| |
| | psad (Site not responding. Last check: 2007-10-21) |
 | | EvilFTP, GirlFriend, SubSeven), DDoS tools (mstream, shaft), and advanced port scans (FIN, NULL, XMAS) which are easily leveraged against a machine via nmap. |
 | | When combined with fwsnort, psad is capable of detecting approximately 50% of all Snort rules, including those that inspect the application portion of IP packets. |
 | | In addition, psad makes use of various packet header fields associated with TCP SYN packets to passively fingerprint remote operating systems (in a manner similar to p0f) from which scans originate. |
| www.cipherdyne.com /psad (269 words) |
|