etch  ] [  etch-m68k  ] [  lenny  ] [  squeeze  ] [  sid  ]
[ Source: nepenthes  ]

Package: nepenthes (0.2.2-4)

versatile tool to collect malware by emulating widespread vulnerabilities

Nepenthes is a low interaction honeypot which emulates known vulnerabilities to collect information about potential attacks. It is designed to emulate vulnerabilities worms use to spread, and to capture these worms. As there are many possible ways for worms to spread, Nepenthes is modular. There are module interface to

  * resolve dns asynchronous
  * emulate vulnerabilities
  * download files
  * submit the downloaded files
  * trigger events (sounds abstract and it is, but is still quite useful)
  * shellcode handler

Tags: System Administration: Logging, Implemented in: C++, User Interface: Daemon, Networking: Server, Role: Program, Security: Intrusion Detection, Purpose: Monitoring

Other Packages Related to nepenthes

  • depends
  • recommends
  • suggests
  • dep: adduser
    add and remove users and groups
  • dep: libadns1 (>= 1.4)
    Asynchronous-capable DNS client library and utilities
  • dep: libc6 (>= 2.3) [amd64]
    GNU C Library: Shared libraries
    also a virtual package provided by libc6-udeb
    dep: libc6 (>= 2.4) [powerpc]
    dep: libc6 (>= 2.6) [sparc]
    dep: libc6 (>= 2.7-1) [not amd64, ia64, powerpc, sparc]
  • dep: libc6.1 (>= 2.7-1) [ia64]
    GNU C Library: Shared libraries
    also a virtual package provided by libc6.1-udeb
  • dep: libcap2 (>= 2.10) [not i386]
    support for getting/setting POSIX.1e capabilities
    dep: libcap2 (>= 2.11) [i386]
  • dep: libcurl3 (>= 7.16.2-1)
    Multi-protocol file transfer library (OpenSSL)
  • dep: libgcc1 (>= 1:4.1.1) [not armel, hppa]
    GCC support library
    dep: libgcc1 (>= 1:4.3) [armel]
  • dep: libgcc4 (>= 4.1.1) [hppa]
    GCC support library
  • dep: libmagic1
    File type determination library using "magic" numbers
  • dep: libpcap0.8 (>= 0.9.3-1) [i386]
    system interface for user-level packet capture
    dep: libpcap0.8 (>= 1.0.0-1) [not i386]
  • dep: libpcre3 (>= 7.7)
    Perl 5 Compatible Regular Expression Library - runtime files
  • dep: libstdc++6 (>= 4.2.1) [not armel]
    The GNU Standard C++ Library v3
    dep: libstdc++6 (>= 4.3) [armel]
  • dep: libunwind7 (>= 0.98.5-6) [ia64]
    A library to determine the call-chain of a program - runtime
  • dep: zlib1g (>= 1:1.1.4)
    compression library - runtime

Download nepenthes

Download for all available architectures
Architecture Package Size Installed Size Files
amd64 7,056.1 kB32788 kB [list of files]
armel 6,520.4 kB21592 kB [list of files]
hppa 8,294.5 kB24760 kB [list of files]
i386 6,455.4 kB21252 kB [list of files]
ia64 7,739.1 kB38164 kB [list of files]
mips 7,041.7 kB22936 kB [list of files]
mipsel 6,637.7 kB22928 kB [list of files]
powerpc 8,173.7 kB24584 kB [list of files]
s390 7,989.4 kB26680 kB [list of files]
sparc 6,730.5 kB22976 kB [list of files]