-ipfilter


Content of RPM :
/etc/psad
/etc/psad/auto_dl
/etc/psad/fw_search.conf
/etc/psad/icmp_types
/etc/psad/kmsgsd.conf
/etc/psad/posf
/etc/psad/psad.conf
/etc/psad/psadwatchd.conf
/etc/psad/signatures
/etc/psad/snort_rules
/etc/psad/snort_rules/VERSION
/etc/psad/snort_rules/attack-responses.rules
/etc/psad/snort_rules/backdoor.rules
/etc/psad/snort_rules/bad-traffic.rules
/etc/psad/snort_rules/chat.rules
/etc/psad/snort_rules/ddos.rules
/etc/psad/snort_rules/deleted.rules
/etc/psad/snort_rules/dns.rules
/etc/psad/snort_rules/dos.rules
/etc/psad/snort_rules/experimental.rules
/etc/psad/snort_rules/exploit.rules
/etc/psad/snort_rules/finger.rules
/etc/psad/snort_rules/ftp.rules
/etc/psad/snort_rules/icmp-info.rules
/etc/psad/snort_rules/icmp.rules
/etc/psad/snort_rules/imap.rules
/etc/psad/snort_rules/info.rules
/etc/psad/snort_rules/local.rules
/etc/psad/snort_rules/misc.rules
/etc/psad/snort_rules/multimedia.rules
There is 53 files more in these RPM.

 
ICM