Syndicate

Syndicate content

Flattr


Flattr this

If you like this, you can use flattr. ;)

Imprint

About
eMail: wishinet at gmail . com
PGP ID: 0xCCCA5E74

Jabber: wishi@jabber.ccc.de

Revision: flowtag Tk

txttxtI had some problems installing Flowtag on a 10.5 Mac... it's solved.
There's lots of very interesting research going on.
The Visual Firewall i. e. sounds more than interesting!!!



You need to reinstall the whole ruby bundle and put +Tk or +mactk (and +thread_hooks) as options into the prompt while installing the dependencies via MacPorts. I recommend +mactk because you don't want x11. mactk seems to be faster.

Very cool tool. It can display graphically where your traffic goes to like iftop. But it's doing this with pcaps. I'll test it out. I like the interface very much.

nsm features flowtag too, easing your work:



Modules:
[-] aimsnarf - Extracts AIM messages from a pcap file
[-] argus-basic - Perform basic argus flow statistics on
the file, see info for details

[-] bro-ids-protocol - The Bro Intrusion Detection System
(analyze protocols for alarms)
[-] bro-ids-stream - The Bro Intrusion Detection System (extract stream contents)
[-] capinfos - Extract information about a capture file
[-] chaosreader - Trace TCP/UDP sessions and fetch application data
[-] clamscan - Scan extracted files for malware
[-] fl0p - Analyze the flow of packets for fingerprints
[-] flowtag - Visualizes the flows of a pcap file
[-] flowtime - Create a timeline for network traffic flows
[-] foremost - Extract files from a data file
[-] harimau - Check IPs in the pcap file against the harimau blacklist
[-] hash - Create hashes of the pcap file
[-] honeysnap - Perform honeysnap analysis on pcap file captured from a honeypot
[-] iploc - Determine location of inbound and outbound traffic
[-] ngrep - Grep through pcap file for data
[-] p0f - Passive OS fingerprinting
[-] pads - Passive Asset Detection System
[-] snort - Generate snort alerts from a pcap file
[-] tcpdstat - Extract statistics about a pcap file
[-] tcpflow - Extract flow information from a pcap file
[-] tcpick - Generate traffic statistics and tcp stream files
[-] tcptrace - Perform trace analysis on the packet file
[-] tcpxtract - Extract data files from a pcap session
[-] trace-summary - Generate a breakdown of network traffic
[-] tshark - Analyze network traffic


These are the modules... Everything is possible! The researching in this network topic is not blocked by reading all the manpages in detail. You can easily concentrate on the network logic. Have fun!

Post new comment

The content of this field is kept private and will not be shown publicly.
CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Save the nature. Don't print this!


I provide textual exports for every blog entry. However let's save the nature together. The nature is everything around us. Every being should be respected. Save the nature - don't print too much.


Die Umgehung dieser Ausdrucksperre ist nach § 95a UrhG verboten!
Inhaltlich Verantwortlicher gemäß § 10 Absatz 3 MDStV: Marius Ciepluch - Anschrift via eMail. Die eMail Adresse entnehmen sie dem Impresseum dieser englischsprachigen Seite.
Aus Datenschutzgründen habe ich weder offiziellen noch behördlichen Schriftverkehr via eMail. Dazu ist die postalische, beim Dienstleister hinterlegte, Anschrift zu verwenden.

Datenerfassung

Es werden keine personenbezogenen Daten erfasst. Logdaten werden anonymisiert.