Security Incidents mailing list archives

Detecting network scans


From: David Brumley <dbrumley () RTFM STANFORD EDU>
Date: Fri, 18 Aug 2000 12:36:38 -0700

-----BEGIN PGP SIGNED MESSAGE-----

Hello,
After a couple of requests, I've put up a quick document on detecting
network scans, including sample source code, at:
http://www.theorygroup.com/Theory/scans.html

Sample perl code is included.

cheers,
david

#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#
David Brumley - Stanford Computer Security -      dbrumley () Stanford EDU
Phone: +1-650-723-2445           WWW: http://www.stanford.edu/~dbrumley
Fax:   +1-650-725-9121     PGP: finger dbrumley-pgp () sunset Stanford EDU
#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#+--+#
c:\winnt> secure_nt.exe
  Securing NT.  Insert Linux boot disk to continue......

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 5.0i for non-commercial use
Charset: noconv

iQCVAwUBOZ2QSZIFJJ0DhGUFAQF8IQP/eT2oTVTS712HXBYlQ8D8SkrzGD1F3e12
qPhHaEbPDulykUoW6XgIANa4+fSDW9tROu7p25Mx3q5I6WyQ299v1SnHDiEehWkZ
gDOlsj+FCYwspUpd04nE2xE0OmK2CBFXB8G/Co469Rs8NMxIY7BsJQyiO2Eet4Lo
nEs24SJMX9E=
=c6lJ
-----END PGP SIGNATURE-----


Current thread: