Mailing List Archive

Support open source code!


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Logging port scans



On Thu, Dec 07, 2000 at 02:25:56PM +0900, A.Sajjad Zaidi wrote:
> Ive been searching for a good port scan logger for a while now, but
> havent had much luck.
> 
> I tried 'scanlogd', but that didnt work at all. I also struggled with
> 'portsentry' from Psionic, but firstly, it took up about 70% cpu and
> then the logging wasnt what i wanted.
Portsentry + Perl.  Edit syslog.conf to log to a seperate file, and a bit of
perl voodoo to parse and do summaries. (Cron it to run once a month).

I've had generaly good luck with it, and the code seems to be farily good,
which is essential for such things...

-- 
Austin K. Kurahone
Tokyo Linux Users Group / SIGUSR1 R&D
Hail Eris! All Hail Discordia!
"Never frighten a small man.  He'll kill you." --Lazarus Long

PGP signature


Home | Main Index | Thread Index

Home Page Mailing List Linux and Japan TLUG Members Links