[TOOL] Hatchet - PF Firewall Log Parser

From: SecuriTeam (support_at_securiteam.com)
Date: 04/15/04

  • Next message: SecuriTeam: "[TOOL] FSTools - FileSystem Investigator"
    To: list@securiteam.com
    Date: 15 Apr 2004 16:23:41 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      Hatchet - PF Firewall Log Parser
    ------------------------------------------------------------------------

    SUMMARY

    DETAILS

    Hatchet is a log parsing/presentation program written for OpenBSD's PF
    logs. The main script, "hatchet", should be run every 5 minutes, or as
    often as you wish. Depending on the size of your logfiles versus the speed
    of your machine, you may wish to tweak how often it runs.

    Hatchet uses a series of Perl regexes to match entries from the pflog
    logs. The log entries are stored in an SQLite database file, allowing for
    highly dynamic queries and statistics. If it finds one it doesn't have a
    match for, it will kick off an email to the system administrator
    (root@localhost) with the details. It's possible to install the web
    interface on a separate web server, the INSTALL document covers each task
    and where it should be performed. Although Hatchet uses SQLite, it does
    not require installation of the full SQLite "suite", only the DBD::SQLite
    module, which incorporates the necessary libraries.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:jason@dixongroup.net> Jason
    Dixon.

    The tool can be downloaded from: <http://www.dixongroup.net/hatchet/>
    http://www.dixongroup.net/hatchet/

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[TOOL] FSTools - FileSystem Investigator"

    Relevant Pages

    • [TOOL] WebRoot - Web Server Brute Forcer
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... CIRT.DK WebRoot is a Webserver auditing tools, ... # cpan> install Bundle::LWP ... sub ChkUpdates ...
      (Securiteam)
    • [NT] Multiple Vendor NOS Microsystems getPlus Downloader Stack Buffer Overflow Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... download, install, and update other software through the browser. ... Adobe uses this control ... for web based installations of Adobe Reader. ...
      (Securiteam)
    • [NT] Zango Adware - Insecure Auto-Update and File Execution
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Zango Adware - Insecure Auto-Update and File Execution ... Initial Install ... You have legitimate control over the DNS server ...
      (Securiteam)
    • [NT] Level Platforms Service Center Install Data HTTP Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Level Platforms Service Center Install Data HTTP Vulnerability ... and a Onsite Manager component. ...
      (Securiteam)
    • [NT] Macrovision InstallShield InstallScript One-Click Install Untrusted Library Loading Vulnera
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Macrovision <InstallShield> InstallShield InstallScript One-Click Install ... untrusted library loading vulnerability in Macrovision's InstallShield ... InstallScript One-Click Install ActiveX control allows remote attackers to ...
      (Securiteam)