Great Circle Associates Firewalls
(May 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Linux network monitoring
From: Phillippe Welsh <pj @ cassens . com>
Date: Mon, 06 May 1996 8:45:56 CDT
To: zarquon @ popalex1 . linknet . net
Cc: firewalls @ GreatCircle . COM
In-reply-to: <199605040649 . BAA01768 @ dsrvlaf1-24 . linknet . net>; from "zarquon @ popalex1 . linknet . net" at May 4, 96 1:49 am

...  What I would really like is a tool like one I saw in use a
> while back, but have been unable to locate. It could detect attempted
> connections on any ports, giving it the ability to effectively detect port
> scans in any port range, while *not* accepting any connections. In other
> words, whoever attempted to connect would *not* have the connection accepted,
> but it would still be logged as a connection attempt.

I use a modification of rexec by Doug Houghes (email Doug .
 Hughes @
 eng .
 auburn .
 edu)
called klaxon.  Works very well.  Give it a try.   Hope this helps.

His home page: 
	http://www.eng.auburn.edu/users/doug/second.html

The program itself:
	ftp://ftp.eng.auburn.edu/pub/doug/klaxon.tar.gz

--
Internet:             | Phillippe J. Welsh        |                          
   welshpj @
 cassens .
 com| Cassens Transport         | Std disclaimers apply.   
Voice:                | 145 N. Kansas Str.        |  (But you knew that!)    
                      | Edwardsville, IL 62025    |                          


Follow-Ups:
References:
Indexed By Date Previous: Re: singoff
From: "Bob Fallon" <fallonb @ corp . macom . com>
Next: Firewalls-Digest V5 #289
From: <casey @ justice . usdoj . gov>
Indexed By Thread Previous: Re: Linux network monitoring
From: Chip Coy <coy @ coy . com>
Next: Re: Linux network monitoring
From: Jeff Fay <fay @ bliss . stetson . edu>

Google
 
Search Internet Search www.greatcircle.com