1
0
mirror of https://git.FreeBSD.org/ports.git synced 2025-01-23 09:10:43 +00:00
Commit Graph

838 Commits

Author SHA1 Message Date
Martin Wilke
fc454f85a8 The tool is a simple flow-analyzing passive L7 fingerprinter. It
examines the sequence of client-server exchanges, their relative
layer 7 payload sizes, and transmission intervals (as opposed to
inspecting the contents, which is what most passive fingerprinters
and "smart" sniffers would do to analyze transmissions). This is
then matched against a database of traffic pattern signatures to
infer some interesting facts about the traffic.

PR:		ports/106351
Submitted by:	trasz <trasz at pin.if.uz.zgora.pl>
2006-12-04 22:33:37 +00:00
Anders Nordby
4162850462 Add sshblock, a tool to block abusive SSH login attempts. 2006-12-03 22:25:18 +00:00
Martin Wilke
40786d825e A library for connecting to and sending commands to a local
ClamAV clamd service - an anti-virus daemon process.

You can find more information about clam anti-virus at
WWW: http://www.clamav.net/

File::Scan::ClamAV was originally based on the Clamd module

Submitted by:	Jan-Peter Koopmann <Jan-Peter.Koopmann at seceidos.de>
2006-11-23 23:08:30 +00:00
Martin Wilke
e56c8c72e0 Sguil (pronounced "sgweel") is a graphical interface to snort,
an open source intrusion detection system.
The actual interface and GUI server are written in tcl/tk.
Sguil also relies on other open source software
in order to function properly.

The client requires gpg, iwidgets and other tcl packages and may
also use wireshark, festival and tls depending on your selection
of options.  Run "make config" in the port to see what options
are available.

Sguil currently functions as an analysis interface and has
no snort sensor or rule management capabilities.

WWW: http://sguil.sourceforge.net/index.php
pauls@utdallas.edu

PR:		ports/105496
Submitted by:	Paul Schmehl <pauls at utdallas.edu>
2006-11-15 21:33:51 +00:00
Frank J. Laszlo
6ebfbc8583 New Port: security/osslsigncode
Platform-independent tool for Authenticode signing of EXE/CAB files - uses
OpenSSL and libcurl. It also supports timestamping.

PR:	ports/105353
Submitted By:	Nick Barkas <snb@threerings.net>
Approved By:	flz (mentor)
2006-11-11 13:55:05 +00:00
Alejandro Pulver
b529c1e197 Sguil is an open source tool to implement Network
Security Monitoring (NSM).  NSM is the collection,
analysis, and escalation of indications and warnings
to detect and respond to intrusions.  NSM tools are
used more for network audit and specialized
applications than traditional alert-centric "intrusion
detection" systems.

Want to learn more about Network Security Monitoring
(NSM)? Then check out Richard Bejtlich's recently
released book, The Tao of Network Security Monitoring:
Beyond Intrusion Detection. An excerpt reads:

"Network security monitoring (NSM) equips security
staff to deal with the inevitable consequences of too
few resources and too many responsibilities. NSM collects
the data needed to generate better assessment, detection,
and response processes--resulting in decreased impact from
unauthorized activities."

WWW: http://sguil.sourceforge.net/index.php
pauls@utdallas.edu

PR:		ports/104227
Submitted by:	Paul Schmehl <pauls at utdallas.edu>
2006-10-31 02:43:25 +00:00
Jeremy Messenger
70cd04b258 Simple commandline wrapper around gpg that makes it store its passphrase
in gnome-keyring.  It is a direct competitor to (the unmaintained)
quintuple-agent.

Submitted by:	ahze
Approved by:	portmgr (kris and marcus)
2006-10-14 09:10:57 +00:00
Boris Samorodov
800e4e5443 Sguil (pronounced "sgweel") is a graphical interface to snort
(www.snort.org), an open source intrusion detection system.
The actual interface and GUI server are written in tcl/tk
(www.tcl.tk). Sguil also relies on other open source software
in order to function properly.

The sensor list includes security/barnyard, security/snort,
security/sancp, tcpdump (a part of the OS) and devel/tcltls as
well as lang/tcl84 and lang/tclX.  Care has been taken to ensure
that everything you need to build a working sguil operation is
in the FreeBSD ports system or part of the OS already.

Sguil currently functions as an analysis interface and has
no snort sensor or rule management capabilities.

WWW: http://sguil.sourceforge.net/index.php
pauls@utdallas.edu

PR:		ports/95018
Submitted by:	Paul Schmehl <pauls at utdallas.edu>
2006-10-09 19:04:38 +00:00
Rong-En Fan
243c063a6a Add p5-openxpki-deployment 0.9.543, perl based enterprise class
trustcenter software for PKI.

PR:		ports/103949
Submitted by:	Sergei Vyshenski <svysh at cryptocom.ru>
2006-10-07 12:32:19 +00:00
Rong-En Fan
0ffdd411b1 Add p5-openxpki-i18n 0.9.538, perl based trustcenter software for PKI:
i18n tools.

PR:		ports/103948
Submitted by:	Sergei Vyshenski <svysh at cryptocom.ru>
2006-10-07 12:31:50 +00:00
Rong-En Fan
ab27869dd7 Add p5-openxpki-client-soap-lite 0.9.421, SOAP-Lite toolkit for
openxpki.

PR:		ports/103947
Submitted by:	Sergei Vyshenski <svysh at cryptocom.ru>
2006-10-07 12:31:24 +00:00
Rong-En Fan
e240e8975b Add p5-openxpki-client-scep 0.9.421, client for SCEP requests to
openxpki server.

PR:		ports/103946
Submitted by:	Sergei Vyshenski <svysh at cryptocom.ru>
2006-10-07 12:30:55 +00:00
Rong-En Fan
2259b7c0e8 Add p5-openxpki-client-html-mason 0.9.546, web interface for local
openxpki daemon.

PR:		ports/103945
Submitted by:	Sergei Vyshenski <svysh at cryptocom.ru>
2006-10-07 12:30:21 +00:00
Rong-En Fan
9f6ee59f79 Add p5-openxpki-client-cli 0.9.459, command line interface for local
openxpki daemon.

PR:		ports/103944
Submitted by:	Sergei Vyshenski <svysh at cryptocom.ru>
2006-10-07 12:29:54 +00:00
Rong-En Fan
84542c0a32 Add p5-openxpki-client 0.9.450, perl based trustcenter software for PKI:
base class for actual clients.

PR:		ports/103943
Submitted by:	Sergei Vyshenski <svysh at cryptocom.ru>
2006-10-07 12:29:03 +00:00
Cheng-Lung Sung
281c4c0d24 Add p5-Crypt-GCrypt 1.15, perl interface to the GNU Cryptographic
library.

PR:		ports/103767
Submitted by:	TAKAHASHI Kaoru <kaoru at kaisei.org>
2006-10-06 04:58:39 +00:00
Alejandro Pulver
a37457ae0e The Metasploit Project
This is the Metasploit Project. The goal is to provide useful
information to people who perform penetration testing, IDS signature
development, and exploit research. This site was created to fill the
gaps in the information publicly available on various exploitation
techniques and to create a useful resource for exploit developers. The
tools and information on this site are provided for legal penetration
testing and research purposes only.

This port is an in-development version of the upcoming Metasploit Framework.
It is based on Ruby instead of perl, and has a different license.

WWW: http://www.metasploit.org

PR:		ports/101280
Submitted by:	Yonatan <onatan at gmail.com>
2006-10-05 00:05:52 +00:00
Andrew Pantyukhin
13656ce767 - Separate sinfp into library (p5-Net-SinFP) and binary+db (sinfp)
- Use latest db snapshot
2006-09-30 15:36:00 +00:00
Martin Wilke
acfcbd1c4c PBNJ is a network suite to monitor changes that occur on a network
over time. It does this by checking for changes on the target
machine(s), which includes the details about the services running on
them as well as the service state. PBNJ parses the data from a scan
and stores it in a database. PBNJ uses Nmap to perform scans.

WWW: http://www.sf.net/projects/pbnj

PR:		ports/100904
Submitted by:	Joshua D. Abraham <jabra(at)ccs.neu.edu>
2006-09-30 07:30:18 +00:00
Cheng-Lung Sung
eede56113d Add blocksshd 0.8, protects computers from SSH brute force attacks.
PR:		ports/102367
Submitted by:	Gea-Suan Lin <gslin at gslin.org>
2006-09-26 10:26:06 +00:00
Martin Wilke
141f8510d6 Fwipe is a secure file erasing program. fwipe0, which actually erases
your files, is immune to filenames containing spaces, carriage returns,
dashes, or any other special characters. You can use it in place of rm
in cron jobs, together with "find ... -print0". The output of fwipe0 is
specially designed to be parsed easily by machine, so it can be embedded
in other applications which need secure file erasure.

WWW: http://jeenyus.net/~budney/linux/software/fwipe.html

PR:		ports/103488
Submitted by:	David Thiel <lx(at)redundancy.redundancy.org>
2006-09-24 21:19:48 +00:00
Andrew Pantyukhin
35da930207 Add port security/shttpscanner:
Simple HTTP Scanner is a creation made for web site pen testing. You can
check for directories and files on the remote web server and get some
server information like the webserver running.

WWW: http://sourceforge.net/projects/shttpscanner/
Author: Paisterist <paisterist@users.sourceforge.net>
2006-09-24 20:18:15 +00:00
Jose Alonso Cardenas Marquez
bfc8d463f6 - Remove security/fpc-md5. It was renamed to security/fpc-hash
Approved by:	garga (mentor, implicit)
2006-09-07 21:40:37 +00:00
Jose Alonso Cardenas Marquez
13c8628fb5 - New port: 2006-09-07 21:09:28 +00:00
Roman Bogorodskiy
bb0e84c435 TLS Lite is a free python library that implements SSL 3.0, TLS 1.0, and TLS
1.1. TLS Lite supports non-traditional authentication methods such as SRP,
shared keys, and cryptoIDs in addition to X.509 certificates. TLS Lite is pure
Python, however it can access OpenSSL, cryptlib, pycrypto, and GMPY for faster
crypto operations. TLS Lite integrates with httplib, xmlrpclib, poplib,
imaplib, smtplib, SocketServer, asyncore, and Twisted.

WWW: http://trevp.net/tlslite/

PR:		ports/102923
Submitted by:	Alexander Botero-Lowry <alex at foxybanana.com>
2006-09-07 05:23:30 +00:00
Alex Dupre
bcfcdf474c Suhosin is an advanced protection system for PHP installations.
It was designed to protect servers and users from known and
unknown flaws in PHP applications and the PHP core.
Suhosin comes in two independent parts, that can be used
separately or in combination. The first part is a small patch
against the PHP core, that implements a few low-level
protections against bufferoverflows or format string
vulnerabilities and the second part is a powerful PHP extension
that implements all the other protections.

Suhosin is binary compatible to normal PHP installation,
which means it is compatible to 3rd party binary extension
like ZendOptimizer.

WWW: http://www.suhosin.org/
2006-09-04 08:02:04 +00:00
Kris Kennaway
0a6f04e280 Remove expired ports 2006-09-02 23:31:26 +00:00
Pav Lucistnik
bf663cc26b The pam_abl provides auto blacklisting of hosts and users
responsible for repeated failed authentication attempts.

WWW: http://www.hexten.net/pam_abl/

PR:		ports/100635
Submitted by:	Petr Rehor <prehor@gmail.com>
2006-09-01 18:34:03 +00:00
Roman Bogorodskiy
070fdc9acb GnuTLS is a portable ANSI C based library which implements the TLS 1.0 and
SSL 3.0 protocols. The library does not include any patented algorithms and
is available under the GNU Lesser GPL license.

Important features of the GnuTLS library include:
- Thread safety
- Support for both TLS 1.0 and SSL 3.0 protocols
- Support for both X.509 and OpenPGP certificates
- Support for basic parsing and verification of certificates
- Support for SRP for TLS authentication
- Support for TLS Extension mechanism
- Support for TLS Compression Methods

Additionaly GnuTLS provides an emulation API for the widely used
OpenSSL library, to ease integration with existing applications.

WWW:	http://www.gnutls.org/
2006-08-27 19:47:30 +00:00
Rong-En Fan
29ae2adb2a Add mosref 2.0.b3, a secure remote execution framework using a compact
Scheme-influenced VM.

PR:		ports/102238
Submitted by:	Piet Delport
2006-08-23 13:13:57 +00:00
Andrew Pantyukhin
c295728bd5 Add port security/sinfp:
SinFP is a new approach to OS fingerprinting, which bypasses
limitations that nmap has.

Nmap approaches to fingerprinting as shown to be efficient for years.
Nowadays, with the omni-presence of stateful filtering devices,
PAT/NAT configurations and emerging packet normalization technologies,
its approach to OS fingerprinting is becoming to be obsolete.

SinFP uses the aforementioned limitations as a basis for tests to be
obsolutely avoided in used frames to identify accurately the remote
operating system. That is, it only requires one open TCP port, sends
only fully standard TCP packets, and limits the number of tests to 2
or 3 (with only 1 test giving the OS reliably in most cases).

WWW: http://www.gomor.org/sinfp
2006-08-21 07:46:31 +00:00
Ion-Mihai Tetcu
cf787a73eb VNCcrack is a fast offline password cracker for VNC passwords.
By sniffing a VNC challenge-response sequence off the network
(typically when VNC is used without a decent cryptographic
wrapper like SSH or SSL), you can recover the password fairly
easily and quickly by letting VNCcrack pound on it.

WWW: http://www.randombit.net/projects/vnccrack/

PR:		ports/102279
Submitted by:	Pankov Pavel <pankov_p at mail.ru>
2006-08-20 12:09:31 +00:00
Shaun Amott
7b94055d70 Finish adding security/openvpn-devel after repocopy. 2006-08-19 15:15:27 +00:00
Rong-En Fan
93af334482 Add bruteblock 0.0.4, software for blocking bruteforce attacks with
ipfw.

PR:		ports/101254
Submitted by:	Dmitry Marakasov <amdmi3 at mail.ru>
2006-08-17 08:27:13 +00:00
Jose Alonso Cardenas Marquez
e00dd18649 - Remove security/linux-krb5-libs, it was integrated to linux_base-fc4.
Approved by:	garga (mentor)
2006-08-14 02:57:11 +00:00
Cheng-Lung Sung
a9fbcd3d1d - ruby-crypt is a pure-ruby implementation of a number of popular
encryption algorithms.
2006-08-10 15:47:15 +00:00
Cheng-Lung Sung
12079d2d9a Add p5-PerlCryptLib 1.03, perl interface to Peter Guttman cryptlib API.
PR:		ports/101658
Submitted by:	Gea-Suan Lin <gslin at gslin.org>
2006-08-09 03:51:27 +00:00
Ion-Mihai Tetcu
5a28389014 This library implements Blowfish, DES, and Triple-DES.
Author:	Gerd Stolpmann
WWW:	http://www.ocaml-programming.de/packages/

PR:		ports/101213
Submitted by:	Stanislav Sedov <ssedov at mbsd.msk.ru>
2006-08-04 16:25:22 +00:00
Jose Alonso Cardenas Marquez
dcac88c148 - New port: security/linux-krb5-libs
Kerberos V5 is an authentication system developed at MIT.

(Linux version)

WWW: http://web.mit.edu/kerberos/

- New port: security/linux-openssl

The OpenSSL Project is a collaborative effort to develop a robust,
commercial-grade, full-featured, and Open Source toolkit implementing
the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security
(TLS v1) protocols with full-strength cryptography world-wide. The
project is managed by a worldwide community of volunteers that use
the Internet to communicate, plan, and develop the OpenSSL tookit
and its related documentation.

OpenSSL is based on the excellent SSLeay library developed by Eric
A. Young and Tim J. Hudson. The OpenSSL toolkit is licensed under
an Apache-style licence, which basically means that you are free
to get and use it for commercial and non-commercial purposes subject
to some simple license conditions.

(Linux version)

WWW: http://www.openssl.org/

Approved by:	garga (mentor)
2006-08-04 15:03:55 +00:00
Rong-En Fan
92cdbfdf92 Add p5-Crypt-OICQ, cryptographic algorithm used by OICQ protocol.
This is for chinese/oicq.
2006-08-02 17:22:08 +00:00
Cheng-Lung Sung
b790572c0f Add pecl-tcpwrap 1.0, a PECL extension which provides tcpwrappers
binding.

PR:		ports/101136
Submitted by:	chinsan <chinsan.tw at gmail.com>
2006-08-01 13:42:17 +00:00
Rong-En Fan
e7ddca584f Add httprint 301, web server fingerprinting tool.
PR:		ports/101004
Submitted by:	Yonatan <onatan at gmail.com>
2006-08-01 13:06:55 +00:00
Jose Alonso Cardenas Marquez
b9c2bea73d New port: security/gpass
The GNOME Password Manager - GPass for short - is a simple
application, written for the GNOME 2 desktop, that lets you manage a
collection of passwords.  The password collection is stored in an
encrypted file, protected by a master-password.

GPass is released under the GNU GPL2 licence.

Features:

    * Clean and easy-to-use user interface.
    * Quick-search facility.
    * Username and password may easily be copied to the clipboard.
    * Encryption is done using the OpenSSL cryptographics library.
    * The built-in password generator helps you generate secure passwords.
    * You can launch a website and the associated username/passwords
      direct from GPass

Author: Kouji TAKAO <kouji -at- netlab.jp>
WWW:    http://projects.netlab.jp/gpass/

PR:		ports/100845
Submitted by:	ports_at_c0decafe.net <ports at c0decafe.net>
Approved by:	garga (mentor)
2006-08-01 11:12:26 +00:00
Rong-En Fan
21f7b02baa Add isnprober 1.02, penTest tool for TCP Initial Sequence Numbers
research.

PR:		ports/101005
Submitted by:	Yonatan <onatan at gmail.com>
2006-07-30 18:15:59 +00:00
Cheng-Lung Sung
c9c4d0a1c6 Add courieruserinfo 1.1.2, user account information retrieval utility.
PR:		ports/100900
Submitted by:	Andrew St. Jean <andrew at arda.homeunix.net>
2006-07-27 08:07:23 +00:00
Martin Wilke
3a02664880 Add trans-proxy-tor, transparent proxy used to redirect TCP
connections into Tor.

trans-proxy-tor is a transparent proxy
that uses PF to redirect TCP connections
through Tor (http://tor.eff.org/).

Programs that aren't aware of Tor
will use it without their knowledge,
and their traffic no longer leaves the
system unencrypted.

PR:		ports/99034
Submitted by:	Fabian Keil <fk at fabiankeil.de>
2006-07-22 09:56:26 +00:00
Martin Wilke
4fb2a83de5 Add dns-proxy-tor, resolves DNS requests through Tor.
dns-proxy-tor is a DNS server that stops
DNS leaks with applications that don't support
or aren't configured to use socks4a or Tor's DNS
resolution.

WWW: http://http://p56soo2ibjkx23xo.onion/

PR:		ports/99033
Submitted by:	Fabian Keil <fk at fabiankeil.de>
2006-07-22 09:47:54 +00:00
Cheng-Lung Sung
20937d1b03 Add p5-Data-Entropy 0.000, entropy (randomness) management.
PR:		ports/100547
Submitted by:	Gea-Suan Lin <gslin at gslin.org>
2006-07-20 01:21:50 +00:00
Erwin Lansing
63b87c5058 This is a pure perl implementation of the new AES Rijndael. You want
to use Crypt::Rijndael where available. This implementation is really
slow, but I am working on it.

WWW:	http://search.cpan.org/dist/Crypt-Rijndael_PP/

PR:		ports/100262
Submitted by:	Gea-Suan Lin <gslin at gslin.org>
2006-07-14 15:45:24 +00:00
Shaun Amott
a2aab3122c Add a port of "knock" - a flexible port-knocking server and client.
PR:		ports/94626
Submitted by:	shaun (me)
Approved by:	ahze (mentor, implicit)
2006-07-12 18:03:24 +00:00