Go Back   The Scream! > COMPUTER RELATED > PC Security

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #1  
Old 01-March-2003, 22:01
Onslo's Avatar
Onslo Onslo is offline
Screamager
 
Join Date: Apr 2001
Location: Newbury, UK
Posts: 4,260
Cool Hogwash

I thought that there was already a thread that mentioned this....

Hogwash

I am sure that Sil mentioend it once....

Anyway..

What is Hogwash?
Hogwash is a packet scrubber (sometimes called a signature based firewall) based on Snort (www.snort.org). It is designed to live inline with the network feed and drop malicious packets.
Hogwash is built on top of layer 2 and is designed to be invisible. It runs without an IP stack loaded. I run Hogwash on a Linux box without IP support compiled into the kernel.

The rules language should be familiar to anyone who has run Snort in the past.

Hogwash is lightweight. It is designed to run on old hardware and embedded systems. I'm currently trying to get some PC-104 hardware to run it on. It scales nicely up to 100mbs so it can be plugged into a large pipe, and it is lightwieght enough to plug in front of a single machine with special needs.
Sounds really kewl and I am certain that it would help eliminate the number of IIS attacks that are logged in my Apache access/error logs

Might give it a whirl soon

The current version as of this date is V0.4-Pre1.

'Slo
__________________
Reply With Quote
 

Tags
None

Thread Tools
Display Modes

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT +1. The time now is 02:30.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright ©1999-2009 The Scream!