Result for 47781BA332E3B9FB84733043590C5D8EB178B8EF

Query result

Key Value
FileName./usr/share/man/man8/psad.8.gz
FileSize11767
MD546A0FA5294254661510B1AA44727F697
SHA-147781BA332E3B9FB84733043590C5D8EB178B8EF
SHA-25689E569B708AFB79C6FD9FE5EE3F3AB70A576EA41057D24963C0260CFB74C8810
SSDEEP192:8pivHXFNYnN8Q9TqvyZm0tFqxGkcEmpaVHxb71NiIMl/rJLUrXiBb5eFWYd96RW+:6ivCN8Q9Tqcm0tIxGPoVRb7viIMTUrXI
TLSHT10B32BFC385461DC5152E2B018BD179CD801D66E73A2B69BC3FA9EB518A449F2E1DEF10
hashlookup:parent-total43
hashlookup:trust100

Network graph view

Parents (Total: 43)

The searched file hash is included in 43 parent files which include package known and seen by metalookup. A sample is included below:

Key Value
FileSize178060
MD55C92B46CA0ACBDEDD32BA03506EE1A91
PackageDescriptionPort Scan Attack Detector PSAD is a collection of four lightweight system daemons (in Perl and C) designed to work with iptables to detect port scans. It features: * a set of highly configurable danger thresholds (with sensible defaults provided); * verbose alert messages that include the source, destination, scanned port range, beginning and end times, TCP flags, and corresponding Nmap options; * reverse DNS information; * alerts via email; * automatic blocking of offending IP addresses via dynamic firewall configuration. . When combined with fwsnort and the iptables string match extension, PSAD is capable of detecting many attacks described in the Snort rule set that involve application layer data.
PackageMaintainerDebian QA Group <packages@qa.debian.org>
PackageNamepsad
PackageSectionadmin
PackageVersion2.4.6-1
SHA-1027AD719E050862C177406F7D55920C6C0D4CA6E
SHA-25607756D5526272DC5987C69FD68BEE895AD6D08A78B245EA7C55F0647A7C2E852
Key Value
FileSize177356
MD508389DBF6C2D52B763549F433D4ABFCD
PackageDescriptionPort Scan Attack Detector PSAD is a collection of four lightweight system daemons (in Perl and C) designed to work with iptables to detect port scans. It features: * a set of highly configurable danger thresholds (with sensible defaults provided); * verbose alert messages that include the source, destination, scanned port range, beginning and end times, TCP flags, and corresponding Nmap options; * reverse DNS information; * alerts via email; * automatic blocking of offending IP addresses via dynamic firewall configuration. . When combined with fwsnort and the iptables string match extension, PSAD is capable of detecting many attacks described in the Snort rule set that involve application layer data.
PackageMaintainerThiago Andrade Marques <andrade@debian.org>
PackageNamepsad
PackageSectionadmin
PackageVersion2.4.6-2
SHA-10C9C3223B7B46C9815773895DA0D52CF8CA37681
SHA-256F53F592525684FBCDEABD81862B4A316DA100AE98E508518E108647AC0607434
Key Value
FileSize150276
MD56A4B3AFB0110211FEB63743B75147F01
PackageDescriptionPort Scan Attack Detector PSAD is a collection of four lightweight system daemons (in Perl and C) designed to work with iptables to detect port scans. It features: * a set of highly configurable danger thresholds (with sensible defaults provided); * verbose alert messages that include the source, destination, scanned port range, beginning and end times, TCP flags, and corresponding Nmap options; * reverse DNS information; * alerts via email; * automatic blocking of offending IP addresses via dynamic firewall configuration. . When combined with fwsnort and the iptables string match extension, PSAD is capable of detecting many attacks described in the Snort rule set that involve application layer data.
PackageMaintainerUbuntu Developers <ubuntu-devel-discuss@lists.ubuntu.com>
PackageNamepsad
PackageSectionadmin
PackageVersion2.4.3-1.2
SHA-11760E1C0467D113ECB633F13FEB7400338DC8A82
SHA-25632647908524B0610FFDF3181763A1F44E430BDF70E9CA2A6717F99231B398904
Key Value
MD5210F4B4EFEA0A524B8BBFABFC615FD58
PackageArchnoarch
PackageDescriptionPort Scan Attack Detector (psad) is a lightweight system daemon written in Perl designed to work with Linux iptables firewalling code to detect port scans and other suspect traffic. It features a set of highly configurable danger thresholds (with sensible defaults provided), verbose alert messages that include the source, destination, scanned port range, begin and end times, tcp flags and corresponding nmap options, reverse DNS info, email and syslog alerting, automatic blocking of offending ip addresses via dynamic configuration of iptables rulesets, and passive operating system fingerprinting. In addition, psad incorporates many of the tcp, udp, and icmp signatures included in the snort intrusion detection system (https://www.snort.org) to detect highly suspect scans for various backdoor programs (e.g. EvilFTP, GirlFriend, SubSeven), DDoS tools (mstream, shaft), and advanced port scans (syn, fin, xmas) which are easily leveraged against a machine via nmap. psad can also alert on snort signatures that are logged via fwsnort (https://www.cipherdyne.org/fwsnort/), which makes use of the iptables string match module to detect application layer signatures.
PackageMaintainerFedora Project
PackageNamepsad
PackageRelease8.fc34
PackageVersion2.4.6
SHA-117783DF975B2FA4FE7460AE895D7B9543EFC1411
SHA-256C341E172679D357503FED7356F6FA03AC9DE0689751CC4DE0BCE96DB666E3302
Key Value
FileSize177660
MD5E999AF4D1388F0EAF56825F09830D92B
PackageDescriptionPort Scan Attack Detector PSAD is a collection of four lightweight system daemons (in Perl and C) designed to work with iptables to detect port scans. It features: * a set of highly configurable danger thresholds (with sensible defaults provided); * verbose alert messages that include the source, destination, scanned port range, beginning and end times, TCP flags, and corresponding Nmap options; * reverse DNS information; * alerts via email; * automatic blocking of offending IP addresses via dynamic firewall configuration. . When combined with fwsnort and the iptables string match extension, PSAD is capable of detecting many attacks described in the Snort rule set that involve application layer data.
PackageMaintainerDebian QA Group <packages@qa.debian.org>
PackageNamepsad
PackageSectionadmin
PackageVersion2.4.6-1
SHA-11D33B3D6F6B92118A2B0CE8CBC43F6A2F5AB989B
SHA-2567B97AF51C6912945866F5D103A452B090E15047E187B736191FF500986512AEA
Key Value
FileSize177320
MD5C20D9FAEF10CC45DA0696AB19EC9C6A4
PackageDescriptionPort Scan Attack Detector PSAD is a collection of four lightweight system daemons (in Perl and C) designed to work with iptables to detect port scans. It features: * a set of highly configurable danger thresholds (with sensible defaults provided); * verbose alert messages that include the source, destination, scanned port range, beginning and end times, TCP flags, and corresponding Nmap options; * reverse DNS information; * alerts via email; * automatic blocking of offending IP addresses via dynamic firewall configuration. . When combined with fwsnort and the iptables string match extension, PSAD is capable of detecting many attacks described in the Snort rule set that involve application layer data.
PackageMaintainerFranck Joncourt <franck.joncourt@gmail.com>
PackageNamepsad
PackageSectionadmin
PackageVersion2.4.3-1.2~deb9u1
SHA-1254D18655CAA3D5036486A7B082CFF2209EC81FE
SHA-2563F62D71A22A246368CFE7520618EDF9B8217046331714BBEC0AB0B04C0793480
Key Value
FileSize177372
MD5E0A9584B09E4C366F26ADBF24E1B03BE
PackageDescriptionPort Scan Attack Detector PSAD is a collection of four lightweight system daemons (in Perl and C) designed to work with iptables to detect port scans. It features: * a set of highly configurable danger thresholds (with sensible defaults provided); * verbose alert messages that include the source, destination, scanned port range, beginning and end times, TCP flags, and corresponding Nmap options; * reverse DNS information; * alerts via email; * automatic blocking of offending IP addresses via dynamic firewall configuration. . When combined with fwsnort and the iptables string match extension, PSAD is capable of detecting many attacks described in the Snort rule set that involve application layer data.
PackageMaintainerThiago Andrade Marques <andrade@debian.org>
PackageNamepsad
PackageSectionadmin
PackageVersion2.4.6-2
SHA-1298F8E6FA531B203E7EC029B08FC8FC8833CDF16
SHA-256E5DD1488C3B1CCD3ACC42D1269C46A6C853FD4DDB39D33B460904F73F2056B8A
Key Value
FileSize176260
MD5A3D06ACE824096E2E7922813809EF3C9
PackageDescriptionPort Scan Attack Detector PSAD is a collection of four lightweight system daemons (in Perl and C) designed to work with iptables to detect port scans. It features: * a set of highly configurable danger thresholds (with sensible defaults provided); * verbose alert messages that include the source, destination, scanned port range, beginning and end times, TCP flags, and corresponding Nmap options; * reverse DNS information; * alerts via email; * automatic blocking of offending IP addresses via dynamic firewall configuration. . When combined with fwsnort and the iptables string match extension, PSAD is capable of detecting many attacks described in the Snort rule set that involve application layer data.
PackageMaintainerFranck Joncourt <franck.joncourt@gmail.com>
PackageNamepsad
PackageSectionadmin
PackageVersion2.4.3-1.2
SHA-14465C983E5B378D3C7CB9015456960959275597E
SHA-256B0EA1A05AF565F34C3B85F9B47C5CA1DD85A9DAD2D1892BF7657915F20629172
Key Value
FileSize178136
MD5D72F4450F016071E0F7F95B86D5020FA
PackageDescriptionPort Scan Attack Detector PSAD is a collection of four lightweight system daemons (in Perl and C) designed to work with iptables to detect port scans. It features: * a set of highly configurable danger thresholds (with sensible defaults provided); * verbose alert messages that include the source, destination, scanned port range, beginning and end times, TCP flags, and corresponding Nmap options; * reverse DNS information; * alerts via email; * automatic blocking of offending IP addresses via dynamic firewall configuration. . When combined with fwsnort and the iptables string match extension, PSAD is capable of detecting many attacks described in the Snort rule set that involve application layer data.
PackageMaintainerDebian QA Group <packages@qa.debian.org>
PackageNamepsad
PackageSectionadmin
PackageVersion2.4.6-1
SHA-14F2327A8A8FBCC2FC22FEF1D8D1F26B4D8B2758F
SHA-2563B0BF844CCF2B9D4588155223021B2C5A2B020679218940D1AF656710BA21B0B
Key Value
FileSize180004
MD550CA7669548668A1AB6BF3C0BA4D3D56
PackageDescriptionPort Scan Attack Detector PSAD is a collection of four lightweight system daemons (in Perl and C) designed to work with iptables to detect port scans. It features: * a set of highly configurable danger thresholds (with sensible defaults provided); * verbose alert messages that include the source, destination, scanned port range, beginning and end times, TCP flags, and corresponding Nmap options; * reverse DNS information; * alerts via email; * automatic blocking of offending IP addresses via dynamic firewall configuration. . When combined with fwsnort and the iptables string match extension, PSAD is capable of detecting many attacks described in the Snort rule set that involve application layer data.
PackageMaintainerDebian QA Group <packages@qa.debian.org>
PackageNamepsad
PackageSectionadmin
PackageVersion2.4.6-1
SHA-151DC5C39CBD129B8F4021B185E7F6820C2E5E351
SHA-2568CC3D8190427387592A010DCE12BCFE6BDC2E361B8B4204302761ED8290A0AA0