From owner-freebsd-security Sat Mar 24 17:46:26 2001 Delivered-To: freebsd-security@freebsd.org Received: from dnull.com (dnull.com [209.133.53.79]) by hub.freebsd.org (Postfix) with ESMTP id 09D1237B71E for ; Sat, 24 Mar 2001 17:46:24 -0800 (PST) (envelope-from jessem@jigsaw.svbug.com) Received: from jigsaw.svbug.com ([198.79.110.2]) by dnull.com (8.8.8/8.8.8) with ESMTP id RAA36357 for ; Sat, 24 Mar 2001 17:46:52 -0800 (PST) Message-Id: <200103250146.RAA36357@dnull.com> Date: Sat, 24 Mar 2001 17:46:18 -0800 (PST) From: jessem@livecam.com Reply-To: jessemonroy@email.com Subject: Fwd: A Simple TCP Port Alarm To: security@freebsd.org MIME-Version: 1.0 Content-Type: TEXT/plain; CHARSET=US-ASCII Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org ------ Forwarded message ------ From: "Jesus Monroy, Jr." Subject: A Simple TCP Port Alarm Date: Sat, 24 Mar 2001 17:43:45 -0800 To: lsec@linux-consulting.com Cc: security@freebsd.org Reply-To: jessemonroy@email.com I've written a simple TCP port alarm in Perl. The default configuration spoofs the daytime service on port 13. It logs all connections, then emails to the configured recipient. You can check it out at: http://www.livecam.com/~jessem/software/perl/spa/spa.html Best Regards Jessem. To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message