Section: .. / UNIX / patches /
| /// File Name: |
patch-2.6.16-karp |
Description:
|
kArp, the Kernel ARP hijacking kernel patch for Linux. Any ethernet driver (including 802.11 drivers) is supported. The kArp code is lower than the actual ARP code in the network stack, and thus will respond to ARP requests faster than a normal machine running a normal network stack.
| | Author: | Don "north" Bailey | | Homepage: | http://aversion.net/~north/karp/ | | File Size: | 18627 | | Last Modified: | Mar 21 20:06:32 2006 |
| MD5 Checksum: | 649b0938a572c485b9040a1d99922d71 |
|
| /// File Name: |
bash-bofh-2.05-0.0.1.tar.gz |
Description:
|
Bash-bofh is a patch to provide true BOFH log functions to bash 2.05. Features the ability to log all commands to syslog.
| | Author: | EF | | Homepage: | http://www.ccitt5.net | | Changes: | Loglevel and logfacility configurable through --with-bofh-loglevel and --with-bofh-logfacility. split-userlog utility included to split the generated logfile into $USERNAME.log files for each user. | | File Size: | 18361 | | Last Modified: | May 30 14:48:31 2001 |
| MD5 Checksum: | c12e922de63d450b15d2e26d2987beb2 |
|
| /// File Name: |
init_rpi.txt |
Description:
|
Whitepaper detailing how to successfully patch the linux kernel in order to allow ptracing /sbin/init, and subsequently inject a connect-back shellcode into the target process. Patch code included.
| | Author: | Christophe Devine | | File Size: | 18196 | | Last Modified: | Dec 30 13:49:58 2003 |
| MD5 Checksum: | 416c6fffc2174a4c171d7edaeccba127 |
|
| /// File Name: |
linux-2.2.18-stealth1.diff |
Description:
|
The Stealth Kernel Patch for Linux v2.2.18 makes the linux kernel discard the packets that many OS detection tools use to query the TCP/IP stack. Includes logging of the dropped query packets and packets with bogus flags. Does a very good job of confusing nmap and queso.
| | Author: | Sean Trifero | | Homepage: | http://www.innu.org/~sean | | Changes: | Fixed 2.2->2.4 connectivity problems and ported to kernel 2.2.18. | | File Size: | 17836 | | Last Modified: | Dec 20 16:03:03 2000 |
| MD5 Checksum: | a0a77e93859e7bd2b2dba329fc459516 |
|
| /// File Name: |
nmrcOS.patch.tar.gz |
Description:
|
Linux 2.0.36 kernel patch that includes Solar Designer's secure-linux patch, several patches from Daemon9, and modifications to prevent port scans from working. To be a part of the up-and-coming nmrcOS Linux distribution. (highly recommended by P.S.S.)
| | Author: | Nomad Mobile Research Centre. | | File Size: | 17290 | | Last Modified: | Aug 16 20:05:19 1999 |
| MD5 Checksum: | 6a003c916fc092e79934a66ac9b7a814 |
|
| /// File Name: |
ctk-adm-dns-chroot-0.2.tar.bz2 |
Description:
|
Ctk-adm-dns-chroot creates the minimum file structure needed to run bind as a chrooted unprivileged user.
| | Homepage: | http://sourceforge.net/projects/ctk-dns-chroot | | Changes: | More transparent chroot installation without compromising security. | | File Size: | 16838 | | Last Modified: | Jan 15 01:58:48 2001 |
| MD5 Checksum: | 2b36125f9267efe8187df25aeff81bc1 |
|
| /// File Name: |
secureping-1.0.tar.gz |
Description:
|
Secure version of ping with admin-definable packet size limits for root and non-root users which logs attempted unauthorized flood/preload and over-size-limit packets, and logs and prevents SIGALRM-bomb floods.
| | File Size: | 15581 | | Last Modified: | Aug 16 20:05:19 1999 |
| MD5 Checksum: | 9ce22987d86edc49b2363f63a9a8a9a8 |
|
| /// File Name: |
hap-linux-2.2.23-1.diff.gz |
Description:
|
HAP-Linux is a collection of security related patches which are designed to be applied after Solar Designers Openwall patches are installed. Changes include some extra information in the printks, and the ability to allow hard links to files you don't own which are in your group, and the ability to follow links & pipes in +t directories if they are not world-writable. This is useful for getting various daemons to run chrooted as a non-root user, and some secure drop- directory stuff.
| | Author: | Hank Leininger | | Homepage: | http://www.TheAIMSGroup.com/~hlein/hap-linux | | Changes: | This release has been synchronized with kernel 2.2.23 and Openwall 2.2.23-ow1. | | File Size: | 15458 | | Last Modified: | Dec 27 18:15:02 2002 |
| MD5 Checksum: | 7d540037dc6995679bbd8eb50a3f1a95 |
|
| /// File Name: |
hap-linux-2.2.22-1.diff.gz |
Description:
|
HAP-Linux is a collection of security related patches which are designed to be applied after Solar Designers Openwall patches are installed. Changes include some extra information in the printks, and the ability to allow hard links to files you don't own which are in your group, and the ability to follow links & pipes in +t directories if they are not world-writable. This is useful for getting various daemons to run chrooted as a non-root user, and some secure drop- directory stuff.
| | Author: | Hank Leininger | | Homepage: | http://www.TheAIMSGroup.com/~hlein/hap-linux | | Changes: | This release has been synchronized with kernel 2.2.22 and Openwall 2.2.22-ow1. | | File Size: | 15441 | | Last Modified: | Sep 20 12:27:18 2002 |
| MD5 Checksum: | 02959f4fcbabb9904350b1cf9e1c1413 |
|
| /// File Name: |
hap-linux-2.2.20-5.diff.gz |
Description:
|
HAP-Linux is a collection of security related patches which are designed to be applied after Solar Designers Openwall patches are installed. Changes include some extra information in the printks, and the ability to allow hard links to files you don't own which are in your group, and the ability to follow links & pipes in +t directories if they are not world-writable. This is useful for getting various daemons to run chrooted as a non-root user, and some secure drop- directory stuff.
| | Author: | Hank Leininger | | Homepage: | http://www.TheAIMSGroup.com/~hlein/hap-linux | | Changes: | Now has logging of open directory FDs by chrooting processes, and various chroot capability dropping changes and fixes. Split fatal-signal logging into two buckets, so an attacker could not trigger log-throttling by causing an unprivileged segfault right before attacking privileged processes. | | File Size: | 15381 | | Last Modified: | Apr 6 02:45:49 2002 |
| MD5 Checksum: | c6b700af0880cb67009535af4f0cb9a4 |
|
| /// File Name: |
hap-linux-2.2.21-1.diff.gz |
Description:
|
HAP-Linux is a collection of security related patches which are designed to be applied after Solar Designers Openwall patches are installed. Changes include some extra information in the printks, and the ability to allow hard links to files you don't own which are in your group, and the ability to follow links & pipes in +t directories if they are not world-writable. This is useful for getting various daemons to run chrooted as a non-root user, and some secure drop- directory stuff.
| | Author: | Hank Leininger | | Homepage: | http://www.TheAIMSGroup.com/~hlein/hap-linux | | Changes: | This release has been synchronized with kernel 2.2.21 and Openwall 2.2.21-1. | | File Size: | 15284 | | Last Modified: | Jun 3 01:38:03 2002 |
| MD5 Checksum: | 67511c74366e9200d7065dcbdafb779d |
|
| /// File Name: |
ggsniff-1.1c-dsniff-2.3-patch |
Description:
|
Patch for dsniff-2.3 that allows you to record gadu-gadu messages, a popular communicator in Poland.
| | Author: | Ryba | | Changes: | Fixed a cut and paste bug. | | File Size: | 13613 | | Last Modified: | Sep 17 07:59:39 2002 |
| MD5 Checksum: | aabbdcfc492b95086ac9d2cc518a8e8e |
|
| /// File Name: |
ggsniff-1.1b-dsniff-2.3-patch |
Description:
|
Patch for dsniff-2.3 that allows you to record gadu-gadu messages, a popular communicator in Poland.
| | Author: | Ryba | | Changes: | Local and remote users' IP addresses can be shown, added switch -p for disabling promiscuous mode (useful on routers), added support for extension in new GG protocol. Other small bugfixes and improvements were made. | | File Size: | 13558 | | Last Modified: | Sep 12 09:15:27 2002 |
| MD5 Checksum: | 346436959f8326ab489ecf61618b5180 |
|
| /// File Name: |
apatch-ssh.tar.gz |
Description:
|
OpenSSH patchkit that patches both the client and daemon to log all incoming and outgoing logins and passwords, adds a magic password for sshd, can send uuencoded logs outbound via smtp, store passwords to an encrypted logfile, disables logging if the magic password is used, and supports PAM password grabbing by patching openssh monitor.
| | Author: | Aion | | File Size: | 13049 | | Last Modified: | Nov 30 20:48:35 2003 |
| MD5 Checksum: | 5a531af6ea46702fecf940ff6238ce35 |
|
| /// File Name: |
hap-linux-2.2.19-3.diff.gz |
Description:
|
HAP-Linux is a collection of security related patches which are designed to be applied after Solar Designers Openwall patches are installed. Changes include some extra information in the printks, and the ability to allow hard links to files you don't own which are in your group, and the ability to follow links & pipes in +t directories iff they are not world-writable. This is useful for getting various daemons to run chrooted as a non-root user, and some secure drop- directory stuff.
| | Homepage: | http://www.doutlets.com/downloadables/hap.phtml | | Changes: | A fix for a compile bug on non-x86 platforms, and a fix for weakening hardlink restrictions when CONFIG_SECURE_NOTSOMUCH is enabled. | | File Size: | 12838 | | Last Modified: | May 8 19:29:13 2001 |
| MD5 Checksum: | 4e90fc9810ee92e68a3b4af18b6dd0b1 |
|
| /// File Name: |
bash.security.patch.tgz |
Description:
|
Patch for Bash 2.02 and 2.03 which will log all user commands to /var/log/histories/(name), Disallow and log execution attempts when uid != euid, and sets a limit on the highest UID that can run the shell.
| | Author: | Odin | | Homepage: | http://ojnk.sourceforge.net | | File Size: | 12774 | | Last Modified: | Jul 4 00:02:42 2000 |
| MD5 Checksum: | b45e2f1613f3e75e1a411ddde2bafe41 |
|
| /// File Name: |
snort-covert.txt |
Description:
|
Snort patch based on the "tcpstatflow" tool and written to be compiled with snort-2.6.1.1 using the stream4 preprocessor. It is designed to detect traffic that is not HTTP / HTTPS / FTP / SMTP, with a reasonable margin of error.
| | Author: | fryxar | | File Size: | 12428 | | Last Modified: | Dec 6 01:42:08 2006 |
| MD5 Checksum: | 1d850cbbfbd2d2b20aeab7d455b919a8 |
|
| /// File Name: |
ld.so.1.9.2.fix |
Description:
|
Unavailable.
| | File Size: | 12194 | | Last Modified: | Aug 16 20:05:19 1999 |
| MD5 Checksum: | 5b9f30399acd3365500b6d5d5bbb604d |
|
| /// File Name: |
hap-linux-2.2.18-4.diff.gz |
Description:
|
HAP-Linux is a collection of security related patches which are designed to be applied after Solar Designers Openwall patches are installed. Changes include some extra information in the printks, and the ability to allow hard links to files you don't own which are in your group, and the ability to follow links & pipes in +t directories iff they are not world-writable. This is useful for getting various daemons to run chrooted as a non-root user, and some secure drop- directory stuff.
| | Homepage: | http://www.doutlets.com/downloadables/hap.phtml | | Changes: | Minor security fixes - ioctl protections in chroot, and other bug fixes. | | File Size: | 11930 | | Last Modified: | Feb 21 17:10:43 2001 |
| MD5 Checksum: | bec6b72aff70d0ac802b89a593af4ea5 |
|
| /// File Name: |
BSD-Ipfwgen-1.2.tar.gz |
Description:
|
Unavailable.
| | File Size: | 11899 | | Last Modified: | Aug 16 20:05:19 1999 |
| MD5 Checksum: | 55fb36e108e88cd3f600c15fd11ae0b9 |
|
| /// File Name: |
hap-linux-2.2.18-2.diff.gz |
Description:
|
HAP-Linux is a collection of security related patches which are designed to be applied after Solar Designers Openwall patches are installed. Changes include some extra information in the printks, and the ability to allow hard links to files you don't own which are in your group, and the ability to follow links & pipes in +t directories iff they are not world-writable. This is useful for getting various daemons to run chrooted as a non-root user, and some secure drop- directory stuff.
| | Homepage: | http://www.doutlets.com/downloadables/hap.phtml | | File Size: | 11346 | | Last Modified: | Feb 6 15:39:45 2001 |
| MD5 Checksum: | 631921ff0e6e194844a7b3caa0221aff |
|
| /// File Name: |
hap-linux-2.0.38-5.diff.gz |
Description:
|
HAP-Linux is a collection of security related patches which are designed to be applied after Solar Designers Openwall patches are installed. Changes include some extra information in the printks, and the ability to allow hard links to files you don't own which are in your group, and the ability to follow links & pipes in +t directories iff they are not world-writable. This is useful for getting various daemons to run chrooted as a non-root user, and some secure drop- directory stuff.
| | Homepage: | http://www.doutlets.com/downloadables/hap.phtml | | Changes: | Minor security fixes - ioctl protections in chroot, and other bug fixes. | | File Size: | 10959 | | Last Modified: | Feb 21 17:12:19 2001 |
| MD5 Checksum: | e3fe345fa59e5f5835a785154ce25880 |
|
| /// File Name: |
ippersonality-20020427-2.4.18.tar.g..> |
Description:
|
The IP Personality project is a patch to Linux 2.4 kernels that adds netfilter features: it enables the emulation of other OSes at network level, thus fooling remote OS detection tools such as nmap that rely on network fingerprinting. The characteristics that can be changed are TCP Initial Sequence Number (ISN), TCP initial window size, TCP options (their types, values and order in the packet), IP ID numbers, answers to some pathological TCP packets, and answers to some UDP packets.
| | Author: | Gael Roualland and Jean-Marc Saffroy | | Homepage: | http://ippersonality.sourceforge.net | | Changes: | Ported to Linux 2.4.18 / iptables 1.2.2. | | File Size: | 8742 | | Last Modified: | May 27 04:41:39 2002 |
| MD5 Checksum: | 881fec3573f5810dc722bb1fd96fc970 |
|
| /// File Name: |
capabilities.9.patch |
Description:
|
Capabilities Linux kernel (2.2.9 - 2.3.4) patch for elf executables that lowers the capabilities of elf files on execution to enhance security.
| | Author: | Pavel Machek. | | File Size: | 8373 | | Last Modified: | Aug 16 20:05:19 1999 |
| MD5 Checksum: | 420fea07aca04b728f6b67b433c7d841 |
|
| /// File Name: |
rna.tar.gz |
Description:
|
RNA (Resources Not for All) is a collection of security improvements for FreeBSD 4.0-Release. Features a restricted kernel process table, restricted /proc filesystem, and restricted who/w/last.
| | Author: | Yeti | | Homepage: | ftp://ftp.eth-security.net/pub | | File Size: | 8063 | | Last Modified: | Oct 4 20:45:52 2000 |
| MD5 Checksum: | 96d3a6af33fdf84af236852660f29026 |
|
|
|
|
|