Result for 78B74BF21A7C133F9E1296CA9CE4686EA5429E33

Query result

Key Value
FileNameusr/sbin/fwsnort
FileSize174948
MD5697AD8364AA66D3B23815A379B1AEEE2
SHA-178B74BF21A7C133F9E1296CA9CE4686EA5429E33
SHA-256F2923E9A9DEA5EE6090350CBD83C013B6156997779B032FF87BFBE0493615753
SSDEEP3072:GoFxrErfkfXeoQTw5CIeRXDab4x429UnflEkJ:GCrKfkfXefIeRXDab4/ZY
TLSHT13F04B45859DBE92842A3B07D9FCC91007A3980BB1569AE1CBCADD2CC9FC5634C1F5BD8
tar:gnameroot
tar:unameroot
hashlookup:parent-total27
hashlookup:trust100

Network graph view

Parents (Total: 27)

The searched file hash is included in 27 parent files which include package known and seen by metalookup. A sample is included below:

Key Value
FileNamehttp://dl-cdn.alpinelinux.org/alpine/latest-stable//community//armv7//fwsnort-1.6.8-r2.apk
MD5BAFD7CD7876BE302A06877AEC7713FC4
SHA-1005FB958B0738687B1BF471BB6CDD0C35E2EC6F4
SHA-2568CAD15DC37C475AC4E60B8763536814E0CC59293B619861C5BB93B0BE401183B
SSDEEP768:AWi57anSeUU6LA4cga83gGXKcTp9A++OVlh0wTpBeNm:ti57anNUUMA4XalGXKO9A+xVswLeI
TLSHT12C13F27A21A45BB6F4B02EE1B4C044DE1B426FB03256DC652E190965673F0EAF3C760C
Key Value
FileNamehttp://dl-cdn.alpinelinux.org/alpine/latest-stable//community//x86//fwsnort-1.6.8-r2.apk
MD571940F74A1F92CC4599FF886EAB4B3C2
SHA-109CC7AE75497B1228E77F6047919118217ACA739
SHA-25605113435DFF810EC04851B450E2F24B9D2E27C00B1D03CD2413E25F8E33EC806
SSDEEP768:Igc7anSeUU6LA4cga83gGXKcTp9A++OVlh0wTpBeNm:u7anNUUMA4XalGXKO9A+xVswLeI
TLSHT16913F27A21A45BBBF4F05EE2B4C0489E1F465FA03256D8696E190965273B0DAF3C760C
Key Value
FileNamehttp://dl-cdn.alpinelinux.org/alpine/latest-stable//community//s390x//fwsnort-1.6.8-r4.apk
MD528E1A34D638A1818D4CB84D38C989A61
SHA-10E8E5AA06F302DEB011748230CA0C235E05C54F2
SHA-25656E9A5D9DEFE6F1537E7999AD834B6B78CB0B4D9101CAD92F927864AF0ED4441
SSDEEP768:Y6uluXJlzqV/Ay9QzkH9NOyqPSg+KM3nTvT0NAuXdsk2ZznzEky8dscUZCUQIVB4:2cXf4WkduPv+KQnX0CIMz28ds7guVIoo
TLSHT12D13F221D6572E73E007E0A1B05A96D416DF3BB4272B9CDB795C45420FB62DB33C964C
Key Value
MD51DE9FB13ED0C22D060A695D6BF5DE2CB
PackageArchnoarch
PackageDescriptionfwsnort translates Snort rules into equivalent iptables rules and generates a Bourne shell script that implements the resulting iptables commands. This ruleset allows network traffic that exhibits Snort signatures to be logged and/or dropped by iptables directly without putting any interface into promiscuous mode or queuing packets from kernel to user space. In addition, fwsnort (optionally) uses the IPTables::Parse module to parse the iptables ruleset on the machine to determine which Snort rules are applicable to the specific iptables policy. After all, if iptables is blocking all inbound http traffic from external addresses, it is probably not of much use to try detecting inbound attacks against against tcp/80. By default fwsnort generates iptables rules that log Snort sid's with --log-prefix to klogd where the messages can be analyzed with a log watcher such as logwatch or psad (see http://www.cipherdyne.org/psad). fwsnort relies on the iptables string match extension to match Snort content fields in the application portion of ip traffic. Since Snort rules can contain hex data in content fields, fwsnort implements a patch against iptables-1.2.7a which adds a "--hex-string" option which will accept content fields such as "|0d0a5b52504c5d3030320d0a|". fwsnort bundles the latest rule set from Emerging Threats (http://www.emergingthreats.net) and also includes all rules from the Snort-2.3.3 IDS - the final Snort rule set that was released under the GPL. fwsnort is able to translate well over 60% of all bundled rules. For more information about the translation strategy as well as advantages/disadvantages of the method used by fwsnort to obtain intrusion detection data, see the README included with the fwsnort sources or browse to: http://www.cipherdyne.org/fwsnort/
PackageMaintainerumeabot <umeabot>
PackageNamefwsnort
PackageRelease2.mga7
PackageVersion1.6.8
SHA-11655E61088A6FEE30058894AE91221A1158B291A
SHA-256BECB99C34E49DE4A9031770B1DD09964E78B3DDA6FF1BCEC3FE851609E0BBBC1
Key Value
FileNamehttp://dl-cdn.alpinelinux.org/alpine/latest-stable//community//x86//fwsnort-1.6.8-r4.apk
MD5BD88ADD051AA90AF991EA245F032F9A6
SHA-1176BD253819209ECBD4859EC241998F56F3087CF
SHA-2564507DCD9A9DF38A03831CB222B95121A516207F12706B824C441FCFD216BE68C
SSDEEP768:IpU9DGTtV/Ay9QzkH9NOyqPSg+KM3nTvT0NAuXdsk2ZznzEky8dscUZCUQIVBCMk:MDWkduPv+KQnX0CIMz28ds7guVIoQ
TLSHT1BE13F231E2976E73D047F0A1F099E6D45A9F2AB4262BACEF745845420F722DB37C864C
Key Value
FileNamehttp://dl-cdn.alpinelinux.org/alpine/latest-stable//community//x86_64//fwsnort-1.6.8-r2.apk
MD59C3E071829A58F9AB6BB873F7E7AAB7E
SHA-123590967287CDC939FB5AF4DB8923AC4CBBD7071
SHA-256CF1BB264842BC3DB8EACB17D3363E53F3DB18EBE0FFB78486735DBF423A42D85
SSDEEP768:iekQ7anSeUU6LA4cga83gGXKcTp9A++OVlh0wTpBeNm:RkQ7anNUUMA4XalGXKO9A+xVswLeI
TLSHT1EC13F17A21A45B7BF4B06EE2B4C048DE1F465FA03256DC652E290965273B0DAF3D760C
Key Value
FileNamehttp://dl-cdn.alpinelinux.org/alpine/latest-stable//community//armv7//fwsnort-1.6.8-r3.apk
MD5AE41D61B1B12DB7A9211026FCAC72B4D
SHA-125439880A71C73D27ABD4D6A52E5FFC88815B82C
SHA-256E4630E1B894019906C4E5B8AED026A728CF75D2611ABB5BC16AF21D286BDA3E1
SSDEEP768:AIRf1xYgPCMKrFml5tghUYcOB9veFHPca3tJWmjZh9A++OVlh0wTpBeNv9/:NKrFm6K+MVk2tomz9A+xVswLeh5
TLSHT15113F1D425F4DC25E750AEE25189A2A6B34397243356D8BB68043A933F3B8C7E59670C
Key Value
FileSize50864
MD5C9171FC2473C243788A86CBDA3313104
PackageDescriptionSnort-to-iptables rule translator Fwsnort translates Snort rules into equivalent iptables rules and generates a shell script that implements the resulting iptables commands. . This allows network traffic that matches Snort signatures to be logged and/or dropped by iptables directly without putting any interface into promiscuous mode or queuing packets from kernel to user space.
PackageMaintainerUbuntu Developers <ubuntu-devel-discuss@lists.ubuntu.com>
PackageNamefwsnort
PackageSectionadmin
PackageVersion1.6.8-1
SHA-12DF4D89B4621D3364581455421637CBBC32AD443
SHA-2566329F4E6D21A3B191AF65928A1E92D2B57E17439572FBCF927FF99209CA4EDC0
Key Value
FileNamehttp://dl-cdn.alpinelinux.org/alpine/latest-stable//community//armhf//fwsnort-1.6.8-r4.apk
MD520DF4049574CC9068E1AA549CDE83EC3
SHA-13030F00A5479047F5EC5631ADCC9FF3640C70526
SHA-2560D9D939EABC82C1EDC00181CF7C31F116DC46DECD1F7174713B1199634D87D26
SSDEEP768:4m1tV/Ay9QzkH9NOyqPSg+KM3nTvT0NAuXdsk2ZznzEky8dscUZCUQIVBCM+kAEQ:v1DWkduPv+KQnX0CIMz28ds7guVIoQ
TLSHT1EE13F232D5675E73D007E0A0B09AD7E856EB3AA4172BACDF745845420FB62EB35C960C
Key Value
FileNamehttp://dl-cdn.alpinelinux.org/alpine/latest-stable//community//riscv64//fwsnort-1.6.8-r4.apk
MD5FC7271A7252986F2700A0FD233622AE7
SHA-13058CACC3B87C2C9F57F4A594815E5E4BC825E6E
SHA-2563730EB874686254E077F898A3195571CFC16B73F4B9A78F1ED529ECEAA0F57DF
SSDEEP768:lLtV/Ay97v5mTKYwTtTntwUgPU20HZRD4AvRMp2oryAoxQlYT+iWtLmmBYxjqirv:5DpmTK3pntOiH3JJM0Ao81iWxmmTc9
TLSHT10413F2313288D5FAD9DA4967D3C32BAEAFCEB00024A9660EA55896035F55F537060FC8