Key | Value |
---|---|
FileSize | 177660 |
MD5 | E999AF4D1388F0EAF56825F09830D92B |
PackageDescription | Port Scan Attack Detector PSAD is a collection of four lightweight system daemons (in Perl and C) designed to work with iptables to detect port scans. It features: * a set of highly configurable danger thresholds (with sensible defaults provided); * verbose alert messages that include the source, destination, scanned port range, beginning and end times, TCP flags, and corresponding Nmap options; * reverse DNS information; * alerts via email; * automatic blocking of offending IP addresses via dynamic firewall configuration. . When combined with fwsnort and the iptables string match extension, PSAD is capable of detecting many attacks described in the Snort rule set that involve application layer data. |
PackageMaintainer | Debian QA Group <packages@qa.debian.org> |
PackageName | psad |
PackageSection | admin |
PackageVersion | 2.4.6-1 |
SHA-1 | 1D33B3D6F6B92118A2B0CE8CBC43F6A2F5AB989B |
SHA-256 | 7B97AF51C6912945866F5D103A452B090E15047E187B736191FF500986512AEA |
hashlookup:children-total | 31 |
hashlookup:trust | 50 |
The searched file hash includes 31 children files known and seen by metalookup. A sample is included below:
Key | Value |
---|---|
FileName | ./usr/share/doc/psad/copyright |
FileSize | 3335 |
MD5 | 84755EC890F3D58C440586EC51349317 |
SHA-1 | 01EB91AB24B4A12CD897F921835FAE0E722A5D8D |
SHA-256 | 1736FC93559540A15BCD1DC1BE3F8ADA363BFACDDFDD7B5C738B5D1E2FE5F189 |
SSDEEP | 96:uVpuieqzeReYrYJ8rYJ6yW3l3jTyjsqo1G:bZqzOeYrs8rs6yW3l3Xasqo1G |
TLSH | T1F06108CF615487E72AD123D57CA2EDC4A259B13E3923CA046098E295EF3702F90FA091 |
Key | Value |
---|---|
CRC32 | 08289A7B |
FileName | ./usr/share/doc/psad/BENCHMARK |
FileSize | 3563 |
MD5 | AE6C8419113F6B32A13048505A37F7F0 |
OpSystemCode | 362 |
ProductCode | 10075 |
RDS:package_id | 10075 |
SHA-1 | 063DA4A16B4EB1AE35B10B1EF335E688B98DD522 |
SHA-256 | E5CF54FFE87CD7E3F4F68C29314B75F5545C2CC93098F809F9160CEBE52DB2AA |
SSDEEP | 96:KX+SisMnDdD0RsYwZQY3ZV3jsH1a/T9+Ul5g9:KOSGLMo/TgUA9 |
SpecialCode | |
TLSH | T1DF718301BDBC3BA6318366323B3C7270C788A77D93242252D58DB1352349D6913F6B82 |
db | nsrl_legacy |
insert-timestamp | 1648735417.0709713 |
source | RDS_2022.03.1_legacy.db |
Key | Value |
---|---|
FileName | ./usr/share/doc/psad/NEWS.Debian.gz |
FileSize | 522 |
MD5 | C9A9EF5C8C20C4D85E1096842EDF3D88 |
SHA-1 | 075BF33C3D43949C0538A9CC8692148BB3273DCD |
SHA-256 | B1CEE761F8F6EE612BB0A3B17F098EF3C96855D4D543AD6DD54C291F2760DCB0 |
SSDEEP | 12:XJYdSPxylUBS0sEBpUHZYQq/Z+sheEcbpjr:XJYdSglUDs+28fh6bN |
TLSH | T181F0206A4BBB4A629801E4B5E52BB870E047741109028ABA4CDD2A8E35C0180E34D690 |
Key | Value |
---|---|
FileName | ./usr/share/doc/psad/SCAN_LOG |
FileSize | 1827 |
MD5 | BC6E539FCA350458B7473032126DA6EE |
SHA-1 | 0D15E5442C124C1D7BC1CDDD9433E9C0C2801D1B |
SHA-256 | 992014A60F4C226D7804B85F192722769F162C7A80B23A6F1872EACA734ED9C5 |
SSDEEP | 48:2l31P6SM8jprApG3YZMtO8FufV7lAJATWyVejpM8R:+1gWApgbuNE+U |
TLSH | T153314F0BBF0171A9E316C6B105B26152D73963A352570828F5DD83F08F93D72B362BA9 |
Key | Value |
---|---|
CRC32 | 984B9036 |
FileName | etc/psad/protocols |
FileSize | 2933 |
MD5 | 2E1E463038CC62E7110E33E21552751F |
OpSystemCode | 362 |
ProductCode | 17075 |
RDS:package_id | 17075 |
SHA-1 | 0E79926BC6DD519321D563978AA865AEE7467024 |
SHA-256 | 234998A1403E45E1B3F263EFB79F7C21E32032B1F7DC65054746DC28F69D2A28 |
SSDEEP | 48:ZzxmX2i8fBK/B1TMSKWhRQs0KxHJFvD74FAMrxAWaW/TTVlsz7Acg6ozHBzc0RW5:7Q2TBCB1ZDd0KjAxAWv//VlWAcab1c8Y |
SpecialCode | |
TLSH | T1475163AED74B17AC01A1D6FAE17D7514DA1F9614D1C0B10C74B0F9DB22830A8C72A1E9 |
db | nsrl_legacy |
insert-timestamp | 1648670115.9078636 |
source | RDS_2022.03.1_legacy.db |
tar:gname | root |
tar:uname | root |
Key | Value |
---|---|
FileName | etc/psad/signatures |
FileSize | 45267 |
MD5 | B77EA87A33B16327B675ED7AAC2E5935 |
SHA-1 | 118A5A51ADA03950E02553ECA2EE7DA5C03005FA |
SHA-256 | 2E54D0E8E49DDB49D822C7C0F173ACF760AC50181E36047717C6359ED5C097B9 |
SSDEEP | 768:gFGfE92g4WR6zi4MpTwmsEjtvhV4QidmsZTZkmzChmZmmSfYwnh8d7gl3nAQv5lP:gFWPAYHC9 |
TLSH | T11813007C2FFC69F347D3F330584A22FBB05E94525AA30918ABEC5194A7189E5B5213B3 |
tar:gname | root |
tar:uname | root |
Key | Value |
---|---|
FileName | etc/psad/auto_dl |
FileSize | 1161 |
MD5 | B8DC937565BD9BDC36841531F383FAAA |
SHA-1 | 1875E5E3BEB14581C8628A038A3E2B959402494E |
SHA-256 | 29D934D3F7A935FF1CE8997623AF6B81202A0177E787142323759EF76EC58F92 |
SSDEEP | 24:yIjfsTZNvGYOsFNORu4s2Z34PmyQMpIRZ+UOSApBnKHOSDcvSv:hjoZNvVOu+oPZQMpIbTBQnYBDcvc |
TLSH | T13021CE9B589321AD031A0248DB4E5156677812E28DB729AD320DDBD82782D203F1FA23 |
tar:gname | root |
tar:uname | root |
Key | Value |
---|---|
FileName | ./etc/psad/psad.conf |
FileSize | 30731 |
MD5 | 4540245319A72839EFFE536C2F671881 |
SHA-1 | 25671CB953DAC42EB804BD8CC0BCC12BCED1B03E |
SHA-256 | 29B64012B2988EAB4415E1DEDBEBF69CD4AA154653913C2179502643B0612083 |
SSDEEP | 384:yyfK0ZpIFBj1S5LSw3HaVuGOD4KhQyShIkctAOB28ChE2Ta:nS0XIfSLSw3HcZOD4K/ShIDVB2m |
TLSH | T1F9D209367F893665068790E8271F72E0131690BD1B23287C73ED925C3356CE9A277AE7 |
Key | Value |
---|---|
FileName | ./usr/share/man/man8/fwcheck_psad.8.gz |
FileSize | 742 |
MD5 | 98A7083B154F40F52888F59D019F7D3E |
SHA-1 | 3FF82CE6936C47E6E12A4ED4B8C5C20EAB7EFA04 |
SHA-256 | 71921BED7E0B9024243A5512101F6F8E7CDBB494DA0530F2F3D97551E1713832 |
SSDEEP | 12:XHi2BQ7KSPuaYzRuyhglEfXYRyHP77bGVlwqybbBr0q9UyptJV4HO:XC29S2aYdRSYP7bGPw7PBr6OtJ+u |
TLSH | T1E801657BB5AC35D757C46A5C71D1028B7280AD4441FAF6C30BD1C32484A08FAD0C0C7E |
Key | Value |
---|---|
FileName | ./usr/share/man/man8/psad.8.gz |
FileSize | 11767 |
MD5 | 46A0FA5294254661510B1AA44727F697 |
SHA-1 | 47781BA332E3B9FB84733043590C5D8EB178B8EF |
SHA-256 | 89E569B708AFB79C6FD9FE5EE3F3AB70A576EA41057D24963C0260CFB74C8810 |
SSDEEP | 192:8pivHXFNYnN8Q9TqvyZm0tFqxGkcEmpaVHxb71NiIMl/rJLUrXiBb5eFWYd96RW+:6ivCN8Q9Tqcm0tIxGPoVRb7viIMTUrXI |
TLSH | T10B32BFC385461DC5152E2B018BD179CD801D66E73A2B69BC3FA9EB518A449F2E1DEF10 |