Hello,

Please review & comments.
It still misses (optional) dep on tcpdstat.

Thanks.
Best regards,

Jul

$ cat net/nsm-console/pkg/DESCR





NSM-Console (Network Security Monitoring Console) is a framework for
performing analysis on packet capture files. It implements a modular
structure to allow for an analyst to quickly write modules of their own
without any programming language experience. Using these modules a large
amount of pcap analysis can be performed quickly using a set of global
(as well as per-module) options. It aims to be simple to run and easy to
understand without a lot of learning time.

$ cat net/chaosreader/pkg/DESCR





A freeware tool to trace TCP/UDP/... sessions and fetch application data
from snoop or tcpdump logs. This is a type of "any-snarf" program, as it
will fetch telnet sessions, FTP files, HTTP transfers (HTML, GIF, JPEG,
...), SMTP emails, ... from the captured data inside network traffic
logs. A html index file is created that links to all the session
details, including realtime replay programs for telnet, rlogin, IRC, X11
and VNC sessions; and reports such as image reports and HTTP GET/POST
content reports. Chaosreader can also run in standalone mode - where it
invokes tcpdump or snoop (if they are available) to create the log files
and then processes them.

$ cat net/pads/pkg/DESCR





Passive Asset Detection System (PADS) was designed to supplement active
scanners by combining a network sniffer with a rule-based detection
engine similar to a network IDS. It will listen to a network and attempt
to provide an up-to-date look at the hosts and services running on the
network. The application operates invisibly and will never release a
packet into the network.

$ cat net/tcpick/pkg/DESCR





tcpick is a textmode sniffer libpcap-based that can track, reassemble
and reorder tcp streams. Tcpick is able to save the captured flows in
different files or displays them in the terminal, and so it is useful to
sniff files that are transmitted via ftp or http. It can display all the
stream on the terminal, when the connection is closed in different
display modes like hexdump, hexdump + ascii, only printable charachters,
raw mode and so on. Available a color mode too, helpful to read and
understand better the output of the program. Actually it can handle
several interfaces, including ethernet cards and ppp. It is useful to
keep track of what users of a network are doing, and is usable with
textmode tools like grep, sed, awk.

$ cat net/tcpxtract/pkg/DESCR





tcpxtract is a tool for extracting files from network traffic based on
file signatures. Extracting files based on file type headers and footers
(sometimes called "carving") is an age old data recovery technique.
Tools like Foremost employ this technique to recover files from
arbitrary data streams. Tcpxtract uses this technique specifically for
the application of intercepting files transmitted across a network.
Other tools that fill a similar need are driftnet and EtherPEG. driftnet
and EtherPEG are tools for monitoring and extracting graphic files on a
network and is commonly used by network administrators to police the
internet activity of their users. The major limitations of driftnet and
EtherPEG is that they only support three filetypes with no easy way of
adding more. The search technique they use is also not scalable and does
not search across packet boundries.

Attachment: obport-nsm-console-20100731.tar.gz
Description: GNU Zip compressed data

Reply via email to